Legal center

Privacy Policy

How SquareCampus gathers, safeguards, and shares personal data for schools and colleges.

1. Company & Data Fiduciary

SquareCampus™ is a trademark (registration pending) of Fairhelm Systems (OPC) Private Limited. All services are provided by Fairhelm Systems (OPC) Private Limited, unless otherwise stated in a written agreement or order form.

References to "SquareCampus" in this Policy mean Fairhelm Systems (OPC) Private Limited.

FAIRHELM SYSTEMS (OPC) PRIVATE LIMITEDRegistered office: No. 33, 4th Floor, 1st Main, Road 3, Ganganagar, R T Nagar, Bangalore North, Bangalore – 560032, Karnataka, IndiaCIN: U62099KA2026OPC225579 · Incorporated in India on 5 August 2026 under the Companies Act, 2013 · One Person CompanyEmail: contact@squarecampus.com

This Policy uses the vocabulary of the Digital Personal Data Protection Act, 2023 (the "DPDP Act"): a Data Principal is the individual the personal data is about, a Data Fiduciary decides why and how it is processed, and a Data Processor processes it on a Fiduciary's instructions.

Fairhelm Systems (OPC) Private Limited is the Data Fiduciary for its own business operations and the SquareCampus website. When processing personal data on behalf of an Institution within the Service, the Institution is the Data Fiduciary and Fairhelm Systems (OPC) Private Limited acts as its Data Processor, as described in the Data Processing Addendum. In that case the Institution's own notice governs its relationship with students, guardians and staff.

SquareCampus service data is hosted and processed in India. We do not transfer or store customer data outside India.

We pledge to keep data within the borders of India, no excuses or compromises.

2. Information We Collect

2.1 Institution Information

We may collect or receive details about the Institution, including:

  • Institution name, type, and registered address;
  • Administrative contacts, emails, and phone numbers;
  • Billing preferences and subscription configurations;
  • Modules, features, and integrations selected by the Institution.

2.2 User Information

We receive, process, or store data about individual users, such as:

  • Names, contact details, roles (student, parent, educator, staff);
  • Authentication records and hashed login credentials;
  • Academic data, attendance, assignments, assessments, and grades;
  • Messages, notifications, and collaboration history generated inside the Service.

2.3 Technical and Usage Data

Automatic information we collect includes:

  • IP address, device, and browser metadata;
  • Pages, modules, and features accessed with timestamps;
  • Diagnostic logs, error events, and performance telemetry;
  • Cookies or tokens used for authentication and session management.

2.4 Sensitive Data and Minors

SquareCampus may process information about minors (students) and data that may be considered sensitive (photographs, health records, disciplinary notes) strictly under the Institution's instructions.

Institutions are responsible for obtaining any necessary parental or guardian permissions before submitting such data through the Service.

3. How We Use the Information

We use the collected data to:

  • Provide, operate, and improve the SquareCampus Service;
  • Authenticate users, maintain sessions, and secure accounts;
  • Generate attendances, reports, notifications, and academic insights;
  • Facilitate communication between teachers, students, and parents;
  • Analyse usage patterns for reliability, performance, and product planning;
  • Comply with legal obligations and respond to lawful requests;
  • Enforce our Terms of Service and detect abuse.

We do not sell personal data to advertisers or unrelated third parties.

5. Data Sharing and Transfers

We may share data with:

  • Authorised Institution staff as allowed by internal controls;
  • Third-party providers acting on our behalf (cloud, messaging, analytics);
  • Professional advisers bound by confidentiality obligations;
  • Government or law enforcement authorities when required by law.

We may use sub-processors to deliver the Service. A current list of sub-processors is available upon request.

6. Data Security

We deploy administrative, technical, and physical measures such as encryption in transit and at rest, role-based access controls, infrastructure hardening, monitoring, backups, and periodic reviews to limit access to authorised personnel only.

No system is 100% secure, but we continually invest in improving our posture and respond quickly to incidents.

Breach notification. On becoming aware of a personal data breach, we intimate each affected Data Principal without delay — describing the nature, extent and timing of the breach, its likely consequences, the mitigation we are applying, the steps they can take, and where to reach us — and we report it to the Data Protection Board of India, followed by a detailed report within 72 hours as Rule 7 of the DPDP Rules, 2025 requires. Where we act as an Institution's Data Processor, we notify the Institution without delay so it can meet its own obligation.

A summary of our security practices is available at https://squarecampus.com/security.

7. Data Retention

Data is retained during active use to provide the Service. After an Institution’s subscription ends, we may keep data for a limited period for legal, accounting, or backup reasons, after which it will be deleted or anonymised.

8. Your Rights as a Data Principal

Where Fairhelm Systems (OPC) Private Limited is the Data Fiduciary, the DPDP Act gives you the following rights. Requests may be sent to the grievance contact in section 11.

  • Access — a summary of the personal data being processed, the processing activities, and the identities of other Data Fiduciaries and Processors it has been shared with (section 11).
  • Correction and erasure — correction, completion, updating, and erasure of your personal data (section 12).
  • Grievance redressal — a readily available means of raising a complaint with us, answered within the period prescribed under the Act, before approaching the Data Protection Board of India (section 13).
  • Nomination — the right to nominate another individual to exercise these rights on your behalf in the event of your death or incapacity (section 14).
  • Withdrawal of consent — where processing rests on your consent, you may withdraw it at any time, with the same ease as it was given. Withdrawal stops further processing for that purpose; it does not undo lawful processing already carried out, nor affect records we must retain by law.

Where your data sits inside an Institution's deployment, that Institution is the Data Fiduciary. Raise the request with the Institution first; we will support it as the Institution's Data Processor. We may need to verify your identity, and your authority where you act for someone else, before acting on a request.

9. Cookies and Similar Technologies

Cookies and similar identifiers support authentication, session persistence, and preference storage. We do not use third-party advertising cookies in the core academic and administrative areas.

10. Children’s and Student Data

Student records are the most sensitive data SquareCampus touches, and a large share of them concern children — anyone under eighteen. Section 9 of the DPDP Act requires verifiable consent from a parent or lawful guardian before a child's personal data is processed, and prohibits tracking, behavioural monitoring, and targeted advertising directed at children. Rule 10 of the DPDP Rules, 2025 adds that the consent must be genuinely verifiable: due diligence is required to confirm that the person giving it is an identifiable adult entitled to act for the child.

SquareCampus is provided to Institutions, not directly to children. The Institution holds the relationship with students and guardians and is responsible for obtaining and recording verifiable parental consent, for managing access on behalf of students, and for its own compliance regarding minors. Our role is to process what the Institution instructs and to make that instruction boundary enforceable in the product.

  • We do not sell student, child, or guardian data, or share it for advertising.
  • We do not track, profile, or behaviourally monitor children, and run no advertising technology in the product.
  • We do not use student or child data to train AI models. The AEGIS posture is read-only, role-scoped, and audit-backed.
  • We undertake no processing that is likely to have a detrimental effect on the well-being of a child.

11. Grievance Redressal

Complaints, rights requests, and questions about this Policy should be addressed to the Grievance Officer, Fairhelm Systems (OPC) Private Limited, at privacy@squarecampus.com, or by post to the registered office at No. 33, 4th Floor, 1st Main, Road 3, Ganganagar, R T Nagar, Bangalore North, Bangalore – 560032, Karnataka, India.

We acknowledge receipt and respond within ninety days, the period prescribed under the DPDP Rules, 2025. Most requests are answered well inside it. If a grievance is not resolved to your satisfaction, you may complain to the Data Protection Board of India directly — no lawyer and no fee are required.

12. Changes to This Policy

We may update this Privacy Policy occasionally. Updated versions will appear on this page, and we may provide additional notices when appropriate.

The DPDP Rules, 2025 were notified on 14 November 2025 and take effect in phases, with full compliance required by 13 May 2027. We are building toward that date rather than waiting for it, and this Policy will be revised as consent, notice, and rights machinery lands in the product.

Continued use after changes means acceptance of the revised policy.

13. Contact Us

If you have questions or requests, contact:

FAIRHELM SYSTEMS (OPC) PRIVATE LIMITED
Registered office: No. 33, 4th Floor, 1st Main, Road 3, Ganganagar, R T Nagar, Bangalore North, Bangalore – 560032, Karnataka, India
CIN: U62099KA2026OPC225579
Email: privacy@squarecampus.com
Website: https://squarecampus.com

This Privacy Policy is intended for transparency and does not constitute legal advice. Institutions should consult legal counsel to confirm compliance with applicable privacy laws.