App-owned editable content

Data Processing Agreement

Last updated: July 23, 2026

This Data Processing Agreement ("DPA") is maintained by EDUNEST pvt.Ltd for schools and other organisations ("Controllers") that use EDUNEST. It describes how EDUNEST processes personal data on behalf of Controllers, and the obligations of each party.

This DPA is an app-owned document. It reflects current practices and the platform capabilities provided by Lovable Cloud. It is not a legal certification or independent audit report.

1. Parties and scope

EDUNEST pvt.Ltd acts as a Processor for the personal data that Controllers upload into EDUNEST. Controllers decide what data is collected, why it is processed, and how long it is kept. EDUNEST processes that data only on documented instructions from the Controller.

2. Categories of data processed

EDUNEST may process the following categories of personal data on behalf of Controllers:

  • School staff and teachers: name, email, phone, role, class/subject assignments, attendance and grading inputs.
  • Students: name, class/section, roll number, attendance, grades, homework, submissions, and bus-route information.
  • Parents: name, email, phone, and their linked children.
  • School administrators: name, email, phone, billing information, and account management data.
  • Demo request contacts: school name, contact name, email, phone, number of students, and message.

Controllers are responsible for ensuring they have a lawful basis to share this data with EDUNEST and that required notices or consents are in place.

3. Purposes and instructions

EDUNEST processes personal data only to:

  • Operate the school management platform and its features.
  • Deliver WhatsApp and email notifications requested by the Controller.
  • Provide security, support, and platform improvements.
  • Comply with legal obligations and this DPA.

EDUNEST will not use personal data for any purpose beyond these instructions, and will not sell, rent, or use it for advertising unrelated to the Controller's use of the platform.

4. Security measures

EDUNEST implements the following technical and organisational measures to protect personal data:

  • Encryption of data in transit using HTTPS/TLS.
  • Encrypted storage at rest through the underlying cloud infrastructure.
  • Role-based access controls and row-level security in the database.
  • Secure authentication for school users.
  • Regular backups and monitoring.
  • Access limited to staff who need it to provide support and operations.

Lovable Cloud provides the underlying platform security controls. The Controller is responsible for managing its own users, roles, and access policies within EDUNEST.

5. Subprocessors

EDUNEST uses the following subprocessors to provide the platform:

  • Lovable Cloud — cloud hosting, database, authentication, and backend infrastructure.
  • Twilio — delivery of WhatsApp messages for notifications and emergency alerts.
  • Email service provider — delivery of transactional emails from notify.edunestapp.co.in.

We will notify Controllers of any new material subprocessor through the app or by email, and provide an opportunity to object before the new subprocessor handles personal data.

6. Confidentiality

EDUNEST personnel who access personal data are bound by confidentiality obligations. Access is limited to what is necessary for service delivery, support, and legal compliance.

7. Data subject requests

Controllers are responsible for handling requests from data subjects (such as students, parents, or staff) to access, correct, delete, or restrict the processing of their personal data. EDUNEST will provide reasonable assistance, including data export or deletion features where available, to help Controllers respond to these requests.

8. Data retention and deletion

EDUNEST retains personal data for as long as the Controller's account is active, plus any period required for backups, legal obligations, or dispute resolution. Upon account termination, EDUNEST will delete or return Controller data according to the terms of service and retention policy.

9. Data breach notification

EDUNEST will notify the Controller without undue delay after becoming aware of a personal data breach that affects the Controller's data. The notice will include known details about the breach and the steps taken or proposed to address it.

10. Controller obligations

Controllers agree to:

  • Have a lawful basis for processing and sharing personal data with EDUNEST.
  • Provide required notices and obtain necessary consents.
  • Maintain accurate and up-to-date data.
  • Use EDUNEST only in compliance with applicable laws and these terms.
  • Promptly notify EDUNEST of suspected data breaches or misuse.

11. Changes and contact

We may update this DPA as our services or subprocessors change. We will post the updated version on this page with a revised "Last updated" date and notify Controllers of material changes.

For questions about this DPA or to request a signed copy, contact:

EDUNEST pvt.Ltd
Email: officialedunest@gmail.com
Phone: +91 98837 19024
Location: Bengaluru, India