Privacy Policy
How Booraverse Schools handles personal data across our website, dashboard, portals, and admission forms.
This document is being finalised and is subject to review. If you have any questions in the meantime, email privacy@booraverse.com.
Our two roles — please read this first
The service is used by schools, which gives us two roles. We are the controller for data about our own website visitors and the people who hold school staff accounts with us, and for our billing and support records. We are a processor for the data a school enters or collects about its pupils and their families — for that data the school is the controller, and we process it only on the school’s documented instructions under a Data Processing Agreement.
If you are a parent, guardian, or pupilwith a question about a child’s data, your school is the first point of contact. We will support the school in answering you and, where the law requires, will respond to you directly.
Data we collect and process
As controller: basic log and device data from website visitors; anything you send us through a contact or demo form; and, for school account holders, name, email, phone, role, the school you belong to, authentication data, and how you use the dashboard. We also keep the records needed for billing and support. (The service records fees offline and does not itself take card or bank payments.)
As processor, on a school’s behalf: pupil details (name, date of birth, class, roll and admission numbers, a platform identifier, photograph, address); guardian and emergency contacts; academic and operational records (attendance, marks, activities, transport, fees and receipts, announcements, concerns); parental approvals and consent records; and, only where a school explicitly opts in for emergency care, blood group — which we treat as sensitive health data.
Children’s data
Most people whose data flows through the service are children, and the service is built for it. Where a child’s data is collected through a public admission form, the form shows a notice and will not submit unless a parent or guardian agrees, and that agreement is recorded. We do not profile children for advertising and we do not sell personal data. Additional rules apply depending on where you are — India’s DPDP Act, GDPR/UK-GDPR child-consent rules, and the US COPPA — and the school, as controller, is responsible for meeting them.
Sensitive data
Blood group is health data (special category under GDPR Article 9; sensitive personal data under the DPDP Act). The service does not collect it by default — a school must deliberately opt in, on the understanding that it is for emergency care only, before the field can be recorded.
AI features and Anthropic
Some optional features use an AI model from Anthropicto draft notices, generate question papers, and produce student insights. When a school enables these, the text to be drafted or translated, and — for insights — a pupil’s subject averages and attendance percentages (no name is sent for insights), are sent to Anthropic, which processes them in the United States. AI output is a suggestion, not a decision: insights are for guidance only, and drafts and papers are unverified drafts a person must review. The service does not make automated decisions with legal or similarly significant effects about a person.
How data is shared
We share personal data only with the school it belongs to and its authorised staff; the sub-processorswho help us run the service; and others where we are required by law or to protect rights and safety, or as part of a business transfer with continued protection. We do not sell personal data or share it for others’ advertising.
Sub-processors and international transfers
We use the sub-processors listed on our sub-processors page. Some — including Anthropic (US) and our storage/CDN provider — may process data outside your country. Where the law requires, such transfers are made under an appropriate safeguard.
Retention
We keep our controller data for as long as the account is active and as long as needed for the purposes above or to meet legal obligations. For data we process on a school’s behalf, retention is set by the school; on the end of a school’s contract we return or delete its data. The service also supports erasing an individual pupil’s identity on request.
Your rights
Subject to your local law, you may have the right to access, correct, or erase your data, to object to or restrict certain processing, to withdraw consent, to data portability, and to complain to a regulator. For a pupil’s or family’s data, exercise these through the school — it is the controller. For your own account or website data, contact us at privacy@booraverse.com.
Security
We use measures appropriate to the risk: each school’s data is isolated so it sees only its own; data travels encrypted; access is controlled by role; media links are signed and expiring; sign-in is rate-limited and locked after repeated failures; and we keep an audit trail of access, changes, and exports.
Data breaches
If a personal-data breach occurs we will act without undue delay to contain and assess it, notify affected schools, and support them in meeting their own notification duties (including the timelines under the DPDP Act and GDPR Articles 33–34).
Contact
Privacy enquiries: privacy@booraverse.com.
Grievance Officer (India, DPDP Act): Manju — privacy@booraverse.com.
Booraverse, #666, Ward 18, Shiv Colony, Jind, Haryana, India.
See also our Terms of Service and sub-processor list.