XYORO
Terms of Service ← Back to Login

Privacy Policy

Effective date: 23 July 2026 · Version 1.0

This Privacy Policy explains how Mynaix (OPC) Private Limited (“XYORO”, “we”, “us”) collects, uses, shares and protects personal data when you use the XYORO school-management platform (the “Service”). Because XYORO serves schools across many countries, this policy includes a set of jurisdiction-specific sections describing how the applicable national and regional laws apply to you. Where a mandatory local law conflicts with the general parts of this policy, the local law and the relevant jurisdiction section prevail.

🇮🇳 India (DPDP Act) GCC (UAE / KSA / Bahrain / Qatar / Oman / Kuwait) EU / EEA (GDPR) United Kingdom United States (FERPA / COPPA / CCPA) Indonesia & Southeast Asia Other jurisdictions

1. Our Role: Controller and Processor

For most data inside the Service — student, academic, attendance, fee and communication records entered by a school — the subscribing institution (the “Tenant”) is the data controller (or equivalent, e.g. “data fiduciary” in India) and XYORO is the data processor acting on the Tenant’s instructions. For a limited set of data — account registration, billing, security logs and product analytics — we act as a controller in our own right. If you are a student, parent or staff member, please also refer to the privacy notice of your school.

2. Personal Data We Process

CategoryExamples
Identity & contactName, email, mobile number, role, photograph, address, guardian relationships.
Student & academicAdmission and enrolment records, class/section, grades, report cards, attendance, timetable, co-curricular activity.
FinancialFee invoices, payment status, and transaction references processed via payment gateways (we do not store full card numbers).
CommunicationsIn-app notifications and messages sent via email, SMS, WhatsApp and push, plus delivery metadata.
Technical & usageLogin events, device/browser, IP address, language preference, and security/audit logs.
Sensitive data (where a school chooses to record it)Health, dietary, disability or similar information necessary for student welfare, processed under stricter safeguards and only where lawful.

3. How and Why We Use Data

  • To provide, operate, secure and support the Service for the school.
  • To enable school administration: admissions, attendance, examinations, fees, timetabling and reporting.
  • To deliver notifications and messages the school chooses to send to staff, students and guardians.
  • To authenticate users, prevent fraud/abuse and maintain audit trails.
  • To provide optional AI assistance (Ask Myna) that helps summarise or draft content within the Service.
  • To bill Tenants and comply with tax, accounting and legal obligations.

We do not sell personal data, and we do not use student data for advertising or to build advertising profiles.

4. Legal Bases

Depending on your jurisdiction, we and the school rely on one or more of: performance of a contract; compliance with a legal obligation; consent (including verifiable parental consent for children); the legitimate interests of the school or XYORO in operating an educational service; and the public interest / official authority of a recognised educational institution. The applicable basis is described further in the jurisdiction sections below.

5. Children’s Data

Children’s privacy is central to a school platform. Student accounts are created and controlled by the school. Where the law requires consent for processing a child’s data, that consent is obtained and managed by the school from a parent or legal guardian. We process children’s data only to provide educational services to the school, never for advertising, profiling or unrelated purposes, and we apply additional access controls and retention limits to it.

6. Sharing & Sub-processors

We share personal data only as needed to run the Service: with cloud hosting, email, SMS, WhatsApp Business, push-notification and payment providers acting as our sub-processors under contract; with a school’s own authorised users according to their roles; and where required by law or valid legal process. We require sub-processors to protect data to standards consistent with this policy. A current list of sub-processors is available on request to privacy@xyoro.net.

7. International Data Transfers

Data may be processed in countries other than your own, including where our hosting or sub-processors operate. Where we transfer personal data across borders, we use appropriate safeguards recognised by the relevant law — such as standard contractual clauses, adequacy decisions, or a lawful transfer mechanism / registration under the applicable national law — and, where a country requires local storage of certain records, we support region-appropriate hosting for those Tenants.

8. Data Retention

We retain personal data for as long as the school’s account is active and as needed to provide the Service, then delete or anonymise it within a reasonable period, unless a longer retention is required by education, tax or other law, or to resolve disputes and enforce agreements. Tenants can request export or deletion of Customer Data as described in Section 10.

9. Security

We apply administrative, technical and organisational measures appropriate to the risk, including encryption in transit, role-based access control, tenant isolation, audit logging and regular backups. No system is perfectly secure; we maintain procedures to detect, respond to and, where required, notify relevant authorities and affected persons of personal-data breaches within the timelines set by applicable law.

10. Your Rights & Choices

Subject to your local law, you may have rights to access, correct, update, delete, restrict or object to processing of your personal data, to data portability, to withdraw consent, and to nominate or complain to a regulator. Because a school is usually the controller, please first contact your school; you may also contact us at privacy@xyoro.net and we will assist or route your request to the school. We respond within the timeframes required by the applicable jurisdiction.

11. Cookies & Similar Technologies

We use strictly necessary cookies and local storage to keep you signed in, remember your language, and secure the Service. We do not use third-party advertising cookies. Where consent for non-essential cookies is required by your jurisdiction, we request it before setting them.

Jurisdiction-Specific Provisions

🇮🇳 India

For personal data processed in India, we and the schools comply with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. The school generally acts as the Data Fiduciary and XYORO as a Data Processor. Processing of a child’s data (a person below 18) requires verifiable consent of a parent or lawful guardian, obtained and managed by the school; we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. You may exercise your rights of access, correction, completion, updating, erasure and grievance redressal. Our Grievance Officer under the DPDP Act and IT Rules is:

Koteswara Rao Vemulapati — kotesh@xyoro.net. You may also approach the Data Protection Board of India if your concern is not resolved.

Gulf Cooperation Council (GCC)

For Tenants in the Gulf region, we support compliance with the applicable national data-protection laws, including:

  • United Arab Emirates — Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), overseen by the UAE Data Office (plus DIFC Data Protection Law No. 5 of 2020 and ADGM Data Protection Regulations 2021 for entities in those free zones).
  • Kingdom of Saudi Arabia — the Personal Data Protection Law (PDPL) and its Implementing Regulations, supervised by SDAIA, including provisions on lawful basis, data-subject rights and cross-border transfer.
  • Bahrain — Personal Data Protection Law (Law No. 30 of 2018).
  • Qatar — Law No. 13 of 2016 concerning Personal Data Privacy Protection.
  • Oman — Personal Data Protection Law (Royal Decree No. 6/2022).
  • Kuwait — the CITRA Data Privacy Protection Regulation.

For these Tenants we honour data-subject rights, apply lawful cross-border-transfer mechanisms, and can offer region-appropriate hosting and Arabic-language support where required. Consent for processing a minor’s data is obtained by the school from the parent or guardian in line with local law.

European Union / EEA

For personal data of individuals in the EU/EEA, we comply with the General Data Protection Regulation (EU) 2016/679 (GDPR). The school is the controller and XYORO is a processor under Article 28, governed by a data-processing agreement. You have the rights of access, rectification, erasure, restriction, portability and objection, and the right not to be subject to solely automated decisions with legal effect. International transfers rely on adequacy decisions or Standard Contractual Clauses. You may lodge a complaint with your national Data Protection Authority. Our EU privacy contact is dpo@xyoro.net.

United Kingdom

For individuals in the UK, we comply with the UK GDPR and the Data Protection Act 2018. Rights and safeguards are equivalent to those described in the EU section, and you may complain to the Information Commissioner’s Office (ICO). Restricted transfers use the UK International Data Transfer Agreement or Addendum.

United States

For US schools and students, we support compliance with education- and child-specific laws:

  • FERPA (Family Educational Rights and Privacy Act) — we act as a “school official” with a legitimate educational interest, use education records only for the school’s authorised purposes, and do not re-disclose them except as permitted or directed by the school.
  • COPPA (Children’s Online Privacy Protection Act) — for children under 13, the school provides consent on behalf of parents in the school context; we collect only data needed for the educational service and do not use it for advertising.
  • State student-privacy laws (e.g. California’s SOPIPA) — we do not sell student data or use it for targeted advertising or profiling.
  • CCPA/CPRA (California) — where applicable to account/billing data we act as a “service provider”; California residents may exercise rights to know, delete, correct and opt out of “sale”/“sharing” (which we do not do for personal data).

Indonesia & Southeast Asia

  • Indonesia — Law No. 27 of 2022 on Personal Data Protection (PDP Law): the school acts as data controller and XYORO as processor; we support data-subject rights, breach notification, and appointment of a data-protection officer where required, with Bahasa Indonesia interfaces available.
  • Singapore — the Personal Data Protection Act 2012 (PDPA), including consent, purpose-limitation and the Do-Not-Call provisions for marketing messages.
  • Malaysia — the Personal Data Protection Act 2010, including the data-protection principles and cross-border rules.

Other Jurisdictions

For Tenants elsewhere (for example Australia’s Privacy Act, Canada’s PIPEDA, Brazil’s LGPD, South Africa’s POPIA, Nigeria’s NDPA and other national laws), we apply the general protections in this policy together with any additional rights, safeguards, localisation or notification requirements imposed by the applicable local law. If your jurisdiction requires specific contractual terms or a local representative, contact us and we will provide the appropriate arrangements.

12. Data-Protection & Grievance Contacts

Data Protection Officer: dpo@xyoro.net
Grievance Officer (India): Koteswara Rao Vemulapati — kotesh@xyoro.net
General privacy contact: privacy@xyoro.net
Operator: Mynaix (OPC) Private Limited

13. Changes to this Policy

We may update this Privacy Policy to reflect changes in our practices or the law. Material changes will be notified in the Service or by email, and the “Effective date” will be updated. Your continued use after the effective date constitutes acceptance of the updated policy.

Copyright © XYORO 2026 · Mynaix (OPC) Private Limited