Your information
Privacy Policy
What JPRAXC collects, why, for how long, who receives it, how it is protected — and every right you have over it.
JPRAXC INFYNEX PRIVATE LIMITED (CIN: U62011UP2026PTC252552), “JPRAXC”, publishes this policy for its public website, its sales, licensing and support services, the JPRAXC ERP products and their portals, Business Email, ConnectX, the WhatsApp API integration, SMS, payment workflows and the JPRAXC mobile apps. The Mobile App Privacy Policy adds what each app keeps on a phone. This policy is the notice required by rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and, where JPRAXC decides the purpose of processing, the notice contemplated by section 5 of the Digital Personal Data Protection Act, 2023 and rule 3 of the DPDP Rules, 2025.
At a glance
- We collect what a request needs — your name, organisation, contact details and what you asked for. We do not sell it. JPRAXC product news and offers need your separate promotional opt-in.
- Your organisation’s records are its own. The organisation controls its operational records; individuals retain their legal rights. JPRAXC processes those records under documented instructions.
- No advertising use of children’s records. School-authorised attendance, transport and learning functions may process activity or location; each needs an appropriate purpose, notice and authority.
- No advertising trackers. The site uses session, preference, product-choice and chat storage as described below.
- Hosted in India, on third-party servers. JPRAXC-hosted services run on infrastructure of third-party hosting providers in India; connected providers, push delivery, support arrangements and email recipients may process information outside India.
- You can see, correct, erase and complain. Write to the Grievance Officer; we answer within 30 days, and tell you if a record must be kept for a legal reason.
Who we are and how to reach us
JPRAXC is a software company incorporated in India with its registered office at C/O Jay Prakash Chaurasia, Bherahritola, Dudhi, Bansgaon, Padrauna, Kushinagar, Uttar Pradesh PIN - 274302, India. For everything in this policy, the person to contact is the Grievance Officer named below, who is also the contact required by rule 9 of the DPDP Rules, 2025 for questions about processing: grievance@jpraxc.com, subject “Privacy request”.
Scope and roles
Where JPRAXC decides (Data Fiduciary)
JPRAXC determines the purposes of its own enquiry, sales, billing, licensing, partner administration, support and security records. For those purposes it acts in its own capacity, including as Data Fiduciary when the relevant DPDP provisions apply. Signing into a school app does not by itself make JPRAXC an independent decision-maker for all school records.
Where an organisation decides (Data Processor)
A school, hospital, clinic, shop or business that uses a JPRAXC product decides why it collects its operational records — students and guardians, patients, employees, customers, suppliers, transactions, messages — who may access them, what it publishes through its portals and apps, and how long they are kept. For those records the organisation is the Data Fiduciary and JPRAXC is its Data Processor: JPRAXC processes them only to provide, secure and support the service, on the organisation’s documented instructions and under the data processing terms in the Terms of Service. A person whose record is held by an organisation should start with that organisation’s administrator and its own privacy notice; JPRAXC will help the organisation answer, and will not act on those records without its instruction unless the law requires it.
An Offline edition runs on the organisation’s own equipment; JPRAXC then has no access to its database unless the organisation gives it for support, migration or an agreed backup. A Cloud edition is hosted by JPRAXC or a hosting provider it arranges; authorised hosting and support personnel may see data only as needed to provide the service and under confidentiality obligations.
What we collect and why
The table lists the personal data JPRAXC itself collects, where it comes from, what it is used for and how long it is kept. It is the itemised description rule 3 of the DPDP Rules asks for. We do not sell this information; contact details are used for JPRAXC promotions only with a separate opt-in, as explained below.
| Category | What it includes | Source | Purpose | Kept for |
|---|---|---|---|---|
| Enquiries and demo requests | Name, organisation, role, email, telephone or WhatsApp number, city, product and deployment interest, expected users or branches, the message you write, the time and IP address of the submission | You, through a form, ConnectX chat, email, WhatsApp or a call | To answer, schedule a demo, prepare an estimate, and to keep a record of what was discussed | 24 months after the last contact, or for the life of the customer account it becomes |
| Purchases, renewals and licences | Organisation and billing details, GSTIN or PAN where an invoice needs them, administrator name and contact, licence edition, capacity, validity, activation and install codes, quotation, purchase-order and invoice references, payment references and status | You, a partner acting with your authority, the payment aggregator | To accept the order, issue the GST invoice, activate and validate the licence, renew, support and account for it | The licence period; accounting evidence follows the separate Companies Act and GST periods below, not an automatic eight-year extension for every account field |
| Portal and app accounts | Sign-in name, email, phone, role, the one-time codes sent to verify you (held as a protected hash), sign-in times and IP addresses, sessions, security checks, actions taken in the account | You, or the administrator who created your account | To let you in, keep others out, and record who did what | While needed for access; security and audit records follow the retention schedule below, including applicable statutory periods and restricted legal holds |
| Support and grievances | Your name and contact details, the organisation, the ticket or grievance, screenshots or files you send, our replies, the outcome | You | To resolve the request and to show later what was decided | Three years after closure |
| Partner applications and accounts | Name, firm, GSTIN, PAN and bank details for commission payouts, territory, the customers and orders a partner submits | The partner, through the JPX Partner app | To assess the application, run the partner account, pay commissions and issue the tax documents the law requires | The partnership and eight financial years after it for payout and tax records |
| Feedback and testimonials | Ratings, comments, and for a testimonial the quote, name, role, organisation and logo you approve | You | To improve the products; a testimonial is published only after you approve the exact text and display | Feedback three years; a testimonial until you ask for it to be withdrawn |
| Website technical data | IP address, browser and device type, the pages requested, timestamps, referrer, and the rate-limiting and verification records that stop abuse of the forms | Your browser, automatically | To serve the site, keep it secure and investigate misuse; not for profiling or advertising | Server logs 180 days |
| Our messages to you | Emails, WhatsApp messages and SMS JPRAXC sends about your enquiry, order, licence, invoice, renewal, support ticket or service notices, and their delivery status; the consent record for any promotional message | JPRAXC | To complete what you asked for and to tell you what you need to know about your service; promotional messages only with your consent | With the record they belong to; consent records for three years after withdrawal |
| Payments to JPRAXC | Payer name, amount, method (card network, UPI, net banking, wallet), masked instrument, aggregator transaction and refund references, bank account details given for a refund by transfer | The payment aggregator; you, for a bank refund | To reconcile receipts, issue invoices and credit notes, process refunds and answer disputes | Eight financial years |
| Records in your organisation’s product | For products and modules actually enabled, what the organisation enters or imports: for a school, students and guardians, admissions, attendance, marks, fees, transport, library, staff and payroll; for a hospital, patients, appointments, clinical notes, prescriptions, laboratory, wards and billing; for a business, customers, suppliers, invoices, stock, accounts, payroll, CRM and projects; and the messages, files and payments each product carries | The organisation and its users | The organisation’s own operations; JPRAXC processes as its processor only | As the organisation decides; on a Cloud edition, deleted after the export period when the service ends |
JPRAXC does not collect personal data from public sources or data brokers, does not buy lists, and does not make decisions about you by automated means that have a legal or similarly significant effect.
JPX School ERP mobile app
The school office app connects an authorised ERP account to the school identified by its School ID. It reads and submits school records, forms, selected photographs and documents, fees and receipts, imports, approvals and messages allowed by the ERP role. These can include student, guardian, staff, health, payroll and financial information held by the school. The school controls purpose, access and retention. School verification uses JPRAXC’s verification service; support messages deliberately sent to JPRAXC are handled for that request. Enabled notification delivery involves Google. The app’s App PIN, optional biometric unlock, device storage, document scanner, ConnectX voice notes and enabled Live Classes are explained in the Mobile App Privacy Policy.
Sensitive personal data and Aadhaar
Public enquiry forms are not a channel for passwords, payment credentials, Aadhaar numbers, biometric data or full health/student records. Product sign-in uses its designated credential flow; authorised payroll, partner payout or refund workflows may need financial details. Card credentials and UPI PINs belong only in the selected payment provider’s checkout, not a JPRAXC support message.
An enabled ERP module may hold sensitive data such as payroll bank details or student health information. The organisation must establish the lawful purpose, authority, notices, access limits and retention appropriate to each field. Recording an Aadhaar number is not UIDAI authentication. Do not use it as a secret password, disclose it publicly, or collect biometrics through JPRAXC. Where an existing school workflow asks for Aadhaar, ask the school about its authority and a non-Aadhaar access arrangement; contact JPRAXC directly if access is blocked. Consent alone does not authorise every use under the Aadhaar framework.
Children’s data
JPRAXC’s own sales and partner services are intended for adults. If a child submits information directly, contact the Grievance Officer so it can be assessed, access restricted and unnecessary information removed, subject to any necessary child-protection or legal preservation duty.
Schools control children’s educational records and guardian access. Under the DPDP framework, a child is generally a person under eighteen. Section 9 and the relevant Rules commence in the later phase described above. The educational-institution exemption in rule 12 and the Fourth Schedule is limited to the specified institution, activity and purpose; it is not a blanket exemption for JPRAXC or permission to reuse student records. Attendance, educational monitoring, transport/location and live-class recording each need appropriate school authority, notices and guardian arrangements. JPRAXC does not use those records for targeted advertising or unrelated profiling. Parent access is for authorised guardians.
Legal basis and consent
Current processing must satisfy the law applicable to the information and JPRAXC’s role, including the IT Act and SPDI Rules where applicable. For DPDP readiness, each purpose is assessed against consent or a specified legitimate use; performing a contract is not a separate, general DPDP ground.
- Consent: where required, a clear, informed and purpose-specific choice; optional promotion and testimonial publication are separate from support.
- Voluntarily provided information: section 7(a), when its conditions are met, covers a specified purpose for which information is provided without indicating refusal.
- Required records and disclosures: accounting, tax, incident and court-order duties are assessed individually. Section 7(c) concerns State functions, not a general private-company legal-duty ground; sections 7(d) and 7(e) concern specified disclosures to the State and orders/judgments.
- Employment: section 7(i) concerns employment-related purposes; independent partners are not automatically employees.
- Customer processing: customer instructions define our service but do not replace the customer’s own lawful ground.
Withdraw consent through the relevant opt-out control, permission setting or direct privacy contact. Withdrawal does not undo earlier lawful processing; we explain necessary continuing records or feature limitations. A complaint or information request does not require acceptance of unrelated contracts or marketing.
Marketing messages
On demo, pricing, purchase and renewal forms, the promotional choice is separate and starts unticked. It covers JPRAXC product news, offers and promotional follow-up by email, phone, SMS or WhatsApp using the submitter’s own primary contact details, not another person’s billing or administrator details. We record the choice, notice version, source and time against the request. Leaving it unticked does not block the request. See Contact & promotional preferences ↗ for the purpose, data used and withdrawal routes. A later form submission does not by itself cancel an earlier withdrawal.
JPRAXC sends promotional email, WhatsApp or SMS only to people who have opted in, and every such message tells you how to stop it. Transactional and service messages — a verification code, an invoice, a renewal reminder, a security notice, a reply to your enquiry — are classified according to their actual content and applicable rules; a service label does not permit promotion without the required consent. SMS is sent under the TRAI Telecom Commercial Communications Customer Preference Regulations, 2018 as amended and in force: the applicable sender registration, headers, templates, consent/preferences and opt-out requirements depend on the message category. The September 2026 amendment has phased commencement; see the Legal page. WhatsApp messages follow Meta’s WhatsApp Business Messaging Policy and are sent only to numbers that have opted in. If you receive a JPRAXC message you did not agree to, forward it to the Grievance Officer.
Cookies and browser storage
| Name or kind | What it does | Type | Lasts |
|---|---|---|---|
| Session cookie | Keeps a form’s security token and your sign-in state while you use the site | Strictly necessary | Until the browser closes |
| Theme preference | Remembers whether you chose light or dark | Functional, local storage, set only when you press the toggle | Until you clear browser storage |
| Product choice | Carries the product and edition you picked to the pricing or purchase form | Functional, session storage | Until the tab closes |
| ConnectX chat | Keeps your website conversation together across pages if you open the chat | Functional, set only when you use the chat | The conversation |
The JPRAXC website does not use advertising cookies, third-party analytics tags, social-media pixels or fingerprinting. The Google Maps location previews load when visible and remain loaded while the page is open. Google receives the map request and may use its own cookies under its privacy policy. A payment aggregator’s checkout, a WhatsApp link and an app store have their own cookies and policies. JPRAXC-operated portals set the session and security cookies they need to sign you in and nothing else.
Who receives information
JPRAXC does not sell personal data and does not share it for anyone else’s marketing. It is disclosed only to the people and providers a function needs, subject to contract and law; some recipients, including payment providers, also act independently for their regulated responsibilities:
- Hosting and infrastructure: the hosting arrangement selected for a service — Google Cloud, Hostinger and Amazon Web Services (Amazon SES for email delivery) are the providers JPRAXC uses; the order or service agreement names the one that applies.
- Communications: Meta Platforms for a configured WhatsApp integration (the message, the number and delivery status); the SMS gateway and telecom operators that carry an SMS; the mail systems that deliver an email to its recipient.
- Payments: the RBI-authorised payment aggregator named in the checkout — the integrations JPRAXC supports include Razorpay, Cashfree Payments, PhonePe, PayU, Easebuzz, SabPaisa, PayGlocal and Zoho Payments — and the banks and card networks behind it. JPRAXC receives the transaction result and a masked instrument, never the card number or PIN.
- App distribution and push: Google Play distributes Android apps. In FCM-enabled builds, Google Firebase Cloud Messaging processes registration identifiers and delivery payloads. This does not mean Analytics or Crashlytics is enabled. See the app disclosure.
- Partners: the JPRAXC partner who introduced or serves your organisation sees the order and licence details needed for that, under the partner agreement.
- Professional advisers and successors: auditors, lawyers and, if JPRAXC’s business is reorganised or transferred, the successor, who must honour this policy.
- Law: a court, regulator, CERT-In or a law-enforcement agency where the law requires it, and where necessary to investigate misuse, protect accounts or establish or defend a legal claim. JPRAXC checks that a request is lawful and discloses only what it covers.
An organisation’s records held in its ERP are shared only as the organisation configures — with the guardians, staff, payers and recipients it authorises and the gateway, carrier or WhatsApp account it connects. A provider’s logo on this website does not mean every customer’s data reaches that provider.
Where data is kept
The order identifies the primary hosting arrangement; JPRAXC-hosted Cloud databases ordinarily use Indian infrastructure unless the order states otherwise. This does not establish India-only processing for backups, support, push, WhatsApp, payment providers or email transit/recipients. Offline databases stay on the organisation’s equipment, while licensing, updates, push and authorised support may contact online services. Transfers must meet applicable SPDI rule 7 safeguards and other current restrictions; DPDP section 16 and rule 15 requirements apply as they commence, including applicable government conditions, not merely a country blacklist.
Ask the privacy contact for the providers, purposes, regions and support-access arrangements applicable to your deployment before activation or adding an integration. Not every listed vendor receives every customer’s data. Meta onboarding, when enabled, involves business/WABA and phone identifiers, granted permissions, messages and webhook status needed for that connection; disconnect through the service and Meta’s account controls.
How long we keep it
The category periods above are service retention commitments, subject to these distinctions and applicable preservation duties. Customer records follow authorised instructions and the agreed export/deletion schedule, not the accounting period for JPRAXC invoices.
- Company books and vouchers generally follow eight financial years under Companies Act section 128. GST records generally follow 72 months from the annual-return due date under CGST section 36, with applicable extensions for proceedings.
- Covered ICT logs must remain for 180 days within India under CERT-In directions. Future DPDP rule 6 security-record and rule 8(3) personal-data/traffic-log requirements need category-specific application when they commence; they do not justify indefinite retention.
- Account closure, download expiry, removal from live storage and backup expiry are different events. Necessary evidence may remain under restricted legal hold. We explain the applicable reason and scope rather than promising immediate deletion of every copy.
Live Classes: where purchased and enabled, normal school-administrator recording downloads are designed to expire 24 hours after the class actually ends. This access window is not a guarantee that every media object, database entry and backup is already erased. Activation must identify the approved media, metadata, backup, deletion-retry and lawful-preservation schedule. Future rule 8(3) must be reconciled with it before commencement. A school-downloaded copy is under the school’s control. This notice does not authorise an undisclosed permanent archive.
Security and breach notice
JPRAXC is responsible for reasonable, proportionate security and the security commitments in its service agreements: access restrictions, protected credentials, secure transport, administrative records, backup arrangements and incident handling. Controls differ by product and deployment; this notice is not a claim of ISO certification, end-to-end encryption, or independent verification that every update package is signed. Request the security schedule for the purchased service. Organisations remain responsible for equipment, permissions and exported copies.
JPRAXC assesses containment, notification and reporting duties applicable to its role, and notifies a customer whose data it processes without undue delay. Listed reportable cyber incidents are notified to CERT-In within six hours of noticing or being informed, as required; not every harmless event is reportable. DPDP section 8(6) and rule 7, when in force, require affected-person/Board intimation without delay and the prescribed detailed Board report within 72 hours, subject to permitted extension. Report suspected breaches through direct reporting; no decided ticket is needed.
Third-party hosting and loss of data. JPRAXC’s hosted services run on servers and storage operated by third-party hosting and cloud providers. JPRAXC applies reasonable security safeguards and keeps backups where the plan includes them, but no method of electronic storage or transmission is completely secure or immune from failure, and JPRAXC cannot guarantee that information will never be lost, corrupted or become unavailable. To the fullest extent the law permits, JPRAXC is not responsible for loss of data at any stage; the contractual position, including the organisation’s duty to keep its own backups and restoration from the latest available backup as the remedy, is in clause 8 of the Terms of Service. This does not reduce the breach-notification duties above or any right you have under the Digital Personal Data Protection Act, 2023 or the Information Technology Act, 2000.
Your rights
For JPRAXC-controlled data, these request channels are available. Applicable SPDI rights operate now; the DPDP statutory rights in sections 11–14 operate on their commencement. Additional contractual assistance does not change those dates:
- Access — a summary of the personal data JPRAXC holds about you, what it is used for, and the categories of recipients it has been shared with.
- Correct, complete or update — inaccurate, incomplete or out-of-date data.
- Erase — data that JPRAXC no longer needs for the purpose or a legal duty; we tell you if a record must stay and why.
- Withdraw consent — at any time, as easily as you gave it.
- Nominate — a person to exercise these rights for you if you die or cannot act.
- Complain — to the Grievance Officer first, and after that to the Data Protection Board of India as the Act provides.
Contact grievance@jpraxc.com or use direct reporting. An exact subject line, purchase or prior support ticket is not required. Give only enough information to locate the issue; do not send raw identity documents. We accept the request first and may proportionately verify identity or authority before disclosure or account changes, including where registered email is compromised. We aim to answer within 30 days, subject to any shorter applicable requirement, with no request fee. Applicable SPDI grievances must be addressed within one month. Future rule 14’s maximum 90-day grievance period is not a general extension for every request. For school/employer records, contact that administrator; JPRAXC can help identify the route and handle concerns about its own processing. Necessary retention and any refusal are explained.
You may decline an optional device permission or remove local access; the Mobile App Privacy Policy explains what each app keeps. In JPX School ERP, Sign out locks the remembered account, while More › Remove from this phone removes its remembered sign-in and App PIN. Neither action deletes school records, audits or backups. Ask the school administrator to assess ERP account access and record-removal requests, or use the direct privacy request route for information JPRAXC handles.
Grievance Officer
The Grievance Officer named here is the officer required by rule 5(9) of the SPDI Rules, rule 3(2) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and rule 4(4) of the Consumer Protection (E-Commerce) Rules, 2020, and the person to contact under rule 9 of the DPDP Rules, 2025.
Changes and contact
JPRAXC updates this policy when its services, its providers or the law change, and records the date at the top. A material change to how data already collected is used is notified to the people it affects by email or in the product before it takes effect, and consent is asked again where the law requires it. This policy complements each organisation’s own notice and its service agreement with JPRAXC, and does not limit any right you have under applicable law. The Terms of Service, the Refund & Cancellation Policy and the Legal page set out the rest of the agreement.
JPRAXC INFYNEX PRIVATE LIMITED
C/O Jay Prakash Chaurasia
Bherahritola, Dudhi
Bansgaon, Padrauna, Kushinagar
Uttar Pradesh PIN - 274302, India
Privacy requests: grievance@jpraxc.com · Orders: sales@jpraxc.com · Support: +91 9792908836
