Privacy Policy
Last updated: 18 Jul 2026
1. Scope and legal entity
This Privacy Policy explains how personal data is handled when educational institutions and their authorised users use Campate for attendance management, academic administration, notifications, reporting, billing, and related services.
Campate is a product of Exciton Technologies LLP. Campate is the product name, and Exciton Technologies LLP is the legal entity that provides and operates the service described in this policy. References to “we”, “us”, or “Campate” mean Exciton Technologies LLP unless the context requires otherwise.
This policy is intended to align with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), rules framed under it, and other applicable Indian laws. Where another law is more specific (for example telecom, education, or messaging-platform rules), that law also applies.
2. Roles under the DPDP Act
Under the DPDP Act:
- Data Principal means the individual to whom personal data relates (for example a student, parent, guardian, faculty member, or staff user).
- Data Fiduciary means the person who alone or with others determines the purpose and means of processing personal data.
- Data Processor means a person who processes personal data on behalf of a Data Fiduciary.
Educational institutions that use Campate typically act as Data Fiduciaries for personal data they decide to collect and process for academic and administrative purposes (for example student rolls, attendance, parent contacts, and when to send notifications). Institutions determine what data is entered, why it is processed, and who may access it within their organisation.
Exciton Technologies LLP acts as:
- a Data Processor when we process institutional personal data on the institution’s instructions to provide Campate (hosting, storage, workflows, notifications, reports, support); and
- a Data Fiduciary for personal data we determine the purposes of independently—such as account registration for institutional users, authentication, security logs we control, billing and subscription records for the contracting institution, product analytics limited to operating and improving the service, and Platform Data we receive from third-party platforms (including Meta) in connection with operating Campate’s integrations.
DPDP Act responsibilities for notices, lawful basis, and data-principal rights for institutional records primarily sit with the institution. We support institutions in meeting their obligations through product features and reasonable assistance.
3. Personal data we may process
Depending on institutional configuration and product features in use, Campate may process:
- identity and contact data (names, email addresses, phone numbers, roles);
- academic and organisational data (courses, programmes, batches, divisions, schedules, attendance, exam-related records, learning-activity data);
- parent, guardian, and other notification-contact details supplied by the institution;
- notification and messaging logs (channel, status, timestamps, and related delivery metadata);
- user account, authentication, and audit-log data;
- support communications;
- billing and payment-related data (invoices, plan, usage where applicable; card data is handled by payment providers as described below); and
- technical data needed for security and operations (for example IP address, device or browser metadata, and application logs).
Where messaging integrations are enabled (for example WhatsApp, SMS, Telegram, or email), we may process identifiers and content required to send or receive operational messages, including data received from or sent via those platforms’ APIs (such as phone numbers, message identifiers, template metadata, delivery status, and, where a feature requires it, media such as voice notes used for attendance workflows).
4. Purposes of processing
We process personal data for purposes that include:
- providing and securing Campate (accounts, access control, multi-tenant isolation, audit trails);
- attendance, academic administration, reporting, and related institutional workflows;
- sending operational notifications configured by the institution (including SMS, email, WhatsApp, Telegram, or similar channels);
- billing, payments, tax records, and subscription administration;
- customer support and service communications;
- preventing fraud, abuse, and security incidents;
- complying with law and valid legal process; and
- improving reliability, performance, and features of the service in a manner consistent with this policy.
We process personal data for the purposes for which it was collected or for compatible purposes permitted under the DPDP Act and other applicable law. We do not sell personal data.
5. Notice, consent, and lawful use
Institutions should provide required notices to Data Principals and maintain a lawful basis for processing under the DPDP Act and other applicable laws. Institutions are responsible for collecting, recording, maintaining, and proving valid consents, notices, opt-ins, and communication preferences for the contacts they add to Campate. This includes consent or authorisation from parents, lawful guardians, students, staff, or other recipients where required by law, institutional policy, telecom rules, or messaging-platform policies.
Where we act as Data Fiduciary (for example institutional user accounts and billing), we process personal data as needed to provide the service requested by the contracting institution, to perform our contract, to meet legal obligations, and for legitimate uses recognised under applicable law.
Institutions must keep consent and communication records current, honour opt-outs and withdrawals, and avoid uploading or using contact details where they do not have a valid basis to communicate.
6. Children and persons with disability
Campate is used by educational institutions that may process personal data of children (as defined under the DPDP Act) and other students. Where the DPDP Act or other law requires verifiable consent of a parent or lawful guardian, or other safeguards for children or persons with disability, the institution is responsible for obtaining and maintaining that consent or authorisation before using Campate to process such data or send related communications.
We do not knowingly use Campate to target children with advertising. Features are designed for institutional academic and administrative operations.
7. Communications and WhatsApp
Campate may use SMS, email, WhatsApp, Telegram, or similar messaging channels for operational notifications. Message delivery may involve third-party platforms (including Meta for WhatsApp) and their applicable terms, business policies, and data processing terms. Institutions should ensure recipients have been appropriately informed and, where needed, have opted in or consented to receive such messages.
Campate processes communication data based on institutional instructions and configuration. To the maximum extent permitted by law, Campate is not responsible for an institution’s failure to collect, maintain, update, or evidence required consent, or for communications sent to contacts that the institution has provided without proper authorisation.
Data obtained through Meta or other platform APIs (for example access tokens, phone-number identifiers, message metadata, webhook payloads, and media required for a product feature) is used only to operate the requested integration and related security, logging, and support functions—not for selling data or unrelated advertising by Campate.
8. Payments
Payment data may be processed by third-party payment gateways, payment aggregators, banks, or other payment service providers. Campate should not store full card numbers or sensitive payment authentication data unless expressly stated and legally permitted. Payment providers may run fraud, KYC, settlement, refund, dispute, failed-payment, tax, and compliance processes under their own terms.
9. Sharing, processors, and cross-border transfers
We may share personal data with service providers who process data on our behalf or as independent providers where necessary to operate Campate, including hosting providers, communication providers (for example SMS, email, WhatsApp/Meta, Telegram), AI or speech-to-text providers used for specific features (for example parsing voice attendance input), support tools, analytics or monitoring tools, payment providers, and professional advisers.
We expect service providers to process data under appropriate confidentiality, security, and contractual controls, and only for the purposes we instruct or that are necessary to provide their service.
Personal data may be stored or processed in India or in other countries where our service providers operate. Where cross-border transfer is restricted by law or government direction under the DPDP Act framework, we will take steps reasonably required to comply. Institutions that require data residency commitments should agree those in writing with us.
10. Legal, safety, and compliance disclosures
We may preserve, disclose, restrict, or process data where required or permitted by applicable law, court order, government or regulatory direction, law-enforcement request, payment-provider requirement, messaging-platform requirement, or other legally valid process. We may also process data to investigate misuse, prevent fraud, protect platform security, enforce terms, or protect students, institutions, users, and the service.
11. Requests from public authorities
When we receive a request from a public authority, court, regulator, or law-enforcement agency for personal data or other information held in connection with Campate, we apply the following processes, subject to applicable law (including any lawful non-disclosure or secrecy obligations):
- Legality review. We review whether the request appears to be issued by a competent authority and supported by a valid legal basis under applicable Indian law or other binding process before disclosing personal data, except where immediate action is required by law or to prevent imminent harm.
- Challenge of unlawful or overbroad requests. Where we reasonably consider a request unlawful, incomplete, or overbroad, we may seek clarification, request narrowing of scope, object, or challenge the request through appropriate legal channels, to the extent permitted by law.
- Data minimisation. We disclose only the personal data and related information that is reasonably necessary to satisfy a valid request, and not bulk access by default.
- Documentation. We maintain internal records of such requests, our assessment of legal basis, what was disclosed or refused, and the personnel involved in handling the request, for so long as needed for legal compliance, audit, and defence of legal claims, unless law prohibits such records.
Where the request concerns data controlled by an educational institution as Data Fiduciary, we may notify or coordinate with the institution unless we are legally prohibited from doing so or notification would create a risk of harm or obstruction of lawful process.
12. Security and retention
We use reasonable technical and organisational safeguards to protect personal data against unauthorised access, loss, misuse, or alteration, having regard to the nature of the data and the risks involved. No method of transmission or storage is completely secure. Institutions should configure access carefully, use strong authentication where available, and remove users who no longer need access.
We retain personal data only as long as needed for the purposes described in this policy, including service delivery, legal compliance, dispute handling, security, audit requirements, or institutional instructions, after which we delete or de-identify it where reasonably practicable, subject to backup and legal hold constraints.
13. Rights of Data Principals and grievance redressal
Under the DPDP Act and other applicable law, Data Principals may have rights such as the right to access information about processing, seek correction and erasure of personal data, withdraw consent where processing is based on consent, and nominate another person in accordance with applicable rules, subject to legal exceptions and the roles described in this policy.
For personal data processed by an educational institution as Data Fiduciary (for example student and parent records entered by the institution), requests should usually be directed first to that institution. We may assist institutions in responding to valid requests.
For personal data for which Exciton Technologies LLP is the Data Fiduciary, or where we are required to assist, contact us using the details below. We will respond within a reasonable period and as required by applicable law.
Grievance redressal. Data Principals may raise privacy grievances with us at the contact below. If a grievance is not resolved to your satisfaction, you may have the right to approach the Data Protection Board of India or other competent authority under applicable law once those mechanisms are available and applicable to your request.
14. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may be communicated through the service, email, or our website where appropriate. Continued use of Campate after an update constitutes notice of the revised policy to institutional users, without limiting rights that cannot be waived under law.
15. Contact
For privacy questions, Data Principal requests that we handle, or grievances related to personal data processing by Exciton Technologies LLP in connection with Campate, contact:
Exciton Technologies LLP
Email: sales@campate.com
Jurisdiction: India (see also our Terms of Service for governing law and courts at Kottayam, Kerala)