Security at Prepdha
Schools and parents trust Prepdha with the personal data of children, and we treat that as one of our most important responsibilities. This page summarises, in plain language, how Civilsphere Educational Services Private Limited (“Prepdha”, “we”, “us”, “our”) protects personal data on the Prepdha platform, websites, and apps (the “Platform”).
It supplements our Privacy Policy and, for schools, our Data Processing Agreement. It is a summary of our practices and not a technical specification; our specific controls evolve as the Platform grows and as threats change.
At a glance
- We apply security measures appropriate to the sensitivity of the data, with extra care for children’s data.
- Access is role-based and limited — for example, a teacher sees only their own students.
- We encrypt data in transit, log and monitor activity, and segregate student data.
- We do not track, profile, or advertise to children.
- If a breach occurs, we follow the DPDP breach-notification process, including a report to the Data Protection Board.
- You can report a security concern to us at communications@prepdha.com.
1. Our approach
We implement technical and organisational security measures appropriate to the risk, taking into account the sensitivity of the data we handle and the fact that most of our users are children. Security is not a one-time exercise — we review and strengthen our measures as the Platform grows, and we build data protection into how we design and operate the service (“privacy and security by design”).
Our approach is aligned with the security expectations of India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and the Information Technology Act, 2000.
2. How we protect data
- Access control and least privilege. Access to personal data is role-based and limited to the people who genuinely need it for their work — for example, a teacher can see only their own students. Internal access is restricted, granted on a need-to-know basis, and logged.
- Student data segregation. Student learning and performance data is kept logically separated and handled so that it is used only for the educational purpose for which it was collected.
- Encryption in transit. Data exchanged between your device and the Platform is encrypted in transit using industry-standard protocols (such as TLS), to protect it from interception.
- Reputable infrastructure. The Platform runs on reputable cloud infrastructure with network and application-level safeguards. We primarily store and process personal data in India, consistent with our Privacy Policy.
- Secure development and change management. We follow secure development practices and review and test changes before they go live, so that updates do not weaken the security of the Platform.
- Logging and monitoring. We log access and key events and monitor for unusual or unauthorised activity, so that we can detect and investigate potential issues. We retain relevant logs for at least the period required by law (currently a minimum of one year).
- Confidentiality and training. Our staff are bound by confidentiality obligations and receive guidance on handling personal data, with particular emphasis on the care required for children’s data.
- Service-provider (processor) diligence. Where service providers process data on our behalf, they are bound by contract to protect it, to act only on our instructions, and to use it only to provide their service to us — never for their own purposes or for advertising.
- Resilience. We maintain measures intended to keep the Platform available and to help recover data in the event of a disruption.
3. Special care for children
Protecting children is built into how the Platform works, not bolted on afterwards:
- We do not track, behaviourally monitor, or profile children for non-educational purposes, and we do not serve advertising to children.
- Restricted student accounts limit or switch off features that could let a child expose personal information about themselves (such as public profile fields or public messaging), and leaderboards display only the minimum needed to motivate learning.
- AI features (such as the doubt solver) are designed with adult oversight — parents and teachers can review a child’s AI activity, and students are prompted not to share personal information.
More detail is in our Children’s Privacy Notice.
4. Incident response and breach notification
We maintain procedures to detect, investigate, contain, and remediate security incidents.
If a personal data breach occurs, we will act promptly and follow the requirements of the DPDP framework, including:
- notifying affected data principals (and, for school accounts, the relevant school) with a plain-language description of what happened, the data involved, the likely consequences, the measures we are taking, and steps they can take to protect themselves; and
- notifying the Data Protection Board of India, including providing a detailed report within 72 hours (or such period as the law allows) of becoming aware of the breach.
We then review the incident to learn from it and to further strengthen our safeguards.
5. Your role in keeping data secure
Security is a shared effort. You can help protect your account and your child's data by:
- using a strong, unique password and not sharing your login with others;
- keeping your devices and apps updated, and using a device lock;
- signing out on shared or public devices;
- being cautious of phishing — we will never ask for your password by email or phone; and
- telling us promptly if you think an account has been accessed without permission.
Schools can help by managing staff access responsibly and removing access when a staff member leaves.
6. Reporting a security issue (responsible disclosure)
We welcome reports from security researchers and users who believe they have found a vulnerability. If you have a security concern, please email communications@prepdha.com with enough detail for us to reproduce and investigate the issue.
We ask that you give us a reasonable opportunity to address the issue before disclosing it publicly, and that you avoid accessing or modifying other users’ data. We will not pursue good-faith researchers who follow responsible-disclosure practices, and we will work to address valid reports promptly.
7. Contact
- Security / Privacy: communications@prepdha.com · +91 79954 67223
- Civilsphere Educational Services Private Limited 202, R Hub, Madhapur, Hyderabad 500081
This page summarises our security practices and reflects our commitments under the DPDP Act, 2023 and applicable Indian law. If you have any questions, please contact us using the details above.