TantraDev · Legal

Privacy Policy

What we collect on this site, what the platform processes for your school, and your rights under India's DPDP Act 2023.

Last updated: 10 September 2026

Who we are

This website, and the preschool management platform it describes, are run by TantraDev Information Technologies LLP — a Limited Liability Partnership registered in Pune, Maharashtra. It is an LLP, not a private limited company.

Legal entityTantraDev Information Technologies LLP
LLPINACM-788
GSTIN27AAXFT7282J1Z5
Registered officeC1304, C1305, 41 Evoke, Ravet, Pune, Maharashtra 412101, India
Emailadmin@tantradev.com
Phone+91 92703 85626

In this policy, “we” and “TantraDev” mean that LLP. “You” means whoever is reading it — a preschool owner looking around the site, or a parent whose child’s school uses our platform. Those are two very different situations, so this policy is written in two parts. Please read the part that applies to you. The date this policy last changed is shown at the top of this page.

The two parts, and why they are separate

Part A covers this website. The only thing it collects is a demo request you choose to send us. That is a business enquiry from an adult.

Part B covers the platform itself — the software a school licenses from us to run its admissions, attendance, daily reports, photos, fees and health records. That software holds records about young children. The rules there are stricter, and our role is different: the school decides what happens to the data, and we act on the school’s instructions.

Mixing these two up is the usual mistake in a policy like this, so we have kept them apart. Everything after Part B — your legal rights, retention, security, breaches, the Grievance Officer — applies to both.

One thing you should know before reading further: the platform is new and not yet in public use. At the date of this policy no school is live on it and it holds no children’s records. Part B describes what will happen when a school signs up, written in advance so you can read it before you decide anything.

Part A — What this website collects

Browsing this site requires nothing from you. You do not need an account, and there is nothing to log in to. The only place the site asks for anything is the demo request form on the contact page, and you fill it in only if you want us to call you back.

That form asks for:

  • Your name and your school’s name — required, so we know who we are talking to.
  • Your email address — required, because it is how we reply.
  • Phone or WhatsApp number — optional, only if you would rather we call.
  • Your city and roughly how many children you have — both optional, so we can show you the parts of the product that fit a school your size.
  • A free-text message — optional, and entirely whatever you choose to write there.

Please do not put any child’s name, photo or health detail in that message box. We do not need it to show you a demo, and this form is not the right place for it.

How the form actually works. It does not post anything to a server of ours. When you press the button, the form opens your own email application with the details already filled in, addressed to admin@tantradev.com. Nothing reaches us until you press send yourself, in your own email program. After that your message sits in our mailbox like any other email. There is no database behind this website, and apart from the ordinary hosting records described below, no record of you is created anywhere else. If we ever change the form so that it submits directly to a server, we will update this policy before we switch that on.

Part A — Why we ask, and how long we keep it

For a demo enquiry, TantraDev is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 — we decide why your enquiry is used and how, so the responsibility for it is ours and nobody else’s. That is the opposite of our role in Part B, where the school decides and we only act on its instructions.

We use your enquiry for exactly one thing: to reply to you and arrange a demo of the product. We do not add you to a mailing list, we do not sell or rent your details, and we do not pass them to anyone else for their own purposes.

We keep the email while we are talking, and for up to twelve months after your last message, in case you come back to us. After that we delete it. If you would rather we delete it sooner, email admin@tantradev.com and we will, and we will confirm when it is done.

Part A — No analytics, no advertising cookies, no trackers

This is worth stating plainly, because most sites cannot. As of the date of this policy this website carries:

  • no analytics of any kind — no Google Analytics, no Plausible, no visitor counter;
  • no advertising or marketing cookie, and no tracking pixel;
  • no session recording, no heatmaps, no chat widget, no A/B testing tool;
  • no advertising or tracking script, and no social media embeds.

We build no profile of you, and we cannot follow you to any other website. There is nothing here to opt out of, which is why you were not asked to dismiss a cookie banner.

The three exceptions, stated honestly. These are the only outside parties this website involves, and not one of them is advertising or analytics.

  • Google Fonts. The site loads its two typefaces from Google, so your browser fetches those font files from Google’s servers. That request tells Google your IP address and browser type, as a request to any server does. It sets no cookie and we receive nothing from it.
  • Our hosting provider. It keeps ordinary server logs — IP address, page requested, time — under its own retention policy, for security and to keep the site running. We do not use those logs for marketing and we do not combine them with anything else.
  • The platform this site is built and hosted on. Where its script is present on the page you loaded, it is sent an automatic report if the site crashes in your browser: the error message, where in our code it happened, and which page you were on. It is not sent anything you typed into the demo form. If we remove that reporting, we will say so here.

Part B — When your school uses the platform: who is responsible for what

When a preschool licenses our platform, the school stays in charge of its own data. In the language of the Digital Personal Data Protection Act, 2023:

  • The school is the Data Fiduciary. A Data Fiduciary is whoever decides why and how personal data is used. The school decides which children are enrolled, what is recorded about them, who on its staff may see what, and how long it is kept. The school also owns the relationship with parents — it is the school that admitted the child, and the school that parents deal with.
  • TantraDev is the Data Processor. A Data Processor holds and handles the data on the Fiduciary’s instructions and for no purpose of its own. We store the school’s records, run the software, and keep it working. That is the whole of our role.

In practice this means we do not decide what goes into your school’s records and we do not use them for our own ends. We do not sell school or child data. We do not share it with data brokers or advertisers. We do not use it to train machine learning models. We do not read a school’s records except when the school asks us to help with a specific problem, or where the law compels us — and when we do, we tell the school what we looked at and why.

The details of this arrangement — our instructions, our duties, deletion on exit, liability — sit in the written agreement we sign with each school before it goes live. Under Section 8(2) of the DPDP Act a Data Fiduciary may engage a processor only under a valid contract, so this is not optional for either of us.

Part B — What the platform holds

Once a school is using the platform, it can hold the records a preschool actually keeps. That includes:

  • student profiles — name, date of birth, class, photograph, enrolment details;
  • guardian and parent details — names, relationship to the child, phone, email;
  • attendance records and daily reports on meals, naps, mood and activities;
  • photographs uploaded by staff during the day;
  • health records, allergies, medication notes and emergency contacts;
  • uploaded documents, such as a birth certificate or an immunisation record;
  • fee invoices and records of payments received;
  • incident reports recorded by staff;
  • messages between school staff and parents.

Health details and allergies are sensitive personal data or information under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. They are held only because a preschool must be able to act in an emergency, and they are visible only to the staff the school gives access to.

Part B — Fees, invoices, and why we hold no card details

There is no payment gateway anywhere in our platform, and none on this website. The software issues GST-ready invoices with gap-free legal numbering, and records payments the school has already received by other means — bank transfer, UPI, cheque or cash. It does not take money online.

So the platform stores no card numbers, no CVVs, no UPI credentials and no bank passwords, because it never has them in the first place. What it holds is the invoice and the note that a payment was received.

Our own licence fee to the school is a yearly plan sized to its register, from ₹9,000 a year, with GST at 18% added on top — the price is exclusive of GST. We invoice the school for that directly.

Your rights, and how to use them

Under the DPDP Act you have the right to:

  • Access — ask what personal data is held about you or your child, and what has been done with it.
  • Correction and completion — have anything wrong put right, and anything incomplete or out of date updated.
  • Erasure — ask for data to be deleted when it is no longer needed for the purpose it was collected for, and the law does not require it to be kept.
  • Withdrawal of consent — take back a consent you gave, as easily as you gave it. What was lawfully done before you withdrew it stands, but the processing stops.
  • Grievance redressal — complain under Section 13 of the DPDP Act and get an answer, without having to go to court first.
  • Nomination — nominate another person to exercise these rights on your behalf if you die or become unable to act for yourself.

Where to send the request depends on which part you are in.

  • About a demo enquiry (Part A): email admin@tantradev.com with Data request in the subject line. We answer within 30 days.
  • About a child’s records on the platform (Part B): ask the school first. The school is the Data Fiduciary, it holds the relationship with you, and it can act on your request directly in the software. If you write to us instead, we will not change the records ourselves — we will pass the request to the school and tell you we have done so, because acting alone would mean overriding the school’s instructions. Where the school needs technical help to answer you, we give it.

If you are unhappy with how a request was handled, you may complain to the Data Protection Board of India after raising it with us or with the school.

How long anything is kept

Demo enquiries. Kept while we are in conversation and for up to twelve months after your last message, then deleted. Sooner if you ask.

School and child records. Kept for as long as the school’s subscription runs, because they are the school’s working records. How long the school itself keeps a particular record is the school’s decision, and the school’s own retention policy governs it. If the school instructs us to delete a record sooner, we delete it.

When a school leaves. We give the school a copy of its data in a machine-readable form, then delete what we hold within 30 days of the school confirming it has what it needs. Manual backup copies containing that data are deleted at the same time. We keep only what tax law obliges us to keep about our own invoices to the school — not the children’s records.

Sub-processors, and where data is hosted

This website. Four third parties are involved and no others: the hosting provider that serves these pages, the platform this site is built on and its crash reporting, Google Fonts for the two typefaces, and our own email provider, which carries your demo enquiry to our inbox in the ordinary way email works. Your enquiry also passes through whichever email provider you use to send it, because the form sends it from your own mail application.

The platform. It is not yet publicly deployed, so there is no live hosting arrangement to describe and we will not invent one. Before any school goes live, and before a single child’s record is entered, we name in that school’s written agreement the hosting provider we use, the region the data sits in, and every sub-processor with access. We will not add a new sub-processor without telling the school in advance and giving it a fair chance to object.

The DPDP Act allows personal data to be transferred outside India except to countries the Central Government restricts. We will tell each school exactly where its data is stored before it uploads anything, so it can make that judgement for itself.

How the platform is protected — and what we do not claim

The SPDI Rules, 2011 require us to keep reasonable security practices and procedures proportionate to the information we hold, and we accept that duty. Security claims are easy to write and hard to keep, so here is only what is actually built and running:

  • Tenant isolation in the database itself — PostgreSQL row-level security, so one school’s records cannot be read from another school’s session. The rule is enforced by the database, not only by application code.
  • Password hashing with argon2id — passwords are never stored in a form anyone can read, including us.
  • RS256 signed JSON Web Tokens for sessions, with rotating refresh tokens and reuse detection — if an old token is replayed, the whole session family is treated as compromised and shut down.
  • Role-based access control — a teacher, a principal and an owner see different things, and the school decides who is which.
  • Rate limiting on sensitive endpoints, to blunt brute-force and scraping attempts.
  • Security headers on responses from the application.
  • Instrumentation with OpenTelemetry and Prometheus — the software records how it is behaving, so failures and unusual patterns are there to be found. We do not staff a round-the-clock monitoring desk, and we do not claim one.

What we do not claim, and will not pretend. We do not claim encryption at rest or a key management service. We do not claim scheduled or automatic backups — a backup today is taken by an operator running a script by hand. We hold no SOC 2 report, no ISO 27001 certificate and no other security certification, and we will not display a badge we have not earned. We do not promise an uptime percentage, a disaster recovery guarantee or 24/7 support. If any of that changes, this section changes with it, and not before.

No system is perfectly secure. What we owe you is honesty about where we stand, and prompt telling when something goes wrong.

If there is a data breach

If personal data we hold is lost, exposed, or accessed by someone who should not have it, we treat that as a breach whether or not harm is proven.

  • For platform data, we tell the affected school without undue delay, and in any case within 72 hours of becoming aware, with what we know: what happened, what data was involved, what we have done, and what we advise. The school, as Data Fiduciary, must then intimate the Data Protection Board of India and every affected Data Principal, as the DPDP Act requires. We give the school whatever it needs to do that, including records from the audit trail.
  • For demo enquiries from this website, we are the Data Fiduciary, so the duty is ours: we contact the affected people directly, because there is no school in between, and we intimate the Data Protection Board of India ourselves in the form and time the DPDP Act and its rules require.

We will not delay telling you while we work out how it looks.

Children’s data under Section 9 of the DPDP Act

Under the DPDP Act a child is anyone under the age of eighteen. Every student record in this platform is therefore a child’s record, and nearly all of them belong to children under six. This service exists for preschools and the children in them, and we make no pretence otherwise. Section 9 sets specific limits, and they apply to us in full:

  • Verifiable parental consent comes first. A child’s data may be processed only with the verifiable consent of the parent or lawful guardian. The school obtains it, the consent ledger records it, and the media gate enforces it.
  • No behavioural tracking or monitoring of children. We do not track, profile or behaviourally monitor any child. There is no behavioural analytics in the platform, no profiling engine, and no third-party tracking code. A daily report written by a teacher is a note to a parent about their own child, not surveillance, and it is visible only to that child’s guardians and to the staff the school authorises.
  • No targeted advertising directed at children. There is no advertising in the platform at all, targeted or otherwise. We will not introduce any, and we will not sell or supply children’s data to anyone who advertises.
  • Nothing likely to harm a child’s wellbeing. We do not process a child’s data in any way likely to have a detrimental effect on their wellbeing.

We also do not use children’s data to train machine learning models, and we do not mine it for our own product research.

Changes to this policy

We will update this policy when what we do changes — a new sub-processor, a real server endpoint behind the demo form, a security control that becomes true. The date at the top always shows when it last changed.

If a change materially affects a school, or the children whose records it holds, we tell the school in writing before it takes effect rather than quietly editing this page. Schools should pass that on to parents, since the school owns that relationship.

Governing law

This policy is governed by the laws of India. The courts at Pune, Maharashtra have exclusive jurisdiction over any dispute arising from it. This matches the position in our terms of service.

Grievance Officer

Under Rule 5(9) of the SPDI Rules, 2011 and Section 13 of the DPDP Act, we name a Grievance Officer. If you have a complaint about how your data, or your child’s data, has been handled, write to them.

Grievance OfficerPrashant Sambhaji Chavan
Emailadmin@tantradev.com
Phone+91 92703 85626
AddressC1304, C1305, 41 Evoke, Ravet, Pune, Maharashtra 412101, India
We respond within30 days of receiving your complaint

We acknowledge every complaint and answer it within 30 days of receiving it. If your complaint is about a child’s records on the platform, please write to the school as well — the school is the Data Fiduciary and can usually resolve it fastest. If our answer does not satisfy you, you may take the matter to the Data Protection Board of India.

Who you are dealing with

Legal entity
TantraDev Information Technologies LLP
LLPIN
ACM-788
GSTIN
27AAXFT7282J1Z5
Registered office
C1304, C1305, 41 Evoke, Ravet, Pune, Maharashtra 412101, India
Email
admin@tantradev.com
Phone
+91 92703 85626