Privacy Notice
This notice explains, in plain words, what personal data Codewaala collects, why we need it, who helps us process it, how long we keep it, and how you (or your parent) can see, fix, download or delete it.
यह सूचना हिंदी में भी उपलब्ध है — grievance@codewaala.com पर लिखें / This notice is available in Hindi on request.
1. Who we are
Codewaala is run by Indrashikha Educational (OPC) Private Limited, a company registered in India.
| Company | Indrashikha Educational (OPC) Private Limited |
| CIN | U62011UP2018OPC104206 |
| GSTIN | 09AAECI8731P2ZU |
| Registered office | Mishirpur, Surwa, Fatanpur Raniganj, Patti, Pratapgarh, Uttar Pradesh 230306, India |
| Products | Codewaala, CodeShaala, CoderLand, CodeBattles and CodeShaala AI |
| Websites & app | codewaala.com, code.techwaveacademy.com, codewaala.indrashikha.com and the Codewaala Android app |
In this notice, "we", "us" and "our" mean this company. "You" means the person using Codewaala — a student, a parent or guardian, a teacher, or a school leader.
2. Our two roles
Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the organisation that decides why and how personal data is used is called the Data Fiduciary. We play one of two roles:
- We are the Data Fiduciary for independent students (who sign up themselves, with a parent's consent if under 18), their parents or guardians, school staff accounts we create, people who send us a school enquiry, and people who contact us.
- The school is the Data Fiduciary for students it enrols. The school decides to use Codewaala, tells parents about it and obtains verifiable parental consent. We process those students' data for the school, on its instructions, under a written data processing agreement. If you are a parent of a school-enrolled student, you can contact the school or us — we will help, and pass your request to the school where the decision is theirs.
3. Children's data — our promises
Most people who use Codewaala are children in Grades 1–12. Under the DPDP Act, anyone under 18 is a child. We take extra care:
- Verifiable parental consent first. If someone under 18 signs up on their own, we email their parent or guardian a secure link. The parent reads this notice, chooses which purposes to allow and sets the account password. Until the parent approves, the account cannot be used, and if it is not approved within 7 days it is deleted automatically.
- School students are covered by the consent their school obtains from parents.
- No ads. We never show advertising to children.
- No tracking or behavioural monitoring. We do not track children across sites, we do not keep IP addresses, device details or click-by-click timelines for student accounts, and we do not use any analytics scripts on student pages.
- No profiling and no targeted advertising. We do not build profiles of children or use their data to target them with anything.
- Gentle leaderboards. CodeBattles leaderboards need a login, show only a first name and the first letter of the last name (for example "Aarav S."), and by default show only children from the same school. A parent can switch leaderboard visibility off.
- AI features only with permission. The CodeShaala AI builder and the Help chat send what a child types to an AI service. For independent students under 18 these work only if the parent has switched on the "AI features" purpose.
- Parents stay in control. A parent can download the child's data, correct it, delete the account, or withdraw consent at any time.
4. What we collect and why
We only collect what we need. Here is each kind of data, the reason we use it, the basis we rely on, and how long we keep it.
| What we collect | Why we need it | Basis / consent purpose | How long |
|---|---|---|---|
| Independent student account: name, email, date of birth, grade, school name (optional), mobile number (optional), password (stored only as a one-way hash) | To create and run your account, let you sign in, show the right grade content, and check your age (date of birth tells us if parental consent is needed) | Consent — Account & learning (given by the parent for under-18s) | While the account is active; deleted after 2 years of inactivity (48-hour email warning first) or when you delete it |
| Parent / guardian: name and email | To ask for and record verifiable parental consent, let the parent re-approve optional purposes, send the parent notices about the child's account, and tell the parent if a data breach ever affects the child | Legal obligation (DPDP Act s.9) and consent | The parent's name and email are kept on the child's account for as long as the account exists. A pending approval link holds the email until the parent responds (max 7 days). The consent record itself keeps only a one-way hash of the parent's email, plus the purposes chosen and the date |
| School staff (principal, teachers): name, email, password hash, school name | To run the school's account, classes and billing | Contract with the school | Until the school's contract ends + 90 days, or until the staff account is removed |
| School-enrolled students: name (entered by the school), a generated username, PIN (stored as a one-way hash), class | To let the student sign in and learn, and to let their teacher see progress | Processed for the school, which holds parental consent | Until the school's contract ends + 90 days, or earlier if the school deletes the student |
| Learning activity: lessons completed, scores, CodeBattles problems solved and points | To show progress to the student and their teacher, award points, and (only if allowed) show the leaderboard | Consent — Account & learning; leaderboard only with Leaderboard visibility | Same as the account |
| AI prompts: what you type into the CodeShaala AI builder or the Help chat | Sent to an AI provider to generate code or an answer. Email addresses and phone numbers are stripped out automatically before sending. On teacher dashboards, the Help chat sends only the page title, never the page contents | Consent — AI features | Not stored by us beyond the request itself |
| Usage counters: number of AI builds and chats per day, failed sign-in attempt counters | Fair use limits and protecting accounts from password guessing | Legitimate use for security and service operation | 30 days |
| Payments: plan bought, amount, date, Razorpay order and payment IDs | To activate your plan, and to keep tax (GST) and accounting records. Card, UPI and bank details are handled by Razorpay — we never see them | Contract and legal obligation (GST and accounting law) | 8 years |
| School enquiry (lead) form: school name, your name, email, phone, city, approximate student numbers, message, browser type | To reply to your enquiry and set up a pilot | Consent (you send it to us) | 12 months |
| Grievance and rights requests: your name, email, optional phone, your request and our replies | To handle your request and show we did | Legal obligation | 3 years after the request is closed |
| Technical and security data: IP address (used for a moment to choose India or international pricing and to protect the service), platform security logs | Security, fraud prevention and showing the right prices | Legitimate use for security; legal obligation (CERT-In) | IP for pricing is not stored; security logs 1 year |
| Session activity: for students, only anonymous counts (for example "12 students used CodeBattles this hour") | To understand load and keep the service healthy | Legitimate use; contains no identity | Rows are deleted once counted |
We do not collect Aadhaar numbers, photos, location, contacts or biometric data.
5. Purposes you choose (consent)
When you (or your parent) give consent, you choose which purposes to allow. Boxes for optional purposes are never pre-ticked.
| Purpose | Required? | What it allows |
|---|---|---|
| Account & learning | Required | Creating the account, lessons, progress, CodeBattles scoring |
| AI features | Optional | CodeShaala AI builder and the Help chat (what you type is sent to an AI provider) |
| Leaderboard visibility | Optional | Showing first name + last initial on CodeBattles leaderboards |
| Product updates by email | Optional | Occasional emails about new lessons and features (never ads to children) |
You can withdraw consent at any time — as easily as you gave it — from Privacy & data when signed in, or by writing to us. Withdrawing does not make earlier lawful processing unlawful. Withdrawing the required Account & learning purpose means closing the account, because we cannot run it without that data.
For independent students under 18: the child (or parent) can switch optional purposes off at any time from Privacy & data. Switching an optional purpose back on needs the parent's approval — we send the parent a fresh approval email. Adults choose their own password at sign-up; for under-18s the parent chooses the password (at least 8 characters) on the approval page. We never email passwords.
6. Cookies and analytics
- One essential cookie. When you sign in we set a single secure, HttpOnly cookie called
cs_sessionthat keeps you signed in for up to 30 days. It is needed for the service to work. - No advertising cookies and no third-party trackers on student pages.
- Adult marketing pages only: a first-party analytics script from techwaveacademy.com (our group
website) runs only on the school-marketing pages
/schoolsand/pitch.html, which are meant for school leaders. It records page views, the referring page and basic browser/device information. It never runs on student, lesson, dashboard or school-website pages.
7. Who we share data with
We never sell personal data. We use a small number of trusted service providers ("Data Processors") who process data only on our instructions and under contract:
| Provider | What they do | Data involved |
|---|---|---|
| Microsoft Azure | Hosting, database (Table storage) and file storage (Blob storage); Azure OpenAI for the Help chat and AI builder; Azure Communication Services to send emails (verification codes, parent consent links) | All account and learning data; AI prompts; email addresses for emails we send |
| Google (Gemini API) | Generates code for the CodeShaala AI builder when enabled | The AI builder prompt (with emails/phone numbers stripped) and the current project code |
| Google (Gmail) | Hosts the mailbox that receives email sent to grievance@codewaala.com and contact@codewaala.com, and copies of grievance form submissions | Your name, email, phone (if given), your message and our replies |
| Razorpay | Payment processing | Payment details you enter on Razorpay's checkout; plan and order IDs |
| Cloudflare | Domain name system (DNS), content delivery and security | Technical request data such as IP address |
Where data is stored: your data is stored on the Microsoft Azure cloud. Emails you send us, and our replies, are kept in our Google (Gmail) mailbox. AI providers may process prompts on servers outside India. We only transfer personal data to countries that are not restricted by the Government of India under section 16 of the DPDP Act.
We may also share data if the law requires it (for example a valid order from a court or government authority), and with a school only for its own enrolled students.
8. How long we keep data
We delete data when we no longer need it. Our retention periods are:
| Data | Kept for |
|---|---|
| Sign-up verification (OTP) codes | 24 hours |
| Accounts waiting for parental consent | 7 days, then deleted |
| Inactive independent student accounts | 2 years without sign-in — we email 48 hours before deleting |
| School student accounts | Until the school's contract ends + 90 days |
| School enquiry (lead) details | 12 months |
| Throttle and usage counters | 30 days |
| Payment records | 8 years (GST and accounting law) |
| Security logs | 1 year |
| Grievance and rights requests | 3 years after closure |
When an account is deleted, we keep only a one-way hashed "tombstone" (which cannot be turned back into your identity) and the date of deletion, so we can prove the deletion happened. Payment records we must keep by law are kept in minimised form, no longer linked to your account.
9. Your rights
Under sections 11 to 14 of the DPDP Act you have the right to:
- Access — get a summary of your personal data and how we use it, and who we shared it with.
- Correction, completion and updating — fix anything wrong or out of date.
- Erasure — have your data deleted when it is no longer needed or you withdraw consent (except what the law makes us keep, such as payment records).
- Nomination — nominate another person to use your rights if you die or become unable to.
- Grievance redressal — complain to us and get a reply.
- Withdraw consent — at any time, as easily as you gave it.
For a child, the parent or guardian uses these rights on the child's behalf.
10. How to use your rights
- Signed in? Go to Privacy & data to Download my data, Delete my account or Manage consent.
- Anyone can use the grievance & rights request form or email grievance@codewaala.com. You get a ticket number.
- We may ask you to confirm your identity (for example by replying from the account's email). We respond within 15 working days, and never later than the 90 days allowed under the DPDP Rules, 2025.
School-enrolled students and their parents should make rights requests through the school or our request form; we pass them to the school where the decision is theirs. The school's principal can also erase a student's account from the school dashboard.
11. Grievance Officer
Amrrish Anand — Grievance Officer
Phone: +91 70339 76796
Email: grievance@codewaala.com (secondary: contact@codewaala.com)
Post: Indrashikha Educational (OPC) Private Limited, Mishirpur, Surwa, Fatanpur Raniganj, Patti, Pratapgarh, Uttar Pradesh 230306, India
12. Complaints to the Data Protection Board of India
If you are not satisfied with how we handled your grievance, you can complain to the Data Protection Board of India. Under section 13(3) of the DPDP Act, you need to use our grievance process first before going to the Board.
13. Security and data breaches
- All traffic is encrypted in transit (HTTPS with HSTS).
- Passwords and PINs are stored only as salted one-way hashes; we cannot read them.
- Access to data is limited to people who need it; school data is separated per school.
- Sign-in attempts are rate-limited to stop password guessing.
- If a personal data breach happens, we will tell affected users (parents, for children) and the Data Protection Board of India without delay, send the Board a detailed report within 72 hours, and report to CERT-In as the law requires. We will tell you what happened, what it means for you, and what you can do.
14. Changes to this notice
We will update this notice when our practices change. Each version has a number and an effective date. For important changes we will tell you by email or on the site before they take effect and, where needed, ask for fresh consent.
The DPDP Act, 2023 and the DPDP Rules, 2025 apply fully from 13 May 2027. We are following them early, because children's data deserves the highest protection now.
Version history: 1.1 — 1 October 2026 — added Google (Gmail), which hosts our grievance and contact mailbox. 1.0 — 30 September 2026 — first published version.
Version 1.1 · Effective 1 October 2026 · See also our Terms of Use, Your data & the DPDP Act and Grievance & requests.