← Back to Home
Data Protection
Last updated: April 4, 2026
Our Commitment
At bloometrics, protecting student and parent data is not just a legal requirement — it is a core principle. We handle data belonging to children, and we take that responsibility seriously.
Data Architecture
- Complete School Isolation: Each school's data is fully isolated. There is no cross-school data access at any level.
- Role-Based Access: Teachers see only their assigned classes. Parents see only their own child. Principals see their entire school. No exceptions.
- Row-Level Security: Database-level enforcement ensures data isolation cannot be bypassed by application code.
- No Shared Identifiers: Public links use UUIDs — no personally identifiable information appears in URLs.
Infrastructure Security
- India-Based Servers: All data is stored and processed on servers located in India
- Encryption in Transit: All data transmitted between users and our servers is encrypted using TLS 1.2+
- Encryption at Rest: Database storage is encrypted at rest
- Authentication: Google OAuth 2.0 with PKCE flow, or bcrypt-hashed passwords
- No Local Storage of Sensitive Data: The application does not cache sensitive student data in browser storage
Data Minimization
We only collect data that is directly necessary for the service:
- No photographs or videos of children
- No biometric data
- No Aadhaar or government ID numbers
- No financial information
- No location tracking
Data Retention & Deletion
- Schools own all their data and can request full export at any time
- Upon service termination, all data is permanently deleted within 30 days
- Parents can request deletion of their feedback submissions through the school
Third-Party Access
We do not share, sell, or provide access to any student or parent data to third parties. Our infrastructure providers process data solely to deliver the service.
Contact
Nisha Kondi
Email: kbnisha29@gmail.com
Phone: +91-9951701580
NIYAMKAVACH AI LABS PRIVATE LIMITED, Bengaluru, India