Privacy Policy

Two roles

When you visit klasso.online or sign up for an institute account, we decide how your data is used. We are the Data Fiduciary for it.

When an institute stores data about its students, parents and staff in Klasso, the institute decides how that data is used, and is the Data Fiduciary. We process it only on the institute's instructions, as its Data Processor. If you are a student or parent, please send requests about your data to your institute first; we will help them respond.

What we collect

Account details: the institute's name and address, and the name, email, mobile number and password (stored only as a secure hash) of each user.

Data institutes add: for example student and parent names, contact details, date of birth, photos, batch, attendance, test marks, fee records, uploaded documents and messages.

Billing: invoices and payment status. Card and UPI details are handled by the payment gateway; we never see or store full card numbers.

Technical data: IP address, browser type, and sign-in times, used for security (for example limiting repeated failed sign-ins) and to keep an audit log of changes in each institute.

Website: if analytics is turned on, Google Analytics records pages visited and buttons clicked, using cookies.

How we use it

To provide and secure the service, sign people in, send receipts, password-reset emails and the messages institutes choose to send, bill institutes for their plan, answer support requests, and meet legal duties such as tax records.

We do not sell personal data, and we do not use student data for advertising or to build profiles of students.

Who we share it with

We use a small number of service providers to run Klasso: cloud hosting and backups, Cloudflare (network security and delivery), email delivery, SMS gateways, Meta's WhatsApp Business Platform, Razorpay (payments) and, only when an institute uses AI features, an AI model provider. Each gets only the data needed for its job and is bound to protect it.

We disclose data to authorities only when Indian law requires it.

Children's data

Many students are under 18. Institutes must obtain verifiable consent from a parent or guardian before adding a child's data, as the DPDP Act requires. Klasso does not track children's behaviour or show them advertising.

Security

Each institute's data is kept separate from every other institute's. We use encrypted connections (HTTPS), hashed passwords, optional two-step verification, role-based permissions, audit logs, encrypted storage of payment gateway keys, and regular backups. No system is perfectly secure; if a breach affects your data we will tell the affected institute and the Data Protection Board of India as the law requires.

How long we keep it

We keep data while the institute's account is open. After an account closes, the institute has 30 days to request an export; we then delete its data, and backups are overwritten within a further 30 days. We keep our own invoices and tax records for as long as tax law requires (currently 8 years).

Your rights

Under the DPDP Act you can ask for a summary of your data, ask for it to be corrected or erased, withdraw consent, and name someone to act for you. For data held by an institute, contact the institute; for your own Klasso account, email hello@klasso.online. We reply within 30 days.

Cookies

Signed-in pages use one essential cookie to keep you signed in. The public website sets no cookies unless analytics is turned on, in which case Google Analytics cookies are used to count visits.

Grievance Officer

If you have a complaint about how we handle personal data, contact our Grievance Officer: Grievance Officer, TriSpark Innovate, hello@klasso.online. We acknowledge complaints within 48 hours and aim to resolve them within 30 days. If you are not satisfied, you may approach the Data Protection Board of India.

Changes

We will post any changes here and update the date above. For important changes we will also email institute owners.