Data protection — DPDP & GDPR
Last updated 17 September 2026 · The formal framework behind the privacy policy — written for school offices, data-protection officers and careful parents
1. The laws we work under
PrepShorts is an Indian service and is built first for India’s Digital Personal Data Protection Act, 2023 (DPDP), together with the Information Technology Act, 2000 and its rules. Where a user is in the European Union — a family abroad for a year, an international school — the EU General Data Protection Regulation (GDPR) applies to their data as well. Rather than run two standards, we apply the stricter rule everywhere: the protections described here are the same for every student.
2. Roles, precisely
Under the DPDP Act, when a student joins through a school, the school is the Data Fiduciary for its roster relationship and PrepShorts acts as the Data Processor, handling study data on the school’s documented instructions. For students who join independently, PrepShorts is the Data Fiduciary. In GDPR vocabulary the same split reads controller/processor. A data-processing annexe recording instructions, sub-processors, audit rights and deletion duties is in preparation and will be part of the school agreement; ask and we will send it as soon as it is ready. Until 9 September 2026 this page said a signed copy could be requested at any time, which ran ahead of the document.
3. Lawful bases
We process personal data on three bases and no others: consent, carried by the school’s own enrolment where a student joins with a school code — the school holds the parent relationship and its enrolment is what authorises us; and, where a student joins without a school code, carried by the account holder’s own consent, against which we collect the minimum a teaching product needs and nothing about a household; performance of the service the school or user asked for — progress maps, dashboards, doubts; and legal obligation, where Indian law requires retention or disclosure. We do not process on “legitimate interest” grounds for marketing, because we do no marketing to users.
4. Data minimisation and purpose limitation
Every field we collect is listed in the privacy policy with its purpose, and nothing is collected “in case it’s useful later”. Study data is used for study features; account data for access; technical data for reliability. Aggregates used to improve videos — say, that 40% of a class missed the same check question — are computed over groups and stripped of identity. We do not build advertising profiles, we do not train third-party AI systems on student data, and we do not enrich our records from outside sources.
5. Where data lives
Student personal data is held by the sub-processors named in the next section, each under a written contract limiting processing to our instructions. Cross-border transfers are made under the safeguards the law requires — the DPDP Act’s transfer rules, and, where GDPR applies, the standard contractual clauses or adequacy findings of its Chapter V. Public content — the marketing pages and the single ungated sample video — carries no student data and is served globally.
6. Sub-processors
We keep the list short and boring: a cloud-infrastructure provider for compute, storage and backups; an email delivery service for sign-in and notification messages; a content-delivery, edge-security and object-storage provider that fronts the site and stores and serves the videos themselves; Google, to sign you in and, through Google Tag Manager and Google Analytics 4, to measure visits to every page; Meta, whose Pixel measures our own advertising; and OpenAI, which answers the “Ask about this video” box on a topic page. That last one is the only place a student’s own words leave our systems: the question typed into that box is sent, together with the video’s transcript, and nothing identifying the student goes with it — no name, no email, no account identifier — and neither the question nor the answer is stored. It was added here on 9 September 2026; the feature shipped before this sentence did, which is our error and is recorded rather than quietly corrected. The infrastructure providers work under a written contract limiting processing to our instructions; Google Analytics and the Meta Pixel run under Google’s and Meta’s business terms. Schools are notified 30 days before any sub-processor is added or replaced, with the right to object.
7. Security measures
TLS for every connection; role-based access, so support staff see the minimum needed for a ticket; and a record, naming the person and the moment, of every occasion on which someone at PrepShorts acts as a student, teacher or school office — the only way anyone here can see a pupil’s screen as they see it. We are precise about the limit of that: ordinary reads inside our own operator console, such as opening the registration queue or a class summary, are not individually logged, and this page said they were until 9 September 2026. And a nightly database backup, each one checked that it is readable and carries the tables it should, with a full restore rehearsed into a scratch database — last done on 9 September 2026, when all twelve tables came back with the row counts the live database had. There are no passwords to store: sign-in is Google, and PrepShorts never sees or holds one. An independent security review is planned; none has been commissioned yet, and this line will name the date of the first one when it has happened.
8. Breach response
If personal data is breached we follow a written plan: contain and assess immediately; notify the Data Protection Board of India and affected Data Fiduciaries (schools) as the DPDP Act requires; where GDPR applies, notify the competent supervisory authority within 72 hours; and tell affected users plainly what happened, what data was involved, and what we and they should do next. We do not sit on bad news.
9. Children’s data, specifically
The DPDP Act forbids tracking, behavioural monitoring and targeted advertising directed at children, and processing likely to cause a child harm. No advertising exists anywhere in the product, and “monitoring” of study is limited to the progress the school and parent are supposed to see. The website and the app do load Google Tag Manager, which runs Google Analytics 4 and the Meta Pixel to measure visits and our own advertising; what they receive is set out in §4 and §11 of the privacy policy. Every child-facing feature is reviewed against the commitments on our child-safety page before it ships.
10. Exercising rights & the Grievance Officer
Access, correction, export, deletion and complaint are described in the privacy policy, Section 10 — a request costs nothing and needs no legal form; an email is enough. Under the IT Rules and the DPDP Act our Grievance Officer can be reached at grievance@prepshorts.com (Aditya Kedia, who runs PrepShorts, Jaipur, Rajasthan); we acknowledge within 48 hours and resolve within 30 days. If you are not satisfied, you may escalate to the Data Protection Board of India; EU residents may also contact their local supervisory authority. School-routed requests — a parent asking through the office — are honoured the same way.
11. Impact assessments and review
2 September 2026. A line-by-line pass of this document against the database that actually stores the data. Section 7 said passwords are stored as salted hashes; there are no passwords, because sign-in is Google. It also claimed an annual independent security review — none has been commissioned, and the line now says so.
Before any feature that changes what data is collected or who can see it, we run a documented data-protection impact assessment: what’s collected, why, who sees it, what could go wrong, and what mitigates it. This page and the privacy policy are reviewed together every six months, and their “last updated” dates move only when the text does.