Legal

Privacy Policy

Effective date: September 1, 2025  ·  E2X Infotech Private Limited

1. Overview

E2X Infotech Private Limited (“we”, “our”, or “us”) operates E2X Education, a school management platform accessible via web at hubpanel.e2xhub.cloud and via the E2X Education mobile application for Android and iOS (collectively, the “Platform”).

This Privacy Policy explains how we collect, use, store, share, and protect information about schools, their administrators, teachers, students, and parents who use our Platform. By using E2X Education, you agree to the practices described in this Policy.

If you are a school administrator entering data about students or parents, you are responsible for informing those individuals that their data is being processed through E2X Education and for obtaining any consent required under applicable law.

2. Data We Collect

2.1 School and Account Data

When a school registers on the Platform, we collect: school name, address, board affiliation, contact person name, email address, phone number, and school logo.

2.2 User Account Data

For all user accounts (School Admin, Teacher, Student, Parent, Guard/Gate Staff), we collect: full name, email address, phone number, WhatsApp number (optional), profile photo (optional), role, and encrypted password. We also log the timestamp of the last login and whether the email has been verified.

2.3 Student Records

School administrators enter comprehensive student records including:

  • Personal details: full name, date of birth, gender, photograph, blood group, nationality, religion, caste/category
  • Government identification numbers: Aadhaar number, mother’s Aadhaar number, father’s Aadhaar number, PEN number, APAAR ID
  • Family details: father’s name and occupation, mother’s name, guardian’s name and education
  • Contact information: parent phone number, parent email, WhatsApp number
  • Address: present address, permanent address, PIN code, distance from school
  • Academic information: admission number, roll number, class, section, academic year

Important: Government ID numbers (Aadhaar) are collected solely for school admission compliance requirements as mandated by Indian regulatory bodies. We do not share these numbers with any third party except as required by law.

2.4 Teacher and Staff Records

Employee number, qualification, experience, date of joining, department, designation, assigned subjects and classes.

2.5 Operational Data

We collect and store operational data generated through platform use, including: attendance records, examination marks and results, fee payment records (amount, date, transaction ID, receipt number), homework submissions, leave requests, timetable entries, and school announcements.

2.6 Communication Logs

When SMS or push notifications are sent through the platform, we log the message content, recipient phone numbers or device tokens, delivery status, and timestamp. This log is retained to enable delivery confirmation and troubleshooting.

2.7 Device and Technical Data (Mobile App)

The E2X Education mobile app collects: device model, operating system version, device ID (used solely to generate an encryption key for local secure storage), and Firebase Cloud Messaging (FCM) token (used solely to deliver push notifications). We do not collect precise location, contact lists, browser history, or any data beyond what is described here.

2.8 Authentication Tokens

JWT access tokens are stored in browser cookies (web) and encrypted MMKV storage (mobile app). Refresh tokens are stored in our database in hashed form. Tokens expire automatically and are deleted on logout.

3. AI Voice Agent Data Processing

E2X Education includes an AI Voice Agent feature that allows authorised school users to query school data using spoken commands. When the AI Voice Agent is used, the following data processing occurs:

  • Audio recording: The mobile app records your spoken query as an audio file (M4A format) and transmits it to our backend server over an encrypted HTTPS connection. The audio is processed immediately and is not stored on our servers by default (unless the school administrator has explicitly enabled audio persistence via the VOICE_AGENT_PERSIST_AUDIO setting).
  • Speech-to-text via Sarvam AI: Your audio is sent to Sarvam AI’s speech-to-text API for transcription. Sarvam AI processes the audio to produce a text transcript. The audio is sent solely for this purpose. Sarvam AI’s use of the audio is governed by their privacy policy.
  • Reasoning via Google Gemini: The text transcript (not the audio) is sent to Google’s Gemini API along with a system prompt describing the school’s data context. Gemini uses this to determine what school data to retrieve and to generate a spoken response. No raw student PII (such as Aadhaar numbers) is sent to Gemini. Structured summaries (e.g., attendance counts, fee dues) are used.
  • Conversation history: Voice conversation turns (the text transcript of your query and the assistant’s text response) are stored in your school’s database for session continuity. These records can be deleted by the school administrator.

Microphone access on the mobile app is used only when you actively trigger the Voice Agent. We do not listen passively or record in the background.

4. Third-Party Services and Sub-Processors

We use the following third-party services to operate the Platform. Each service receives only the data necessary for its specific function:

ServicePurposeData Shared
Firebase (Google)Push notification deliveryFCM device token, notification title and body
RazorpayOnline fee payment processingStudent name, fee amount, order reference (no card data — handled entirely by Razorpay)
Sarvam AIVoice-to-text transcriptionAudio recording of voice query (transient, not retained by default)
Google GeminiAI reasoning for voice agentText transcript of query, structured school data summaries (no Aadhaar or raw PII)
MSG91 / HSP SMSSMS delivery to parents and staffRecipient phone number, message text
Nodemailer / SMTPTransactional email (password reset)Recipient email address, message content

We do not use any third-party analytics services (Google Analytics, Mixpanel, etc.), crash reporting services (Sentry, Bugsnag, etc.), or advertising networks. No data is sold to third parties.

Payment data: We do not store card numbers, CVV codes, or bank account details. All payment card processing is handled exclusively by Razorpay on their servers. We receive only a payment ID and cryptographic signature to confirm a successful transaction.

5. Data Storage and Security

All school data is stored in a MySQL relational database hosted on our managed servers in India. Uploaded files (student photographs, documents) are stored on the same server infrastructure. We do not currently use cloud storage services (S3, Google Cloud Storage, etc.) for user-uploaded files.

Data in transit is encrypted using TLS (HTTPS). Authentication tokens on the mobile app are stored in MMKV encrypted storage, with the encryption key derived from the device hardware ID. We implement role-based access control to ensure users can only access data appropriate to their role within their own school.

Each school’s data is stored in a logically isolated database. No school can access another school’s data. System administrators at E2X Infotech can access all school databases for the purpose of support, maintenance, and legal compliance only.

6. Data Retention

We retain personal data for as long as a school’s account is active on the Platform, plus a reasonable period afterward to allow for dispute resolution and regulatory compliance.

  • Active account data: retained for the duration of the subscription
  • After account termination: data is retained for up to 90 days before secure deletion, unless a longer period is required by law
  • Financial records (fee payments, receipts): retained for 7 years as required by Indian tax and audit regulations
  • Government ID data (Aadhaar): retained only for the period required by applicable school admission regulations
  • Voice conversation transcripts: retained as long as the school account is active; can be deleted by the school administrator at any time
  • FCM device tokens: deleted immediately on logout or when the token is reported as invalid by Firebase

7. Your Rights

Subject to applicable law, users and the schools who act as data controllers have the following rights:

  • Access: Request a copy of personal data we hold about you or your school
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your account and associated data (see our Data Deletion page)
  • Portability: Request your school’s data in a portable format
  • Objection: Object to processing where we rely on legitimate interest as the legal basis

To exercise any of these rights, contact us at privacy@e2xinfotech.com. We will respond within 30 days.

Account and data deletion: You may request deletion of your account and all associated data via our Data Deletion Request page. Upon verification, we will delete your data within 30 days, except where retention is required by law (e.g., financial records).

8. Children's Privacy

E2X Education is an institutional platform used by schools. Student records — including records of minors — are entered by authorised school administrators, not directly by students or their parents. Schools are responsible for obtaining appropriate consent from parents or guardians before entering a student’s information into the Platform.

We do not knowingly collect personal information directly from children under 13 years of age. If you believe a child’s data has been entered without appropriate consent, please contact us at privacy@e2xinfotech.com.

9. Security Measures

We implement the following technical and organisational security measures:

  • All passwords are stored as bcrypt hashes; plaintext passwords are never stored
  • All data in transit is encrypted via TLS 1.2 or higher
  • JWT access tokens have a short expiry; refresh tokens are hashed before storage
  • Mobile app tokens are stored in encrypted MMKV storage (hardware-bound key)
  • Role-based access control prevents cross-school data access
  • Automated database backups are performed regularly
  • Server access is restricted to authorised personnel only

Despite these measures, no system is 100% secure. In the event of a data breach that affects your personal data, we will notify affected schools in accordance with applicable law.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify school administrators via email or in-app notification. Your continued use of the Platform after such changes constitutes acceptance of the updated Policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact:

E2X Infotech Private Limited

Unit 207, Tower B, ITHUM TOWER, Block A, Industrial Area, Sector 62, Noida, Uttar Pradesh 201309, India

Email: privacy@e2xinfotech.com

General: e2xinfotech@gmail.com

Phone: +91 97921 31452