Privacy Policy

Effective Date: January 1, 2026

Last Updated: August 13, 2026

We prioritize data protection and confidentiality above all else—especially regarding the data of minors. We commit to:

  • Zero Commercial Exploitation: We do not sell, rent, lease, or trade personal data or student data to any third party for marketing, advertising, or profiling.
  • Strict Customer Data Isolation: We maintain multi-tenant separation to ensure one educational customer's data is never accessible by or combined with another customer's data.
  • Absolute Protection of Minors: Student data is processed strictly for educational purposes and handled with maximum privacy safeguards.

1. Introduction & Scope

EdOptimize ("Company", "we", "us", or "our"), headquartered in India, is the creator and operator of Smart Paper technology. We provide educational technology (EdTech) solutions designed to facilitate learning, assessment, grading, and educational management for institutions, teachers, parents, and students. This Privacy Policy applies to all personal data collected, stored, processed, or transferred across our platform, websites (including www.getsmartpaper.com and www.edoptimize.com), applications, and associated services (collectively, the "Services").

2. Our Role: Data Processor vs. Data Fiduciary / Controller

When acting on behalf of Educational Institutions: Where an educational institution (school, district, or university) licenses Smart Paper or EdOptimize services, the institution acts as the primary Data Fiduciary (India) / Responsible Party (South Africa) / Data Controller (Global). EdOptimize acts as the Data Processor / Operator, processing student and educator data strictly according to the institution's contractual instructions.

When serving End-Users Directly: For direct sign-ups by parents, teachers, or adult users, EdOptimize acts as the Data Fiduciary / Responsible Party.

3. Information We Collect

We adhere strictly to the principle of data minimality—collecting only what is strictly necessary to deliver, maintain, and secure our educational services.

  • Student / Minor Data: Name, grade/class level, student ID number assigned by the school; assessment results, responses, academic evaluations, grading records, and performance analytics generated through Smart Paper technology.
  • Parent / Legal Guardian Data: Name, email address, phone number, and communication preferences.
  • Educator / School Staff Data: Name, professional email address, institutional affiliation, class rosters, and teaching assignments.
  • Technical & System Usage Data: IP address, system logs, device identifier, browser type, and diagnostic performance metadata required for platform security and operational stability.

4. Protection of Minors & Children's Data

Because our technology is used in primary and secondary education environments, we apply heightened protections for children and minors:

  • Verifiable Consent: Minors' data is processed only with explicit, verifiable consent obtained from a parent, legal guardian, or authorized school administration acting on behalf of the parent.
  • No Profiling or Targeted Ads: We do not build behavioral profiles of students for non-educational purposes, nor do we serve targeted ads, native ads, or third-party marketing within the platform.
  • Absolute Secrecy & Strict Isolation: Student data is encrypted, logically separated by institution, and strictly restricted from unauthorized access, cross-customer analytics, or external exposure.

5. How We Use Information (Purpose Specification)

Data collected by EdOptimize is used exclusively for legitimate educational and operational purposes:

  • Processing and grading student assessments via Smart Paper technology.
  • Generating academic progress reports for authorized educators and parents.
  • Providing operational customer support, platform maintenance, and bug fixes.
  • Ensuring cybersecurity, preventing fraud, and verifying authorized platform access.
  • Complying with legal, regulatory, or audit requirements.

6. Strict Data Isolation & Zero Third-Party Sharing

  • Customer Data Separation: All institutional and individual user data is partitioned within isolated cloud database instances or strict row-level security logic, ensuring absolute zero data leakage between different customers or schools.
  • No Selling or Renting: We explicitly pledge that student, parent, and teacher data will never be sold, rented, monetized, or shared with third-party data brokers or advertisers.
  • Sub-Processors / Vendor Contracts: We engage carefully vetted third-party infrastructure providers (e.g., enterprise cloud hosts such as AWS or Google Cloud) to host and operate our services. All such third parties are bound by strict Operator Agreements / Data Processing Agreements (DPAs) requiring them to implement equal or higher security standards and process data solely on our written instructions.

7. Data Security & Technical Safeguards

EdOptimize implements robust technical, organizational, and physical security measures to safeguard personal data, including:

  • Encryption in Transit: All network communication is encrypted using Industry Standard Transport Layer Security (TLS 1.3 / HTTPS).
  • Encryption at Rest: All stored customer and student data is encrypted using advanced encryption standards (e.g., AES-256).
  • Access Control: Strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) ensure that EdOptimize staff access system environments only on a strict need-to-know basis.
  • Data Segregation: Logical database architecture ensures complete customer data isolation.
  • Vulnerability & Audit Monitoring: Regular automated vulnerability scans, logging, monitoring, and penetration testing to preemptively catch security risks.

8. Data Retention & Deletion

We retain personal data only for as long as necessary to fulfill the educational purposes for which it was collected, or as required by law.

  • Account Termination: Upon termination of an agreement with a school or individual user, all associated student and institution data is permanently deleted or anonymized within 90 days, unless retention is explicitly required by applicable law.
  • Right to Request Erasure: Parents, guardians, and educators can request the deletion of their personal data or their child's personal data at any time via their educational institution or by contacting our Data Protection Officer.

9. Rights of Data Subjects / Users

Subject to their local laws, users, parents, and educators have the right to:

  • Access: Request a copy of the personal data held about them or their child.
  • Correction / Rectification: Request correction of inaccurate, incomplete, or outdated data.
  • Erasure / Deletion: Request the deletion of personal data when processing is no longer required.
  • Withdrawal of Consent: Withdraw consent for data processing at any time (subject to applicable legal and contractual conditions).
  • Grievance Redressal: Submit complaints regarding data processing directly to EdOptimize's Grievance / Information Officer.

10. Security Compromises & Breach Protocol

In the event of a security breach affecting personal data:

  • EdOptimize will activate its Incident Response Team immediately to contain, investigate, and remediate the issue.
  • We will notify the relevant data protection authorities (such as the Information Regulator in South Africa and the Data Protection Board in India) as required by law.
  • We will notify affected institutions, parents, or users without undue delay, outlining the nature of the breach, potential consequences, and corrective actions taken.

11. Changes to this Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our technology, regulatory updates, or operational requirements. Any material changes will be communicated through our website, directly via email, or through administrative notifications within the Smart Paper platform.

12. Contact & Grievance Information

For any questions, requests for data access/deletion, or concerns regarding this Privacy Policy, please contact our Data Protection Team:

  • Company Name: EdOptimize (Creator of Smart Paper)
  • Grievance Officer (India) / Information Officer (South Africa): Nirmal Patel
  • Email: nirmal@edoptimize.com
  • Website: www.edoptimize.com | www.getsmartpaper.com
  • Corporate Address: C-13, Shop 1, Snehkunj Society, Panchvati, Vadodara, Gujarat - 390016 (India)

Jurisdiction-Specific Addendums

Addendum A: India (Primary Jurisdiction)

Governed by the Digital Personal Data Protection Act, 2023 (DPDPA).

  • Consent of Minors (Children < 18 Years): For users under 18 years of age, processing is performed only after obtaining verifiable consent from a parent or legal guardian (or through authorized educational institutions acting under lawful authority).
  • No Harmful Processing / Tracking: EdOptimize does not perform tracking, behavioral monitoring, or targeted advertising directed at children.
  • Data Fiduciary Duties: EdOptimize maintains effective mechanisms for notice, consent withdrawal, data correction, and grievance redressal as required under the DPDPA.
  • Right to Approach Data Protection Board: Users in India have the right to approach the Data Protection Board of India if grievances are not resolved satisfactorily by our Grievance Officer within legal timelines.

Addendum B: South Africa

Governed by the Protection of Personal Information Act 4 of 2013 (POPIA). In accordance with POPIA regulations enforced by the Information Regulator (South Africa), EdOptimize guarantees the following:

  • Information Officer: EdOptimize has designated and registered an Information Officer responsible for enforcing POPIA compliance within the organization.
  • Processing Conditions (Sections 8–13): Accountability – EdOptimize takes active responsibility for compliance; Processing Limitation & Minimality – data is processed lawfully, minimally, and transparently; Specific Purpose – data is collected solely for designated EdTech and educational functionalities.
  • Processing Special Personal Information & Children's Data (Sections 26 & 34–35): Processing of special personal information or children's personal information is strictly carried out with explicit consent from a competent person (parent/legal guardian) or under statutory educational justification.
  • Operator Agreements (Section 21): All third-party infrastructure sub-processors sign formal written agreements binding them to maintain POPIA-compliant security standards.
  • Cross-Border Transfers (Section 72): Where data is transferred or hosted outside South Africa (e.g., enterprise cloud nodes), EdOptimize ensures that the recipient country provides adequate data protection laws or that binding agreements/explicit consent cover the transfer.
  • Security Compromise / Breach Notification (Section 22): In the event of a suspected or actual security breach involving personal information, EdOptimize will notify the Information Regulator (South Africa) and affected data subjects/institutions as soon as reasonably possible, via digital notification and our incident response workflow.
  • Complaints to Information Regulator: South African users have the right to lodge complaints directly with the South African Information Regulator at complaints.IR@inforegulator.org.za.

Addendum C: Global & Rest of World

Governed by General Data Protection Standards (e.g., GDPR principles).

  • Lawful Basis: Data processing is conducted based on performance of contract (delivering Smart Paper services), explicit consent, or legitimate interest in maintaining educational continuity and platform security.
  • International Data Transfers: International transfers are governed by standard contractual clauses (SCCs) or equivalent adequacy protections.
  • Universal Non-Discrimination: Users exercising privacy rights will receive equal service without bias, discrimination, or service degradation.

By using our service, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.