TantraDev · Legal
Privacy Policy
What we collect on this site, what the platform processes for your school, and your rights under India's DPDP Act 2023.
Last updated: 10 September 2026
Who we are
This website, and the preschool management platform it describes, are run by TantraDev Information Technologies LLP — a Limited Liability Partnership registered in Pune, Maharashtra. It is an LLP, not a private limited company.
| Legal entity | TantraDev Information Technologies LLP |
|---|---|
| LLPIN | ACM-788 |
| GSTIN | 27AAXFT7282J1Z5 |
| Registered office | C1304, C1305, 41 Evoke, Ravet, Pune, Maharashtra 412101, India |
| admin@tantradev.com | |
| Phone | +91 92703 85626 |
In this policy, “we” and “TantraDev” mean that LLP. “You” means whoever is reading it — a preschool owner looking around the site, or a parent whose child’s school uses our platform. Those are two very different situations, so this policy is written in two parts. Please read the part that applies to you. The date this policy last changed is shown at the top of this page.
The two parts, and why they are separate
Part A covers this website. The only thing it collects is a demo request you choose to send us. That is a business enquiry from an adult.
Part B covers the platform itself — the software a school licenses from us to run its admissions, attendance, daily reports, photos, fees and health records. That software holds records about young children. The rules there are stricter, and our role is different: the school decides what happens to the data, and we act on the school’s instructions.
Mixing these two up is the usual mistake in a policy like this, so we have kept them apart. Everything after Part B — your legal rights, retention, security, breaches, the Grievance Officer — applies to both.
One thing you should know before reading further: the platform is new and not yet in public use. At the date of this policy no school is live on it and it holds no children’s records. Part B describes what will happen when a school signs up, written in advance so you can read it before you decide anything.
Part A — What this website collects
Browsing this site requires nothing from you. You do not need an account, and there is nothing to log in to. The only place the site asks for anything is the demo request form on the contact page, and you fill it in only if you want us to call you back.
That form asks for:
- Your name and your school’s name — required, so we know who we are talking to.
- Your email address — required, because it is how we reply.
- Phone or WhatsApp number — optional, only if you would rather we call.
- Your city and roughly how many children you have — both optional, so we can show you the parts of the product that fit a school your size.
- A free-text message — optional, and entirely whatever you choose to write there.
Please do not put any child’s name, photo or health detail in that message box. We do not need it to show you a demo, and this form is not the right place for it.
How the form actually works. It does not post anything to a server of ours. When you press the button, the form opens your own email application with the details already filled in, addressed to admin@tantradev.com. Nothing reaches us until you press send yourself, in your own email program. After that your message sits in our mailbox like any other email. There is no database behind this website, and apart from the ordinary hosting records described below, no record of you is created anywhere else. If we ever change the form so that it submits directly to a server, we will update this policy before we switch that on.
Part A — Why we ask, and how long we keep it
For a demo enquiry, TantraDev is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 — we decide why your enquiry is used and how, so the responsibility for it is ours and nobody else’s. That is the opposite of our role in Part B, where the school decides and we only act on its instructions.
We use your enquiry for exactly one thing: to reply to you and arrange a demo of the product. We do not add you to a mailing list, we do not sell or rent your details, and we do not pass them to anyone else for their own purposes.
We keep the email while we are talking, and for up to twelve months after your last message, in case you come back to us. After that we delete it. If you would rather we delete it sooner, email admin@tantradev.com and we will, and we will confirm when it is done.
Part A — No analytics, no advertising cookies, no trackers
This is worth stating plainly, because most sites cannot. As of the date of this policy this website carries:
- no analytics of any kind — no Google Analytics, no Plausible, no visitor counter;
- no advertising or marketing cookie, and no tracking pixel;
- no session recording, no heatmaps, no chat widget, no A/B testing tool;
- no advertising or tracking script, and no social media embeds.
We build no profile of you, and we cannot follow you to any other website. There is nothing here to opt out of, which is why you were not asked to dismiss a cookie banner.
The three exceptions, stated honestly. These are the only outside parties this website involves, and not one of them is advertising or analytics.
- Google Fonts. The site loads its two typefaces from Google, so your browser fetches those font files from Google’s servers. That request tells Google your IP address and browser type, as a request to any server does. It sets no cookie and we receive nothing from it.
- Our hosting provider. It keeps ordinary server logs — IP address, page requested, time — under its own retention policy, for security and to keep the site running. We do not use those logs for marketing and we do not combine them with anything else.
- The platform this site is built and hosted on. Where its script is present on the page you loaded, it is sent an automatic report if the site crashes in your browser: the error message, where in our code it happened, and which page you were on. It is not sent anything you typed into the demo form. If we remove that reporting, we will say so here.
Part B — When your school uses the platform: who is responsible for what
When a preschool licenses our platform, the school stays in charge of its own data. In the language of the Digital Personal Data Protection Act, 2023:
- The school is the Data Fiduciary. A Data Fiduciary is whoever decides why and how personal data is used. The school decides which children are enrolled, what is recorded about them, who on its staff may see what, and how long it is kept. The school also owns the relationship with parents — it is the school that admitted the child, and the school that parents deal with.
- TantraDev is the Data Processor. A Data Processor holds and handles the data on the Fiduciary’s instructions and for no purpose of its own. We store the school’s records, run the software, and keep it working. That is the whole of our role.
In practice this means we do not decide what goes into your school’s records and we do not use them for our own ends. We do not sell school or child data. We do not share it with data brokers or advertisers. We do not use it to train machine learning models. We do not read a school’s records except when the school asks us to help with a specific problem, or where the law compels us — and when we do, we tell the school what we looked at and why.
The details of this arrangement — our instructions, our duties, deletion on exit, liability — sit in the written agreement we sign with each school before it goes live. Under Section 8(2) of the DPDP Act a Data Fiduciary may engage a processor only under a valid contract, so this is not optional for either of us.
Part B — What the platform holds
Once a school is using the platform, it can hold the records a preschool actually keeps. That includes:
- student profiles — name, date of birth, class, photograph, enrolment details;
- guardian and parent details — names, relationship to the child, phone, email;
- attendance records and daily reports on meals, naps, mood and activities;
- photographs uploaded by staff during the day;
- health records, allergies, medication notes and emergency contacts;
- uploaded documents, such as a birth certificate or an immunisation record;
- fee invoices and records of payments received;
- incident reports recorded by staff;
- messages between school staff and parents.
Health details and allergies are sensitive personal data or information under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. They are held only because a preschool must be able to act in an emergency, and they are visible only to the staff the school gives access to.
Part B — Children’s data, and how consent works
Nearly every person whose data this platform holds is a child under six. We say that openly, because it is the whole point of the product. It is also why the obligations below are heavier than they would be for ordinary business software, not lighter.
The school obtains the consent. Parents and guardians enrol their child with the school, and the school is the one that must obtain verifiable consent from the parent or lawful guardian before a child’s data is processed, as Section 9(1) of the DPDP Act requires. We never approach parents for consent ourselves, and we are not a party to that conversation.
The platform records it and enforces it. What we provide is the machinery that makes the school’s consent real rather than a signature in a drawer:
- An immutable consent ledger — every consent given, refused or later withdrawn is written to a record that cannot be quietly edited afterwards, with who recorded it and when. If a parent asks the school what they agreed to, the answer is on file.
- A media sharing consent gate — a photo of a child cannot be shared to a parent through the platform without a consent check passing first. The gate is part of the sharing operation itself, not a reminder that staff can ignore.
- Data principal rights requests with an audit trail — when a parent exercises a right, the school can log and answer it in the platform, and the trail of what was done and when is kept.
Withdrawing consent. A parent may withdraw consent at any time by telling the school. The school records the withdrawal in the ledger, and from that point the gate stops sharing on that basis. Withdrawal is not retrospective — it does not undo what was lawfully done earlier — and it does not remove records the school must keep by law, such as fee and tax records.
Part B — Fees, invoices, and why we hold no card details
There is no payment gateway anywhere in our platform, and none on this website. The software issues GST-ready invoices with gap-free legal numbering, and records payments the school has already received by other means — bank transfer, UPI, cheque or cash. It does not take money online.
So the platform stores no card numbers, no CVVs, no UPI credentials and no bank passwords, because it never has them in the first place. What it holds is the invoice and the note that a payment was received.
Our own licence fee to the school is a yearly plan sized to its register, from ₹9,000 a year, with GST at 18% added on top — the price is exclusive of GST. We invoice the school for that directly.
The law we work under, and our legal basis
Two Indian laws govern everything above.
The Digital Personal Data Protection Act, 2023 (DPDP Act). This is India’s data protection law. It calls a person whose data is processed a Data Principal, whoever decides how that data is used a Data Fiduciary, and anyone processing it for them a Data Processor. For a child, the parent or lawful guardian exercises the child’s rights on their behalf.
The Information Technology Act, 2000 and the SPDI Rules, 2011. These remain in force and set the requirements for handling sensitive personal data such as health information — a published privacy policy, consent before collection, reasonable security practices, and a named Grievance Officer.
Our legal basis for each thing we do:
- Your demo enquiry — your own consent. You typed it in and pressed send, for the stated purpose of us replying. You can withdraw that consent at any time by asking us to delete the email.
- A school’s records on the platform — the consent the school obtained from the parent or guardian, together with the school’s own uses permitted by law, such as keeping fee and tax records. We process those records on the school’s documented instructions and on no other basis.
Your rights, and how to use them
Under the DPDP Act you have the right to:
- Access — ask what personal data is held about you or your child, and what has been done with it.
- Correction and completion — have anything wrong put right, and anything incomplete or out of date updated.
- Erasure — ask for data to be deleted when it is no longer needed for the purpose it was collected for, and the law does not require it to be kept.
- Withdrawal of consent — take back a consent you gave, as easily as you gave it. What was lawfully done before you withdrew it stands, but the processing stops.
- Grievance redressal — complain under Section 13 of the DPDP Act and get an answer, without having to go to court first.
- Nomination — nominate another person to exercise these rights on your behalf if you die or become unable to act for yourself.
Where to send the request depends on which part you are in.
- About a demo enquiry (Part A): email admin@tantradev.com with Data request in the subject line. We answer within 30 days.
- About a child’s records on the platform (Part B): ask the school first. The school is the Data Fiduciary, it holds the relationship with you, and it can act on your request directly in the software. If you write to us instead, we will not change the records ourselves — we will pass the request to the school and tell you we have done so, because acting alone would mean overriding the school’s instructions. Where the school needs technical help to answer you, we give it.
If you are unhappy with how a request was handled, you may complain to the Data Protection Board of India after raising it with us or with the school.
How long anything is kept
Demo enquiries. Kept while we are in conversation and for up to twelve months after your last message, then deleted. Sooner if you ask.
School and child records. Kept for as long as the school’s subscription runs, because they are the school’s working records. How long the school itself keeps a particular record is the school’s decision, and the school’s own retention policy governs it. If the school instructs us to delete a record sooner, we delete it.
When a school leaves. We give the school a copy of its data in a machine-readable form, then delete what we hold within 30 days of the school confirming it has what it needs. Manual backup copies containing that data are deleted at the same time. We keep only what tax law obliges us to keep about our own invoices to the school — not the children’s records.
Sub-processors, and where data is hosted
This website. Four third parties are involved and no others: the hosting provider that serves these pages, the platform this site is built on and its crash reporting, Google Fonts for the two typefaces, and our own email provider, which carries your demo enquiry to our inbox in the ordinary way email works. Your enquiry also passes through whichever email provider you use to send it, because the form sends it from your own mail application.
The platform. It is not yet publicly deployed, so there is no live hosting arrangement to describe and we will not invent one. Before any school goes live, and before a single child’s record is entered, we name in that school’s written agreement the hosting provider we use, the region the data sits in, and every sub-processor with access. We will not add a new sub-processor without telling the school in advance and giving it a fair chance to object.
The DPDP Act allows personal data to be transferred outside India except to countries the Central Government restricts. We will tell each school exactly where its data is stored before it uploads anything, so it can make that judgement for itself.
How the platform is protected — and what we do not claim
The SPDI Rules, 2011 require us to keep reasonable security practices and procedures proportionate to the information we hold, and we accept that duty. Security claims are easy to write and hard to keep, so here is only what is actually built and running:
- Tenant isolation in the database itself — PostgreSQL row-level security, so one school’s records cannot be read from another school’s session. The rule is enforced by the database, not only by application code.
- Password hashing with argon2id — passwords are never stored in a form anyone can read, including us.
- RS256 signed JSON Web Tokens for sessions, with rotating refresh tokens and reuse detection — if an old token is replayed, the whole session family is treated as compromised and shut down.
- Role-based access control — a teacher, a principal and an owner see different things, and the school decides who is which.
- Rate limiting on sensitive endpoints, to blunt brute-force and scraping attempts.
- Security headers on responses from the application.
- Instrumentation with OpenTelemetry and Prometheus — the software records how it is behaving, so failures and unusual patterns are there to be found. We do not staff a round-the-clock monitoring desk, and we do not claim one.
What we do not claim, and will not pretend. We do not claim encryption at rest or a key management service. We do not claim scheduled or automatic backups — a backup today is taken by an operator running a script by hand. We hold no SOC 2 report, no ISO 27001 certificate and no other security certification, and we will not display a badge we have not earned. We do not promise an uptime percentage, a disaster recovery guarantee or 24/7 support. If any of that changes, this section changes with it, and not before.
No system is perfectly secure. What we owe you is honesty about where we stand, and prompt telling when something goes wrong.
Legal retention exceptions
A request to erase data is not always a duty to erase everything at once. Where another law requires us to keep a record, that requirement takes precedence over an ordinary deletion request, and we keep it.
We may therefore retain certain information after an account closes, or after an erasure request, where retention is required to meet a legal, tax, accounting, audit, fraud-prevention, security or regulatory obligation. Anything kept on that basis is restricted to the purpose that required it — it is not used for anything else — and it is deleted once the applicable period expires.
We do not state a number of years here. The retention period that applies to invoices and accounting records under Indian tax law depends on interpretation we are not qualified to publish as fact, so the honest statement is: for the period required under applicable Indian law, and no longer.
How that works out, in practice:
| Student profiles | Deleted under our retention schedule |
|---|---|
| Parent and guardian profiles | Deleted under our retention schedule |
| Attendance records | Deleted after the retention period |
| Daily reports and photographs | Deleted after the retention period |
| Messages and announcements | Deleted after the retention period |
| Support conversations | Deleted after the retention period |
| Invoices | Kept while law requires it |
| GST records | Kept while law requires it |
| Accounting entries | Kept while law requires it |
| Payment records | Kept while law requires it |
| Audit and security logs | Often kept longer, for legal and security reasons |
If you want to know what is still held about a particular child after an erasure request, ask the Grievance Officer named below and we will tell you what remains and why.
If there is a data breach
If personal data we hold is lost, exposed, or accessed by someone who should not have it, we treat that as a breach whether or not harm is proven.
- For platform data, we tell the affected school without undue delay, and in any case within 72 hours of becoming aware, with what we know: what happened, what data was involved, what we have done, and what we advise. The school, as Data Fiduciary, must then intimate the Data Protection Board of India and every affected Data Principal, as the DPDP Act requires. We give the school whatever it needs to do that, including records from the audit trail.
- For demo enquiries from this website, we are the Data Fiduciary, so the duty is ours: we contact the affected people directly, because there is no school in between, and we intimate the Data Protection Board of India ourselves in the form and time the DPDP Act and its rules require.
We will not delay telling you while we work out how it looks.
Children’s data under Section 9 of the DPDP Act
Under the DPDP Act a child is anyone under the age of eighteen. Every student record in this platform is therefore a child’s record, and nearly all of them belong to children under six. This service exists for preschools and the children in them, and we make no pretence otherwise. Section 9 sets specific limits, and they apply to us in full:
- Verifiable parental consent comes first. A child’s data may be processed only with the verifiable consent of the parent or lawful guardian. The school obtains it, the consent ledger records it, and the media gate enforces it.
- No behavioural tracking or monitoring of children. We do not track, profile or behaviourally monitor any child. There is no behavioural analytics in the platform, no profiling engine, and no third-party tracking code. A daily report written by a teacher is a note to a parent about their own child, not surveillance, and it is visible only to that child’s guardians and to the staff the school authorises.
- No targeted advertising directed at children. There is no advertising in the platform at all, targeted or otherwise. We will not introduce any, and we will not sell or supply children’s data to anyone who advertises.
- Nothing likely to harm a child’s wellbeing. We do not process a child’s data in any way likely to have a detrimental effect on their wellbeing.
We also do not use children’s data to train machine learning models, and we do not mine it for our own product research.
Changes to this policy
We will update this policy when what we do changes — a new sub-processor, a real server endpoint behind the demo form, a security control that becomes true. The date at the top always shows when it last changed.
If a change materially affects a school, or the children whose records it holds, we tell the school in writing before it takes effect rather than quietly editing this page. Schools should pass that on to parents, since the school owns that relationship.
Governing law
This policy is governed by the laws of India. The courts at Pune, Maharashtra have exclusive jurisdiction over any dispute arising from it. This matches the position in our terms of service.
Grievance Officer
Under Rule 5(9) of the SPDI Rules, 2011 and Section 13 of the DPDP Act, we name a Grievance Officer. If you have a complaint about how your data, or your child’s data, has been handled, write to them.
| Grievance Officer | Prashant Sambhaji Chavan |
|---|---|
| admin@tantradev.com | |
| Phone | +91 92703 85626 |
| Address | C1304, C1305, 41 Evoke, Ravet, Pune, Maharashtra 412101, India |
| We respond within | 30 days of receiving your complaint |
We acknowledge every complaint and answer it within 30 days of receiving it. If your complaint is about a child’s records on the platform, please write to the school as well — the school is the Data Fiduciary and can usually resolve it fastest. If our answer does not satisfy you, you may take the matter to the Data Protection Board of India.