Privacy Policy
Effective Date: 21st May 2026
1. Scope of This Policy
This Privacy Policy applies to all users of the Teach Us application and related services (the "App & Web"), operated by ThinkMonk Edutech Private Limited ("Teach Us", "Company", "we", "us", or "our"). User categories include students, parents/guardians, faculty members, and institutional administrators.
The Applications are made available to educational institutions ("Partner Institutions") under a separate Agreement. User accounts are provisioned solely based on data provided by the Partner Institution.
This Policy does NOT apply to:
- Third-party websites or services linked from the App.
- Data processed by the Partner Institution through its own independent systems.
- Any offline or non-digital services provided by the Partner Institution.
The Company makes no representations regarding the privacy practices of Partner Institutions or any linked third parties, and assumes no liability for their data handling.
2. Roles and Data Responsibility
Under the Digital Personal Data Protection Act, 2023 ("DPDPA") and equivalent applicable frameworks, the following role designations apply:
Partner Institution — Data Fiduciary
The Partner Institution is the Data Fiduciary and is solely responsible for:
- Determining the purposes and means of personal data processing.
- Obtaining all required consents and maintaining a lawful basis for data collection and sharing.
- Ensuring the accuracy and legality of all data submitted to the App.
Teach Us — Data Processor / Service Provider
The Company acts exclusively as a Data Processor, processing institutional and personal data only on documented instructions from the Partner Institution and only to the extent necessary to deliver the App's contracted services.
The Company bears no independent liability for:
- Data collected by the Partner Institution before upload to the App.
- Unlawful processing instructions issued by the Partner Institution.
- Any Partner Institution's failure to obtain lawful consents or authorisations from data subjects.
Partner Institutions are required to execute a Memorandum of Understanding ("MoU")/Proposal with the Company before App deployment. In the event of any conflict between this Policy and an executed MoU/Proposal, the MoU/Proposal shall prevail with respect to institutional data flows.
3. Personal Data We Process
The Company processes only such institutional and personal data as Partner Institutions provide or direct, pursuant to the executed MoU/Proposal. All personal data received by the Company has been collected, verified, and authorised for transmission by the Partner Institution prior to upload. The Company does not collect personal data directly from individual users.
A. Data Received from Partner Institutions
The data transmitted by the Partner Institution and subsequently processed by the Company may include:
Identity Information: Name, government-issued identifiers (as supplied by the institution), educational information, institution affiliation, and role designation (Students, Parent/Guardian, Faculty, Admin).
Contact Information: Email address and contact number.
Academic Information: Attendance records, grades and academic performance, notes, notices, syllabus, achievements, user feedback, class schedules, assignments, and related academic activities.
B. Data Generated Through App Operation
The Company also generates and processes the following data as a result of the App's operation and delivery of contracted services:
Communication Data: Notifications, institutional announcements, and messages sent through the platform.
Technical / Device Information: Device model name, operating system name and version, device type, crash reports, and diagnostic data collected automatically upon App use.
The Company does not independently verify the accuracy of data provided by Partner Institutions and is not responsible for inaccuracies in data so supplied. The Company does not intentionally collect personal data beyond what is required to provide the Application's contracted services.
4. Purpose of Processing
Personal data is processed solely for the following specified purposes:
- Provisioning and operating user accounts on the App.
- Managing academic records and institutional administrative workflows as directed by the Partner Institution.
- Delivering authorised institutional communications and notifications.
- Maintaining system integrity, security, and misuse prevention.
- Diagnosing technical errors and improving App performance and reliability.
- Complying with applicable legal obligations and regulatory requirements.
The Company will not process personal data for any purpose incompatible with the above without prior written instruction from the Partner Institution, or as required by applicable law. The Company does not use personal data for profiling, behavioural advertising, or any commercial purpose unrelated to the operation of the App.
5. Legal Basis for Processing
The Company relies on the following lawful bases for processing personal data, in order of priority:
- Documented instructions from the Partner Institution in its capacity as Data Fiduciary, as documented in the executed MoU/Proposal or subsequent written directives issued thereunder.
- Performance of the MoU/Proposal entered into with the Partner Institution.
- Legitimate interests of the Company in operating, securing, and improving the App, to the extent not overridden by data subject rights.
- Compliance with applicable legal obligations, including CERT-In Directions 2022, court orders, and regulatory requirements.
The Partner Institution is contractually obligated to ensure all required consents, authorisations, or other lawful bases are in place before transmitting any personal data to the Company.
6. Third-Party Service Providers and Sub-Processors
The Company may engage third-party sub-processors solely to facilitate the App's operation. All sub-processors are contractually bound to:
- Process data only on the Company's documented instructions.
- Implement technical and organisational security measures no less protective than those of the Company.
- Not use personal data for their own independent commercial purposes.
Categories of sub-processors currently engaged include:
- Cloud Infrastructure and Storage: secure data hosting, redundancy, and backup services.
- Analytics and Diagnostics: performance monitoring and crash reporting.
- Communication Services: transactional emails, SMS notifications, and OTP delivery.
- Payment Processors: where applicable, for fee collection services.
A current list of named sub-processors is available to Partner Institutions upon written request. The Company reserves the right to update its list of sub-processors.
The Company does not sell, rent, or trade personal data to any third party for advertising or other commercial purposes.
7. International Data Transfers
Where personal data is processed or stored outside India, the Company shall ensure such transfers comply with applicable cross-border transfer requirements under DPDPA 2023 and any rules notified by the Central Government. Sub-processors located outside India are bound by contractual clauses providing protections equivalent to those required under Indian law.
8. Data Security
The Company implements commercially reasonable technical and organisational security measures, including:
- Encryption of data in transit and at rest using industry-standard protocols.
- Role-based access controls.
- Regular vulnerability assessments and penetration testing of applications and production infrastructure.
- Incident response procedures aligned with CERT-In Directions 2022.
- Restricted administrative access on a need-to-know basis.
In the event of a confirmed personal data breach affecting the App, the Company shall notify affected Partner Institution(s), becoming aware of the breach, to the extent legally permissible and practicable. Notifications to the Data Protection Board of India and/or CERT-In will be made in accordance with applicable mandatory reporting timelines (including the 6-hour reporting window under CERT-In Directions 2022 for applicable incident types).
SECURITY DISCLAIMER: NO DIGITAL SYSTEM CAN GUARANTEE ABSOLUTE SECURITY. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE COMPANY DISCLAIMS ALL LIABILITY FOR SECURITY INCIDENTS ARISING FROM VULNERABILITIES OUTSIDE THE COMPANY'S REASONABLE CONTROL, INCLUDING DEVICE-LEVEL COMPROMISES, CREDENTIAL THEFT, AND PARTNER INSTITUTION NETWORK BREACHES.
9. Data Retention and Deletion
The Company retains personal data for the duration of the active MoU/Proposal with the Partner Institution, plus a post-termination retention period not exceeding 6 months, unless a shorter period is specified in the applicable Data termination policy (as maintained by the Company and made available to Partner Institutions upon request) or required by law.
Academic records subject to statutory minimum retention requirements will be retained for the minimum period required under such law.
Upon expiry of the applicable retention period, personal data will be securely deleted or irreversibly anonymised. Aggregated and fully anonymised data — from which individual identification is not reasonably possible — may be retained indefinitely for operational analytics and product improvement purposes.
10. User Rights
Subject to applicable law and the conditions set out herein, data subjects may have the following rights with respect to their data:
- Right to Access: The right to obtain confirmation of whether personal data is being processed and a summary of such data.
- Right to Correction: The right to correction of inaccurate or incomplete personal data.
- Right to Erasure: The right to request deletion of personal data where it is no longer necessary for the purpose for which it was collected, subject to applicable legal retention obligations.
- Right to Grievance Redressal: The right to have grievances addressed by the Company's designated Grievance Officer within the timelines specified in Clause 15.
Because the App operates under institutional control, the Partner Institution is the primary point of contact for most data-related requests. Users should direct requests to their respective institution. The Company will act on erasure, correction, or access instructions received from the Partner Institution.
The Company reserves the right to decline requests that:
- are repetitive or manifestly unfounded;
- would compromise the privacy or rights of other individuals;
- would conflict with a legal or regulatory obligation; or
- fall outside the scope of data processed by the Company.
11. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:
THE COMPANY'S TOTAL AGGREGATE LIABILITY TO ANY PARTNER INSTITUTION OR USER ARISING OUT OF OR RELATED TO THIS POLICY OR THE PROCESSING OF PERSONAL DATA SHALL NOT EXCEED THE TOTAL FEES PAID BY THE RELEVANT PARTNER INSTITUTION TO THE COMPANY IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
THE COMPANY SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING LOSS OF DATA, LOSS OF REVENUE, LOSS OF PROFITS, OR LOSS OF BUSINESS OPPORTUNITY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
THE COMPANY SHALL NOT BE LIABLE FOR ANY PROCESSING PERFORMED IN GOOD FAITH ON INSTRUCTIONS ISSUED BY THE PARTNER INSTITUTION THAT SUBSEQUENTLY PROVE TO BE UNLAWFUL OR UNAUTHORIZED.
Nothing in this clause limits liability that cannot lawfully be excluded or capped under mandatory applicable law.
12. Indemnification
Each Partner Institution agrees to indemnify, defend, and hold harmless the Company and its employees from and against any claims, regulatory penalties, losses, damages, and expenses (including reasonable legal fees) arising from or related to:
- The Partner Institution's failure to obtain required consents or to maintain a lawful basis for data collection and sharing.
- Inaccurate, unlawful, or unauthorised personal data submitted to the Company by the Partner Institution.
- The Partner Institution's breach of the executed MoU/Proposal, or any applicable data protection law.
- Any claim by a data subject arising from the Partner Institution's own data practices.
13. Changes to This Privacy Policy
The Company reserves the right to modify this Policy at any time to reflect changes in applicable law, business operations, security practices, or service offerings.
Material changes will be notified to Partner Institutions at least 30 days before the effective date, via registered email address on record and/or in-App notification.
Non-material changes (including corrections, clarifications, and contact information updates) take effect upon posting, without advance notice.
If a Partner Institution objects to a material change, it must notify the Company in writing within the 30-day notice period. Failure to do so constitutes acceptance. Continued use of the App by any user after the stated effective date of any updated Policy constitutes binding acceptance of the revised terms.
14. Governing Law and Dispute Resolution
This Policy is governed by and construed in accordance with the laws of India, without regard to its conflict of law principles.
Any dispute, controversy, or claim arising out of or in connection with this Policy or the processing of personal data shall be resolved as follows:
Step 1 — Negotiation: The parties shall first attempt resolution through good-faith negotiations for a period of 30 days from written notice of the dispute.
Step 2 — Arbitration: If unresolved, the dispute shall be referred to binding arbitration under the Arbitration and Conciliation Act, 1996, before a sole arbitrator mutually agreed upon by the parties. The seat and venue of arbitration shall be Mumbai, Maharashtra, India.
Step 3 — Interim Relief: Notwithstanding the above, the courts of Mumbai, Maharashtra, India shall have exclusive jurisdiction to grant interim or injunctive relief pending the outcome of arbitration.
15. Grievance Officer and Contact Information
In accordance with the Digital Personal Data Protection Act, 2023, the Company has designated a Grievance Officer to address privacy-related queries, access requests, and data complaints:
| Organization | ThinkMonk Edutech Private Limited |
|---|---|
| Grievance Officer | Chintan Vyas |
| support@teachusapp.com | |
| Response Timeline | 30 business days from receipt of written complaint |
BY INSTALLING, ACCESSING, OR USING THE TEACH US APPLICATION, YOU CONFIRM THAT YOU HAVE READ, UNDERSTOOD, AND AGREED TO THIS PRIVACY POLICY IN ITS ENTIRETY. IF YOU DO NOT AGREE, YOU MUST IMMEDIATELY DISCONTINUE USE OF THE APPLICATION. CONTINUED USE AFTER ANY POLICY UPDATE CONSTITUTES BINDING ACCEPTANCE OF THE REVISED TERMS.