Data processing
How Edumia handles institution data in the platform, and what an institution can expect from us as its processor.
The roles, and what this website has to do with it
For student and staff data held in the platform, the institution is the data controller and Edumia acts as its data processor: the institution decides what is collected and why, and Edumia stores and processes it on the institution's instructions. This website plays no part in that relationship — it holds no institutional data and is not connected to the platform's databases. An institution is only asked to agree to processing terms inside the platform, where the relationship actually exists.
Multi-tenancy, stated plainly
The platform is multi-tenant: each institution's data is held in its own tenant, and one institution cannot see another's records through normal use of the product. This is a description of how the platform is built, not a substitute for a security commitment — the auditable commitments belong in the sections below.
Security measures and certification not drafted
Placeholder, pending legal review. This clause must cover:
The specific technical and organisational measures to be committed to — encryption at rest and in transit, access control, backup frequency and restoration, logging, staff confidentiality, and whether Edumia holds or is pursuing ISO 27001 or SOC 2. Institutions in the Gulf will ask for this list in writing; vague assurances will not clear procurement.
Sub-processors and data location not drafted
Placeholder, pending legal review. This clause must cover:
The hosting and infrastructure providers, where institutions' data is physically held, and the notice period and objection right if a sub-processor changes. If data is held outside India or the Gulf, the transfer basis needs to be stated. Any published data-residency claim in the marketing pages must match this section exactly.
Breach notification not drafted
Placeholder, pending legal review. This clause must cover:
How quickly an institution is told about a personal-data breach, through what channel, and in what detail. The window is a commitment Edumia can be held to, and it interacts with the institution's own reporting deadline under the DPDP Act, so it should be set with that deadline in mind rather than chosen for convenience.
On termination: return and deletion not drafted
Placeholder, pending legal review. This clause must cover:
What an institution receives when it leaves — export format, the window in which data remains retrievable, and the point at which it is destroyed, including backups. Exit terms are read closely in education procurement, and an institution that cannot leave cleanly will not sign.
Questions about this document: care@edumia.net
Also Privacy notice · Terms of use