
Loading data...

Loading data...
Trust & Security
Effective Date: September 16, 2026 · Last Updated: September 16, 2026
EduWindow Private Limited (“EduWindow”, “we”, “us”, or “our”) is committed to protecting the security and confidentiality of information processed through the EduWindow platform, applications, websites, APIs, and related services (“Services”).
This Security Policy describes the general technical and organizational measures used by EduWindow to protect institutional data and maintain the security, availability, and integrity of the Services.
This Policy should be read together with the EduWindow Privacy Policy, Terms of Service, and Acceptable Use Policy.
EduWindow follows reasonable security practices designed to:
This Security Policy applies to the EduWindow platform and the systems, infrastructure, applications, and services controlled by EduWindow that are used to provide the Services.
Certain third-party services and infrastructure providers may operate independently under their own security practices and policies.
EduWindow applies reasonable technical and organizational measures to protect institutional data and personal information processed through the Services.
Security controls may include:
Where technically appropriate, EduWindow uses encryption and secure communication protocols to protect data during transmission and, where supported by the underlying infrastructure, while stored.
The exact encryption technologies and configurations may vary depending on the type of data, service, infrastructure, and third-party provider involved.
EduWindow does not represent that every piece of information processed through every component of the Services is encrypted using the same technology or configuration.
EduWindow uses authentication mechanisms designed to restrict access to authorized users.
Depending on the applicable feature or account type, authentication may include:
Institutions and users are responsible for maintaining the confidentiality of their credentials and authentication information.
EduWindow uses role-based access controls ("RBAC") and related authorization mechanisms where applicable.
Access to features and information may depend on the user's assigned role and permissions.
Institutions and authorized administrators are responsible for assigning appropriate roles and permissions to their users.
Users must not attempt to access information or functionality outside their assigned permissions.
EduWindow seeks to limit internal and technical access to information based on legitimate operational requirements.
Authorized EduWindow personnel may access institutional information only where reasonably necessary for purposes such as:
Internal access is subject to appropriate controls.
EduWindow limits access to institutional data and systems to authorized personnel whose responsibilities require such access.
Personnel may be subject to confidentiality obligations and applicable internal security requirements.
Access may be modified or revoked when personnel change responsibilities or leave the organization.
Where technically feasible, EduWindow maintains logs relating to relevant system and security activities.
Logs may include information such as:
Logs may be used for security, troubleshooting, auditing, fraud prevention, service improvement, and incident investigation.
EduWindow may monitor relevant systems and technical activity for purposes including:
Monitoring is conducted subject to applicable law and EduWindow's Privacy Policy.
EduWindow uses cloud and technology infrastructure provided by established third-party service providers.
Infrastructure security may include:
The exact infrastructure configuration may change as EduWindow evolves its technology architecture.
EduWindow uses third-party cloud infrastructure and service providers to operate parts of the Services.
Institutional data may be stored or processed using infrastructure configured for India-based storage, including services operating in India.
Certain application services, processing, networking, backups, or third-party infrastructure may operate in other jurisdictions or regions, including Singapore.
EduWindow takes reasonable measures to manage such infrastructure in accordance with applicable contractual, privacy, and security requirements.
EduWindow seeks to incorporate reasonable security practices into application development and maintenance.
These practices may include:
Security practices may evolve as new threats and technologies emerge.
EduWindow applies authentication, authorization, rate limiting, and other reasonable controls to supported APIs and programmatic interfaces.
API access may be subject to:
Direct access to internal databases and infrastructure is not permitted.
EduWindow maintains reasonable backup and recovery mechanisms for important platform data and systems.
Backup practices may include scheduled backups of applicable databases and infrastructure.
Backups are intended to support recovery from accidental deletion, system failures, security incidents, or other operational events.
Backups do not guarantee that every piece of data can always be restored without loss.
Institutions are encouraged to maintain independent copies or exports of important records where appropriate.
EduWindow maintains reasonable operational measures designed to support service recovery following significant technical or infrastructure disruptions.
Recovery procedures may address events including:
Recovery times and recovery results may vary depending on the nature and severity of the incident.
EduWindow seeks to identify and address security vulnerabilities affecting the Services and supporting infrastructure.
Depending on the nature and severity of a vulnerability, EduWindow may:
The Services may depend on third-party providers for infrastructure, authentication, messaging, payments, analytics, storage, communication, and other functionality.
EduWindow evaluates and manages third-party services based on relevant operational, security, and business requirements.
Third-party providers may maintain their own security controls, terms, and policies.
EduWindow cannot guarantee the security, availability, or uninterrupted operation of services independently controlled by third parties.
EduWindow personnel do not receive unrestricted access to institutional data.
Access may be granted only where reasonably necessary for legitimate purposes such as support, troubleshooting, maintenance, security investigations, or legal obligations.
Where technically feasible, relevant access may be logged or otherwise controlled.
Security is a shared responsibility.
Institutions are responsible for:
EduWindow cannot be responsible for security incidents caused solely by compromised institution-controlled credentials, devices, networks, or unauthorized user actions, except where caused by a confirmed failure of EduWindow's own security controls.
Users must:
EduWindow maintains procedures for identifying, investigating, containing, and responding to security incidents affecting the Services.
Depending on the circumstances, response activities may include:
If EduWindow confirms a security incident involving institutional or personal data that requires notification under applicable law or contractual obligations, EduWindow will notify the relevant institution or other appropriate party without unreasonable delay after confirming the incident and assessing the available facts.
Where appropriate and legally permitted, notifications may include:
Notification timing and content may depend on the nature of the incident, available information, legal requirements, and the need to protect the investigation.
EduWindow encourages responsible reporting of suspected security vulnerabilities.
Security researchers and users should report vulnerabilities privately through the designated security or support channel and provide sufficient information to reproduce or investigate the issue.
Researchers should avoid:
Unauthorized penetration testing, vulnerability scanning, automated probing, security testing, or similar activities against EduWindow systems are prohibited.
Such testing requires prior written authorization from EduWindow.
EduWindow takes reasonable measures to protect the Services against malicious activity.
Users and institutions must not upload, distribute, or execute malware, ransomware, viruses, malicious scripts, or other harmful code through the Services.
Where EduWindow relies on third-party cloud or infrastructure providers, physical data-center security is generally managed by those providers.
EduWindow relies on the physical security controls provided by its infrastructure partners while maintaining appropriate contractual and operational oversight where applicable.
Security-related information, activity logs, backups, and other technical records may be retained for periods appropriate to their purpose, including:
Retention periods may vary depending on the type and purpose of the information.
EduWindow may periodically modify, upgrade, replace, or improve its security controls, infrastructure, technologies, and procedures.
Security practices may change as a result of:
EduWindow uses reasonable technical and organizational safeguards but no internet-based service, software, infrastructure, or electronic transmission can be guaranteed to be completely secure.
EduWindow does not guarantee that the Services will be free from every vulnerability, security incident, unauthorized access attempt, or interruption.
Where the Services use third-party communication channels such as email, SMS, WhatsApp, push notification services, or similar providers, delivery and security may depend partly on those providers, network infrastructure, and user devices.
EduWindow cannot guarantee uninterrupted delivery or security of communication channels independently controlled by third parties.
Security and privacy controls are designed to operate together.
EduWindow may apply security measures to protect personal and institutional information while processing such information in accordance with its Privacy Policy and applicable agreements.
Institutional data remains subject to the ownership and processing provisions described in the Terms of Service and applicable Data Processing Agreement.
EduWindow does not acquire ownership of institutional data merely because it is stored or processed through the Services.
EduWindow seeks to maintain security practices appropriate to the nature, scope, and risks associated with the Services.
Specific security commitments, audit rights, certifications, penetration testing arrangements, or compliance obligations may be established separately in an applicable institutional agreement or Data Processing Agreement.
EduWindow may update this Security Policy from time to time to reflect changes in technology, infrastructure, security practices, legal requirements, or the Services.
Material changes may be communicated through the EduWindow platform, registered institution email, website, or other appropriate channels.
The latest version of this Security Policy will be made available through the EduWindow website.
Security-related concerns, suspected vulnerabilities, or security incidents should be reported to EduWindow through the designated support or security channel.
EduWindow Private Limited
Registered Office:
Ward No. 7, Rajgarh Road,
Solan, Himachal Pradesh - 173212, India
Email: hello@eduwindow.tech
Phone: +91 93178 70027
Website: www.eduwindow.tech
For security incidents involving institutional data, institutions should provide relevant details sufficient to assist EduWindow with investigation and response.
© 2026 EduWindow Private Limited. All rights reserved.
EduWindow | One Window. Smarter Institutions.