EDU Matrix Interlinked ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at https://edumatrixinterlinked.com.
1. Information We Collect
1.1 Information You Provide
- Account registration data (name, email, password)
- Profile information (bio, profile photo, education, work experience, skills)
- Institution data (institution name, address, type, when registered by admins)
- Academic records (grades, attendance, assignments, exam responses) managed by institutions
- Content you create (posts, messages, comments, files, community room conversations)
- Payment information (processed by Paddle for platform subscriptions and institution verification badge purchases, or by institution-configured gateways for institution-level payments)
- Support requests and feedback submissions
1.2 Information Collected Automatically
- Device information (browser type, operating system, device type)
- Usage data (pages visited, features used, time spent)
- IP address and approximate location
- Presence and activity status (online/offline/away indicators)
- Real-time interaction data (typing indicators, read receipts in messaging)
2. How We Use Your Information
We use collected information to:
- Provide, operate, and maintain the Platform and its 13 services
- Authenticate your identity and manage your unified profile across services
- Process payments and manage subscriptions (via Paddle for platform-level, via institution gateways for institution-level)
- Enable real-time features (messaging, notifications, live attendance, exam proctoring)
- Generate analytics and reports for institutions (attendance trends, grade distributions)
- Send service-related communications (notifications, alerts, announcements)
- Improve the Platform through usage analytics and feedback
- Enforce our Terms of Service and protect against misuse
- Comply with legal obligations
3. How We Share Your Information
We do NOT sell your personal data. We share information only in these circumstances:
3.1 Within the Platform
- Your profile information is visible to other users based on your privacy settings
- Institution administrators see academic data for their institution's members
- Teachers see data for their assigned classes and subjects
- Parents see data for their linked children only
- Posts, comments, and social activity are visible per your sharing settings
3.2 Third-Party Service Providers
- Paddle — Our Merchant of Record for platform subscriptions (processes billing, taxes, invoicing)
- Cloudflare — Content delivery and security (CDN, R2 for file storage)
- Resend — Transactional email delivery
- Institution-configured payment gateways (Stripe, Razorpay, JazzCash, Easypaisa, etc.) — only for institution-level transactions
3.3 Legal Requirements
We may disclose information when required by law, court order, or governmental regulation, or when necessary to protect our rights, safety, or property.
4. Data Security
We implement robust security measures to protect your data:
- Encryption at rest: AES-256-GCM for sensitive financial data
- Encryption in transit: TLS/SSL for all communications
- Webhook verification: HMAC-SHA256 signature validation for all payment webhooks
- Multi-tenant isolation: Each institution's data is logically isolated; all queries are filtered by institution ID
- Role-based access: Strict authorization controls (Supreme Admin, Institution Admin, Teacher, Student, Parent)
- Soft deletion: Data is soft-deleted (recoverable) before permanent removal
- Rate limiting: Redis-based rate limiting to prevent abuse
5. Cookies & Local Storage
We use cookies and local storage for:
- Authentication: Session cookies to keep you signed in (NextAuth session)
- Preferences: Theme settings (dark/light mode), language preferences
- Real-time: WebSocket connection state (Socket.IO)
- Analytics: Anonymous usage patterns to improve the platform
You can control cookie preferences through your browser settings. Disabling essential cookies may affect Platform functionality.
6. Data Retention
Active accounts: We retain your data for as long as your account is active.
Deleted accounts: Upon account deletion, personal data is removed within 30 days, except where retention is required by law (e.g., financial records for tax compliance are retained for the legally required period).
Institution data: Academic records may be retained for longer periods as required by educational regulations and institution policies.
Cache data: Redis cache entries expire automatically based on configured TTL values (5 minutes to 7 days depending on data type).
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access — Request a copy of the personal data we hold about you
- Rectification — Request correction of inaccurate personal data
- Erasure— Request deletion of your personal data ("right to be forgotten")
- Portability — Request your data in a portable format
- Restriction — Request limitation of processing
- Objection — Object to processing based on legitimate interests
To exercise any of these rights, contact us at privacy@edumatrixinterlinked.com. We will respond within 30 days.
8. Children's Privacy
Users under 13 may only access the Platform through their institution's account, with parental or guardian consent. We do not knowingly collect personal information from children under 13 without verifiable parental consent.
Parents can review, update, or delete their child's information through the Parent Dashboard or by contacting us.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure that appropriate safeguards are in place for such transfers, in compliance with applicable data protection laws.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy on this page with a new "Last updated" date and, where appropriate, via in-app notification or email.
Contact Us
For privacy-related questions, contact our Data Protection team at privacy@edumatrixinterlinked.com.