Scope and our two roles
This policy covers anovish.com and the Anovish School ERP platform. Anovish acts in two different roles, and your rights — and who you should contact — depend on which applies.
- When you contact us through this website
- Anovish decides how your enquiry details are used. For this information Anovish is the Data Fiduciary and is responsible directly to you.
- When an institution uses the ERP platform
- The institution decides what student, parent and staff records are held and why. The institution is the Data Fiduciary; Anovish is a Data Processor acting only on its documented instructions. Parents, students and staff should contact their institution first.
Anovish handles personal information in line with India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (the “DPDP Rules”). The terms on which we process institution data — including our security commitments, our breach-notification undertaking and our commitment to help the institution respond to data-principal requests — are set out in a written Data Processing Agreement, available to institutions on request.
In this policy, “you” or “Data Principal” means the individual to whom the personal data relates. Where the individual is a child or a person with a disability, this includes their parent or lawful guardian.
Information we collect
Information you give us
- Demo and enquiry details: your name, institution name, phone number, email address, approximate number of students, the modules you are interested in, and anything you write in the message field.
- Account details: the name, role, email address and phone number of each Authorised User an institution sets up.
- Request and grievance details: the information you provide when you contact us to exercise a right or raise a grievance, and our correspondence with you about it.
Information an institution enters into the platform
Institutions record data needed to run their operations. Depending on the modules they use, this can include student names and admission details, parent or guardian contact details, attendance, examination marks and results, fee and receipt records, staff records, salary information, and transport allocations. We process this only as the institution’s Data Processor.
Information collected automatically
- IP address, browser type, device type and operating system.
- Pages viewed, referring page, and the date and time of visits.
- Access and activity logs generated when Authorised Users use the platform.
- Cookies and similar technologies, described in the cookies section below.
Children’s information
A school ERP necessarily holds records about children. Anovish does not collect information directly from children through this website, and the website is not directed at them.
Where children’s data is held inside the platform, it has been entered by the institution as part of running its own operations. The institution, as Data Fiduciary, is responsible for having the lawful basis for holding it and for obtaining verifiable parental consent where the DPDP Act requires it. The DPDP Rules exempt educational institutions from certain parental-consent and monitoring restrictions only to the extent processing is for educational activities or the safety of children; institutions remain responsible for staying within that scope.
Anovish processes children’s data only on the institution’s instructions and does not use it for any purpose of its own. In particular, we do not use children’s data for tracking, behavioural monitoring, profiling or targeted advertising, and we do not sell it.
Parents wanting to see, correct or remove a child’s record should contact the institution.
How we use information
- To respond to demo requests and enquiries, and to follow up on them.
- To provide, operate, support and maintain the platform.
- To create and manage user accounts and permissions.
- To send service messages such as maintenance notices and account alerts.
- To raise invoices and manage payments.
- To investigate security incidents, prevent misuse and meet legal obligations.
- To respond to requests to exercise rights and to handle grievances.
- To understand how the website is used so we can improve it.
We use personal information only for the purpose for which it was collected, or a purpose you have consented to. We do not sell personal information, and we do not use institution data for advertising.
Our basis for processing
Under the DPDP Act, we process personal information for which we are the Data Fiduciary only on one of the following grounds:
- Consent — for example, where you agree to be contacted about a demo, or to optional analytics cookies.
- Legitimate uses permitted by Section 7 of the DPDP Act, including where:
- you have voluntarily provided the information for a specified purpose (such as submitting an enquiry form) and have not indicated that you do not consent to its use for that purpose;
- we must process it to comply with a law in force in India, or with a judgment, decree or order; and
- any other legitimate use the DPDP Act permits in the circumstances.
Where Anovish acts as a Data Processor for an institution, the institution determines the basis for processing and Anovish follows its documented instructions.
Consent and withdrawing it
Where we ask for your consent, we will show you a clear notice at the point of collection explaining what data we will use, why, and how you can withdraw consent or raise a complaint. Consent must be given by a clear affirmative action — we do not use pre-ticked boxes.
You can withdraw consent at any time, and withdrawing will be as easy as giving it:
- use the unsubscribe link in any marketing or follow-up email we send you;
- turn off analytics cookies in your browser settings, as described in the cookies section; or
- email info@anovish.com with the subject “Withdraw consent”, and we will action it without asking you for a reason.
Once you withdraw consent, we will stop processing the relevant information within a reasonable time, and will ask our service providers to do the same, unless the law requires or permits us to keep it. Withdrawal does not affect the lawfulness of processing carried out before you withdrew. If withdrawal means we can no longer provide something you asked for (such as a demo), we will tell you.
How long we keep information
We keep personal information only as long as needed for the purpose it was collected for, or as required by law. Specifically:
| Information | How long we keep it |
|---|---|
| Enquiry and demo details | For as long as needed to respond and follow up, and up to 12 months after our last contact with you, unless you become a customer or ask us to delete it sooner. |
| Account and institution data | For the duration of the subscription. After it ends, retained for 90 days to allow export, then deleted or anonymised unless a longer period is required by law. |
| Access logs and traffic data | At least one year, as required by the DPDP Rules for security and investigation purposes, and then deleted unless required longer by law. |
| Grievance and rights-request records | For as long as needed to resolve the matter and for any period required to meet legal obligations or defend claims. |
| Invoices and payment records | For the period required under tax and accounting laws. |
Where required by the DPDP Rules, we will give you at least 48 hours’ notice before erasing your personal data because it is no longer needed, so that you can log in or otherwise contact us if you wish it to be retained.
How we protect information
We apply reasonable security safeguards, including access controls, individual user credentials and role-based permissions so that people reach only the records their role requires. Access to sensitive areas such as payroll and accounts is granted deliberately and can be withdrawn.
Connections between users’ browsers and Anovish — both this website and the ERP platform — are encrypted in transit using HTTPS/TLS, and platform data is encrypted at rest. Access to personal data is logged and monitored so that unauthorised access can be detected and investigated.
Backups are taken to an agreed schedule so that data can be restored. Our service providers are contractually required to maintain appropriate safeguards.
Online fee payments are processed by third-party payment gateways. Card and bank-account details are entered with the gateway and are not stored by Anovish.
We describe here only measures that are actually in place. No system can be guaranteed completely secure, and we do not claim any certification we have not been awarded. If your institution requires specific written commitments on hosting location, encryption or backup frequency, ask us and we will set out the actual arrangement in your proposal.
If a data breach happens
If we become aware of a personal data breach affecting information for which Anovish is the Data Fiduciary, we will:
- inform affected Data Principals without delay, in plain language, describing what happened, the likely consequences, what we are doing to limit the harm, what you can do to protect yourself, and who to contact;
- intimate the Data Protection Board of India without delay, and provide the Board a detailed report within 72 hours of becoming aware of the breach, or any longer period the Board allows; and
- take steps to contain the breach, investigate its cause and prevent recurrence.
Where the breach concerns data held for an institution, we will notify that institution promptly under our Data Processing Agreement and support it in meeting its own notification duties.
Your rights
Under the DPDP Act, in respect of personal data for which Anovish is the Data Fiduciary, you have the right to:
- Access information: obtain a summary of the personal data we process about you and the processing activities, the identities of the other Data Fiduciaries and Data Processors with whom it has been shared (with a description of the data shared), and any other information the law provides for.
- Correction, completion and updating: have inaccurate or misleading data corrected, incomplete data completed, and data updated.
- Erasure: have your data erased where it is no longer needed for the purpose it was collected, or where you withdraw consent, unless the law requires us to keep it.
- Withdraw consent where our processing relies on it (see Consent and withdrawing it).
- Grievance redressal: have a readily available means to raise a grievance with us (see Grievance redressal).
- Nomination: nominate another person to exercise these rights on your behalf in the event of your death or incapacity.
How to exercise your rights
To make a request, email info@anovish.com with the subject “Data rights request”, or write to us at the address in Questions about this policy. Please include:
- your name and the email address or phone number you used with us (this is the identifier we will use to find your records);
- which right you want to exercise and, for corrections, what should change; and
- for a nomination, the nominee’s name and contact details.
We may need to verify your identity before acting, and we will only ask for what is needed to do so.
| Step | Our commitment |
|---|---|
| Acknowledgement | Within 3 working days, with a reference number. |
| Response to your request | Within 30 days of receiving a verified request, and in any case within 90 days. If we need longer or cannot act, we will tell you why. |
| Cost | Free of charge. |
If your request concerns records held by an institution using our platform, we will forward it to that institution (as the Data Fiduciary) and tell you we have done so, and we will help the institution respond.
Your duties
The DPDP Act also places duties on Data Principals. When exercising your rights or raising a grievance, please provide accurate information, do not impersonate another person, do not suppress material information, and do not file false or frivolous complaints.
Where information is held
Information is processed in India. Where a service provider processes information outside India, we take steps to ensure it remains protected to a comparable standard and that any transfer meets the DPDP Act and any restrictions notified by the Government of India. We do not transfer personal data to any country or territory the Government has restricted. On request, we will tell you where your information is processed.
Grievance redressal
If you have a concern about how your personal information has been handled, or about how we responded to a request to exercise your rights, you can raise a grievance with our Grievance Officer. This person is also our designated contact who can answer questions about how we process personal data.
- Name
- Ravi Mishra
- Designation
- Grievance Officer
- info@anovish.com (subject: “Grievance”)
- Phone
- +91-77019 22088 (Monday–Saturday, 10:00–18:00 IST)
- Address
- D-41, Sector 59, Noida, Uttar Pradesh 201301, India
Parents, students and staff: if your concern is about records your school or institution keeps in the ERP, the institution is the Data Fiduciary and you should raise it with the institution’s own grievance contact first. If you contact us, we will pass it to the institution and help it resolve the matter.
How your grievance is handled
- You raise it. Email, call or write to the Grievance Officer. Tell us your name, how to contact you, the identifier you used with us, and what happened. If you call, we will record your grievance in writing and confirm it to you by email.
- We acknowledge it. Within 3 working days we confirm receipt and give you a grievance reference number to use in all follow-ups.
- We investigate. The Grievance Officer reviews the matter and may contact you for more details or identity verification. Where it concerns institution data, we involve the institution.
- We resolve and respond. We send you a written response setting out our findings and any action taken, within 30 days of receipt and in any case not later than 90 days, as required by the DPDP Rules. If we need more time within that limit, we will tell you why and when to expect a reply.
- You can escalate. If you are not satisfied with our response, or do not receive one within 90 days, you may complain to the Data Protection Board of India (see below).
Complaints to the Data Protection Board of India
The Data Protection Board of India is the authority established under the DPDP Act to hear complaints from Data Principals. Under Section 13(3) of the DPDP Act, you must first exhaust our grievance redressal process described above before making a complaint to the Board.
If you remain dissatisfied after that, you may file a complaint with the Board through the means it publishes, including its digital complaints platform. Details are available from the Ministry of Electronics and Information Technology (meity.gov.in) and from the Board.
For grievances about records held by an institution, the complaint should generally be directed to that institution first, as the Data Fiduciary, and then to the Board.
Changes to this policy
We update this policy when our practices or the law change. The current version is always published here with the date it was last updated. Where a change is significant, we will notify institutions by email to their registered contact, and where a change affects processing based on your consent, we will seek your consent again where the law requires.
Version history
- 21 September 2026: Aligned with the DPDP Rules, 2025 — added a step-by-step grievance process with resolution timelines and escalation to the Data Protection Board; response timelines for rights requests; breach-notification commitments; easier consent withdrawal; Section 7 “legitimate uses”; log-retention periods; and Data Principal duties.
- 17 September 2026: Previous version.
Questions about this policy
Write to us and we will respond. For anything contractual, please quote your institution name so we can find your agreement.