Classfold · Vinidra Infotech Pvt. Ltd.
Privacy Policy
This page is a product documentation draft for transparency. It is not legal advice. Have qualified counsel review it before you rely on it for compliance or contracting.
This Privacy Policy explains how Vinidra Infotech Pvt. Ltd. (“Vinidra”, “we”, “us”) collects, uses, shares, and protects personal information when you use Classfold, our multi-tenant learning management platform. It is written for institute administrators, staff, learners, parents or guardians acting for minors, and visitors to our public marketing site.
Scope and roles
This policy covers personal information processed in connection with Classfold product accounts, billing and subscription administration, platform operations and security telemetry, and public marketing pages operated by Vinidra Infotech Pvt. Ltd.
Classfold is a multi-tenant SaaS product that uses a shared-database architecture with tenant isolation controls. Each customer institute (the “tenant”) typically decides what academic, staff, and student information is entered into its Classfold workspace. For that tenant-hosted content, the institute is ordinarily the data controller (or equivalent under applicable law), and Vinidra / Classfold acts as a processor or service provider processing that content on the institute’s documented instructions and configuration.
Separately, Vinidra is the controller for platform-level account identity used to access Classfold, commercial and billing records for the customer relationship, product analytics and operational logs needed to run and secure the service, and information you submit directly to us (for example support tickets or marketing inquiries).
Nothing in this policy transfers an institute’s independent obligations under education, child-protection, or local privacy laws. Institutes remain responsible for lawful collection notices, consents, and parental permissions required for their own students and staff.
Information we collect
We collect information in three main ways: you provide it directly; your institute or other authorized users enter it into a tenant workspace; or it is generated automatically when the product or our sites are used.
Account and customer data may include name, work email, phone number, role or designation, organization or institute name, authentication credentials or tokens, and preferences related to notifications and locale.
Tenant content is information that customers and their authorized users upload or create inside Classfold. Depending on how an institute configures and uses the product, this can include course structures, assignments, grades, attendance, messages, files, roster details, and other academic or administrative records. We process this content to provide the service to that tenant.
Usage, device, and log data may include IP address, browser or app type, device identifiers where available, timestamps, pages or features accessed, referrer information, diagnostic error reports, and security-relevant events. We use this primarily for reliability, abuse prevention, and product improvement.
Payment-related metadata is handled through payment service providers. We may receive limited billing details such as payer name, billing address, transaction status, invoice identifiers, and last-four or similar non-sensitive payment descriptors. We do not store full payment card numbers on Classfold systems; card data is collected and processed by the payment provider under its own terms and controls.
- Account profile and authentication data
- Tenant-hosted academic and administrative content
- Product usage, device, and security logs
- Support communications and marketing inquiries you send us
- Payment and subscription metadata via payment service providers (not full card numbers)
Purposes and legal bases
We process personal information to operate Classfold, authenticate users, host and deliver tenant workspaces, provide customer support, bill and collect subscription fees, monitor security and prevent abuse, improve reliability and features, communicate service-related notices, and comply with law.
For individuals in India, we process personal data in line with the Digital Personal Data Protection Act, 2023 (DPDP) and rules issued under it, including processing for legitimate uses recognized by law and processing based on free, specific, informed, unconditional, and clear consent where consent is the applicable ground.
Where EU or UK GDPR applies to a processing activity, we rely on one or more lawful bases such as performance of a contract, legitimate interests (for example securing the platform and understanding aggregate product usage in a way that does not override individual rights), legal obligation, and consent where required (for example certain optional analytics cookies).
Where California or similar U.S. state privacy laws apply, we process personal information for business purposes such as providing the service, security, debugging, short-term transient use, quality assurance, and internal research consistent with those laws. We do not sell personal information. We do not sell or share personal information for cross-context behavioral advertising as those terms are commonly defined under the CCPA/CPRA.
- Provide, maintain, and secure the Classfold service
- Manage accounts, roles, and tenant administration
- Process subscriptions, invoices, and tax documentation where required
- Respond to support requests and service communications
- Detect, investigate, and mitigate fraud, abuse, and security incidents
- Improve product performance and understand high-level usage patterns
International transfers
Classfold may be accessed from multiple countries, and supporting infrastructure or service providers may process data in locations other than where you or your institute are established.
When we transfer personal information across borders, we use appropriate safeguards required by applicable law. These may include contractual measures with recipients, transfer mechanisms recognized under relevant privacy regimes, and technical and organizational controls designed to protect data in transit and at rest.
Institutes that export or allow access to tenant content outside their primary jurisdiction remain responsible for assessing whether their own cross-border sharing complies with local education and privacy rules.
Retention
We retain personal information only as long as reasonably necessary for the purposes described in this policy, including providing the service, meeting legal, tax, and accounting requirements, resolving disputes, and enforcing agreements.
Account and customer relationship records are generally kept for the life of the customer relationship and for a further period needed for legitimate business and legal record-keeping after the account ends.
Tenant content is retained according to the customer’s subscription status, product configuration, and deletion or export requests. When a tenant workspace is closed, we follow our contractual and product deletion processes; residual copies in backups are removed or become inaccessible over the ordinary backup lifecycle.
Security and operational logs are typically retained for shorter periods appropriate to troubleshooting, fraud prevention, and security investigations, unless a longer period is required for an active investigation or legal hold.
When retention is no longer required, we delete or de-identify information in accordance with our systems and procedures, subject to technical limitations of backups and legal holds.
Security
We implement administrative, technical, and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. Measures include encrypted transport, access controls, tenant-scoped data access patterns in our multi-tenant architecture, and operational monitoring.
No method of transmission or storage is completely secure. We work to reduce risk continuously, but we cannot guarantee absolute security. Additional detail on our security approach is available at /security.
Customers are responsible for safeguarding their own account credentials, configuring roles appropriately inside their tenant, and ensuring endpoint security for devices their users use to access Classfold.
Your rights
Depending on your location and role, you may have rights to access, correct, update, or delete personal information; withdraw consent where processing is consent-based; nominate or use a grievance path under Indian DPDP rules; and obtain information about how we process your data.
Where GDPR or similar laws apply, you may also have rights to restrict or object to certain processing, request data portability, and lodge a complaint with a supervisory authority. Where CCPA/CPRA or similar U.S. state laws apply, you may have rights to know, access, correct, delete, and opt out of sale or sharing of personal information. We restate that we do not sell personal information and do not share it for cross-context behavioral advertising.
If you are a student, parent, teacher, or staff member whose data lives primarily inside an institute’s Classfold tenant, please contact your institute first. The institute is usually best placed to locate, correct, or delete tenant-hosted academic records. We will support controllers in responding to verified requests as required by law and contract.
Platform-level requests (for example about a billing contact account we control directly) can be sent to support@classfold.com. We may need to verify identity and authority before acting, and we may decline or limit requests where an exemption applies (for example legal retention duties or rights of others).
Children and education contexts
Classfold is an education technology platform used by institutes that may enroll minors. We do not knowingly market Classfold as a consumer social product directed at children independently of an institute relationship.
Institutes are responsible for ensuring they have a lawful basis to collect and process personal data of minors—including any required notices to parents or guardians and school-policy compliance—before entering that data into Classfold.
If you believe a minor’s personal information has been provided to us in a way that violates applicable law, contact support@classfold.com. We will work with the relevant institute and take appropriate steps, which may include deletion or restriction of the data where we are legally permitted and contractually able to do so.
Contact and grievance
For privacy questions, requests, or concerns about Classfold, contact Vinidra Infotech Pvt. Ltd. at support@classfold.com, phone +91 90083 52471, with operations contact location in Bangalore, Karnataka, India.
Under India’s DPDP framework, you may raise a grievance regarding our processing of personal data through the same support channel. We aim to acknowledge and address grievances in a reasonable time. If you are not satisfied with our response, you may have the right to escalate to the Data Protection Board of India or another competent authority as provided by law.
When you contact us, please describe the issue clearly, identify the relevant account or institute where possible, and avoid sending unnecessary sensitive documents unless we request them for verification.
Changes to this policy
We may update this Privacy Policy from time to time to reflect product, legal, or operational changes. When we make material changes, we will update the effective date shown on this page and, where appropriate, provide additional notice through the product, email, or our website.
Continued use of Classfold after an updated policy becomes effective constitutes acceptance of the revised policy to the extent permitted by law. If you do not agree with material changes, you should stop using the service and contact us or your institute administrator about account closure and data export options.
Prior versions may be available on request where we retain them for reference. For related contractual terms, see /terms. For security practices overview, see /security.