Skip to content
NIKSHAOS
Product Privacy Contact Sign in

← Back to NIKSHA OS

Pre-launch document. The contact address, named Grievance Officer and governing-law seat are marked pending and will be published before public release. For any question about this document, contact support@nikshaos.in.

NIKSHA OS — School / Institution Agreement

Document version: 1.0
Status: Draft for owner sign-off
Provider: NIKSHA OS, contact address — pending ("Provider", "we").
Institution: the school / educational organisation that subscribes to or uses the Service (the "Institution", "you").

This Agreement is the binding contract between NIKSHA OS and a school. It incorporates the Terms & Conditions, the Acceptable Use Policy, the Privacy Policy, the AI Usage & Disclaimer, and includes a Data Processing Addendum (Part B). By onboarding a school and accepting this Agreement in the app, the Institution's authorised signatory (e.g. Principal/Director/Administrator) agrees on the Institution's behalf.


Part A — Service terms

A1. The relationship

  • NIKSHA OS provides the Service to the Institution to run its school operations.
  • The Institution is responsible for how it and its users (staff, teachers, parents, students) use the Service, including configuring modules, entering data, and obtaining any consents the law requires from parents/guardians.

A2. Institution responsibilities

The Institution agrees to:

  1. Provide accurate set-up information and keep its account, roles and staff list current (promptly deactivating staff who leave).
  2. Use the Service lawfully and ensure its users comply with the Acceptable Use Policy.
  3. As Data Fiduciary, establish the lawful basis for processing student, parent and staff data, and obtain and record verifiable parental consent where the law requires it (see Children's Data & Consent).
  4. Set its own fee structures, academic records, and retention preferences, and handle parent disputes about fees and records.
  5. Keep its own copies of any records it is legally required to retain.

A3. Provider responsibilities

NIKSHA OS agrees to:

  1. Provide the Service with reasonable skill and care and apply the security measures in the Security Policy.
  2. Process Institution data only on the Institution's documented instructions (Part B).
  3. Maintain encrypted backups, and work towards verified restore testing, per the Backup & Recovery Policy — which states plainly that a passing restore test is not currently claimed.
  4. Notify the Institution without undue delay of a personal-data breach affecting its data, and assist with its obligations.
  5. Make the legal documents and any material changes available to the Institution.

A4. Fees & term (commercial)

  • Subscription/licence fees, billing cycle, entitlements/plan, and term are as set out in the applicable order form, quote, or plan agreed with the Institution.
  • Unless agreed otherwise, the Agreement runs for the subscribed term and renews per the order form; either party may decline renewal with reasonable notice.
  • Fees are exclusive of applicable taxes (e.g. GST) unless stated.

A5. Suspension & termination

  • Either party may terminate for material breach not cured within 30 days of written notice.
  • NIKSHA OS may suspend access for non-payment, security risk, or unlawful use.
  • On termination: see A6 (exit) and the Data Retention & Deletion Policy.

A6. Exit & data portability

On termination or expiry, NIKSHA OS will, on request and within an agreed window:

  1. Disable access;
  2. Make the Institution's data available for export in a commonly used format; then
  3. Delete or anonymise the Institution's personal data from active systems within a reasonable period (residual copies age out of encrypted backups), except where the law requires retention.

A7. Warranties & disclaimers

The Service is provided with reasonable skill and care but otherwise "as is" as described in the Terms & Conditions §11. AI features are assistive only (see AI Usage & Disclaimer). NIKSHA OS supports — and does not replace — the Institution's professional and legal responsibilities.

A8. Liability

The limitation of liability in the Terms & Conditions §12 applies. For an Institution, the aggregate liability cap is the fees paid by the Institution to NIKSHA OS in the 12 months before the event, except for liabilities that cannot be limited by law (including certain DPDP Act liabilities).

A9. Indemnity

The Institution will indemnify NIKSHA OS against third-party claims arising from the Institution's unlawful processing, its breach of this Agreement or the AUP, or content it or its users upload. NIKSHA OS will indemnify the Institution against claims that the Service's own software infringes a third party's IP rights, subject to the liability cap.

A10. Confidentiality

Each party will keep the other's non-public information confidential and use it only to perform this Agreement.

A11. Governing law

This Agreement is governed by the laws of India, with exclusive jurisdiction of the courts at governing law city — pending, governing law state — pending, subject to amicable resolution via the Grievance Officer first.


Part B — Data Processing Addendum (DPA)

This Addendum governs NIKSHA OS's processing of personal data on the Institution's behalf and reflects the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025.

B1. Roles

  • The Institution is the Data Fiduciary for student, parent and staff personal data it processes through the Service.
  • NIKSHA OS is the Data Processor, processing that data only on the Institution's documented instructions (this Agreement, the Service's configuration, and the Institution's use of features).
  • For limited account/device/diagnostic data NIKSHA OS needs to run the Service itself, NIKSHA OS is the Data Fiduciary (see Privacy Policy).

B2. Scope & purpose of processing

  • Subject matter: operating the school-management Service.
  • Nature/purpose: hosting, storing, organising, retrieving, transmitting and displaying personal data to deliver the modules the Institution uses.
  • Categories of data subjects: students (children), parents/guardians, teachers, staff, administrators.
  • Categories of personal data: identity & contact details; academic records (attendance, marks, results, homework); financial records (invoices, payments, receipts); transport/hostel/library records; communications; optional government identifiers where the Institution chooses to store them (treated as sensitive and masked); device/technical data.
  • Duration: for the term, then per Part A6 and the Retention Policy.

B3. NIKSHA OS's obligations as Processor

NIKSHA OS will:

  1. Process personal data only on the Institution's documented instructions, and not for its own independent purposes (and never to sell data, advertise to children, or train unrelated third-party AI models).
  2. Apply appropriate security safeguards (see Security Policy) and ensure personnel are bound by confidentiality.
  3. Assist the Institution, taking into account the nature of processing, with: - responding to data principals' rights requests (access, correction, erasure, grievance), and - the Institution's breach-notification and accountability obligations.
  4. Notify the Institution without undue delay after becoming aware of a personal- data breach affecting the Institution's data, with information to help the Institution notify the Data Protection Board and affected individuals within the timelines in the DPDP Rules.
  5. On the Institution's instruction, delete or return personal data on exit (Part A6), subject to legal retention.
  6. Make available information reasonably necessary to demonstrate compliance, and allow audits as reasonably required (subject to confidentiality and security).

B4. Sub-processors

  • The Institution authorises NIKSHA OS to engage the sub-processors listed in SUBPROCESSORS.md to provide the Service.
  • NIKSHA OS imposes data-protection obligations on sub-processors consistent with this Addendum and remains responsible for their performance.
  • NIKSHA OS will keep the sub-processor list current and record material changes in the the document changelog. If the Institution reasonably objects to a new sub-processor on data-protection grounds, the parties will work in good faith to find an alternative; if none is feasible, the Institution may terminate the affected feature or the Agreement as its sole remedy.

B5. Children's data

The parties acknowledge the Service is used by and about children. NIKSHA OS processes children's data only to deliver the Service on the Institution's instructions, and applies the protections in Children's Data & Consent: no tracking, behavioural monitoring, or targeted advertising directed at children. Obtaining verifiable parental consent, where required, is the Institution's responsibility.

B6. International transfers

Some sub-processors are outside India (see SUBPROCESSORS.md). NIKSHA OS transfers only the minimum necessary data, under contractual safeguards, consistent with the DPDP Act and Rules, and not to any jurisdiction restricted by the Central Government.

B7. Records & assistance

NIKSHA OS maintains records of categories of processing and provides the Institution reasonable assistance and information to meet the Institution's obligations as Data Fiduciary.

B8. Conflicts

If this Addendum conflicts with another part of the Agreement on the subject of data protection, this Addendum controls. If the law changes, the parties will update this Addendum to remain compliant.


Signature (owner/Institution to complete)

  • For the Provider: NIKSHA OS — name, designation, date.
  • For the Institution: name of school, authorised signatory, designation, date.

NIKSHAOS

One system for the whole school.

Product

  • Overview
  • Privacy & data
  • Sign in

Legal

  • Privacy Policy
  • Parent & User Terms
  • Acceptable Use
  • Institution Agreement
  • Delete your account

Contact

  • support@nikshaos.in

© 2026 NIKSHA OS. All rights reserved.