PRIVACY POLICY
Effective Date: 16 July 2026
Last Updated: 16 July 2026
This Privacy Policy ("Policy") governs the collection, processing, storage, use, disclosure, and protection of personal data by Grid Cohort ("Company," "we," "our," or "us") in our capacity as a Data Fiduciary and/or Data Processor, as applicable, in strict compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 ("IT Act"), and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("IT Rules").
This Policy applies to all Users of the Cohort Educational ERP Suite, including the Cohort Workspace, Cohort Student & Parent, and Cohort SaaS applications, all associated web portals, and all Applicants who submit personal data through Tenant-operated public portals (collectively, the "Software" or "Platform").
Where Grid Cohort processes personal data on behalf of a Tenant (as a Data Processor), the Tenant's own privacy notice and institutional data processing policies govern the processing of such personal data. This Policy applies to Grid Cohort's own processing activities in its capacity as a Data Fiduciary.
1. CATEGORIES OF PERSONAL DATA COLLECTED
1.1. We collect and process the following categories of personal data, strictly limited to what is necessary for the legitimate purpose of administering educational and institutional operations:
(a) Identity Data: Full name, date of birth, gender, photograph, government-issued identification numbers (where required by the Tenant for institutional records).
(b) Contact Data: Email address, telephone number, residential address.
(c) Authentication Data: Encrypted password hashes, session tokens, push notification device tokens, login timestamps, and IP address metadata.
(d) Institutional Data: Role designation, department, class, section, academic year, campus affiliation, employment or enrolment records.
(e) Attendance and Operational Data: Check-in/check-out timestamps, attendance records, leave applications and approvals, timetable allocations.
(f) Financial Data: Fee structures, payment records, transaction identifiers, Razorpay payment reference numbers. All financial data is stored in the smallest currency unit (paise) for INR compliance.
(g) Communication Data: Announcements, messages, and notifications sent or received through the Platform. Audio calls conducted through the Platform are peer-to-peer and are NOT recorded or stored by Grid Cohort.
(h) Application Data: Admission applications, career applications, enquiry forms, and all associated documents and attachments, submitted by Applicants through Tenant-operated public portals.
(i) Device and Technical Data: Device identifiers, operating system version, application version, crash reports, and anonymised performance analytics collected solely for service reliability and improvement.
(j) Location Data: GPS coordinates and timestamped location records of transport personnel (drivers, chaperones) during active school transport trips, collected through the Cohort Workspace application's Transport Features. Location data is collected solely for the purpose of enabling real-time bus tracking and parent notification, and is retained in the Tenant's transport audit log.
(k) Push Notification Token Data: Expo push notification tokens associated with your device, collected for the purpose of delivering institutional notifications (such as leave approvals, attendance alerts, and transport notifications) to your device. These tokens are stored in the Tenant Database and transmitted to Expo's push notification service for delivery.
1.2. Audio Call Data: Audio calls conducted through the Platform's peer-to-peer WebRTC calling feature are NOT recorded, intercepted, or stored by Grid Cohort or the Platform. Grid Cohort processes only the call signalling metadata (caller identifier, receiver identifier, session identifier, and connection timestamps) necessary to establish and log the call for audit purposes.
1.3. Camera and QR Data: Access to the device camera is used solely for QR code scanning at transport boarding/alighting points. No images, video frames, or visual data captured through the camera are retained, transmitted, or stored by Grid Cohort or the Platform.
1.4. We do not collect biometric data (including fingerprints, facial recognition data, iris scans, or voiceprints), caste information, political opinions, religious beliefs, sexual orientation, trade union membership, or genetic data, unless explicitly required by the Tenant for lawful institutional compliance, in which case such collection shall be subject to heightened consent requirements under the DPDP Act.
1.5. We do not engage in behavioural tracking, interest profiling, cross-site tracking, or targeted advertising of any User, including students, parents, and staff.
2. LEGAL BASIS FOR PROCESSING
2.1. We process personal data under the following lawful bases as prescribed by the DPDP Act, 2023:
(a) Consent: Where you have given clear, informed, and unambiguous consent to the processing of your personal data for one or more specific purposes.
(b) Legitimate Use: Where processing is necessary for the performance of obligations under a contractual arrangement to which you are a party, or for compliance with any applicable law, or for the performance of any function under any law for the time being in force in India.
(c) Compliance with Legal Obligations: Where processing is necessary for compliance with any judgment, order, or decree of a court or tribunal, or any directive issued by a statutory authority.
3. CONSENT MECHANISM AND DATA PRINCIPAL RIGHTS
3.1. Consent: By creating an account, logging in, or otherwise using the Software, you provide your free, specific, informed, and unambiguous consent to the collection and processing of your personal data as described in this Policy. Consent for specific data processing activities (including location tracking) may be sought separately through Platform prompts.
3.2. Rights of Data Principals: In accordance with the DPDP Act, 2023, you possess the following rights:
(a) Right to Access: You may request confirmation as to whether your personal data is being processed and, where applicable, access to such data and the processing activities undertaken.
(b) Right to Correction: You may request the correction or completion of inaccurate or incomplete personal data. Certain corrections may be subject to institutional verification by the Tenant.
(c) Right to Erasure: You may request the erasure of your personal data. However, due to the nature of institutional administrative records, specific erasure requests may be subject to:
(i) statutory and regulatory retention mandates applicable to educational institutions;
(ii) requirements of immutable Audit Logs maintained for legal compliance under Section 65B of the Indian Evidence Act, 1872;
(iii) the rights and obligations of the Tenant as an educational institution.
In such cases, data shall be processed via "Soft Deletes" (logical deletion) to maintain institutional and audit integrity, while rendering the data inaccessible for operational use.
(d) Right to Grievance Redressal: You may contact our Grievance Officer (details provided in Section 12) for any complaints or concerns regarding the processing of your personal data.
(e) Right to Nominate: You may nominate any other individual to exercise your rights under the DPDP Act in the event of your death or incapacity, as prescribed by law.
3.3. Withdrawal of Consent: You have the right to withdraw your consent at any time by contacting our Grievance Officer. Upon withdrawal of consent, Grid Cohort shall cease processing your personal data, except to the extent that continued processing is required under applicable law or by the Tenant as Data Fiduciary. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal.
4. PROCESSING OF CHILDREN'S DATA
4.1. As an Educational ERP, the Software necessarily processes the personal data of students, including individuals under the age of eighteen (18) years ("Children" or "Minors").
4.2. In strict compliance with the DPDP Act, 2023:
(a) The processing of any Child's personal data shall be undertaken only with the verifiable consent of the Child's parent or lawful guardian.
(b) The Tenant (School/Institution), in its capacity as the primary Data Fiduciary for the personal data of its students, bears the absolute legal obligation to obtain, verify, authenticate, and securely document such parental or guardian consent prior to entering any Child's data into the Software.
(c) Grid Cohort acts as a Data Processor with respect to Children's data and shall process such data solely on the instructions of and for the purposes specified by the Tenant.
(d) Grid Cohort is fully indemnified against any claim, liability, or penalty arising from the failure of any Tenant to obtain valid parental or guardian consent.
4.3. Grid Cohort strictly prohibits:
(a) Tracking, profiling, or behavioural monitoring of Children;
(b) Targeted advertising directed at Children;
(c) Processing of Children's data in any manner that may cause demonstrable harm to the Child;
(d) Any processing of Children's data that is not reasonably necessary for the provision of educational ERP services.
5. PROCESSING OF THIRD-PARTY APPLICANT DATA
5.1. Tenants may operate public-facing admissions and careers portals through the Platform. Individuals who submit applications through these portals ("Applicants") are not registered Users of the Platform but provide personal data directly to the Tenant through Grid Cohort's infrastructure.
5.2. With respect to Applicant data, Grid Cohort acts solely as a Data Processor processing data on behalf of the Tenant (Data Fiduciary). The Tenant is responsible for:
(a) obtaining valid consent from Applicants at the point of data collection;
(b) providing Applicants with a compliant privacy notice;
(c) ensuring Applicant data is retained only for as long as lawfully necessary;
(d) honouring Applicant data rights requests in a timely manner.
5.3. Applicants who wish to exercise their data rights (including access, correction, erasure, or withdrawal of consent) in respect of data submitted through a Tenant's portal should contact the relevant Tenant directly. Grid Cohort will cooperate with lawful requests from Tenants to action such requests.
6. LOCATION DATA PROCESSING
6.1. The Cohort Workspace application collects GPS location data from transport personnel (drivers and chaperones) during active school transport trips. This location data is:
(a) collected only while the user has an active transport trip open within the application;
(b) transmitted to the Tenant Database in real-time to enable the live bus tracking feature for parents and school administrators;
(c) retained in the Tenant's transport audit log as a historical record of the trip;
(d) not used for any purpose other than school transport management and parent notification.
6.2. Grid Cohort does not aggregate, analyse, or process location data across Tenants and does not use location data for commercial or profiling purposes.
6.3. Collection of background location data is conditional upon the device user granting background location permission through the device's operating system. Such permission may be revoked at any time through the device's settings, which will disable the active transport tracking feature.
7. AUDIO CALL DATA
7.1. The Platform provides a peer-to-peer WebRTC audio calling feature between parents and school staff. Grid Cohort's involvement in this feature is limited to providing the signalling infrastructure (via Supabase Realtime) to establish the peer-to-peer connection.
7.2. Audio call content (the actual voice communication) is transmitted directly between the two parties' devices using peer-to-peer WebRTC technology and is NOT routed through, recorded, stored, or accessible to Grid Cohort's servers at any point.
7.3. Grid Cohort processes only the following call metadata for audit log purposes: caller User ID, receiver User ID, call session ID, call initiation timestamp, and call termination timestamp.
8. PUSH NOTIFICATION TOKENS
8.1. The Platform collects and stores Expo push notification tokens from User devices. These tokens are necessary to deliver push notifications (such as attendance alerts, leave approvals, transport notifications, and fee reminders) to your device.
8.2. Push notification tokens are transmitted to Expo Push Notification Service (a service provided by Expo, Inc., a United States company) for the purpose of delivering notifications to your device. Expo's handling of push notification tokens is subject to Expo's own privacy policy.
8.3. Push notification tokens are stored in the Tenant Database and are deleted upon User account deactivation or upon the User unregistering the device from the Platform.
9. DATA STORAGE, RESIDENCY, AND SECURITY
9.1. Data Residency: All primary data, including personal data, institutional records, documents, and backup data, is stored on servers located in Mumbai, India (Amazon Web Services ap-south-1 region). Please refer to our Data Residency Notice for detailed information.
9.2. Decentralised Architecture: Each Tenant's personal data is stored in a dedicated, provisioned Tenant Database, logically isolated from all other Tenants. Grid Cohort's Central Database stores only tenant routing metadata and does not contain User personal data beyond that necessary for authentication routing.
9.3. Multi-Tenant Data Isolation: All personal data is strictly compartmentalised through database-level Row Level Security (RLS) mechanisms and scope-restricted access controls, ensuring absolute isolation between Tenants, Campuses, and Users.
9.4. Storage Security:
(a) All data is encrypted in transit using industry-standard TLS 1.2 or higher.
(b) All documents, files, and attachments are stored in scope-restricted, access-controlled storage buckets with RLS enforcement, partitioned by tenant.
(c) Authentication credentials are cryptographically hashed and salted; Grid Cohort does not store plaintext passwords.
(d) Grid Cohort implements reasonable security practices and procedures commensurate with the sensitivity of the data processed, as required under Rule 8 of the IT Rules, 2011.
9.5. Limitation of Security Liability: Whilst Grid Cohort implements commercially reasonable security measures, Grid Cohort shall not be held liable for data breaches, unauthorised access, or data loss resulting from:
(a) compromised User credentials due to User negligence or phishing attacks;
(b) vulnerabilities in User devices, networks, or endpoints;
(c) force majeure events, including but not limited to cyberattacks, state-sponsored intrusions, zero-day exploits, or infrastructure failures at the cloud service provider level;
(d) acts or omissions of the Tenant, its administrators, or its authorised personnel;
(e) vulnerabilities in third-party open-source software components incorporated in the Platform.
10. DATA RETENTION
10.1. Personal data shall be retained only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law, whichever is longer.
10.2. Upon expiry of the retention period, or upon a valid erasure request (subject to the exceptions in Section 3.2(c)), personal data shall be erased or anonymised in accordance with the DPDP Act, 2023.
10.3. Immutable Audit Logs shall be retained for a minimum period of eight (8) years, or such longer period as may be required by applicable law.
10.4. Financial records, including fee structures and payment records, shall be retained for a minimum period of eight (8) years for statutory compliance.
10.5. Following termination of a Tenant's Subscription, Tenant Data shall be retained for a period of thirty (30) days to enable data export, after which it may be permanently deleted. Immutable Audit Logs shall continue to be retained as specified in Section 10.3.
11. DISCLOSURE OF PERSONAL DATA
11.1. Grid Cohort shall not sell, rent, lease, or trade your personal data to any third party for commercial or marketing purposes.
11.2. Personal data may be disclosed to:
(a) the Tenant (School/Institution) of which you are a User, in its capacity as a Data Fiduciary;
(b) authorised third-party service providers and sub-processors engaged by Grid Cohort for the sole purpose of delivering and maintaining the Software, subject to appropriate data processing agreements. A list of current sub-processors is maintained in our Data Residency Notice;
(c) law enforcement authorities, regulatory bodies, or courts of competent jurisdiction, pursuant to a lawful order, summons, or directive;
(d) any party where disclosure is necessary to protect the rights, property, or safety of Grid Cohort, its Users, or the public.
11.3. In the event of a merger, acquisition, reorganisation, or sale of assets, your personal data may be transferred as part of such transaction, subject to the provisions of the DPDP Act, 2023, and with advance notice to affected Users where practicable.
12. DATA BREACH NOTIFICATION
12.1. In the event of a personal data breach affecting data held directly by Grid Cohort in its capacity as a Data Fiduciary, Grid Cohort shall notify affected Data Principals and, where required, the Data Protection Board of India ("DPBI"), in accordance with the notification timelines and requirements prescribed under the DPDP Act, 2023, and any rules issued thereunder.
12.2. Where a data breach affects data held within a Tenant Database, Grid Cohort shall notify the affected Tenant without undue delay upon becoming aware of such breach. The Tenant, as Data Fiduciary, shall be responsible for notifying affected Data Principals and the DPBI in accordance with applicable law. Grid Cohort will provide the Tenant with reasonable assistance in fulfilling these obligations.
12.3. Grid Cohort's notification obligations are conditional upon Grid Cohort becoming aware of the breach through its own monitoring or upon notification from a sub-processor. Grid Cohort does not guarantee the detection of all security incidents and shall not be liable for any harm arising from a breach that Grid Cohort was not reasonably able to detect.
13. COOKIES AND TRACKING
13.1. The mobile applications of the Software do not use browser cookies. The web-based components may use strictly necessary cookies for session management and authentication purposes only.
13.2. Grid Cohort does not employ any third-party advertising trackers, behavioural analytics, cross-site tracking technologies, or interest-based advertising systems.
13.3. Anonymised performance and crash data may be collected through the Expo/React Native framework for the sole purpose of improving application stability and performance. This data does not identify individual Users.
14. CROSS-BORDER DATA TRANSFERS
14.1. Grid Cohort stores and processes all primary personal data within the territorial jurisdiction of India, on servers located in Mumbai, Maharashtra, India.
14.2. The following limited cross-border data flows occur in the ordinary course of Platform operation:
(a) Push notification delivery: Expo push notification tokens and notification payloads are transmitted to Expo, Inc. (United States) for delivery to User devices. Notification payloads contain limited institutional notification data (e.g., "Attendance marked" or "Leave approved") and do not contain sensitive personal data.
(b) WebRTC ICE candidates: During call setup, ICE candidate data (network connectivity information used to establish peer-to-peer connections) may transit through STUN/TURN servers that may be located outside India. This data does not constitute personal data and is ephemeral in nature.
(c) Anonymised telemetry: Anonymised crash reports and performance metrics may be processed by Expo's infrastructure outside India. Such data does not identify individual Users.
14.3. No identifiable personal data (including names, contact details, academic records, or financial records) is knowingly transferred to servers outside India for storage or operational processing purposes.
14.4. Notwithstanding the above, certain ancillary technical metadata may transit through international network infrastructure in the ordinary course of internet communication. Such metadata does not constitute a "transfer" of personal data within the meaning of the DPDP Act, 2023.
15. IMMUTABLE AUDIT LOGS
15.1. All significant interactions, transactions, and administrative actions within the Software are permanently recorded in unalterable, tamper-proof Audit Logs stored within each Tenant Database. These logs serve as an essential component of institutional governance, security monitoring, and regulatory compliance.
15.2. Audit Logs constitute electronic records under the IT Act, 2000, and may be produced as evidence in legal proceedings in accordance with Section 65B of the Indian Evidence Act, 1872.
15.3. Users shall not have the ability to modify, delete, or alter Audit Log entries.
16. GRIEVANCE OFFICER
16.1. In accordance with the provisions of the DPDP Act, 2023, and Rule 5(9) of the IT Rules, 2011, Grid Cohort has appointed a Grievance Officer who may be contacted for any complaints, concerns, or queries regarding the processing of personal data:
Name: Grievance Officer, Grid Cohort
Email: grievance@gridcohort.com
Response Time: Within seventy-two (72) hours of receipt of the complaint.
16.2. If you are not satisfied with the resolution provided by the Grievance Officer, you may escalate your complaint to the Data Protection Board of India established under the DPDP Act, 2023.
17. AMENDMENTS TO THIS POLICY
17.1. Grid Cohort reserves the right to amend, modify, or update this Privacy Policy at any time. The revised Policy shall become effective immediately upon publication within the Software, with the "Last Updated" date revised accordingly.
17.2. Continued use of the Software following any amendment shall constitute your acceptance of the revised Privacy Policy.
17.3. Where a material change to this Policy significantly impacts your rights or the processing of your personal data, Grid Cohort shall make reasonable efforts to notify you through the Software or via email.
18. GOVERNING LAW
This Policy shall be governed by and construed in accordance with the laws of India, including but not limited to the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and all rules and regulations framed thereunder. Any disputes arising under this Policy shall be subject to the exclusive jurisdiction of the courts located in Vaniyambadi, Tirupattur District, Tamil Nadu, India.