Data Processing Agreement
Last updated: July 23, 2026
This Data Processing Agreement ("DPA") is maintained by EDUNEST pvt.Ltd for schools and other organisations ("Controllers") that use EDUNEST. It describes how EDUNEST processes personal data on behalf of Controllers, and the obligations of each party.
This DPA is an app-owned document. It reflects current practices and the platform capabilities provided by Lovable Cloud. It is not a legal certification or independent audit report.
1. Parties and scope
EDUNEST pvt.Ltd acts as a Processor for the personal data that Controllers upload into EDUNEST. Controllers decide what data is collected, why it is processed, and how long it is kept. EDUNEST processes that data only on documented instructions from the Controller.
- Processor email: officialedunest@gmail.com
- Processor phone: +91 98837 19024
- Processor address: Bengaluru, India
2. Categories of data processed
EDUNEST may process the following categories of personal data on behalf of Controllers:
- School staff and teachers: name, email, phone, role, class/subject assignments, attendance and grading inputs.
- Students: name, class/section, roll number, attendance, grades, homework, submissions, and bus-route information.
- Parents: name, email, phone, and their linked children.
- School administrators: name, email, phone, billing information, and account management data.
- Demo request contacts: school name, contact name, email, phone, number of students, and message.
Controllers are responsible for ensuring they have a lawful basis to share this data with EDUNEST and that required notices or consents are in place.
3. Purposes and instructions
EDUNEST processes personal data only to:
- Operate the school management platform and its features.
- Deliver WhatsApp and email notifications requested by the Controller.
- Provide security, support, and platform improvements.
- Comply with legal obligations and this DPA.
EDUNEST will not use personal data for any purpose beyond these instructions, and will not sell, rent, or use it for advertising unrelated to the Controller's use of the platform.
4. Security measures
EDUNEST implements the following technical and organisational measures to protect personal data:
- Encryption of data in transit using HTTPS/TLS.
- Encrypted storage at rest through the underlying cloud infrastructure.
- Role-based access controls and row-level security in the database.
- Secure authentication for school users.
- Regular backups and monitoring.
- Access limited to staff who need it to provide support and operations.
Lovable Cloud provides the underlying platform security controls. The Controller is responsible for managing its own users, roles, and access policies within EDUNEST.
5. Subprocessors
EDUNEST uses the following subprocessors to provide the platform:
- Lovable Cloud — cloud hosting, database, authentication, and backend infrastructure.
- Twilio — delivery of WhatsApp messages for notifications and emergency alerts.
- Email service provider — delivery of transactional emails from notify.edunestapp.co.in.
We will notify Controllers of any new material subprocessor through the app or by email, and provide an opportunity to object before the new subprocessor handles personal data.
6. Confidentiality
EDUNEST personnel who access personal data are bound by confidentiality obligations. Access is limited to what is necessary for service delivery, support, and legal compliance.
7. Data subject requests
Controllers are responsible for handling requests from data subjects (such as students, parents, or staff) to access, correct, delete, or restrict the processing of their personal data. EDUNEST will provide reasonable assistance, including data export or deletion features where available, to help Controllers respond to these requests.
8. Data retention and deletion
EDUNEST retains personal data for as long as the Controller's account is active, plus any period required for backups, legal obligations, or dispute resolution. Upon account termination, EDUNEST will delete or return Controller data according to the terms of service and retention policy.
9. Data breach notification
EDUNEST will notify the Controller without undue delay after becoming aware of a personal data breach that affects the Controller's data. The notice will include known details about the breach and the steps taken or proposed to address it.
10. Controller obligations
Controllers agree to:
- Have a lawful basis for processing and sharing personal data with EDUNEST.
- Provide required notices and obtain necessary consents.
- Maintain accurate and up-to-date data.
- Use EDUNEST only in compliance with applicable laws and these terms.
- Promptly notify EDUNEST of suspected data breaches or misuse.
11. Changes and contact
We may update this DPA as our services or subprocessors change. We will post the updated version on this page with a revised "Last updated" date and notify Controllers of material changes.
For questions about this DPA or to request a signed copy, contact:
EDUNEST pvt.Ltd
Email: officialedunest@gmail.com
Phone: +91 98837 19024
Location: Bengaluru, India
