Last updated: 24 June 2026

KAAYO Privacy and Data Policy

Last updated: 24 June 2026

1. Introduction

This Privacy and Data Policy ("Policy") describes how Aumraa Technologies Private Limited collects, uses, stores, shares, protects, retains, and deletes personal data in connection with KAAYO.

KAAYO is a product of Aumraa Technologies Private Limited, a company incorporated under the Companies Act, 2013, with its registered office at 1A, Sai Darshan Villas, 7/150, Kattapomman Street, Agaramthen, Chennai, 600126 ("Aumraa", "KAAYO", "we", "us", or "our").

KAAYO is an India-only mobile and software service for tutors, academies, coaching centres, martial arts schools, dance, music, and sports coaches, tuition centres, and similar education or activity businesses. KAAYO helps customers manage student records, parent and guardian contacts, attendance, class schedules, fee records, payment status, fee reminders, data imports, data exports, and subscriptions.

This Policy is published in compliance with applicable Indian law, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and related rules and regulations as in force from time to time.

This Policy applies to:

  • tutors, academy owners, administrators, managers, and staff who create accounts or use KAAYO;
  • personal data about students, parents, and guardians entered into KAAYO by tutors or academies;
  • individuals who contact KAAYO for support, billing, legal, or grievance-related purposes; and
  • product usage, device, security, and analytics data generated through the use of KAAYO.

This Policy should be read together with the KAAYO Terms and Conditions and the KAAYO Refund, Cancellation and Billing Policy. Defined terms used but not defined in this Policy have the meaning given to them in the KAAYO Terms and Conditions.

2. Key Role Split

KAAYO processes different categories of personal data in different capacities, and the responsibilities differ accordingly.

KAAYO as Data Fiduciary. For account, billing, subscription, support, security, analytics, and product usage data relating to tutors, academy owners, managers, staff, and other direct users of KAAYO, Aumraa Technologies Private Limited determines the purpose and means of processing. For this data, KAAYO acts as the Data Fiduciary or equivalent responsible party under applicable Indian law.

Tutor or Academy as Data Fiduciary. For student, parent, and guardian data entered into KAAYO by a tutor or academy, it is the tutor or academy who determines what data to collect, for what purpose, how it is to be used, and when it should be deleted. For this data, the tutor or academy is the primary Data Fiduciary or equivalent responsible party. KAAYO acts as a Data Processor or service provider that processes such data on behalf of the tutor or academy solely to provide and support KAAYO.

In summary:

  • KAAYO is responsible for how KAAYO handles your account, login, billing, subscription, support, security, and product usage data.
  • Tutors and academies are responsible for the student, parent, and guardian data they enter into KAAYO, including the lawfulness of collection, required notices, required consents, and accuracy of that data.
  • KAAYO is responsible for maintaining appropriate technical and organisational safeguards, product controls, deletion and export functionality, and vendor oversight for all data processed through KAAYO.

3. Personal Data KAAYO Collects

3.1 Account and User Data

When you create an account or use KAAYO, we may collect:

  • name;
  • phone number;
  • email address;
  • login method (such as phone OTP or Google Sign-In);
  • profile role (such as owner, master, manager, admin, or staff);
  • organisation or academy name;
  • branch or centre details;
  • account setup and onboarding status;
  • subscription plan, trial status, coupon redemption, and entitlement details;
  • support messages, feedback submissions, and complaint records;
  • device identifiers, authentication tokens, session data, and security event records; and
  • timestamps and activity logs recording actions taken in the application.

3.2 Student Data Entered by Tutors or Academies

Tutors and academies may enter student-related data into KAAYO, including:

  • student name;
  • registration or student identification number;
  • photograph (optional);
  • gender (optional);
  • blood group (optional);
  • address (optional);
  • date of joining;
  • enrolment status (active or inactive);
  • class type, branch, batch, and schedule information;
  • daily or session attendance records;
  • monthly fee and registration fee amounts, payment status, and payment notes;
  • notes or remarks added by the tutor or academy; and
  • other operational data relevant to class management.

KAAYO does not, in the current product, provide a student-facing login, portal, or direct account creation flow.

3.3 Parent and Guardian Data Entered by Tutors or Academies

Tutors and academies may enter parent or guardian contact data into KAAYO, including:

  • father's name and phone number;
  • mother's name and phone number;
  • preferred WhatsApp contact for fee reminders and operational communications;
  • communication preferences (such as preferred language or preferred contact); and
  • notes relating to communication history or fee follow-up.

3.4 Attendance, Fee, Payment, and Reminder Data

KAAYO processes operational records including:

  • attendance date, session, branch, class type, and attendance status for each student;
  • monthly fee records, registration fees, fee amounts, balances, and due dates;
  • payment mode (cash, UPI, bank transfer, or other);
  • payment date and payment reference or notes;
  • generated fee records and fee history;
  • reminder recommendations generated by KAAYO based on payment status;
  • reminder recipient name and phone number;
  • reminder message content, as prepared and displayed by KAAYO;
  • reminder status (prepared, opened, sent, or confirmed); and
  • reminder history and audit trail.

Unless KAAYO expressly provides an integrated payment collection feature, KAAYO records and displays payment status as entered by you but does not collect money from parents on your behalf.

3.5 Import, Export, and File Data

When you use KAAYO's import or export features, we may process:

  • CSV or compatible files selected by you for import;
  • parsed rows, field mapping, and validation results from imported files;
  • import job status, row-level errors, and processing logs;
  • exported datasets (student, payment, attendance, or other operational data);
  • export logs recording who initiated an export and when; and
  • temporary files generated to support import or export operations.

3.6 Billing and Subscription Data

For paid plans, trials, coupons, and subscriptions, we may process:

  • plan type (Basic, Pro, Ultra, custom, pilot, or trial);
  • subscription status and billing cycle;
  • trial start and end dates, and trial eligibility status;
  • coupon code and redemption status;
  • invoice and receipt details;
  • applicable tax or GST information;
  • payment provider transaction identifiers and payment status; and
  • billing support and dispute records.

We do not store raw payment card numbers, CVV codes, or full payment instrument details within KAAYO's own systems. Payment instrument details are processed by the applicable payment provider or app store under their own terms and security standards.

3.7 Device, Security, and Usage Data

To operate, secure, and improve KAAYO, we may collect:

  • device type, operating system version, application version, and language;
  • IP address or approximate network information;
  • authentication events and session data;
  • crash reports, error logs, and application performance data;
  • audit logs and security event logs;
  • feature usage events and analytics events; and
  • diagnostic data required to operate, debug, secure, and improve KAAYO.

KAAYO is designed to avoid transmitting student names, parent names, phone numbers, addresses, payment amounts, or other direct personal identifiers to third-party analytics providers. Where any analytics data is shared with providers, it is intended to be aggregated or anonymised to the extent practicable.

4. How KAAYO Collects Personal Data

We collect personal data:

  • when you register for or access a KAAYO account;
  • when you complete onboarding and configure your academy workspace;
  • when you add, update, import, or manage student, parent, guardian, attendance, fee, payment, or reminder records;
  • when you import CSV files or export data from KAAYO;
  • when you redeem a coupon, start a trial, or subscribe to a paid plan;
  • when you contact us for support, raise a complaint or grievance, or submit feedback;
  • through Firebase, Google Sign-In, phone OTP infrastructure, analytics tools, crash reporting tools, and similar technology providers integrated into KAAYO;
  • through app stores or payment providers where applicable; and
  • automatically through device, security, session, and usage logs generated during your use of the application.

5. Purposes of Processing

5.1 Providing and Operating the Service

We process personal data to:

  • create and maintain user accounts and organisation workspaces;
  • authenticate users and manage session security;
  • enable management of student, parent, and guardian records;
  • process and display attendance records;
  • manage schedules, branches, class types, and batches;
  • manage fee records, payment status, and payment history;
  • prepare and present reminder suggestions;
  • support data import and export operations;
  • manage plan entitlements and subscription status;
  • process trials, coupon redemptions, subscriptions, and billing;
  • provide customer support and troubleshoot product issues; and
  • maintain the overall functionality and performance of KAAYO.

5.2 Security, Integrity, and Fraud Prevention

We process personal data to:

  • prevent and detect unauthorised access, abuse, fraud, or suspicious activity;
  • maintain audit logs and security event records;
  • investigate security incidents and data breaches;
  • enforce the KAAYO Terms and Conditions;
  • protect the security and integrity of KAAYO and the data processed through it; and
  • comply with legal and regulatory obligations relating to security and accountability.

5.3 Product Analytics and Improvement

We use limited, aggregated, and where possible anonymised account-level and organisation-level analytics data to understand how KAAYO features are used, identify and fix bugs, prioritise product improvements, and improve the reliability and usefulness of the service.

KAAYO does not use student-level personal data for behavioural advertising, targeted advertising directed at children, or profiling of children or their families.

KAAYO does not currently use student or parent personal data for AI or machine-learning model training, targeted advertising, or any commercial purpose unrelated to providing KAAYO. If this changes, we will update this Policy in advance and obtain any legally required consent or agreement before doing so.

5.4 Communication

We use account and contact data to:

  • deliver OTPs and authentication-related messages;
  • respond to support requests and complaints;
  • send service, billing, and subscription notices;
  • send security notices and alerts;
  • send notices of changes to policies or terms; and
  • send marketing or promotional communications where permitted by law or where you have provided consent.

You may opt out of marketing communications at any time using the unsubscribe link or mechanism provided, or by contacting us. Opting out of marketing does not affect our ability to send you service, billing, security, or legal communications that are necessary for the operation of your account.

6. Lawful Basis for Processing

KAAYO processes personal data only where permitted under applicable Indian law, including:

  • where processing is necessary to provide KAAYO and fulfil our contractual obligations to you;
  • where processing is necessary for billing, account management, support, security, or legal compliance;
  • where you or your organisation has provided consent for a specific processing activity;
  • where the tutor or academy, as the relevant Data Fiduciary, has obtained the required consent for student, parent, or guardian data entered into KAAYO;
  • where processing is required or expressly authorised by applicable law, including a court order or regulatory direction; or
  • where processing is otherwise permitted under the DPDP Act or other applicable data protection law.

Where consent is the lawful basis for processing, it must be freely given, specific, informed, unconditional, and based on a clear affirmative action. You may withdraw consent at any time. Withdrawal of consent may affect your ability to use certain KAAYO features or services that depend on the processing for which consent was given.

7. Children, Students, Parents, and Guardians

Many students managed through KAAYO may be under 18 years of age. KAAYO recognises the heightened obligations that apply to children's personal data under applicable Indian law, including the DPDP Act.

Tutors and academies, as the Data Fiduciaries for student data, are responsible for:

  • determining what student and guardian data is necessary for their academy operations and limiting collection accordingly;
  • providing parents or lawful guardians with any notice required under applicable law before collecting student data;
  • obtaining verifiable parental or lawful guardian consent where required by applicable law, including in respect of students who are minors;
  • ensuring that student data is accurate, proportionate to the stated purpose, and not retained beyond the period for which it is needed;
  • ensuring that student data is not used in a manner that is harmful, discriminatory, or contrary to the student's interests; and
  • responding to requests from parents, guardians, or students relating to the exercise of data protection rights, where the tutor or academy is the responsible party for that data.

KAAYO supports these obligations by:

  • providing role-based access controls and workspace-level permission management where available;
  • designing analytics and diagnostics to avoid direct child identifiers where practicable;
  • not offering student-facing targeted advertising or behavioural tracking within KAAYO;
  • not knowingly profiling children for commercial or advertising purposes;
  • providing in-product tools to support data correction, deletion, and export by the relevant tutor or academy; and
  • requiring tutors and academies to confirm their responsibility for parental consent in the KAAYO Terms and Conditions.

If you are a parent or guardian with questions or concerns about student data entered into KAAYO by a tutor or academy, your first point of contact should be that tutor or academy directly. KAAYO may facilitate coordination with the relevant tutor or academy to assist in addressing valid requests.

8. WhatsApp and Reminder Data

In its current product configuration, KAAYO may assist tutors and academies in preparing fee reminders, class updates, or attendance notifications and may open WhatsApp or generate a WhatsApp deep link to enable the tutor to send the message manually. In this model, KAAYO generates the message content and the tutor dispatches it from their own device and WhatsApp account.

Tutors and academies are responsible for:

  • holding valid consent or permission from parents or guardians before initiating WhatsApp or other communications;
  • ensuring that messages sent through KAAYO's reminder tools are accurate, operational, and not misleading;
  • not using KAAYO's reminder features to send unsolicited commercial messages, spam, or any communications that violate applicable telecom, consumer protection, or data protection law;
  • respecting and promptly honouring any opt-out or withdrawal of consent communicated by a parent or guardian; and
  • complying with WhatsApp's platform policies, applicable Telecom Regulatory Authority of India guidelines, and Indian data protection and consumer protection law.

If KAAYO introduces automated WhatsApp Business API messaging in a future version, KAAYO may process additional data including approved message templates, opt-in records, opt-out records, message delivery status, and provider-level data. Additional terms, disclosures, and consent mechanisms will be provided before such a feature is made available.

9. Sharing and Subprocessors

KAAYO may share personal data with third-party service providers and subprocessors to the extent necessary to operate and deliver KAAYO. These providers may include:

  • cloud hosting and database providers, including Firebase (Google LLC) and Google Cloud Platform;
  • authentication infrastructure providers, including Firebase Authentication, Google Sign-In, and phone OTP providers;
  • file and object storage providers, used for photographs or user-uploaded files;
  • analytics and product usage monitoring tools, such as PostHog or similar providers;
  • crash reporting and application performance monitoring tools;
  • mobile platform and app store providers (Google Play, Apple App Store);
  • payment gateways and subscription billing providers, such as Razorpay or other applicable providers;
  • communication and messaging infrastructure providers;
  • email and customer support tools;
  • professional advisors, including legal counsel, accountants, auditors, and tax advisors, who are bound by confidentiality obligations; and
  • government authorities, law enforcement agencies, courts, or regulators, where disclosure is required by law, a court order, or a lawful regulatory direction.

KAAYO uses reasonable contractual and operational measures to ensure that service providers process personal data only for the purposes for which it was shared and maintain appropriate security standards.

A list of material subprocessors is available on written request to ramkumar.g@aumraa.com.

10. Cross-Border Data Processing

KAAYO is designed for users in India and we aim to host core production infrastructure within India where this is technically and commercially practicable.

Some third-party service providers, analytics tools, communication platforms, payment providers, app stores, or crash reporting tools may process or have access to personal data from servers or operations located outside India. Where such processing occurs, it is subject to the terms and security standards of the relevant provider.

KAAYO will take such steps as are reasonably required under applicable Indian law to ensure that any cross-border transfer or access is conducted with appropriate safeguards and in compliance with requirements that may be notified under the DPDP Act or related rules from time to time.

11. Security

KAAYO implements reasonable technical and organisational security measures designed to protect personal data against unauthorised access, disclosure, alteration, loss, destruction, or misuse. Security measures include, but are not limited to:

  • access authentication controls, including OTP and Sign-In mechanisms;
  • role-based access controls within the KAAYO workspace;
  • restrictions on internal staff and contractor access to production data;
  • Firebase and Google Cloud platform security controls and security rules;
  • encrypted data transmission over HTTPS and secure protocols where supported;
  • audit logs and security event logging;
  • backup and data recovery practices;
  • security monitoring and incident investigation processes; and
  • vendor controls and data processing agreements with key service providers.

No information security system is completely impenetrable. You are responsible for securing your device, your login credentials, your staff's access, any exported files, and any communication channels you use in connection with KAAYO. KAAYO's security measures do not relieve you of your own security obligations.

12. Data Retention

KAAYO retains personal data only for as long as is reasonably necessary to fulfil the purposes described in this Policy, unless a longer period is required or permitted by applicable law, tax obligations, accounting requirements, billing and audit needs, security incident management, dispute resolution, or other legitimate business purposes.

The following provides an indicative guide to our retention approach. Specific periods may be updated as KAAYO matures and as applicable legal requirements are clarified.

  • User account data: Retained for the duration of the active account and for a reasonable period following account closure (typically up to 3 years) for legal, support, security, and dispute purposes, unless a shorter or longer period is required by law.
  • Billing and subscription records: Retained for a minimum of 7 years from the date of the transaction, as required for accounting, tax, audit, and legal purposes under Indian law.
  • Student profile and enrolment data: Retained for as long as the tutor or academy maintains the student record as active, and for a reasonable period thereafter as instructed by the tutor or academy or as required by applicable law.
  • Parent and guardian contact data: Retained for as long as required for academy operations as determined by the tutor or academy, and deleted upon instruction or in accordance with the tutor or academy's data management practices.
  • Attendance records: Retained for as long as needed by the tutor or academy for class administration, parent queries, reporting, and dispute resolution.
  • Fee and payment records: Retained for as long as needed for fee administration, accounting, tax compliance, parent queries, and resolution of disputes, and for a minimum period consistent with applicable accounting and tax law.
  • Student photographs and optional sensitive fields: Retained only for the period for which the tutor or academy requires them; tutors and academies should delete these when no longer necessary.
  • Import files and import logs: Temporary import files are deleted or overwritten in accordance with product design and backup cycles; import job logs may be retained for support, accountability, and security purposes for a limited period.
  • Reminder logs: Retained for operational accountability and support, for a period not exceeding what is necessary for those purposes.
  • Security and audit logs: Retained for a minimum of 1 year, and for longer periods where required for regulatory compliance, security incident investigation, or legal proceedings.
  • Analytics events: Retained for a limited period determined by the analytics configuration and business need, not exceeding what is necessary for the relevant product analysis purpose.
  • Backup copies: Retained in accordance with applicable backup schedules and deleted as backups expire and are rotated.

Deletion may not be instantaneous across all systems. Data may remain present in backup copies for a limited period following deletion from active systems, after which it will be purged as backups are rotated.

13. Deletion, Correction, and Export

KAAYO provides, or intends to provide, in-application functionality enabling tutors and academies to correct, deactivate, export, or delete student, parent, attendance, payment, and related data for which they are responsible.

Tutors and academies are responsible for exercising these controls in respect of student and guardian data they have entered and for responding to data rights requests made by parents, guardians, or students.

If you wish to request deletion of your KAAYO account or require assistance with a data correction or access request relating to your own account data, you may do so by contacting KAAYO at ramkumar.g@aumraa.com or through any in-application account management flows that may be available.

Deletion of your account or specific data records will be carried out within a reasonable period. Some data may continue to be retained for a limited time in backup copies, audit logs, security records, billing records, legal records, or records required for dispute resolution, fraud prevention, or compliance with applicable law, after which it will be deleted in accordance with this Policy.

Where KAAYO receives a data rights request from a parent, guardian, student, or staff member that relates to personal data for which a tutor or academy is the responsible party, KAAYO will direct that request to the relevant tutor or academy and may assist them in responding to the extent practicable.

14. Your Rights and How to Exercise Them

Subject to applicable Indian law and to verification of your identity, you may have the following rights in respect of your personal data:

  • Access: to request confirmation of whether KAAYO processes your personal data and to receive a summary of that data;
  • Correction: to request correction of personal data that is inaccurate, incomplete, or out of date;
  • Erasure: to request deletion of personal data that is no longer required for the purpose for which it was collected, subject to applicable retention obligations and other lawful grounds for retention;
  • Withdrawal of consent: to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing prior to withdrawal;
  • Grievance: to raise a grievance with KAAYO's designated grievance contact regarding any alleged violation of applicable data protection law or this Policy;
  • Nomination: to nominate another individual to exercise rights on your behalf in the event of death or incapacity, to the extent provided by applicable law; and
  • Regulatory complaint: to approach the appropriate data protection authority or regulatory body if you are dissatisfied with the outcome of a grievance raised with KAAYO.

To exercise rights relating to your KAAYO account, billing, support, or product usage data, contact KAAYO at ramkumar.g@aumraa.com.

For student, parent, or guardian data entered by a tutor or academy, the tutor or academy is ordinarily the appropriate first point of contact because they are responsible for the purpose and means of processing that data. KAAYO may assist in facilitating a response where required.

We will verify your identity before acting on any rights request. We may decline or limit a request where permitted by law, including where we cannot verify the requester's identity, where the request relates to data for which another party is responsible, or where retention of the data is required for lawful purposes.

15. Grievance Officer

In accordance with the requirements of applicable Indian law, including the Information Technology Act, 2000 and the DPDP Act, Aumraa Technologies Private Limited has designated a Grievance Officer to receive and address complaints or concerns relating to personal data processing.

Grievance Officer / Designated Contact: C K Ganesh, Director, Aumraa Technologies Private Limited

Contact email: ramkumar.g@aumraa.com

Address: 1A, Sai Darshan Villas, 7/150, Kattapomman Street, Agaramthen, Chennai, 600126

We aim to acknowledge grievances within 48 hours of receipt and to resolve or respond substantively within a reasonable period, in compliance with any timelines prescribed under applicable law. Where a grievance relates to student or guardian data controlled by a tutor or academy, we may coordinate with that tutor or academy as part of the resolution process.

16. Data Breach and Incident Notification

If Aumraa Technologies Private Limited becomes aware of a personal data breach affecting personal data for which it is the Data Fiduciary, KAAYO will take reasonable and prompt steps to investigate, contain, and remediate the breach and will notify affected individuals and relevant authorities in accordance with the timelines and requirements prescribed by applicable Indian law, including any requirements notified under the DPDP Act.

Where a breach affects student, parent, or guardian data processed by KAAYO on behalf of a tutor or academy, KAAYO will notify the relevant tutor or academy promptly and will assist them in complying with any notification obligations they may have under applicable law.

You must notify KAAYO without undue delay if you become aware of or suspect any incident involving your KAAYO workspace, including unauthorised access to your account, accidental disclosure of exported data, loss of a device used to access KAAYO, compromise of staff accounts, or any other event that may constitute a personal data breach. Prompt notification enables KAAYO to take timely containment and remediation steps.

17. Marketing Communications

KAAYO may send service, support, billing, security, legal, and operational communications that are necessary for the administration and delivery of KAAYO. These communications are not subject to opt-out as they are required for the service.

KAAYO may send marketing or promotional communications where permitted by applicable law or where you have provided consent. You may opt out of marketing communications at any time by using the unsubscribe link or mechanism included in the relevant communication or by contacting us directly.

Opting out of marketing does not affect the delivery of service, billing, security, or legal communications.

18. Data After Export

When you export data from KAAYO, the exported copy may reside on your device, in another application on your device, in a file-sharing or storage service, or with a third party to whom you transmit it.

From the point of export, you assume full responsibility for the security of that exported copy and for ensuring that it is shared only with persons who are authorised to receive and process it. KAAYO has no ability to control, monitor, or restrict the use of exported data outside KAAYO's own systems.

KAAYO may log export activity, including the identity of the user who initiated the export and the date and time of export, for security, accountability, support, and compliance purposes.

19. Changes to This Policy

KAAYO may update this Policy from time to time to reflect changes in our practices, applicable law, regulatory guidance, or product functionality. When we update this Policy, we will revise the "Last updated" date at the top of this document and may notify you through the application, our website, email, or other appropriate channels.

Where changes are material, we will endeavour to provide reasonable advance notice before they take effect, unless an immediate update is required for legal, security, or operational reasons.

Your continued use of KAAYO following an update to this Policy constitutes your acceptance of the revised Policy. If you do not accept the revised Policy, you must stop using KAAYO.

20. Contact

For questions, concerns, or communications relating to this Policy, contact:

Aumraa Technologies Private Limited

Privacy email: ramkumar.g@aumraa.com

Legal email: ramkumar.g@aumraa.com

Support email: ramkumar.g@aumraa.com

Address: 1A, Sai Darshan Villas, 7/150, Kattapomman Street, Agaramthen, Chennai, 600126

Grievance Officer / Designated Contact: C K Ganesh, Director, Aumraa Technologies Private Limited