Privacy Policy
Indus Valley World School
Effective date: 11 August 2026 | Last updated: 11 August 2026
1. Scope
This Privacy Policy explains how Indus Valley World School (“IVWS”, “the School”, “we”, “us” or “our”) collects, receives, records, organises, stores, uses, shares, secures, retains and deletes personal data. It applies to:
- the School’s website at www.ivwschool.com, online forms, admission enquiries, chatbot, portals, payment links and related digital services;
- prospective, current and former students; parents; lawful guardians; authorised representatives; emergency contacts; alumni; employees; applicants; vendors; visitors and other individuals who interact with the School; and
- personal data initially collected offline that is subsequently digitised.
This Policy is intended to support compliance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) as their provisions become applicable, the Information Technology Act, 2000 and applicable rules, and, where it applies to particular processing, the EU General Data Protection Regulation (“GDPR”). If a more specific notice is supplied for a form, programme, portal, event, photograph, health service or other activity, that notice should be read with this Policy.
2. Who is responsible for personal data
For the processing described in this Policy, Indus Valley World School acts as the “Data Fiduciary” under Indian data-protection law and, where the GDPR applies, as the “data controller”, unless a separate notice states otherwise.
Indus Valley World School488, Ajoy Nagar, Eastern Metropolitan By-Pass
Near Peerless Hospital, Behind Satyajit Ray Film Institution
Kolkata – 700094, West Bengal, India
Telephone: 033-7120-5250
Mobile: +91 98301 66042 / +91 93314 12464
Email: admissions@ivws.org
3. Personal data we may collect
We collect only personal data that is reasonably necessary for a stated purpose. Depending on your relationship with IVWS, this may include:
- Identity and contact data: names, date of birth, age, gender where relevant, photographs, postal address, email address, telephone number, parent/guardian details, relationship to the child, emergency contacts, signatures and government-issued identifiers where required or permitted by law.
- Admissions and educational data: class sought, academic year, application details, previous-school information, academic records, assessments, attendance, learning progress, examination results, co-curricular participation, achievements, behaviour, discipline, educational support and communications about the student.
- Health, accessibility and safeguarding data: allergies, medical conditions, medication, disability or accessibility requirements, dietary needs, accident and first-aid records, counselling or safeguarding information, and other information necessary to protect a student’s health, safety or welfare.
- Financial and transaction data: fee status, invoices, receipts, concessions or scholarships, bank or transaction references and payment status. Payment-card, UPI or banking credentials are generally processed directly by authorised payment providers; the School normally receives confirmation and transaction details rather than complete payment credentials.
- Transport, access and security data: bus route and stop, transport attendance, GPS-derived vehicle location, access records, visitor logs, CCTV footage, incident reports and device or account login information.
- Media and communications: photographs, audio or video recordings, artwork, testimonials, event participation, emails, telephone records where lawfully recorded, form submissions, chatbot conversations, feedback and grievance correspondence.
- Website and technical data: internet protocol (IP) address, browser and device information, operating system, approximate location derived from IP, referring and exit pages, website activity, cookie identifiers, timestamps, security logs and consent preferences.
- Employment and vendor data: qualifications, work history, references, background-verification data, payroll or payment information, tax identifiers, attendance, performance, contracts and business contact details.
We will not ask for Aadhaar or another government identifier unless its collection is authorised, necessary and proportionate for a lawful purpose. Where such an identifier is collected, access and disclosure will be restricted and masking or redaction will be used where appropriate.
4. How we obtain personal data
We may obtain personal data:
- directly from a student, parent, guardian, employee, applicant, visitor or vendor;
- through website forms, admission forms, the School office, emails, calls, portals, payment services, events, surveys or the chatbot;
- from a previous school, examination body, reference provider, health professional, transport provider, authorised representative or government authority, where lawful and relevant;
- from School systems and activities, including attendance, assessments, CCTV, transport, access-control and information-security logs; and
- from publicly available sources or social-media interactions where appropriate and lawful.
If you provide another person’s personal data, you must be authorised to do so, ensure the data is accurate, and make this Policy or the relevant privacy notice available to that person.
5. Why we process personal data and the applicable grounds
Under the DPDP Act, we process digital personal data with valid consent or for another use permitted by law. Where the GDPR applies, we rely on one or more grounds under Articles 6 and 9, as appropriate.
| Purpose | Typical data | Grounds relied upon, as applicable |
|---|---|---|
| Responding to enquiries, arranging campus visits and processing applications | Contact, child’s age/class, prior-school and application information | Consent; processing requested before entering an educational relationship; legitimate use or legitimate interests |
| Providing education and student services | Student records, attendance, assessment, support, activities and communications | Performance of the educational relationship; consent or verifiable parental consent where required; legal obligations; legitimate use or legitimate interests |
| Protecting health, welfare, safeguarding and campus or transport safety | Health, emergency, CCTV, visitor, incident, transport and GPS data | Consent or explicit consent where required; vital interests; legal obligations; substantial public interest where applicable; legitimate use or legitimate interests |
| Collecting fees, maintaining accounts and preventing fraud | Billing, transaction, scholarship and accounting records | Contractual necessity; consent where required; legal obligations; legitimate use or legitimate interests |
| Communicating notices, schedules, emergencies and service information | Parent/student contact information and preferences | Performance of services; legal obligations; legitimate use or legitimate interests; consent for optional promotional messages |
| Publishing achievements, events and School communications | Name, class, achievement, photograph, audio or video | Consent or verifiable parental consent where required; legitimate interests for limited internal or documentary uses, subject to individual rights and child-safety safeguards |
| Operating, securing and improving the website and digital services | Technical, usage, security, cookie and chatbot data | Consent for non-essential cookies; legitimate use or legitimate interests for security and essential functionality; legal obligations |
| Recruitment, employment, procurement and vendor management | Applicant, employee and business-contact data | Contractual necessity; legal obligations; consent where required; legitimate use or legitimate interests |
| Responding to complaints, legal claims, audits and authorities | Relevant records, correspondence and evidence | Legal obligations; establishment, exercise or defence of legal claims; legitimate use or legitimate interests |
When consent is the basis of processing, it will be requested through a clear affirmative action and may be withdrawn as described below. Withdrawal does not affect processing that was lawful before withdrawal and may limit an optional service that requires the relevant data. Core educational records may continue to be processed where another lawful ground applies.
6. Children’s privacy and parental consent
The School processes children’s personal data as an essential part of providing education and maintaining student welfare and safety. Under the DPDP Act, a child is a person under 18 years of age. Before processing a child’s personal data, we obtain verifiable consent from a parent or lawful guardian where the law requires it, and take reasonable steps to verify that the person giving consent is an adult and has parental responsibility or lawful guardianship.
We apply the following child-specific safeguards:
- we collect only data reasonably required for admissions, education, administration, health, safety, safeguarding and authorised School activities;
- we do not process children’s data in a manner likely to cause a detrimental effect on their well-being;
- we do not sell children’s personal data or use it for targeted advertising directed at children;
- tracking or behavioural monitoring is not undertaken for advertising and is used only where lawful, necessary and proportionate for educational activities or the safety of students, with suitable notices and safeguards;
- access is limited to authorised personnel and service providers who need the data for an approved purpose; and
- public disclosures are reviewed to reduce risks such as exposing unnecessary location, contact, routine or sensitive information.
Where GDPR Article 8 applies to an online service offered directly to a child, parental authorisation will be obtained below the applicable digital-consent age in the relevant country. As a School policy, we may require parent or guardian involvement for anyone under 18 even where local law permits consent at a younger age.
If a child has submitted personal data without appropriate authorisation, a parent or guardian should contact us. We will investigate and erase or restrict the data when required, unless retention is lawful and necessary.
7. Health data, photographs, CCTV, GPS and biometrics
Health, disability and safeguarding information
Health, disability, counselling and safeguarding information receives heightened protection. It is used only by authorised persons for care, accessibility, safeguarding, emergency response, legal duties or another clearly notified purpose. Under the GDPR, such data may be “special category” data and will be processed only when an Article 9 condition applies.
Photographs, recordings and student work
Photographs, videos, audio, testimonials and student work may be used for identity records, teaching, internal communications, events, yearbooks, the website, social media, publications or publicity. Where consent is required for an optional public or promotional use, we will seek appropriate consent and offer a practical way to withdraw it for future use. Withdrawal cannot always remove material already lawfully printed or disseminated, but we will take reasonable steps for content under our control. Safety, evidential, journalistic, archival or legally required uses may be treated differently where permitted by law.
CCTV and access control
CCTV may operate in identified campus areas and School vehicles for safety, access control, incident investigation and protection of persons and property. CCTV is not intended for private areas where there is a reasonable expectation of privacy. Footage is accessed only by authorised personnel and may be disclosed to law-enforcement authorities, insurers or advisers when lawful and necessary.
School transport and GPS
Transport and GPS information may be used to operate routes, manage boarding and deboarding, inform authorised parents or guardians, respond to emergencies and protect students. Location data is restricted to persons and providers with an operational need and is not used for advertising.
Biometric data
If the School proposes to use biometric data, it will first issue a specific notice describing the purpose, necessity, retention, security and alternatives, and obtain explicit or verifiable parental consent where required. Biometric data will not be introduced merely for convenience where a less intrusive, reasonably effective method is available.
8. Website, cookies, analytics and online advertising
Our website may use cookies, pixels, local storage and similar technologies. These may be set by us or approved providers.
| Category | Purpose | Choice |
|---|---|---|
| Strictly necessary | Security, network management, forms, session functions, consent settings and essential website operation | Required for the requested service; these cannot generally be disabled through our consent tool |
| Functional | Remembering preferences and enabling optional website features | Used with consent where required |
| Analytics | Understanding aggregate website use, performance and errors | Used with consent where required |
| Advertising | Measuring campaigns, limiting repetition and showing relevant admission information to adults | Used with consent where required; never used by us to direct targeted advertising at children |
Where applicable law requires consent, optional cookies will be activated only after your choice. You may use the website’s cookie-preference tool to accept, reject or change non-essential cookie choices. You may also control cookies through your browser, though blocking strictly necessary cookies may affect website functions.
Advertising audiences must be configured for adults such as parents or guardians. We do not knowingly upload children’s personal data to advertising platforms to create or target advertising audiences.
Browser “Do Not Track” signals are not interpreted consistently across services. We honour legally recognised preference signals where applicable and otherwise rely on the consent controls described above.
9. Chatbot and automated tools
The website may provide a chatbot or other automated assistance to answer general questions and collect admission enquiries. Chat data may include the text entered, contact information you choose to provide, timestamps, session or security identifiers and the chatbot’s response. We use this data to answer the enquiry, arrange follow-up, protect the service and improve the accuracy and usefulness of approved School information.
Please do not enter medical records, passwords, payment credentials, government identifiers or other unnecessary sensitive information in the chatbot. A chatbot response is informational and may not always be complete or accurate; important admission, fee, safety or academic information should be confirmed with the School.
The School does not use the public-facing chatbot to make a final admission, academic, disciplinary or other decision producing legal or similarly significant effects solely by automated means. Where automated tools support staff, meaningful human review and a way to question the outcome will be provided when required by law.
10. When we share personal data
We do not sell or rent personal data. We may share only the data reasonably necessary with:
- School personnel and authorised bodies: teachers, administrators, counsellors, medical or safeguarding personnel, management and governing bodies on a need-to-know basis;
- education and public authorities: CBSE, examination bodies, education departments, courts, regulators, police, emergency services and other competent authorities where required or permitted by law;
- service providers: website hosts and developers, cloud and email services, admission and school-management platforms, payment gateways and banks, analytics and consent platforms, communications providers, chatbot or support providers, transport and GPS providers, security and CCTV providers, event or photography providers, auditors, insurers and professional advisers;
- other schools or institutions: when requested and authorised for a student’s transfer, reference, competition, programme or educational opportunity; and
- transaction or succession parties: if the governance or operation of the School changes, subject to lawful safeguards and continued protection of the data.
Service providers that process data for us are required through appropriate arrangements to act only for authorised purposes, maintain confidentiality and security, support individual rights and erase or return data as required. A provider may also act as an independent data fiduciary or controller for its own regulated services, such as banking or payment processing; its own privacy notice will then apply to that processing.
We may disclose personal data without consent when a law, court order, lawful government request, emergency, safeguarding need or the establishment, exercise or defence of legal claims permits or requires disclosure.
11. International data transfers
Some approved technology or cloud providers may process or support data from locations outside India. Before such transfers, we assess the provider and purpose, limit the data, use contractual and security controls, and comply with restrictions or requirements notified under Indian law.
Where the GDPR applies to a transfer from the European Economic Area to a country not recognised as providing adequate protection, we use an approved transfer mechanism where required, such as the European Commission’s Standard Contractual Clauses, together with supplementary safeguards when appropriate. You may contact us for information about the safeguards relevant to your data, subject to confidentiality and security limitations.
12. How long we retain personal data
We retain personal data only for as long as necessary for the notified purpose, the educational relationship, safeguarding, dispute resolution, audit, archival value and compliance with applicable laws. We then securely erase, anonymise or archive it with restricted access.
| Record category | Normal retention approach |
|---|---|
| General admission enquiries and chatbot leads that do not become applications | Up to 24 months after the last meaningful interaction, unless consent is withdrawn earlier or a longer period is justified |
| Unsuccessful or withdrawn admission applications | Up to 3 years after the admission cycle, unless a legal, safeguarding or dispute-related need requires longer retention |
| Core student, academic, transfer and certification records | For the period required by education, examination, limitation and archival rules; certain permanent registers, certificates and academic records may be retained permanently |
| Routine student administration, communications and support records | Normally for enrolment plus up to 8 years, subject to the nature of the record and legal requirements |
| Safeguarding, serious incident and health records | For the period required to protect the child, meet legal duties and respond to claims; potentially longer than routine student records |
| Fees, accounting, tax, contracts and transaction records | Normally 8 years after the relevant financial year or longer where law, audit or a dispute requires |
| CCTV footage | Normally 30 to 90 days, unless preserved for an incident, safeguarding matter, investigation, legal claim or lawful request |
| Visitor, access, transport and GPS operational records | Normally 6 to 12 months, unless an incident, safeguarding purpose or legal requirement justifies longer retention |
| Website security and system logs | Normally at least 180 days where required for cyber-security compliance and longer when needed to investigate an incident |
| Optional marketing contacts | Until consent is withdrawn, an objection is received, the purpose ends or the contact is inactive under our retention schedule; a minimal suppression record may be kept to honour an opt-out |
| Publications and School archives | Selected non-sensitive records may be kept for long-term institutional, historical or evidential purposes with access and child-safety safeguards |
These periods may be shortened or extended when required by law, a regulator, litigation hold, safeguarding need, contract or a documented assessment. Backup copies are protected and expire through controlled backup cycles. When the DPDP Rules require advance notice before erasure, we will provide that notice in the prescribed manner.
13. How we protect personal data
We use reasonable and proportionate technical and organisational safeguards appropriate to the sensitivity and risk of the data. These may include:
- role-based access, least-privilege permissions and periodic access review;
- password controls, multi-factor authentication where appropriate and secure account administration;
- encryption or equivalent protection in transit and at rest where appropriate;
- secure backups, recovery measures, security logging, monitoring and malware protection;
- physical security for paper records, devices, servers and restricted areas;
- vendor due diligence, contracts and controlled data sharing;
- staff confidentiality, training and procedures for handling children’s and sensitive data;
- data minimisation, accuracy checks, retention controls and secure disposal; and
- incident-response and business-continuity procedures.
No online or storage system is completely secure. Individuals should use secure devices, protect login credentials, avoid sending unnecessary sensitive information through ordinary email or chat, and notify us promptly of suspected unauthorised access.
14. Personal-data breaches
We maintain procedures to identify, contain, investigate and remediate suspected personal-data breaches. We will preserve relevant evidence, assess risks, take reasonable mitigation measures and notify affected individuals, the Data Protection Board of India, supervisory authorities or other bodies in the form and within the time required by applicable law.
Where the GDPR applies, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a reportable breach. Where a breach is likely to result in a high risk to an individual’s rights and freedoms, we will also communicate it to the affected individual without undue delay, unless an applicable exception applies.
15. Your rights under Indian data-protection law
Subject to the provisions, exemptions and commencement dates of applicable Indian law, a Data Principal may:
- withdraw consent with comparable ease to the way it was given;
- request a summary of personal data being processed and the processing activities;
- request available information about other data fiduciaries and data processors with whom the data has been shared, subject to lawful exceptions;
- request correction of inaccurate or misleading data, completion of incomplete data and updating of data;
- request erasure when the purpose is complete, consent is withdrawn, or erasure is otherwise required, unless retention remains necessary for the specified purpose or compliance with law;
- use our grievance-redressal mechanism; and
- nominate another individual to exercise applicable rights in the event of death or incapacity.
A parent or lawful guardian will normally exercise rights for a child. We may verify the requester’s identity and authority before acting. Requests must be made honestly, must not impersonate another person, and should provide accurate information needed to locate the relevant record. We will respond within the period required by applicable law.
16. Additional rights where the GDPR applies
Where the GDPR applies to the processing, and subject to its conditions and exemptions, a data subject may have the right to:
- be informed and obtain access to personal data;
- rectify inaccurate or incomplete personal data;
- request erasure;
- restrict processing;
- object to processing based on legitimate interests and object at any time to direct marketing;
- receive eligible data in a structured, commonly used, machine-readable format and transmit it to another controller;
- withdraw consent at any time where consent is the basis of processing;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to lawful exceptions; and
- lodge a complaint with the data-protection supervisory authority in the country of habitual residence, place of work or alleged infringement.
These rights are not absolute. For example, educational, safeguarding, examination, legal-claim and third-party privacy requirements may limit access or erasure. We normally respond to a valid GDPR request within one month, subject to a lawful extension for complexity or number of requests.
17. Service communications, marketing and opt-out
We may send essential communications about an enquiry, application, admission, education, fees, transport, safety, schedules, events or School administration. These are service communications and may be necessary to provide the requested service.
Optional promotional communications are sent to adults such as prospective parents or guardians with consent or another lawful basis. You may opt out using the unsubscribe method in the message or by contacting us. Opting out of promotional messages will not stop necessary service, safety or legal communications.
We do not conduct direct marketing addressed to children and do not use children’s profiles for targeted advertising.
18. Third-party websites and services
The website may link to admission platforms, payment services, social networks, maps, video platforms or other external services. When you leave our website or use a service controlled independently by another organisation, that organisation’s privacy notice and terms apply. We encourage you to review them. A link does not make IVWS responsible for the independent provider’s privacy practices.
19. Changes to this Privacy Policy
We may update this Policy to reflect changes in law, School operations, technology or service providers. The current version will be posted on the School website with its effective and last-updated dates. If a change materially affects the purpose of processing or an individual’s rights, we will provide an additional notice and seek fresh consent where required.
20. Privacy requests, grievance redressal and complaints
To ask a privacy question, exercise a right, withdraw consent or raise a grievance, contact:
Privacy and Grievance ContactIndus Valley World School
488, Ajoy Nagar, Eastern Metropolitan By-Pass
Near Peerless Hospital, Behind Satyajit Ray Film Institution
Kolkata – 700094, West Bengal, India
Email: admissions@ivws.org
Telephone: 033-7120-5250
Please use the subject line “Privacy Request” and state your name, relationship with the School, the right or concern involved, and enough detail for us to identify the relevant record. Do not send passwords, full payment credentials or unnecessary identity documents. We may request proportionate verification before disclosing or changing personal data.
We will acknowledge and resolve grievances within the time required by applicable law. Under the DPDP Act, a Data Principal must ordinarily use the School’s grievance mechanism before making a complaint to the Data Protection Board of India. Where the GDPR applies, the right to lodge a complaint with a competent supervisory authority remains available.
This Policy should be read with any consent form, cookie notice, student/parent handbook, safeguarding policy, acceptable-use policy, employment notice or activity-specific privacy notice provided by the School.