// Legal

Privacy Policy

What DoxaEd Timetables collects, why, who else sees it, and how long it is kept.

Effective date: 28 July 2026Last updated: 28 July 2026


01Who is responsible for your data

The Service at timetables.doxaed.com is operated by DoxaEd, H/No 249, Midland, Dimapur, Nagaland, 797112, India. Privacy questions go to doxaedoffice@gmail.com or 9612165794.

Where your institution decides what to put into the Service, your institution is the Data Fiduciary for that information under India’s Digital Personal Data Protection Act, 2023, and we process it as a Data Processor on its behalf. For your own account details, DoxaEd is the Data Fiduciary.

02What we collect

Account information

A username, an email address and a password. The password is stored only as a hash — we never hold it in readable form and cannot tell you what it is. We also record which plan the account is on and when that plan expires.

Usage signals

We record a “last active” timestamp for each account, written at most once every five minutes when the account calls the API, so we can tell which accounts are in use. Our web server also writes an ordinary access log: for each request, the IP address it came from, the date and time, the URL and method, the response status and size, the browser’s user-agent string and the referring page. These logs are used only to run and secure the Service and are kept for no more than 30 days, after which they are deleted or overwritten.

The scheduling data you enter

This is the bulk of what the Service holds, and it is entirely what you or your colleagues type in or import:

  • Projects — project name, institution name, term or semester label and your own comments.
  • Classes and sections — the class name, grade and section labels and a number of students.
  • Subjects — names, colours and elective groupings.
  • Teachers — the teacher’s name and their scheduling attributes (periods per day, eligible subjects and classes, proxy eligibility, availability).
  • Rooms and places — rooms, buildings and campus areas with their capacities.
  • Lessons and rules — activities, durations, and every scheduling constraint you configure.
  • Duties, cover and calendar — break-duty rosters, leave types, recorded absences, substitute assignments and per-teacher proxy ledgers, and calendar entries such as holidays, exams, tests, activities, staff days and events.
  • Generated timetables and their versions.

Two things the Service deliberately does not hold. There is no student record in DoxaEd: a class is stored as a name plus a headcount, never as a list of individual students. And the teacher record has no contact fields — the app does not ask for a teacher’s email address, phone number, address, employee ID or date of birth.

Collaborator invitations

When you invite someone to a project you supply their email address, which we store so the invitation can be matched to their account when they sign up, and so the project can show who it is shared with.

Demo and enquiry requests

The demo and contact forms collect a name, email address, organisation, phone number, a preferred date and time and your message. These are stored so we can respond, and a notification is emailed to our team.

AI assistant conversations

If you use the AI assistant, the conversation is stored against your account: the session title, every message, the tool calls the assistant made and their payloads, and the contents of any file you attach to the chat.

Payment information

Payments are handled by our payment partner Razorpay. Card, UPI, netbanking and wallet details are entered with Razorpay and are never received or stored by us. We keep the record of which plan was bought, when, the amount, and the payment reference Razorpay returns.

03Why we use it

  • To operate the Service: authenticate you, run the scheduling engine, and store and display your data.
  • To enforce plan limits and feature entitlements, and to handle billing and renewals.
  • To send transactional email — password resets, renewal reminders, and notification of a demo or contact request.
  • To keep the Service secure, diagnose faults and prevent abuse.
  • To respond to your enquiries and support requests.

We do not sell your data, we do not use your scheduling data to advertise to you, and we do not use it to train AI models. To decide what to build next we look only at aggregate, non-identifying counts — how many accounts, projects and timetables exist and which features are used. We look at an individual account’s data only when you ask us to (for example to investigate a fault you have reported), or where we must to protect the Service or comply with the law.

04Cookies and browser storage

The application does not set advertising or analytics cookies, and no third-party tracking or analytics script is embedded in it. It does use your browser’s local storage for things it needs to work:

  • your sign-in tokens, so you stay signed in between visits (the access token lasts 12 hours and the refresh token 30 days);
  • which project you last had open;
  • interface preferences such as saved analytics date ranges and duty-matrix layout;
  • on a public duty-roster link, the access code you entered, for the duration of that browser session only.

You can clear these at any time through your browser; clearing the sign-in tokens simply signs you out.

05Who else receives data

These are the third parties this application actually reaches out to:

  • Google Fonts. The site loads its typefaces from fonts.googleapis.com and fonts.gstatic.com, so Google receives your IP address and basic browser information when a page loads.
  • Google’s Gemini API. Used only when you use the AI assistant or AI builder. Your prompt, any attached file, and the project data the assistant reads or writes are sent to Google for processing.
  • Third-party AI clients you connect yourself. If you link an external AI client such as ChatGPT or Claude to your account through our connector, that client and its provider receive whatever project data it requests, under your authorisation.
  • Razorpay (Razorpay Software Private Limited, India) — our payment gateway. When you buy or renew a plan, Razorpay collects your payment details and contact details directly and processes them under its own privacy policy; it returns to us only the outcome and a payment reference.
  • Email delivery. Transactional email — password resets, renewal reminders and enquiry notifications — is sent through a third-party SMTP email provider, which handles the recipient address and the message content solely in order to deliver it. We will name our current provider on request to doxaedoffice@gmail.com.
  • Hosting. The application, its PostgreSQL database and its backups run on a Linux virtual private server that we rent from a commercial cloud hosting provider and administer ourselves. We will confirm the current provider and the data-centre region on request to doxaedoffice@gmail.com.

That list is complete. No other third party receives personal data from the Service today, and if we add one we will update this page before it begins processing. We may also disclose data where we are legally required to, for example in response to a lawful order from a court or a public authority.

07How long we keep it

  • Deleted timetables go to the trash and can be restored for 7 days, after which they are purged permanently.
  • An expired or cancelled paid plan does not delete anything. The account continues on the Free plan and the data stays in place, for as long as the account exists.
  • Account and project data after you ask us to delete an account: the account and everything in it is deleted within 30 days of your request.
  • Backups: database backups are kept on a rolling 30-day basis and are then destroyed, so deleted data disappears from backups within 30 days of the deletion.
  • Demo and enquiry records: kept for 24 months from our last contact with you about the enquiry, then deleted.
  • Server access logs: no more than 30 days.
  • Billing records — what was bought, when, for how much, and the payment reference — are kept for six years from the end of the financial year they relate to, the period Indian income-tax law requires. These are kept even after an account is deleted, because we are obliged to keep them.

08Security

These are measures present in the Service today:

  • the site and API are served over HTTPS;
  • passwords are stored hashed, never in readable form;
  • API access requires an authenticated token, and every project is scoped to its owner and the accounts explicitly invited to it;
  • sharing tokens and access codes are generated with a cryptographically secure random generator, and access codes can be rotated at any time;
  • the AI assistant’s tools are confined to the project of the chat session.

No system is perfectly secure, and we would rather tell you plainly what we do not have. DoxaEd holds no formal security certification — no SOC 2, no ISO 27001, no other — and we make no claim to hold one. We do not currently commission third-party penetration testing. Data is encrypted in transit; at rest it is protected by our hosting provider’s storage encryption and by the database’s own access controls, and we do not additionally encrypt individual fields other than password hashes.

If a personal data breach happens, we will notify the Data Protection Board of India and every affected account holder, by email to the address on the account, without delay and in any event within 72 hours of becoming aware of it, describing what happened, what data was involved, what the likely consequences are, and what we are doing about it.

09Your rights

You can view and correct most of your data directly in the app, and export it. To request access to, correction of, or deletion of information you cannot reach yourself, email us at doxaedoffice@gmail.com.

Under India’s Digital Personal Data Protection Act, 2023, which is the law that applies to this Service, you have the right to:

  • obtain a summary of the personal data we process about you and what we do with it, and the identities of anyone we have shared it with;
  • have inaccurate or incomplete data corrected, completed or updated;
  • have your personal data erased where we no longer need it for the purpose it was given for and no law requires us to keep it;
  • nominate another person to exercise these rights on your behalf if you die or become unable to exercise them yourself;
  • a readily available means of grievance redressal — see section 12.

We answer requests within 30 days. We may need to confirm your identity before acting on one. If you are not satisfied with our answer, you may complain to the Data Protection Board of India. Where your institution is the Data Fiduciary for the data in question, we will pass your request to it and support it in answering you.

10Children

The Service is intended for use by institutions and their staff, not by children. As noted above, it holds no individual student records — a class is a name and a headcount. Accounts should be created only by staff aged 18 or over, and we do not knowingly collect personal data of a child. If you believe a child’s data has reached us, tell us at doxaedoffice@gmail.com and we will delete it.

11Changes to this policy

We may update this policy. The version on this page, with the effective date at the top, is the current one. Where a change is material we will notify you by email to the address on your account at least 30 days before it takes effect.

12Contact and grievances

Privacy contact: doxaedoffice@gmail.com.

As required by the Digital Personal Data Protection Act, 2023, DoxaEd has a Grievance Officer. To raise a grievance about how your personal data has been handled, contact:

  • The Grievance Officer, DoxaEd
  • Email: doxaedoffice@gmail.com
  • Telephone: 9612165794 (Monday to Saturday, 10:00–18:00 IST)
  • Post: H/No 249, Midland, Dimapur, Nagaland, 797112, India

We acknowledge every grievance within 3 working days and give you a substantive answer within 30 days. If you remain dissatisfied you may complain to the Data Protection Board of India.

See also our Terms & Conditions and our Contact Us page.