Effective date: 01 Jan 2026 | Last updated: 01 September 2026
GRR IT Services ("GRR IT Services", "we", "us", or "our") respects your privacy and is committed to protecting personal data. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard information when you visit www.grritservices.com, contact us, or use our software, mobile applications, School ERP platform, and related services (collectively, the "Services").
For information submitted directly through our website or business communications, GRR IT Services generally determines why and how that information is processed. When a school or educational institution uses our School ERP or related products, that institution generally determines the purposes of processing student, parent, guardian, teacher, and staff information, and GRR IT Services processes that information on its behalf and in accordance with our agreement and applicable law.
Depending on the modules selected by an institution, our systems may process:
We may use personal data to:
We process personal data with consent where required and may also process it for other purposes permitted by applicable law, including providing a service requested by you, complying with law, preventing fraud, and protecting users and our systems. Where processing depends on consent, you may withdraw that consent by using the available account controls or contacting us. Withdrawal does not affect processing already lawfully completed.
We may use essential cookies to operate secure sessions and optional cookies or similar technologies to remember preferences, measure website usage, and improve performance. You can delete or block cookies through your browser. Some functions may not work properly if essential cookies are disabled. Third-party integrations may set their own cookies in accordance with their privacy policies.
We do not sell or rent personal data. We may disclose information:
Service providers are authorized to process information only for agreed purposes and subject to applicable obligations.
Online transactions may be processed by banks, payment gateways, or other payment providers. We may receive the amount, payment status, transaction reference, and related reconciliation information. Card, banking, UPI, or other financial credentials entered directly with a payment provider are governed by that provider's privacy and security practices.
Our education products may process children's personal data on behalf of a school or institution. The institution, parent, guardian, or other authorized person is responsible for providing appropriate notice and obtaining verifiable parental or guardian consent where required. We do not knowingly use children's data for targeted advertising, tracking, or behavioral monitoring. If you believe a child's data has been provided without appropriate authorization, contact the relevant institution or us promptly.
We use reasonable technical and organizational safeguards appropriate to the nature of the information, which may include access controls, authentication, encryption in transit, monitoring, backups, and restricted production access. No method of internet transmission or electronic storage is completely secure, and we cannot guarantee absolute security.
We retain personal data only for as long as reasonably necessary to provide the Services, fulfil the purpose for which it was collected, comply with contractual and legal requirements, resolve disputes, prevent fraud, and maintain security. Data processed for an institution may be retained, returned, or deleted according to that institution's instructions, our agreement, backup cycles, and applicable law.
Our infrastructure or service providers may process information outside your state or country. Where applicable, we use reasonable contractual, technical, and organizational measures for such processing and comply with applicable transfer requirements.
Subject to applicable law, you may have the right to:
We may need to verify your identity before completing a request. If a school or institution controls the relevant data, please first send your request to that institution; we will assist it where required.
The Services may contain links to third-party websites or integrations. We do not control their privacy or security practices. Please review the privacy notice of each third party before submitting personal information.
We handle personal data in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 and rules made under it, to the extent those requirements apply to our processing and are in force.
We may revise this Privacy Policy to reflect changes to our Services, practices, or legal obligations. The updated policy will be posted on this page with a revised "Last updated" date. Material changes may also be communicated through the Services or another appropriate channel.
For questions, privacy requests, corrections, or grievances, contact:
GRR IT Services