Your students’ data is not our asset.
We act as a data processor under your institution’s instruction. That is not a marketing line — it determines what we are architecturally able to do, and it is the reason we cannot offer you a cross-sector benchmark.
What is architectural, not contractual.
Each of these is a property of how the platform is built rather than a policy we could quietly revise. That distinction matters when you are assessing a vendor.
Which law applies, and what we do about it.
| Framework | Our role | What we provide |
|---|---|---|
| DPDP Act, 2023 (India) | Data Processor; your institution is the Data Fiduciary | Processing agreement, India residency, breach notification within 72 hours, assistance with data principal requests |
| FERPA (United States) | School Official under the institution’s direct control | Written agreement, use limited to the stated purpose, no redisclosure |
| GDPR (EU/EEA students) | Processor under Article 28 | DPA with SCCs where required, records of processing, DPIA support |
| Institutional policy | Whatever your policy defines | We enforce your retention, visibility and access rules rather than substituting ours |
We are not a law firm and this table is not legal advice. It describes our operating posture so your counsel has something concrete to assess. Our DPA and security questionnaire responses are available on request to info@eduplatter.com.
The unglamorous part.
Encryption and access control are table stakes, and any vendor will claim them. The controls that actually differ between vendors are the ones about who inside the company can see student records, and under what circumstances.
Named individuals, time-boxed, logged
Production access to institutional data requires a ticket, expires automatically, and is logged in a record your institution can request. There is no standing engineering access to student records.
In transit and at rest
TLS 1.3 in transit; AES-256 at rest with keys managed in a hardware security module. Per-tenant key separation on dedicated deployments.
Per-institution tenancy
Logical isolation as standard, dedicated tenant or on-premises on System engagements. No shared analytical layer across institutions.
On instruction, verified
Deletion on your instruction or at contract end, with written confirmation and backup expiry within 35 days.
Listed, and you are notified
The current list is in the DPA. Material changes come with 30 days’ notice and a right to object.
Honest limits.
Written here because a security page that only lists strengths is not useful to the person evaluating it.
We are not certified to ISO 27001 yet
We operate to its control set and can share our internal assessment, but we do not hold the certificate. If your procurement requires one, say so early — it may be a blocker and we would rather you know in week one than month three.
We cannot fix upstream data quality
If attendance is recorded on paper in half your departments, our models will be weaker for those students. We report that in the validation phase rather than imputing quietly.
Shared notes create a real privacy tension
Cross-department visibility is useful for coordination and risky for students. We default to the narrowest sensible setting and require an explicit institutional decision to widen it, but the call is yours.
Predictions can be wrong about individuals
A model with good aggregate precision still misclassifies people. That is why we refuse to wire a risk score to an automatic consequence, and why every prediction shows its factors.
Send us your security questionnaire.
We answer institutional questionnaires directly and will flag gaps rather than working around the question.