# Data Policy | Legal | SwaVid

SwaVid data governance, child data, retention, vendor, transfer, security, and rights policy.

Canonical: https://www.swavid.com/legal/data-policy

Source: https://swavid.com/legal/data-policy

# Data Policy

## Table Of Contents

## 1. Status And Scope

## 2. Data Classification

## 3. Collection Principles

## 4. Use Limitation

## 5. AI And Learning Analytics Data

## 6. Retention And Deletion

## 7. Access Controls And Security

## 8. Vendors And Sub-processors

## 9. Cross-border Transfers

## 10. Rights, Requests, And Governance

## 11. Minimum Product Controls For Child Data

## 12. Data Protection Impact And AI Governance

## Related Legal Documents

Legal document | Last updated 20 June 2026

This Data Policy forms part of the public legal framework of Swavid Edutech Private Limited for the operation of SwaVid. It is intended to be read together with the Privacy Policy, Terms and Conditions, Children Privacy Notice, Cookie Policy, Parent Consent Notice, Sub-processor List, Data Processing Addendum, and Student Data Protection Agreement.

This Data Policy sets out the internal-facing and user-facing principles by which SwaVid collects, classifies, uses, discloses, stores, retains, deletes, secures, and governs personal data, student data, education records, learning analytics, AI interaction data, operational logs, support records, and vendor-processed data.

All data rights, privacy, grievance, school, parent, deletion, export, access, correction, consent-withdrawal, and legal requests must be sent to info@swavid.com.

This Data Policy applies to SwaVid websites, mobile applications, dashboards, assessments, diagnostics, learning-debt tools, AI tutoring systems, voice and chat learning tools, parent reports, teacher dashboards, school tools, support channels, payment records, analytics systems, and related services.

This Data Policy applies to personal data processed by SwaVid as a data fiduciary, controller, business, processor, service provider, operator, school official, vendor, sub-processor, or equivalent role, depending on the applicable legal framework and the written agreement governing the processing.

If a signed school agreement, institutional agreement, data processing addendum, or student data protection agreement imposes stricter obligations than this Data Policy, the stricter obligation shall apply to that relationship to the extent legally enforceable.

SwaVid classifies data according to sensitivity and expected risk. Public data includes marketing pages and public legal notices. Internal data includes operational documentation, product analytics, and non-public business records. Confidential data includes account records, support records, billing metadata, school records, contracts, and vendor records. Restricted data includes children personal data, student learning records, diagnostic outputs, voice or chat transcripts, authentication credentials, security logs, private reports, and any data capable of identifying a child or revealing sensitive learning patterns.

Restricted data must be handled under enhanced controls, including role-based access, minimisation, secure transfer, limited retention, vendor review, and deletion or de-identification when the legal or operational purpose expires.

SwaVid shall collect personal data only for specified, lawful, educational, contractual, security, support, payment, analytics, or compliance purposes. SwaVid shall not knowingly collect child personal data merely because it may be useful in the future.

Where a student is under 18, SwaVid applies a parent-led or school-authorised collection model unless the applicable law permits a different lawful basis. The product should avoid collecting a child direct phone number, precise location, government identity number, unnecessary image, or unrelated personal information unless required for a specific lawful purpose.

Where SwaVid collects personal data directly from a parent, guardian, student, teacher, school, partner, or visitor, SwaVid shall make available appropriate notices describing the categories collected, purposes, rights, retention, sharing, contact channel, and any material AI or profiling use.

SwaVid uses data to provide educational diagnostics, adaptive lessons, personalised tutoring, learning recommendations, parent reports, teacher visibility, school analytics, support, payments, account administration, safety, security, legal compliance, and product improvement.

SwaVid shall not sell children personal data. SwaVid shall not use children learning data for unrelated advertising. SwaVid shall not knowingly direct targeted advertising to children. SwaVid shall not use identifiable child learning records to train general-purpose models unless the processing is legally permitted and specifically authorised by the parent, school, or applicable agreement.

SwaVid may use aggregated, anonymised, or de-identified data for research, product improvement, quality measurement, safety testing, model evaluation, curriculum-quality analysis, and business reporting, provided reasonable measures are used to prevent re-identification and the data is not used to make decisions about an identifiable child unless legally permitted.

AI interaction data may include student prompts, typed answers, spoken answers, transcripts, response timing, hint use, confusion signals, diagnostic answers, generated explanations, model responses, and teacher or parent feedback. SwaVid treats this data as restricted where it can identify a student or reveal a learning profile.

SwaVid shall apply minimisation before sending prompts or context to AI providers where practicable. The prompt context should be limited to what is required to generate the requested educational output, safety response, or learning recommendation.

AI and learning analytics may be used to personalise instruction, recommend practice, detect prerequisite gaps, generate reports, improve explanations, and help parents or teachers understand learning needs. These outputs are educational aids and must not be treated as medical, psychological, clinical, or legally determinative assessments.

SwaVid shall retain personal data only for as long as reasonably necessary for the purposes described in the applicable notice, contract, consent, school instruction, legal obligation, security requirement, dispute, tax obligation, fraud-prevention need, backup cycle, or legitimate service operation.

Student learning records and diagnostic reports should remain available while the account, school relationship, parent consent, or learning programme is active, unless deletion is requested and no legal or contractual retention basis applies. Voice and chat history should be retained only for limited operational, safety, support, or personalisation purposes unless a parent, school, or applicable law authorises longer retention.

Deletion may involve erasure, de-identification, anonymisation, archive restriction, or backup expiry, depending on the data type and system. SwaVid may retain limited records necessary to prove compliance, resolve disputes, prevent fraud, comply with law, maintain accounting records, or protect child safety.

Access to restricted data must be limited to authorised personnel, service providers, school administrators, parents, guardians, teachers, or users with a legitimate need and appropriate permissions. Access should be reviewed when roles change or accounts are terminated.

Security controls may include authentication, authorisation, encryption in transit, protected backend routes, ownership checks, audit logging, rate limiting, abuse detection, vendor security review, backup controls, secure development review, incident response, and least-privilege permissions.

No security control can eliminate all risk. SwaVid shall maintain reasonable safeguards proportionate to the sensitivity of student and children data and shall improve them over time based on law, product risk, incident lessons, and vendor changes.

SwaVid may use hosting, database, AI, speech, email, messaging, payments, analytics, monitoring, storage, customer-support, security, and professional-service vendors. Vendors that process restricted data should be subject to appropriate contractual obligations, confidentiality duties, security controls, breach assistance, deletion obligations, and transfer safeguards where required.

SwaVid should maintain a current sub-processor list for production school, child, EU, UK, US, or other regulated deployments. Schools and enterprise customers may request vendor information through info@swavid.com.

Because SwaVid is operated from India and uses global digital infrastructure and AI providers, data may be processed in India and other countries. Cross-border transfers shall be governed by applicable law, contract, vendor safeguards, transfer impact assessment where required, Standard Contractual Clauses where applicable, and any governmental restriction binding on SwaVid.

Where a school or institutional customer imposes data-residency or restricted-transfer requirements, those requirements must be documented in the applicable signed agreement before onboarding regulated student data.

Parents, guardians, eligible students, users, schools, and authorised representatives may request access, correction, update, completion, export, deletion, consent withdrawal, objection, restriction, grievance review, or human review where available under applicable law and subject to verification.

SwaVid may deny, limit, defer, or condition a request where required or permitted by law, where the requester cannot be verified, where the requester lacks authority over a child or school record, where disclosure would compromise another person privacy, where retention is legally required, or where the request is manifestly abusive or technically infeasible within legal limits.

SwaVid shall maintain internal responsibility for data governance, including legal review, product review, security review, vendor review, incident response, child-safety review, retention review, and documentation of material compliance decisions.

SwaVid child-data controls should include parent-led account creation, consent records, separate marketing consent, child-safe defaults, no targeted advertising to children, no unnecessary child phone collection, private profiles by default, limited sharing, authenticated report access, school-authorised role controls, and a rights-request workflow.

Where a product control is not yet fully automated, SwaVid may handle the request manually through info@swavid.com until an in-product control exists. Manual handling does not remove the obligation to verify authority, document the request, take timely action, and record the outcome.

SwaVid should assess higher-risk processing before launch or material change, including AI tutoring, learning profiling, voice transcription, school integrations, child analytics, international transfers, vendor changes, and automated recommendations that may affect a student learning path.

The assessment should consider purpose, necessity, proportionality, data minimisation, child welfare, bias, explainability, human oversight, security, vendor controls, retention, lawful basis, consent, and available alternatives. The outcome should be documented and reviewed by appropriate product, security, and legal owners.

The following documents form part of SwaVid&#x27;s public legal framework and may be incorporated by reference where applicable. Formal notices and requests should be sent to info@swavid.com .

- 1 . Status And Scope
- 2 . Data Classification
- 3 . Collection Principles
- 4 . Use Limitation
- 5 . AI And Learning Analytics Data
- 6 . Retention And Deletion
- 7 . Access Controls And Security
- 8 . Vendors And Sub-processors
- 9 . Cross-border Transfers
- 10 . Rights, Requests, And Governance
- 11 . Minimum Product Controls For Child Data
- 12 . Data Protection Impact And AI Governance
- Privacy Policy
- Terms and Conditions
- Children Privacy
- Cookie Policy
- Parent Consent
- Refunds
- Grievance
- AI Safety
- Sub-processors
- Security
- DPA
- Student Data

## Key Links

- [SwaVid](https://swavid.com/)
- [Legal](https://swavid.com/legal/privacy-policy)
- [info@swavid.com](https://swavid.commailto:info@swavid.com)
- [Privacy Policy](https://swavid.com/legal/privacy-policy)
- [Terms and Conditions](https://swavid.com/legal/terms-of-service)
- [Children Privacy](https://swavid.com/legal/children-privacy-notice)
- [Cookie Policy](https://swavid.com/legal/cookie-policy)
- [Parent Consent](https://swavid.com/legal/parent-consent-notice)
- [Refunds](https://swavid.com/legal/refund-cancellation-policy)
- [Grievance](https://swavid.com/legal/grievance-redressal)
- [AI Safety](https://swavid.com/legal/ai-safety-disclaimer)
- [Sub-processors](https://swavid.com/legal/sub-processors)
- [Security](https://swavid.com/legal/security)
- [DPA](https://swavid.com/legal/data-processing-addendum)
- [Student Data](https://swavid.com/legal/student-data-protection-agreement)