Enquire Now WhatsApp

DATA PRIVACY POLICY, PROCEDURES & STANDARD OPERATING PROCEDURES

DATA PRIVACY POLICY, PROCEDURES & STANDARD OPERATING PROCEDURES

1. Policy Statement

1. Policy Statement

Dreamtime Learning School is committed to protecting the privacy, confidentiality, and security of digital personal data belonging to enrolled online students, parents/guardians, educators, and website visitors. In alignment with the Digital Personal Data Protection Act, 2023, the school recognizes that children below 18 years of age are a vulnerable group and accords the highest level of protection to children's personal data across all online learning platforms and digital services.

2. Objectives

2. Objectives

· Lawful & Transparent Processing:Ensure lawful, fair, and transparent processing of student and parent data across digital ecosystems.

·  Robust Digital Protection:Protect students' online data, learning records, and communications from unauthorized access, breach, or misuse.

·  Parental Empowerment:Empower parents with verifiable consent controls and accessible data rights over their child's digital footprint.

·  Clear Operational SOPs:Establish clear operational procedures and Standard Operating Procedures (SOPs) for educators, technical staff, and cloud service providers.

·  Institutional Compliance:Maintain full institutional compliance with Indian data privacy regulations and benchmark standards.

3. Scope

3. Scope

This policy applies across all digital touchpoints operated by Dreamtime Learning School:

·  Online Student Data: Applies to all enrolled online students below 18 years of age across Pre-Primary, Primary, Middle, Secondary, and Senior Secondary levels.

·  Parent & Guardian Data: Applies to data collected from parents/guardians for enrollment, identity verification, fee payments, and academic progress updates.

·  School Personnel: Applies to all teaching personnel, learning coaches, technical administrators, and contractual staff.

·  Third-Party Digital Processors: Applies to EdTech vendors, Learning Management System (LMS) platforms, cloud hosts, online doubt-solving tools, and CRM partners processing data on behalf of the school.

4. Categories of Data Collected

4. Categories of Data Collected

4.1 Online Student Personal Data

4.1 Online Student Personal Data

·  Identity & Demographics: Full name, date of birth, age, grade level, student photograph, and avatar profile.

·  Academic & Learning Records: Live class attendance, assessment submissions, digital portfolio artifacts, learner-driven symposium records, novel writing drafts, and English Lab progress logs.

·  Digital Communication: Official school email communications, online doubt-resolution inquiry logs, and virtual classroom interaction records.

4.2 Parent / Guardian Personal Data

4.2 Parent / Guardian Personal Data

· Contact & Verification Details: Name, primary email address, mobile phone number, residential address, and parent identity verification credentials.

· Financial Details: Fee payment receipts, transaction reference numbers, and billing records.

4.3 Technical & Platform Data

4.3 Technical & Platform Data

·  System Access Logs: LMS user login timestamps, IP addresses, device browser parameters, session duration, and feature access logs.

5. Consent & Rights of Data Principals

5. Consent & Rights of Data Principals

5.1 Verifiable Parental Consent

5.1 Verifiable Parental Consent

Explicit, verifiable consent from an adult parent or legal guardian is mandatory before collecting or processing any child's personal data or creating a student account. Parental identity is verified through registered adult accounts, Digital Locker integration, or government-authorized identity tokens. Parents may review or withdraw consent at any time through their account dashboard or by contacting the school.

5.2 Rights of Parents and Online Students

5.2 Rights of Parents and Online Students

·  Right to Access:Parents have the right to request a summary of personal data held by the school and processing activities undertaken.

·  Right to Correction & Completion:Parents may request correction of inaccurate data or completion of incomplete student records.

·  Right to Erasure:Parents may request deletion of student data when no longer required for educational purposes or upon enrollment cancellation.

·  Right to Grievance Redressal: Parents have the right to file privacy grievances and receive timely resolution.

6. Data Protection Principles & Security Procedures

6. Data Protection Principles & Security Procedures

·  Data Minimization: Only personal data strictly necessary for online education delivery, academic evaluation, and student welfare is collected.

·  Encryption & Technical Safeguards: All student data is encrypted using AES-256 standards at rest and TLS 1.3 standards in transit across all web applications and cloud databases.

·  Role-Based Access Control: Access to student records is strictly restricted to authorized educators and staff on a need-to-know basis using Multi-Factor Authentication (MFA).

·  Log Retention: System access logs, traffic data, and transaction records are retained for a minimum of one year for security monitoring and audit compliance.

·  Prohibition of Child Tracking: The school strictly prohibits behavioral tracking, targeted advertising, or commercial profiling directed at students. Student accounts are restricted strictly to email communication and educational delivery.

7. Standard Operating Procedures (SOPs)

7. Standard Operating Procedures (SOPs)

The DPDP SOP contains the following sections

1. Data Collection & Consent: Obtain documented parental consent prior to account registration. Verify adult identity and collect only mandatory educational fields.

2. Technical Infrastructure Security: Maintain cloud backups on encrypted, password-protected servers. Conduct annual cybersecurity vulnerability audits.

3. Access Control & Usage Restrictions: Enforce role-based access rules. Record automated user logs. Strictly prohibit non-educational processing or commercial profiling.

4. Retention & Automated Erasure: Archive student academic portfolios upon graduation. Send an advance notice to parents at least 48 hours prior to complete data erasure upon account expiration.

5. Data Breach Management: In the event of a security breach, immediately contain the incident. Notify the Data Protection Board of India and affected parents without delay, detailing impact and mitigation measures.

6. Staff Training & Awareness: Conduct annual privacy training for learning coaches and IT staff. Provide parents with digital safety guidelines.

8. Accountability & Institutional Governance

8. Accountability & Institutional Governance

Dreamtime Learning School maintains a dedicated Data Protection Officer and Grievance Officer responsible for monitoring compliance, conducting periodic Data Protection Impact Assessments (DPIAs), and handling privacy inquiries.

9. Policy Review & Updates

9. Policy Review & Updates

This policy is reviewed annually or upon significant statutory updates and is published prominently on the official school website.

10. DESIGNATED DATA PROTECTION & GRIEVANCE DIRECTORY

10. DESIGNATED DATA PROTECTION & GRIEVANCE DIRECTORY

For any privacy queries, consent withdrawal, or grievance redressal, parents and users may directly contact our designated privacy officers below:

Designated Role

Contact Channels

Official Address

Grievance Officer - Online School

Plot 505, Road Number 22, Jubliee Hills, Hyderabad, Telangana - 500033

Data Protection Officer

Plot 505, Road Number 22, Jubliee Hills, Hyderabad, Telangana - 500033