Privacy policy

Written to be read. Last revised 6 October 2026. A draft pending review by counsel — the substance will not change, the wording may.

Who we are

Aragya Infotech Private Limited, which runs the Campunix brand ("Campunix"), provides software to schools and colleges. The institution you deal with is responsible for your data under the Digital Personal Data Protection Act, 2023; Campunix processes it on the institution's instructions.

What we collect

From institutions: staff names, work emails and phone numbers. From the institution's records: student names, class, date of birth, guardian names and phone numbers, fee and attendance records, marks. From public forms: only what you type into them — a name, a phone number, and for admission forms the details the form asks for.

Why

To run the institution's admissions, fees, attendance, results and messages. We do not sell personal data, show advertising, or use children's data for anything beyond the educational purpose the institution set.

Children's data

Schools hold children's data for education and safety, which the DPDP Rules permit. Anything beyond that — marketing, for instance — requires a parent's verifiable consent, which the institution records in Campunix before any such use.

Where it is stored

In India, in the Mumbai region, with encrypted connections and encryption at rest. Payment card and bank details are handled by the payment provider, never stored by Campunix.

Messages

Fee reminders, attendance alerts and enquiry replies are sent on WhatsApp through Meta's business platform using approved templates. Your number is used only for messages from the institution you are dealing with.

How long

For as long as the institution uses Campunix for you, and for the period the law requires fee and academic records to be kept afterwards. Institutions can export and delete their data on request.

Your rights

To see, correct or erase personal data, ask the institution first. If that does not resolve it, write to [email protected]. We respond within 30 days. Security incidents affecting you are reported as the DPDP Rules require.

Changes

This policy will change as the product and the law do. The date below is the last revision.