Privacy Policy

Last Updated: 2026

This Privacy Policy describes how infoEIGHT ("the Platform", "We", "Us", or "Our") collects, processes, stores, and protects personal information when educational institutions use our School ERP platform.

The platform is a multi-tenant Software-as-a-Service (SaaS) system used by schools, colleges, and educational institutions ("Institutions") to manage academic administration, student information, communication, finance, attendance, examinations, and related services.

Each Institution using the platform acts as the primary data controller for the personal data of its students, parents, staff, and other users. The ERP Provider typically acts as a data processor that processes information on behalf of the Institution.


1. Scope of This Policy

This Privacy Policy applies to:

This policy applies to all services, modules, applications, APIs, mobile applications, and integrations provided as part of the ERP platform.


2. Roles and Responsibilities

2.1 ERP Provider

The ERP provider operates and maintains the technical infrastructure of the platform including servers, databases, authentication systems, and security controls.

2.2 Institution (Client)

The Institution determines what data is collected from students, parents, and staff and how that information is used.

Institutions are responsible for:


3. Categories of Information Collected

3.1 Student Information

3.2 Parent or Guardian Information

3.3 Teacher and Staff Information

3.4 Administrative Data

3.5 Technical Information


4. How Information Is Collected

Information may be collected through:

5. Purpose of Data Processing

Personal data may be used for:

6. Legal Basis for Processing

Depending on jurisdiction, processing may rely on:

7. Data Sharing and Disclosure

Information may be shared with:

Data is shared only when necessary to provide ERP functionality or to comply with legal requirements.


8. Third-Party Subprocessors

The platform may use third-party service providers for: These providers process data only according to contractual obligations.

9. Data Security

Security controls include:

10. Data Retention

Data is retained based on: Archived records may be stored securely for regulatory or historical purposes.

11. User Rights

Depending on jurisdiction, individuals may have the right to: Requests should generally be directed to the Institution administering the account.

12. Cookies and Tracking

The platform may use cookies and similar technologies to:

13. Children's Data Protection

The platform processes information about minors only on behalf of educational institutions. Schools are responsible for ensuring that appropriate consent has been obtained from parents or guardians.

14. Cross-Border Data Transfers

Data may be processed or stored in data centers located in different countries depending on the hosting infrastructure. Appropriate safeguards are implemented for international transfers.

15. Data Breach Notification

If a data breach occurs, we will:

16. System Logs and Monitoring

For security and operational purposes, the platform maintains logs including: These logs help detect unauthorized activity and maintain system stability.

17. Policy Updates

This Privacy Policy may be updated periodically. Institutions using the platform will be notified of significant changes.

18. Contact Information

If you have questions about this policy, contact:

ERP Provider: infoEIGHT
Email: support@infoeight.com