Legal
Privacy Policy
This Privacy Policy explains what personal data Instione collects, why we collect it, who we share it with, how long we keep it and the rights you have. It covers our website at instione.com and our institute management app at manage.instione.com (together, “Instione”).
We have written it to meet India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Digital Personal Data Protection Rules, 2025, together with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which apply today.
Who we are
Instione is operated by Mohamed Jakkariya R (Sole proprietor, trading as Instione), based in Chennai, Tamil Nadu, India. In this policy, “we”, “us” and “our” mean Instione.
For any privacy question, email [email protected]. For a complaint, contact our Grievance Officer.
Our two roles: data fiduciary and data processor
Under the DPDP Act, the organisation that decides why and how personal data is used is the data fiduciary. An organisation that handles personal data on a fiduciary’s behalf is a data processor.
- We are the data fiduciary for our own data: people who visit our website, people who send us an enquiry or book a demo, the analytics we collect, and the accounts of the institute owners and administrators who sign up for Instione.
- We are a data processor for the records an institute keeps in the app — its students, parents or guardians, staff, enquiries (leads), courses, batches, enrolments and fees. The institute is the data fiduciary for that data. It decides what to record and why, and it is responsible for giving notice to, and getting consent from, the people concerned. We handle that data only on the institute’s instructions, under our Data Processing Addendum.
If you are a student, parent or staff member of an institute that uses Instione and you have a question about your records, please contact your institute first. We will help the institute respond, and if you write to us we will pass your request on to them.
What we collect
When you visit our website
- Request data. Like every website, our hosting provider (Cloudflare) receives your IP address, browser type and the page you asked for, so that it can deliver the page and protect the site from attacks.
- Visit counting without cookies. Before you make any choice, we count visits with a small beacon sent to PostHog, our analytics provider, without cookies or any identifier stored on your device. It records page views, clicks on our main buttons (such as “Start free” or “Book a demo”), page-speed measurements, whether a demo booking was opened or completed, whether the contact form was sent (with the institute size band only), and which feature, solution, pricing and resource pages were viewed. Each page load gets a new random ID that is kept only in memory, so separate visits are not linked together. Your IP address is used by PostHog only to work out an approximate location (such as the country or city) and is not stored: we configure our analytics to discard IP addresses.
- Analytics, only if you accept. If you choose “Accept analytics”, PostHog’s full analytics script loads. It stores a random identifier in a cookie and in your browser’s local storage so that it can recognise repeat visits, and it records sessions (session replay) with everything you type masked. The same identifier is added to Start free and Log in links to manage.instione.com only after you accept analytics; it will be used to connect a website visit to sign-up once self-serve sign-up launches. See our Cookies & tracking page for the details.
When you use our contact form
We collect what you type: your name, institute name, phone number, email address, the size of your institute (a student-count band) and your message. A Cloudflare bot check (Turnstile) runs when the form is shown, to stop spam. Our website sends your enquiry by email (through Resend) to our own inbox and sends you a short acknowledgement email. The form data is not stored in a database; it is kept as email in our inbox and briefly in our email provider’s delivery logs.
When you book a demo
Demo booking is handled by Cal ID, a scheduling service run by OneHash Technologies Limited (India). Nothing from Cal ID loads until you click “Book a demo”. Cal ID collects your name, email address and the slot you choose, and any answers you give in its booking form, and shares the booking with us. Cal ID’s own privacy policy also applies to what you enter there.
When your institute uses the app
- Account data (we are the fiduciary). For owners, administrators and staff with an Instione login: name, email address, phone number, role and branch, and a securely hashed password (we never store it in readable form). We also keep security and activity logs, such as sign-in times, IP addresses and changes made in the app.
- Product analytics in the app (we are the fiduciary). To provide, secure and improve the app, we send PostHog usage events linked to your account (your user ID, email address and branch) about how signed-in staff use it: the screens you open and the actions you complete (for example, “receipt issued”). These events describe the action, not the contents of the records you work with. When the app hits an unexpected error, it also sends an error report to help us find and fix bugs; error reports are designed not to include record contents. Session replay is turned off in the app, so your screen is never recorded and no record contents are captured.
- Institute records (we are a processor). Whatever the institute enters or imports: student and staff profiles (such as names, contact details, date of birth, photos, addresses and emergency contacts), parent or guardian details, enquiries and follow-ups, course enrolments and batches, and fee records such as charges, receipts, refunds and credit notes. Instione records cash and UPI/QR payments that the institute has received; we do not process card or bank payments and we do not collect card or bank account numbers.
Why we use it, and on what basis
| Purpose | Data | Basis under the DPDP Act |
|---|---|---|
| Deliver and secure the website | Request data | Legitimate use: you asked for the page; keeping the service secure |
| Reply to your enquiry and arrange a demo | Contact form, Cal ID booking | Legitimate use: you gave us the data voluntarily for this purpose (section 7(a)) |
| Count visits without cookies | Page views, clicks, page speed, demo-booking and contact-form outcomes (institute size band only), feature/solution/pricing/resource pages viewed; IP address used only for approximate location and then discarded | No cookies or device identifiers; IP addresses are not stored; used only in aggregate |
| Analytics with cookies and session replay | Identifier, events, masked session recordings | Your consent, which you can withdraw at any time |
| Provide the app, support your institute and keep accounts secure | Account data, security logs | Processing necessary to provide the service under our contract with your institute and our Terms of Service |
| Provide, secure and improve the app | Usage events linked to your account (user ID, email address and branch) and error reports; no screen recording | Processing necessary to provide, secure and improve the service we supply to your institute under our contract with it. You can ask us to stop by emailing [email protected]; we will stop sending analytics for your account within 15 days of your request |
| Process institute records | Institute records | The institute’s instructions, as its data processor; the institute is responsible for its own lawful basis |
| Meet legal duties | Logs and records the law requires | Compliance with Indian law (section 7(d) and (i)) |
We do not sell personal data. We do not use personal data for advertising, and we do not build advertising profiles.
How long we keep it (retention)
- Contact form enquiries: kept in our inbox for up to 24 months after our last conversation, then deleted — unless your institute becomes a customer, when we keep the correspondence for as long as the account is active.
- Demo bookings: kept in Cal ID and our calendar for up to 24 months after the meeting.
- Website visit counts and analytics events: up to 12 months. Session recordings: up to 30 days.
- Consent choice: the
instione_consentcookie lasts 6 months, after which we ask again. - Account data: for as long as the account is active. When an account or institute is closed, we delete it within 60 days, except what we must keep by law.
- Security and activity logs: at least one year, as the DPDP Rules require, and no longer than we need them for security and legal purposes.
- Institute records: for as long as the institute’s subscription is active. After it ends, the institute has 30 days to export its data, and we then delete it from our live systems within a further 30 days. Encrypted backups are overwritten on our database provider’s rolling schedule.
- Billing records: we do not charge anything today. Once paid plans exist, invoices and payment records will be kept for as long as Indian tax law requires (currently up to eight years).
Who we share it with, and where it is stored
We share personal data only with the service providers (processors) who help us run Instione, each bound by contract to use it only to provide their service to us:
- Cloudflare — website hosting, DNS and bot protection (global network).
- Render — hosting for the app and its database (Singapore).
- Supabase — storage for files uploaded to the app (India, Mumbai).
- Resend — sending transactional email, such as contact-form messages and app notifications (United States).
- PostHog — website and product analytics (United States).
- Cal ID (OneHash Technologies) — demo scheduling (India; some data may be held outside India).
The full list, with the data each one handles, is on our Sub-processors page. We may also disclose personal data where Indian law requires it, for example to a court or a government authority acting lawfully, or to protect the security of our service and its users.
Transfers outside India
Institute records are stored in the app’s database in Singapore; files uploaded to the app are stored in India (Mumbai). Some of our providers therefore process data outside India, in Singapore and the United States, as listed above. The DPDP Act allows such transfers except to countries the Government of India restricts by notification; we will stop or change any transfer if a restriction applies. Our providers protect the data with security measures at least as strong as those described below.
How we protect it (security)
We use reasonable security practices, including:
- encryption in transit (HTTPS everywhere, with HSTS on our website) and encryption at rest by our infrastructure providers;
- role-based access in the app, checked on our servers for every request, and separation of each institute’s and branch’s data, with database row-level security as a second layer;
- passwords stored only as salted hashes, and sign-in sessions held in secure cookies that scripts cannot read, with protection against cross-site request forgery;
- private file storage, where uploaded files are shared only through time-limited signed links;
- service keys kept on our servers and never sent to browsers, and access to production systems limited to the people who need it;
- security logs, backups managed by our database provider, and a plan for responding to incidents.
No system is perfectly secure. If a personal data breach happens, we will inform the people affected and the Data Protection Board of India as the DPDP Rules require, and CERT-In where the law requires it. If the breach affects institute records, we will tell the institute without undue delay so it can meet its own duties. More detail is on our Security page.
Your rights
Under the DPDP Act, you can ask us to:
- access information about your personal data: a summary of what we hold, how we use it, and who we have shared it with;
- correct, complete or update personal data that is inaccurate or incomplete;
- erase personal data we no longer need for the purpose it was collected for, unless the law requires us to keep it;
- withdraw consent at any time, where we rely on consent — as easily as you gave it. For website analytics, use the “Privacy choices” link in the footer. Withdrawing consent does not affect processing that happened before, and we will stop the processing (and ask our processors to stop) within a reasonable time;
- nominate another person to exercise your rights if you die or become unable to do so because of illness or incapacity;
- have a grievance about how we handle your data redressed, through our Grievance Officer.
To use any right, email [email protected] from the email address we have for you, or tell us how we can confirm who you are. We will not charge you. We will respond within 15 days, and if we need longer we will tell you why. If your data is part of an institute’s records, we will pass your request to that institute and help it respond, because the institute decides what happens to those records.
The DPDP Act also asks you to give accurate information and not to make false or frivolous complaints.
Children
The DPDP Act treats anyone under 18 as a child. Many institutes that use Instione teach children.
- Our website is meant for institute owners and staff, not children. We do not knowingly collect personal data from children through the website. If you think a child has sent us their details, email [email protected] and we will delete them.
- In the app, the institute is responsible for children’s data. Before recording a child’s personal data, the institute must obtain verifiable consent from the child’s parent or lawful guardian, as the DPDP Act and Rules require.
- We process children’s data only on the institute’s instructions, only to provide the app. We do not track or monitor the behaviour of children, we do not direct any advertising at children, and we do not use children’s data for anything that could harm their well-being. Product analytics in the app covers only signed-in institute staff.
Cookies and analytics
We use one essential cookie by default and use analytics cookies only if you accept them. Our Cookies & tracking page explains every cookie and how to change your choice.
Grievances and complaints
If you are unhappy with how we have handled your personal data, contact our Grievance Officer, Mohamed Jakkariya R, at [email protected]. We will resolve your grievance within 15 days. If you are not satisfied with our response, you can complain to the Data Protection Board of India. See our Grievance Officer page.
Changes to this policy
We may update this policy when our service or the law changes. Each version has a number and an effective date at the top of this page. If we make a material change, we will tell account holders by email or in the app at least 30 days before it takes effect, and, where we rely on your consent, we will ask for it again. When the cookie section changes, the website will ask for your analytics choice again.
Contact
Privacy questions: [email protected]. General support: [email protected]. Grievances: [email protected].