01
The Data Fiduciary
FAIRHELM SYSTEMS (OPC) PRIVATE LIMITED (CIN U62099KA2026OPC225579), incorporated in India on 5 August 2026 under the Companies Act, 2013 and operating as Fairhelm Systems, is the Data Fiduciary for the personal data described in this notice. Its registered office is No. 33, 4th Floor, 1st Main, Road 3, Ganganagar, R T Nagar, Bangalore North, Bangalore – 560032, Karnataka, India.
This notice is written against the Digital Personal Data Protection Act, 2023 (the DPDP Act) and uses its vocabulary: a Data Principal is the individual the data is about, a Data Fiduciary decides why and how the data is processed, and a Data Processor processes it on a Fiduciary's instructions.
Where Fairhelm processes personal data on behalf of a school, trust, or other contracting customer, that customer is the Data Fiduciary and Fairhelm acts as its Data Processor. In that case the customer's own notice governs the Data Principal relationship, and the signed agreement governs Fairhelm's handling.
02
Categories of personal data
The categories below are the full set Fairhelm may process across the public website and a contracted deployment. The public website itself processes only the first two categories.
- Technical and delivery data: IP address, user agent, timestamp, requested path, response status, and security signals generated by the infrastructure that serves and protects the site.
- Inquiry data: the name, work email, organisation, role, and message content a visitor chooses to submit through the contact form or send by email.
- Institutional user data: names, contact details, role and authority assignments, and audit records for the staff and administrators authorised to use a deployed system.
- Student data: enrolment and identification records, class and section, attendance, assessment and academic records, fee and payment status, and guardian linkage — processed only inside a contracted deployment, on the institution's instructions.
- Children's data: much student data belongs to Data Principals under eighteen. Fairhelm treats it as children's personal data under section 9 of the DPDP Act, and the additional restrictions below apply to all of it.
- Guardian and parent data: contact details, relationship to the student, consent and authorisation records, and communications.
03
Children's and student data
Student records are the most sensitive data Fairhelm touches, and a large share of them concern children — anyone under eighteen. Section 9 of the DPDP Act requires verifiable consent from a parent or lawful guardian before a child's personal data is processed, and prohibits tracking, behavioural monitoring, and targeted advertising directed at children. Rule 10 of the DPDP Rules, 2025 adds that the consent must be genuinely verifiable: due diligence is required to confirm that the person giving it is an identifiable adult entitled to act for the child.
In a school deployment the institution holds the relationship with students and guardians, and is responsible for obtaining and recording verifiable parental consent. Fairhelm's role is to process what the institution instructs and to make that instruction boundary enforceable in the product.
- Fairhelm does not sell student, child, or guardian data, and does not share it for advertising or marketing by anyone.
- Fairhelm does not track, profile, or behaviourally monitor children, and runs no advertising technology in any product surface.
- Fairhelm does not use student or child data to train AI models. The AI posture is read-only, role-scoped, and audit-backed.
- No processing is undertaken that is likely to have a detrimental effect on the well-being of a child.
- This public marketing website is directed at institutional decision-makers. It is not intended for children, and students, parents, and schools should not use it to transmit operational records.
04
Purposes of processing
Personal data is processed only for a specified purpose, and only for as long as that purpose remains live.
- Delivering the website reliably, and protecting it against abuse, intrusion, and denial of service.
- Understanding and responding to an inquiry, and assessing whether an engagement is a good fit.
- Providing, operating, supporting, and securing a contracted product or service for an institution.
- Maintaining audit records, access logs, and evidence of authority so institutional decisions stay reviewable.
- Meeting accounting, tax, corporate, and other legal obligations that apply to the company.
05
Consent and legitimate uses
Where Fairhelm is the Data Fiduciary, processing rests on the consent you give when you contact the company, or on a legitimate use recognised by section 7 of the DPDP Act — including data you voluntarily provide for a purpose you have not objected to, and processing required to comply with a legal obligation.
Consent given to Fairhelm may be withdrawn at any time, with the same ease as it was given, by writing to the grievance contact below. Withdrawal stops further processing for that purpose; it does not undo processing already carried out lawfully, and it does not affect records the company must retain by law.
Fairhelm does not use consent notices to bundle unrelated purposes together, and does not treat silence as consent.
06
Retention and erasure
Personal data is erased once the purpose it was collected for is served and no legal requirement keeps it alive, in line with section 8(7) of the DPDP Act.
- Website delivery and security logs: retained for a short operational window sufficient for reliability and incident investigation, then discarded.
- Inquiry correspondence: retained while a conversation or evaluation is active, and for a reasonable period afterwards for business records; erased on request where no legal obligation requires otherwise.
- Contracted product data, including student and children's data: retained and deleted according to the institution's documented instructions and the signed agreement, subject to technically reasonable backup cycles.
- Statutory records: retained for the period the Companies Act, tax law, or other applicable law requires.
08
Security safeguards
Fairhelm applies reasonable security safeguards to prevent a personal data breach, as section 8(5) of the DPDP Act requires. The product posture is role-based access control, least privilege, tenant separation, encryption in transit, and audit records that make access reviewable after the fact.
On becoming aware of a personal data breach, Fairhelm intimates each affected Data Principal without delay — describing the nature, extent and timing of the breach, its likely consequences, the mitigation being applied, the steps the person can take, and where to reach us — and reports it to the Data Protection Board of India, followed by a detailed report within 72 hours as Rule 7 of the DPDP Rules, 2025 requires. Where Fairhelm acts as a Processor, it notifies the customer without delay so the customer can meet its own obligation.
No safeguard is absolute. Do not send credentials, government identifiers, payment details, health information, or student records in an initial email; a governed transfer method should be agreed first.
09
Your rights as a Data Principal
Where Fairhelm is the Data Fiduciary, the DPDP Act gives you the following rights. Requests may be sent to the grievance contact below.
- Right to access: a summary of the personal data being processed, the processing activities, and the identities of other Fiduciaries and Processors it has been shared with (section 11).
- Right to correction, completion, updating, and erasure of your personal data (section 12).
- Right of grievance redressal: a readily available means of raising a complaint with Fairhelm, answered within the period prescribed under the Act, before approaching the Data Protection Board (section 13).
- Right to nominate another individual to exercise these rights on your behalf in the event of your death or incapacity (section 14).
- Right to withdraw consent at any time, as described above.
10
Grievance contact
Complaints, rights requests, and questions about this notice should be addressed to the Grievance Officer, Fairhelm Systems (OPC) Private Limited, at hello@fairhelmsystems.com, or by post to the registered office at No. 33, 4th Floor, 1st Main, Road 3, Ganganagar, R T Nagar, Bangalore North, Bangalore – 560032, Karnataka, India.
Fairhelm may need to verify your identity, and your authority where you are acting for someone else, before acting on a request. Requests are acknowledged on receipt and answered within ninety days, the period prescribed under the DPDP Rules, 2025. Most are answered well inside it.
If a grievance is not resolved to your satisfaction, you may complain to the Data Protection Board of India directly — no lawyer and no fee are required.
Where your data is held inside a school or trust deployment, that institution is the Data Fiduciary. Please raise the request with the institution first; Fairhelm will support it as the institution's Processor.
11
Changes to this notice
The DPDP Rules, 2025 were notified on 14 November 2025 and take effect in phases, with full compliance required by 13 May 2027. Fairhelm is building toward that date rather than waiting for it, and this notice will be revised as products move into production and processing changes. Material updates are reflected here with a revised date. Signed customer agreements take precedence over this page for their subject matter.
Last updated: 10 August 2026