1. Who we are
Chronbyte Global Solution (a duly registered business entity) provides a multi-tenant, cloud-hosted software service to schools and educational institutions. We do not sell physical hardware, CDs, or shipped goods. Contact details are published on our company website Contact page.
2. Data Controller vs. Data Processor
For student, parent, and staff records entered into the platform, the subscribing school or institution («School», «you») is the Data Fiduciary / Data Controller. The School decides what data is collected and the lawful purpose. Chronbyte acts only as a Data Processor / service provider: we store and process that data on the School's instructions to operate the cloud service. For our own marketing website leads (demo requests, contact forms), Chronbyte is the Data Fiduciary.
3. Categories of data we process
School account data: institution name, address, billing contacts, subscription plan, GST/billing identifiers. Platform data uploaded by the School: student and staff names, roll numbers, class/section, attendance, fees, academic records, parent/guardian contact details, and related operational records. Website visitors: name, mobile, email, school name from lead forms. Technical data: IP address, browser/device type, audit logs, session identifiers, and security events — retained only as needed for operations and security.
4. How we use personal data
We use data to: provide and maintain the Cloud Platform; authenticate users; deliver support and onboarding; process subscriptions and invoices; send service-related notifications; improve reliability and security; comply with law; and enable optional integrations (e.g. WhatsApp/SMS messaging) only when configured by the School. We do not sell school or student data to advertisers or data brokers.
5. Payment data — Razorpay
Online fee collections and subscription payments may be processed through authorised payment partners such as Razorpay. Chronbyte does not store full credit card numbers, CVV, or raw bank account credentials on our application servers. Payment card and banking details are handled by the payment gateway under their own privacy and security standards. We may retain transaction references, payment status, receipt metadata, and billing records required for accounting and support.
6. Multi-tenant isolation
Each School tenant is logically separated in our cloud architecture. One School cannot access another School's data through the platform. Role-based access controls apply across admin, teacher, group, and parent portals. Our security program includes tenant-scoped queries, access logging, and periodic reviews — details may evolve as the product matures.
7. Security measures and limitations
We apply industry-standard cloud security practices including encrypted transmission (HTTPS/TLS), access controls, hashed passwords, daily backups, and monitoring. No method of transmission or electronic storage is completely secure. While we work to protect personal data, we cannot guarantee absolute security against all threats. Schools should use strong admin passwords and limit staff access appropriately.
8. Data retention and deletion
We retain School platform data for the subscription term and for a reasonable period thereafter to allow export, billing reconciliation, and legal compliance. Schools may request data export or deletion subject to contractual terms and applicable law. Website lead data is retained only as long as needed for sales follow-up or legal obligations, then deleted or anonymised.
9. Data Principal rights (DPDP Act)
Data Principals (parents, staff, or other individuals) should first contact their School to exercise access, correction, erasure, or grievance rights regarding data the School controls. Chronbyte will assist the School as processor where technically feasible. For data where Chronbyte is Data Fiduciary (website leads), contact us using the details on the Contact page with subject line «Privacy request». We will respond within reasonable timelines prescribed by applicable law.
10. Cookies, analytics, and third-party links
Our company website may use cookies for language preference, session management, and (where enabled) analytics such as Google Analytics. Third-party websites linked from our site have their own policies; we are not responsible for their practices. We will update this policy if we materially change tracking technologies.
11. Cross-border processing
Data may be processed on cloud infrastructure located in India or other jurisdictions where our hosting and subprocessors operate, always subject to contractual safeguards and applicable law. Schools requiring specific data residency commitments should discuss this before subscription.
12. Changes and contact
We may update this Privacy Policy from time to time. The «Last updated» date at the top will change when we do. Material changes may be notified via the website or service communication. Questions: support/contact email listed on chronbyte.com — subject «Privacy request».