Prepdha legal

Privacy Policy

This policy explains how Prepdha collects, uses, shares, stores, and protects personal data across the platform.

This Privacy Policy explains how Civilsphere Educational Services Private Limited ("Prepdha", "we", "us", or "our") collects, uses, shares, stores, and protects personal data when you use the Prepdha platform, websites, mobile and tablet apps, and any school-issued devices we provide (together, the "Platform").

Prepdha is an AI-powered learning and retention platform used by schools, teachers, students, and parents. Because most of our student users are under the age of 18, protecting children's data is central to how we operate.

This Policy should be read together with our Children's Privacy Notice, Parental Consent Notice, Cookie Policy, Grievance Redressal Policy, and Terms and Conditions. We handle personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 (together, "DPDP"), the Information Technology Act, 2000 and the rules made under it, and other applicable Indian law.

At a glance

  • We collect only the data we need to teach, support, and protect our users — especially students.
  • Depending on how you reached us, either your child's school or Prepdha is responsible for the data (Section 2).
  • We do not sell personal data, and we do not advertise to children or track, monitor, or profile them beyond what is needed to provide the educational service.
  • You have clear rights — access, correction, erasure, withdrawal of consent, nomination, and grievance redressal (Section 11).
  • We keep data only as long as needed (Section 9) and protect it with appropriate security (Section 10).

1. Key terms

  • Personal data — any information about an identifiable individual (for example, a name, email, phone number, device identifier, or learning record).
  • Processing — anything done with personal data: collecting, storing, using, analysing, sharing, or deleting it.
  • Data Principal — the individual the personal data is about. For a child, this includes the parent or lawful guardian acting for them.
  • Data Fiduciary — the entity that decides why and how personal data is processed.
  • Data Processor — an entity that processes personal data on behalf of, and on the instructions of, a Data Fiduciary.
  • Child — an individual who has not completed 18 years of age.

2. Who is responsible for your data (our role)

Prepdha operates in two different roles depending on how you reached us:

  • School deploymentsPrepdha is a Data Processor. When a school subscribes to Prepdha and adds its students, teachers, and staff, the school is the Data Fiduciary (it decides why and how the data is processed), and Prepdha acts as a Data Processor on the school's documented instructions. Our handling of that data is governed by the agreement and Data Processing Agreement we sign with the school, and the school's own privacy notice also applies.
  • Direct sign-upsPrepdha is the Data Fiduciary. When a parent or guardian signs up directly through our website or app (for example, a free trial or a direct subscription for their child), Prepdha is the Data Fiduciary for that account, and is directly responsible for obtaining verifiable parental consent and for honouring data-principal rights.

This Policy describes our practices in both roles. Where a school is the Data Fiduciary, that school's instructions govern, and we act on them.

3. The personal data we collect

We practise data minimisation — we collect only what we need to run the Platform. What we collect depends on whether you are a student, parent/guardian, teacher, or school administrator.

CategoryWhat it includesTypically about
Account and identityName, email, phone number, role (student/parent/teacher/admin), and the school, class, and section a user belongs toAll users
Parent-child linkThe relationship between a parent account and one or more child accounts (supporting our single-parent, multiple-children model and any sibling discounts)Parents, students
Age assurance & consentInformation used to confirm whether a user is a child, and to verify a parent/guardian, in line with DPDPStudents, parents
Learning and performanceSubjects, chapters and topics studied; questions attempted; answers and accuracy; diagnostic results; concept mastery and confidence scores; revision schedules and flashcard activity; notes, assignments, and submissionsStudents
GamificationXP points, streaks, levels, badges, and leaderboard standingStudents
Usage, device, and technicalLog data, device identifiers, browser/app type, operating system, IP address and approximate location inferred from it, pages and features used, timestamps, and crash/diagnostic data; data from cookies and similar technologies (see our Cookie Policy)All users
Communications and supportMessages you send us, demo and contact-form submissions, support requests, and feedbackAll users
Payment (direct subscriptions)Subscription plan, billing records, and transaction referencesParents/adult users

Payment data. Card and bank details are handled by our third-party payment processors. We do not store full card numbers on our systems.

We do not intentionally collect sensitive data beyond what is necessary for education, and we do not require students to share information unrelated to learning.

4. How and why we use personal data, and our lawful basis

We use personal data for the purposes below. For each, we rely on the lawful basis shown.

PurposeWhat it involvesLawful basis
Provide the PlatformCreate and manage accounts, deliver lessons, practice, assessments, flashcards, and notes, and link parent and child accountsConsent; performance of contract
Personalise learningRun our diagnostic engine, spaced-repetition scheduler, AI flashcards, AI doubt solver, and adaptive difficulty so each student gets a suitable path (see Section 6)Consent; performance of contract
Measure progressGenerate mastery scores, XP, streaks, leaderboards, and dashboards for students, teachers, parents, and school leadersConsent; performance of contract
Support and communicateRespond to queries, provide onboarding and training, and send service and account notices (and, where you have opted in, information about features and plans)Consent; legitimate uses
Operate and improve our businessBilling, security, fraud prevention, debugging, and analytics to improve the PlatformLegitimate uses; legal obligation
Keep the Platform safeDetect and prevent misuse, abuse, and security incidentsLegitimate uses; legal obligation

Where consent is the basis (including a parent or guardian's consent for a child), it is free, specific, informed, unconditional, and given by clear affirmative action, and you can withdraw it at any time, as easily as it was given (Section 11).

We do not use children's data for behavioural advertising, and we do not track, monitor, or profile children except as necessary to deliver and improve the educational service the school or parent has asked for.

5. The notice we give you

Before or at the time we collect your personal data on the basis of consent, we give you a clear, plain-language notice that itemises the personal data we collect, the specific purposes for which it will be processed, and the goods or services it enables, along with how you can withdraw consent, exercise your rights, and raise a grievance. This Policy, together with our Children's Privacy Notice and Parental Consent Notice, forms part of that notice.

6. Artificial intelligence and automated processing

Prepdha uses AI to make learning more effective:

  • Diagnostics and personalisation identify weak topics and recommend practice, simulations, and revision tailored to a student.
  • Spaced-repetition scheduling decides when a concept should be revised, based on the student's past performance.
  • AI flashcards and the AI doubt solver generate and respond to study material.

These features process student learning and performance data to produce recommendations and scores. They are designed to assist students and teachers, not to make decisions that have legal or similarly significant effects on a student without human involvement. Academic actions (such as remediation or grading decisions) remain under the oversight of the student's teachers and school. If you have questions about how an AI-generated recommendation or score was produced, contact us using Section 16.

Transparency and safeguards for the AI doubt solver. Because this involves a child interacting with AI:

  • Parent and teacher visibility. Parents (for their linked children) and the student's teachers can review the student's doubt-solver history, so an adult always has oversight of the student's AI interactions.
  • Kept to the subject. The doubt solver is designed for academic questions, and we prompt students not to enter personal information (such as their full name, address, phone number, or photos) into it.
  • Minimal retention. We retain doubt-solver inputs only for as long as needed to provide and improve the feature, and we do not retain any image a student shares for longer than needed to answer.

We do not use identifiable student data to train third-party foundation models for purposes unrelated to providing the Platform.

7. Special protections for children

Because most students on Prepdha are under 18, the following apply (see the full Children's Privacy Notice):

  • We process a child's personal data only after obtaining verifiable consent from a parent or lawful guardian, or on the verified instructions of a school acting in accordance with applicable law.
  • We do not undertake tracking, behavioural monitoring, or profiling of children, and we do not serve targeted advertising to children.
  • We do not process children's data in a way likely to cause a detrimental effect on the well-being of a child.
  • Restricted child accounts. Student accounts are restricted by design: features that would let a child broadcast or disclose personal information about themselves (such as free-text profile fields, public messaging, or sharing identifying details on leaderboards) are limited or switched off. Leaderboards and similar features display only the minimum needed to motivate learning.
  • Gamification (XP, streaks, leaderboards) exists to support learning and motivation, not to manipulate engagement or to advertise.
  • Parents and guardians can review their child's data, correct or delete it, and withdraw consent at any time.

8. When we share personal data

We do not sell personal data. We share it only where necessary:

  • With the student's school — teachers and authorised school staff can see the learning and performance data of their own students, which is core to how the Platform works.
  • With parents/guardians — for the children linked to their account.
  • With service providers (Data Processors) acting on our behalf — for example, secure cloud hosting, communications, analytics, and payment processing — under contracts that require them to protect the data, process it only on our instructions, and use it only to provide their service to us.
  • For legal and safety reasons — to comply with law, enforce our Terms, respond to lawful requests by public authorities, or protect the rights, safety, and property of users (especially children) and the public.
  • In a business transfer — if we are involved in a merger, acquisition, or asset sale, subject to this Policy continuing to apply to your personal data.

We do not permit our service providers to use data collected through the Platform for their own purposes or for advertising, and they are bound to security and confidentiality obligations consistent with DPDP.

9. Data retention and deletion

We keep personal data only for as long as needed for the purposes described in this Policy, or as required by law or by our contract with a school.

Type of dataHow long we keep it
Account data (student, parent, teacher)While the account is active, then deleted within 90 days of account closure or withdrawal of consent
Learning and performance data (diagnostics, mastery scores, revision/flashcard activity, XP, streaks)While the account is active, then deleted within 90 days of account closure — or sooner if you ask us to delete it
AI doubt-solver inputs and shared imagesOnly as long as needed to answer and improve the feature; images are not kept beyond what is needed to respond
Support and communications dataUp to 24 months after the query is resolved
Security and access logsRetained for at least the period required by law (currently a minimum of one year) to help detect and investigate unauthorised access
Billing and transaction recordsAs required by Indian tax, accounting, and company law (typically up to 8 years)
Consent recordsFor as long as needed to demonstrate that valid consent was obtained, and a reasonable period thereafter

When the purpose is fulfilled, when consent is withdrawn, or when a school instructs us, we erase the relevant personal data, except where the law requires us to keep it. Where a school is the Data Fiduciary, retention and deletion follow the school's instructions and our contract. Where required, we will notify the relevant data principal (or parent/guardian) before erasure, at least 48 hours in advance where the applicable time-limit rules require it.

10. How we protect personal data

We implement reasonable technical and organisational security safeguards appropriate to the risk, which include:

  • access controls and role-based permissions (so, for example, a teacher sees only their own students);
  • encryption of data in transit, and masking or other protections where appropriate;
  • segregation of student data and limits on internal access;
  • logging, monitoring, and review to detect and investigate unauthorised access, with logs retained as required;
  • backups and continuity measures; and
  • staff confidentiality obligations and training.

We also require our service providers to maintain appropriate safeguards by contract. More detail is on our Security page.

If a personal data breach occurs, we will act to contain it and will notify the affected data principals and the Data Protection Board of India in accordance with DPDP — including providing the Board with a detailed report within 72 hours (or such period as the law allows) and giving affected individuals a plain-language description of what happened, what data was involved, and the steps they can take.

No system is completely secure, but we work continuously to protect the data entrusted to us.

11. Your rights

Subject to applicable law, data principals (and parents/guardians acting for a child) have the right to:

  • Access — obtain a summary of the personal data we hold about you and how it is processed, including the processors and other parties with whom it has been shared;
  • Correction, completion, and updating of inaccurate or incomplete data;
  • Erasure of personal data where it is no longer needed and erasure is not restricted by law;
  • Withdraw consent at any time, as easily as it was given (this does not affect processing already carried out lawfully, and some processing is essential, so withdrawal may affect your use of the Platform);
  • Nominate another individual to exercise your rights in the event of your death or incapacity; and
  • Grievance redressal — raise a complaint and have it addressed (see Section 16 and our Grievance Redressal Policy).

How to exercise your rights. Contact us using Section 16. We aim to respond to rights requests within 30 days. To protect you (and, for a child's data, the child), we may need to verify your identity and, where relevant, your relationship to the child before acting. Where a school is the Data Fiduciary, we may direct your request to the school or act on the school's instructions.

12. Cookies and similar technologies

We use cookies and similar technologies for essential functionality, security, and analytics. Student-facing experiences are not used for behavioural advertising. See our Cookie Policy for full details and your choices.

13. Third-party services and links

The Platform may integrate with or link to third-party services (for example, a payment processor on billing pages). Where a third-party acts on our behalf, it is bound by contract as a Data Processor. Where you choose to use a third-party service of your own, that service's own privacy policy applies. We are not responsible for third-party services we do not control.

14. Storing and processing data (cross-border)

We primarily store and process personal data in India. Where any processing or storage occurs outside India (for example, through a service provider), we do so in accordance with DPDP. Under the current framework, transfers outside India are permitted except to any country or territory that the Government specifically restricts, and we require appropriate protections to be in place wherever data is processed.

15. A note on our regulatory status

We are a Data Fiduciary that is not currently designated a Significant Data Fiduciary (SDF) under the DPDP Act. As such, we maintain a grievance-redressal mechanism and a published contact for data-protection queries (Section 16). If we are designated an SDF in future, additional obligations would apply — such as appointing a Data Protection Officer based in India, conducting periodic data-protection impact assessments and audits, and enhanced due diligence — and we would update this Policy accordingly.

16. How to contact us

For any privacy question, request, or to exercise your rights:

  • Data Protection / Privacy contact: Kumar S - communications@prepdha.com
  • Grievance Officer: Kumar S - communications@prepdha.com
  • Civilsphere Educational Services Private Limited 202, R Hub, Madhapur, Hyderabad 500081 Phone: +91 79954 67223

We aim to acknowledge and respond to requests and complaints within the timelines required by law. If you are not satisfied with our response to a data-protection grievance, you may escalate to the Data Protection Board of India, as described in our Grievance Redressal Policy.

17. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here with a new "Last updated" date and, where the change is significant, take reasonable steps to notify you. Continued use of the Platform after an update means you accept the revised Policy.

This Privacy Policy reflects our commitments under the DPDP Act, 2023, the DPDP Rules, 2025, and other applicable Indian law. If you have any questions, please contact us using the details in Section 16.