Syamabala Learning Software ("we," "us," "our") operates with the understanding that your personal and academic data is among the most sensitive information that exists. This Privacy Policy outlines our binding commitment to absolute confidentiality, data minimization, and security — applied to all students, parents, guardians, and visitors who interact with our platforms, services, or personnel.
Table of Contents
Information We Collect
We collect only what is strictly necessary to deliver our services. This includes:
Identity Information
Full legal name of the student and parent/guardian, date of birth, government-issued ID numbers (where required for verification), and profile photographs (optional).
Contact Information
Email addresses, phone numbers (including WhatsApp), residential address, and emergency contact details.
Academic Data
School name and board, current grade level, standardized test scores (SAT, ACT, UCAT, MAT, STEP, JEE, etc.), past academic transcripts, Olympiad participation records, and AI diagnostic assessment results.
Admissions Data
Target universities, application essays drafts, recommendation letter content, interview preparation notes, and admissions strategy documents.
Technical Data
IP address, browser type, device information, pages visited, session duration, and interaction data with our AI diagnostic tools and portals.
Payment Data
Transaction IDs, payment timestamps, and invoice details. We do not store credit card numbers, CVV, or bank account details. All payment processing is handled by PCI-DSS compliant third-party gateways.
How We Use Your Information
Your data is used exclusively for the following purposes:
- Delivering personalized academic mentoring, Olympiad training, and admissions strategy services.
- Operating the AI Diagnostic engine and generating skill-gap analysis reports.
- Granting and managing access to the Student Portal and Parent Portal.
- Communicating session schedules, progress updates, and critical deadlines.
- Generating invoices, processing payments, and maintaining financial records as required by law.
- Improving our AI models, platform UX, and service delivery through anonymized analytics.
- Complying with legal obligations, regulatory requirements, and lawful directives from competent authorities.
We will never use your data for: unsolicited marketing to third parties, selling or renting your information to any entity, or building commercial profiles for advertising networks.
Confidentiality Commitment
Confidentiality is not a feature — it is a foundational principle of our existence. We treat every student's academic profile, admissions strategy, and personal information as strictly privileged.
Non-Disclosure to Peers
No student or parent will ever be informed about the identity, scores, targets, or progress of any other student — under any circumstance.
Mentor & Staff NDAs
Every mentor, consultant, and staff member signs a legally binding Non-Disclosure Agreement before accessing any student data. Violation results in immediate termination and legal action.
Application Material Protection
All essays, personal statements, and application content created during our engagement are the intellectual property of the student. We do not reuse, share, or archive them for any other purpose.
Results & Testimonials
Any public display of results, hall of fame entries, or success stories is published only after obtaining explicit written consent from the student and/or parent. Students can request removal at any time.
Data Sharing & Third Parties
We do not sell, rent, trade, or otherwise distribute your personal data to any third party for commercial purposes. Data is shared only in the following narrowly defined scenarios:
- ● Payment Gateways: Transaction processing through PCI-DSS certified processors (e.g., Razorpay, Stripe). Only transaction metadata is shared — never full card or bank details.
- ● Cloud Infrastructure: Data is stored on encrypted servers via certified cloud providers with SOC 2 Type II compliance. Data remains ours — the provider cannot access or use it.
- ● Communication Services: Email delivery (e.g., SendGrid, AWS SES) and messaging APIs (e.g., WhatsApp Business API) receive only the minimum data required to deliver messages.
- ● Legal Requirements: If required by a court order, government subpoena, or applicable law, we may disclose specific data to the extent legally mandated. We will, where legally permissible, notify the affected individual before such disclosure.
Data Security Measures
We implement industry-leading security controls to protect your data:
AES-256 encryption at rest. TLS 1.3 for all data in transit. End-to-end encryption for portal communications.
Role-based access with principle of least privilege. Multi-factor authentication for all staff and admin accounts.
24/7 intrusion detection, real-time anomaly alerting, and comprehensive audit logging of all data access events.
Automated daily backups with geo-redundant storage. Regular penetration testing and vulnerability assessments.
Data Retention
We retain your data for the minimum period necessary:
- Active All data is retained while the student is actively enrolled or the engagement is ongoing.
- Post-Engagement Academic records and strategy documents are retained for 3 years after the engagement ends, in case the student wishes to re-engage or requires reference documentation.
- Financial Invoice and payment records are retained for 7 years as required by applicable tax and accounting regulations.
- Deletion Upon written request after the retention period, all personally identifiable data will be permanently deleted within 30 days, except where legal retention requirements override.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Request a complete copy of all personal data we hold about you.
Request correction of any inaccurate or outdated information.
Request permanent deletion of your data, subject to legal retention obligations.
Receive your data in a structured, machine-readable format.
Object to specific processing activities, including direct marketing.
Request that we limit how we process your data in certain circumstances.
To exercise any of these rights, contact us at helpdesk@eduglobalinstitute.com. We will respond within 30 days.
Cookies & Tracking
We use minimal, purpose-driven cookies:
- ● Essential Cookies: Session management, authentication tokens, and security features. These cannot be disabled without breaking the site.
- ● Analytics Cookies: Anonymized page view and interaction data to improve our platform. No personally identifiable information is tracked.
- ● No Advertising Cookies: We do not use retargeting, behavioral advertising, or third-party ad tracking pixels.
Children's Data (Minors)
Since our services are primarily directed at students (many of whom are minors), we have elevated protections:
- Data collection from minors requires verifiable parental/guardian consent before any engagement begins.
- Minors' data receives the highest classification level in our internal security framework.
- Parents/guardians have full authority to access, correct, or request deletion of their child's data at any time.
AI & Automated Processing
Our AI Diagnostic engine processes academic performance data to generate skill-gap analyses and personalized learning path recommendations. Key points:
- ● AI processing does not make autonomous admission decisions, eligibility determinations, or evaluative judgments about any student.
- ● All AI-generated insights are advisory and are always reviewed by a human mentor before being communicated to students or parents.
- ● AI training data is fully anonymized. No student's personal identity or specific academic record is used to train models.
International Data Transfers
Given our global student base (India, USA, UK, UAE, Singapore, Australia), data may be transferred to and stored in servers located outside your country of residence. All such transfers are protected by:
- ● Standard Contractual Clauses (SCCs) or equivalent legal mechanisms where required.
- ● Encryption in transit and at rest, regardless of data location.
- ● Cloud provider agreements that guarantee data residency options and GDPR-level protections.
Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email to registered users and/or a prominent notice on our website. Continued use of our services after changes take effect constitutes acceptance of the revised policy.
Contact
For any privacy-related questions, concerns, or to exercise your data rights: