Legal
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between your institute (“you”, the data fiduciary) and Mohamed Jakkariya R (Sole proprietor, trading as Instione) (“Instione”, “we”, the data processor). It applies whenever we process personal data on your behalf in the Instione app, and it is written to meet the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), the Digital Personal Data Protection Rules, 2025, and the Information Technology Act, 2000 and its rules.
Words such as “personal data”, “data principal”, “data fiduciary”, “data processor” and “personal data breach” have the meanings given in the DPDP Act. If this DPA conflicts with the Terms on how institute personal data is handled, this DPA wins.
Scope and roles
You decide why and how your institute’s personal data is processed; you are the data fiduciary. We process it only to provide Instione to you; we are your data processor. Our own data — such as your administrators’ account details, security logs and product analytics — is covered by our Privacy Policy, where we act as data fiduciary.
Details of the processing
- Subject matter and purpose: hosting and operating the Instione app so that your institute can manage its students, staff, courses, batches, enrolments, enquiries, fees and notifications.
- Nature of processing: collection through the app and imports, storage, organisation, retrieval, display, calculation (for example, fee balances), export, sending emails you trigger, backup and deletion.
- Duration: for as long as your subscription is active, and then until deletion as set out in Deletion or return at the end.
- Data principals: your students and prospective students (enquiries), their parents or guardians, and your staff and instructors.
- Categories of personal data: names, contact details (phone, email, address), dates of birth, gender, photographs, emergency contacts, course and batch enrolments, enquiry history and notes, and fee records (charges, receipts, refunds and credit notes). We do not require, and you should not upload, bank account numbers, card numbers, passwords of other services, health or biometric data.
Processing only on your documented instructions
We process your institute’s personal data only on your documented instructions. These Terms and this DPA, and the way you configure and use the app (for example, creating a student, importing a file, or sending a notification), are your instructions. We will not process the data for any other purpose — including our own marketing, advertising or profiling — unless Indian law requires it, in which case we will tell you first unless the law forbids that. If we believe an instruction breaks the DPDP Act or other law, we will tell you and may decline to follow it.
Your responsibilities
As data fiduciary, you are responsible for:
- having a lawful basis (consent or a legitimate use under the DPDP Act) for all personal data you put into Instione, and giving each data principal the notice the DPDP Act requires;
- making sure the data is accurate and complete when you use it to make decisions about people;
- responding to data principals who exercise their rights, and running your own grievance process;
- deciding how long to keep records, and deleting or exporting them when you no longer need them.
Children’s data
Many institutes teach people under 18, who are children under the DPDP Act. You must obtain verifiable consent from a child’s parent or lawful guardian before you record the child’s personal data, as the DPDP Act and Rule 10 of the DPDP Rules require, and keep a record of that consent. For a person with a disability who has a lawful guardian, you must obtain the guardian’s verifiable consent.
On our side, we commit to:
- process children’s personal data only on your instructions and only to provide the app;
- not undertake tracking or behavioural monitoring of children, and not direct targeted advertising at children;
- not process children’s data in any way likely to harm a child’s well-being;
- not use children’s data in our product analytics, which covers only signed-in institute staff.
Confidentiality
Everyone we authorise to access your institute’s personal data is bound by confidentiality obligations and accesses it only when needed — to support you at your request, to investigate a problem, or to keep the service secure.
Security measures
We maintain reasonable security measures appropriate to the risk, including:
- encryption of data in transit (HTTPS/TLS) and at rest (by our infrastructure providers);
- role-based access control enforced on our servers for every request, with each record scoped to an institute and branch, and database row-level security as a second layer of isolation;
- passwords stored only as salted hashes; secure, script-inaccessible session cookies with cross-site request forgery protection;
- private file storage, with files served only through time-limited signed links;
- service keys and secrets kept only on our servers; production access limited to authorised people;
- logging of access and changes, with logs kept for at least one year so that incidents can be detected and investigated, as the DPDP Rules require;
- backups managed by our database provider, and a documented incident-response process.
We review these measures as the service grows. More detail is on our Security page.
Sub-processors
You authorise us to use the sub-processors that process your institute’s personal data: Cloudflare (network and hosting protection), Render (app hosting and database), Supabase (file storage), Resend (email) and PostHog (product analytics about signed-in staff; session replay is turned off in the app and no record contents are captured). Our full list, which also covers services we use only for our own website — such as Cal ID for demo booking, which never receives your institute’s records — is on our Sub-processors page. Each sub-processor is bound by a written contract with substantially similar data-protection obligations, and we remain responsible to you for their work.
Change notice. Before we add or replace a sub-processor that will process your institute’s personal data, we will update the Sub-processors page and tell your account’s administrators by email at least 30 days in advance. You may object on reasonable data protection grounds within that period by writing to privacy@instione.com. We will then work with you on a solution; if we cannot find one, you may end the service and export your data before the change takes effect. In an emergency (for example, a provider failure), we may make a change at shorter notice and will tell you as soon as possible.
Personal data breaches
If we become aware of a personal data breach affecting your institute’s personal data, we will notify you without undue delay, and in any event within 48 hours — well within the 72 hours you have under the DPDP Rules to send a detailed report to the Data Protection Board of India. Our notice will describe, as far as we know at the time, what happened and when, the data and people affected, the likely consequences, what we have done to contain it, and a contact for further information. We will update you as we learn more.
We will help you meet your duties to inform the Data Protection Board and each affected data principal, and we will report to CERT-In where Indian law requires us to. We will not notify your data principals directly unless you ask us to or the law requires it.
Assistance with data principal requests
If a data principal asks you to access, correct, complete, update or erase their personal data, to withdraw consent, or to nominate another person, you can usually do it yourself in the app. Where you cannot, we will help you respond, promptly and without charge. If a data principal contacts us directly about data we hold for you, we will pass the request to you without undue delay and will not respond to it ourselves except on your instructions.
Other assistance and information
We will give you the information you reasonably need to show that you comply with the DPDP Act for data we process for you, and will answer reasonable written questions about our security and processing. If you are notified as a Significant Data Fiduciary, we will reasonably help with your data protection impact assessments and audits.
Transfers
Your institute’s database is stored in Singapore and uploaded files are stored in India (Mumbai). Some processing therefore takes place outside India, where our sub-processors operate — in Singapore (app hosting and database) and the United States (email and product analytics). We will not transfer personal data to any country that the Government of India restricts by notification under section 16 of the DPDP Act.
Deletion or return at the end
When your subscription ends, you have 30 days to export your data (except where the law prohibits it) in a machine-readable format (such as CSV), and we will help you do so. After that window we delete your institute’s personal data from our live systems within a further 30 days, and it is removed from backups as they are overwritten on our database provider’s rolling schedule. You can ask us instead to return the data to you and then delete it. We may keep data only where Indian law requires us to, and then only for that purpose and for as long as the law requires. On request, we will confirm deletion in writing.
You can also ask us to delete specific records, or all of your data, at any time while your subscription is active.
Liability
Each party’s liability under this DPA is subject to the limitation of liability in the Terms of Service, except where the law does not allow it to be limited.
Contact
Questions about this DPA or data protection: privacy@instione.com. Breach reports and urgent security matters: hello@instione.com.