Privacy Policy

Last updated: 12 July 2026

This Privacy Policy (“Policy”) describes how Hybreed Technologies (“Hybreed”, “we”, “us”, “our”), the developer and operator of the ceraaa platform (“ceraaa”, the “Platform”, the “Service”), collects, uses, discloses, retains and safeguards personal data of users (“you”, “your”), including students, parents, guardians, teachers, faculty and institute administrators. This Policy is issued in compliance with the Information Technology Act, 2000 and rules thereunder, the Digital Personal Data Protection Act, 2023 (“DPDP Act”) of India, and other applicable laws.

By accessing or using ceraaa, you acknowledge that you have read and understood this Policy and consent to the collection, processing, storage and disclosure of your personal data in accordance with its terms. If you do not agree, please do not use the Platform.

1. Roles under the DPDP Act

ceraaa is licensed by Hybreed Technologies to educational institutes, coaching centres and similar organisations (each an “Institute”). Where an Institute uploads or manages personal data of its students, parents or staff on the Platform, the Institute is the Data Fiduciary and determines the purpose and means of processing. Hybreed acts as a Data Processor and processes such data solely on the Institute’s documented instructions and as required to operate the Service. For data collected directly by Hybreed (for example, account registration, support requests, billing and website analytics), Hybreed is the Data Fiduciary.

2. Personal data we collect

Depending on your role and use of ceraaa, we may collect:

  • Identity and contact data: name, gender, date of birth, photograph, email address, phone number, postal address, emergency contact details.
  • Academic and institutional data: enrolment records, batches, standards, syllabus progress, attendance, marks, test results, timetables, faculty assignments, teaching hours.
  • Financial data: fee structures, invoices, receipts, payment status, salary, payslips and other institute-generated financial records. We do not store full card numbers or bank credentials; payments (if enabled) are handled by regulated third-party gateways.
  • Guardian and family data: parent/guardian names, contact details and relationship to the student.
  • Account and technical data: user ID, hashed authentication credentials, session tokens, IP address, device, browser, timezone, log data, audit trails, feature usage.
  • Communications: emails, notifications, support tickets and other correspondence with us.

Children’s data. ceraaa may process personal data of children (individuals below 18 years of age) as part of an Institute’s operations. Such processing is performed strictly on behalf of the Institute, which is required under the DPDP Act to obtain verifiable parental / lawful guardian consent. We do not undertake behavioural tracking, targeted advertising or profiling of children.

3. How we collect data

  • Directly from you when you register, sign in, or update your profile.
  • From your Institute or its authorised administrators, teachers or staff (for example, when a student is enrolled or a payment is recorded).
  • Automatically through cookies, log files and similar technologies as you use the Platform.
  • From service providers who help us operate the Service.

4. Purposes of processing and lawful basis

We process personal data for the following purposes:

  • Providing the core functionality of ceraaa — user authentication, role- based access, dashboards, attendance, syllabus, fees, salary, tests and reporting.
  • Facilitating communication between Institutes, faculty, students and parents (notifications, reminders, receipts, statements).
  • Billing, invoicing and financial reconciliation between Hybreed and the Institute.
  • Ensuring security, preventing fraud or abuse, maintaining audit logs and complying with legal obligations.
  • Improving the Platform, diagnosing technical issues and developing new features (using aggregated or de-identified data wherever feasible).
  • Responding to your requests and providing customer support.

The lawful bases for processing are (i) your consent, (ii) legitimate uses permitted under the DPDP Act (such as employment, performance of a contract, and provision of services or benefits you have requested), and (iii) compliance with applicable law.

5. Cookies and analytics

We use strictly necessary cookies for authentication and session management and may use limited analytics cookies to understand aggregate usage. You can control non-essential cookies through your browser settings. Disabling essential cookies will impair the functioning of the Platform.

6. Sharing and disclosure

We do not sell personal data. We may share data with:

  • Your Institute and users authorised by it (for example, teachers can see students in their batches; parents can see their children’s records).
  • Sub-processors and service providers that host, store, transmit, secure or support the Platform (including cloud hosting, database, email delivery, error monitoring and payment processing providers). Such parties are bound by contractual confidentiality and data-protection obligations.
  • Legal and regulatory authorities where disclosure is required by law, court order or to protect the rights, safety or property of Hybreed, its users or the public.
  • Successors in the event of a merger, acquisition, reorganisation or sale of assets, subject to equivalent protections.

7. Data storage, location and transfers

Personal data is primarily stored on secure cloud infrastructure. Data may be processed in India and, where necessary, in other jurisdictions that are not restricted by notifications issued under the DPDP Act. We rely on appropriate contractual and technical safeguards for any cross-border transfer.

8. Data retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to satisfy legal, accounting, tax and audit obligations, and to resolve disputes. Institute-owned data is retained for the duration of the Institute’s subscription and may be deleted or returned upon termination in accordance with our agreement with the Institute. Backups may persist for a limited period thereafter before secure deletion.

9. Security

We implement reasonable technical and organisational measures to protect personal data, including encryption in transit (HTTPS/TLS), encryption at rest for supported stores, hashed passwords, role-based access controls, row-level security policies, principle-of-least-privilege access, audit logging and regular reviews. No method of transmission or storage is, however, completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your login credentials and for all activities under your account.

10. Your rights (DPDP Act)

Subject to applicable law, you have the right to:

  • Obtain confirmation and a summary of the personal data being processed.
  • Request correction, completion or updating of inaccurate data.
  • Request erasure of personal data that is no longer necessary or where consent has been withdrawn, subject to legal retention requirements.
  • Withdraw consent previously given, without affecting the lawfulness of prior processing.
  • Nominate another individual to exercise your rights in the event of death or incapacity.
  • Grievance redressal through the mechanism described below.

Where your personal data is processed by us on behalf of an Institute (Data Fiduciary), we will forward such requests to the Institute or, where appropriate, direct you to raise them with the Institute.

11. Third-party links and services

ceraaa may contain links to or integrate with third-party services (for example, payment gateways or communication providers). This Policy does not apply to any personal data collected by such third parties, and we encourage you to review their privacy policies.

12. Changes to this Policy

We may update this Policy from time to time to reflect changes in law, technology or our practices. The updated Policy will be posted on this page with a revised “Last updated” date. Material changes will be communicated through the Platform or via email where appropriate. Your continued use of ceraaa after the effective date constitutes acceptance of the updated Policy.

13. Limitation of liability

To the maximum extent permitted by law, Hybreed’s aggregate liability arising from or relating to this Policy or the processing of personal data shall be governed by, and limited in accordance with, the terms of service or master services agreement executed between Hybreed and the relevant Institute.

14. Grievance officer and contact

For any questions, requests, complaints or to exercise your rights under this Policy or the DPDP Act, please contact the Grievance Officer:

We will acknowledge and endeavour to resolve grievances within the timelines prescribed by applicable law.

15. Governing law and jurisdiction

This Policy is governed by the laws of India. Subject to any exclusive jurisdiction agreed with your Institute, the courts of competent jurisdiction in India shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy.