Document text
Use the page contents to navigate or print this page for your records.
Your privacy matters. Children's privacy deserves additional care.
This Privacy Policy explains how Nilofin Technologies Pvt Ltd, operating under the brand name nilo ("nilo", "we", "us" or "our"), collects, uses, stores, protects and shares personal data when people use our websites, student learning platform, school and teacher dashboards, parent features, educational content, assessments, communications and related services.
nilo is a financial-confidence and financial-literacy education platform. We design age-appropriate learning experiences that help students develop practical money knowledge and responsible decision-making skills.
We are not a bank, non-banking financial company, investment adviser, broker, portfolio manager, insurer, payment service provider, trading platform or financial-product marketplace.
1. Who We Are
The Services are operated by:
Nilofin Technologies Pvt Ltd
Operating brand: nilo
Correspondence address:
Koramangala 8th Block
Bengaluru – 560095
Karnataka, India
Privacy and grievance contact:
Privacy Contact / Grievance Officer: Sashidharan K
Email: hello@nilofin.com
Suggested subject: Privacy Request
Before publication, Nilofin Technologies Pvt Ltd should ensure that the address above matches the company's current official correspondence or registered-office details.
2. Who This Policy Applies To
This Privacy Policy applies to personal data relating to:
- Students using nilo through a participating school or authorised family arrangement
- Parents and legal guardians
- Teachers
- School administrators and authorised school personnel
- Website visitors
- People who contact nilo
- Participants in nilo pilots, workshops or educational programs
- Organisations and partners interacting with nilo
- Individuals using nilo educational tools and resources
Additional contractual terms may apply where nilo works with a school, school group, organisation, CSR partner or other institution.
3. A Special Note About Children
For the purposes of India's Digital Personal Data Protection framework, a person under 18 years of age is treated as a child.
nilo's student experience may be used by children. We therefore apply additional safeguards to student personal data.
Our approach is based on the following principles:
- Collect as little student personal data as reasonably necessary
- Use student data primarily for educational, administrative, safety and authorised reporting purposes
- Keep student accounts private by default
- Restrict access according to authorised school, teacher and parent roles
- Do not sell student personal data
- Do not rent or trade student personal data
- Do not use student personal data for targeted advertising
- Do not create advertising profiles about children
- Do not require sensitive financial information from students
- Do not require students to provide banking credentials
- Avoid unnecessary tracking of children
- Do not publicly expose identifiable student performance without appropriate authority and permission
- Apply additional care to AI-enabled features used by children
4. Parent or Guardian Consent
Where applicable law requires parental or guardian consent before a child's personal data may be processed, nilo will take appropriate steps to obtain or confirm that consent before the relevant processing begins.
Consent should be:
- Informed
- Specific
- Freely given where required
- Connected to clearly explained purposes
- Capable of being withdrawn where applicable
Where legally required, nilo will also take appropriate steps to verify that the person providing consent is an identifiable adult parent or lawful guardian.
Verification may be carried out through methods permitted by applicable law, including reliable identity or age information, an authorised verification service, an appropriate digital token or another legally acceptable mechanism.
We do not intend to collect Aadhaar merely to obtain parental consent.
If identity or age verification becomes necessary, nilo should prefer privacy-preserving verification methods and avoid retaining copies of identity documents unless retention is genuinely necessary and legally permitted.
5. Role of Schools in Consent
A school may help nilo:
- Provide privacy information to parents
- Distribute consent requests
- Verify parent-student relationships
- Maintain school permission records
- Communicate withdrawals or changes
- Administer student access
However, school authorisation alone will not be treated as a substitute for parental or guardian consent where applicable law specifically requires verifiable parental or guardian consent from nilo or the relevant Data Fiduciary.
The exact responsibilities of nilo and a participating school may also be defined in the school's service agreement, data-processing terms or pilot agreement.
6. School and nilo Data Responsibilities
Depending on the service arrangement, a school and nilo may have different responsibilities concerning student data.
Where a school determines why student information is processed and instructs nilo to process that information solely for the school's authorised educational purposes, nilo may act as a service provider or Data Processor on behalf of that school.
For activities where nilo independently determines the purpose and means of processing—for example, operating nilo accounts, maintaining platform security, handling privacy requests or meeting legal obligations—nilo may have independent responsibilities regarding that processing.
Neither party is relieved of responsibilities imposed directly upon it by applicable law.
7. Student Personal Data We May Collect
Depending on how a school configures nilo, we may process limited information such as:
- Student name
- Student username or internal account identifier
- School
- Grade
- Class or section
- School-issued student identifier, where necessary
- Account-access information
- Module assignments
- Lesson progress
- Module completion
- Quiz responses
- Quiz scores
- Pre-assessment and post-assessment results
- Mission or activity completion
- Reflection responses
- Certificates and badges
- Learning progress
- Language preference
- Teacher feedback associated with learning
- Questions submitted through approved learning features
- Technical information required to operate and protect the account
For younger students, nilo should avoid collecting personal mobile numbers and personal email addresses unless there is a specific, documented reason to do so.
8. Information We Do Not Require From Students
Students should not provide nilo with:
- Bank-account numbers
- Debit-card numbers
- Credit-card numbers
- CVV numbers
- UPI PINs
- ATM PINs
- Internet-banking credentials
- OTPs
- Investment-account credentials
- Demat-account credentials
- PAN details
- Aadhaar numbers
- Passport copies
- Government identity documents
- Parent salary slips
- Family income documents
- Tax returns
- Loan statements
- Private family financial documents
- Health or medical information unless specifically required by law for a separate approved purpose
- Precise home-location information unless specifically required, lawful and appropriately authorised
Students should never share passwords, PINs, OTPs or financial credentials anywhere within nilo.
9. Parent or Guardian Information
We may process:
- Parent or guardian name
- Contact email
- Contact number, where required
- Relationship to the student
- Student-account linkage
- Consent status
- Consent timestamp and records
- Verification status, where legally required
- Parent feedback
- Support requests
- Communication preferences
- Access to authorised student progress information
We should collect only information reasonably necessary for the relevant purpose.
10. Teacher and School Information
We may process:
- Teacher or administrator name
- School name
- Role
- Official school email
- Contact number, where necessary
- Classes or students assigned
- Account activity
- Dashboard activity
- Module-assignment activity
- Reporting activity
- Teacher feedback
- Training information
- Support communications
11. Website and Technical Data
When people access our website or Services, we may receive limited technical information such as:
- IP address
- Device type
- Browser
- Operating system
- Login timestamps
- Session information
- Security events
- Error information
- Application activity
- Performance information
- Cookies and similar technologies
We use this information to operate, troubleshoot, secure and improve our Services.
12. Why We Use Personal Data
Depending on the Service, personal data may be processed to:
- Create authorised accounts
- Authenticate users
- Deliver lessons
- Deliver assessments
- Record learning progress
- Provide quizzes
- Support missions and activities
- Issue certificates
- Assign learning content
- Show student progress
- Support teachers
- Provide authorised school dashboards
- Generate school reports
- Provide authorised parent summaries
- Measure learning outcomes
- Respond to support requests
- Maintain platform security
- Detect misuse or unauthorised access
- Prevent fraud or abuse
- Resolve technical problems
- Maintain legally required records
- Meet contractual obligations
- Respond to lawful government or regulatory requests
- Improve educational content using appropriately de-identified or aggregated information
We will not knowingly repurpose identifiable student data for an unrelated commercial purpose without appropriate notice, authority and consent where required.
13. Learning Analytics and Progress Measurement
nilo may analyse:
- Assigned modules
- Participation
- Completion
- Quiz performance
- Assessment results
- Learning progress
- Certificate eligibility
- Aggregate class performance
These measurements are intended to support education and help schools evaluate learning outcomes.
They should not be used by nilo to make high-impact decisions about a child's:
- Admission
- Academic promotion
- Employment
- Creditworthiness
- Insurance
- Financial eligibility
- Access to financial products
nilo assessments are educational measurements and are not financial-risk scores or credit scores.
14. Student Profiling, Tracking and Advertising
nilo does not intend to use children's personal data for targeted commercial advertising.
We do not intend to:
- Build advertising profiles about students
- Sell student behavioural data
- Share student behaviour with advertisers
- Target students based on financial circumstances
- Target students based on learning performance
- Promote investments, loans, insurance or trading products to children based on their personal data
Any learning-progress monitoring carried out through nilo should be limited to legitimate educational, operational or safety purposes and implemented consistently with applicable law.
15. Leaderboards, Competitions and Recognition
Student rankings, competitions or future features such as class or school challenges must be designed with child privacy in mind.
Identifiable student information should not be published on an unrestricted public leaderboard by default.
Where recognition features are enabled, nilo may use:
- First name only
- Initials
- Avatar
- Pseudonym
- Class-level totals
- School-level totals
- Other privacy-preserving presentation methods
Separate permission should be obtained before publicly displaying an identifiable child's name, photograph, video, testimonial or individual performance where required.
Participation in public promotional recognition should not be a condition for receiving core educational access.
16. Photographs, Videos, Testimonials and Marketing
nilo will not assume that educational-platform consent automatically gives permission to use a student's:
- Photograph
- Video
- Voice
- Full name
- Testimonial
- School work
- Personal story
for public advertising, social media, promotional campaigns or case studies.
Where identifiable student media is used for such purposes, nilo should obtain separate, specific permission from the appropriate parent or guardian and any required school authorisation.
Parents should be able to refuse promotional-media consent without preventing their child from accessing normal educational services.
17. AI-Supported Educational Features
nilo may introduce AI-supported learning capabilities.
Where enabled, AI tools may process information such as:
- Student questions
- Learning topic
- Grade level
- Relevant lesson context
- Limited progress information where necessary
- User-provided prompts
AI-supported features are intended to explain educational concepts.
They are not financial, investment, tax, legal, banking, insurance, credit or trading advice.
Students must not enter private financial information, passwords, OTPs, government identity information or private family documents into AI features.
nilo does not intend to use identifiable student conversations to train publicly available or general-purpose AI models.
Where a third-party AI provider processes information for nilo, nilo will seek appropriate contractual, privacy and security protections and minimise the personal information sent to that provider.
18. Sharing Personal Data
We may share personal data only where reasonably necessary and legally permitted.
Recipients may include:
- The student's authorised school
- Authorised teachers
- Authorised school administrators
- An appropriately verified parent or guardian
- Hosting providers
- Database providers
- Authentication providers
- Communication providers
- Security providers
- Analytics providers used for legitimate platform purposes
- Support providers
- Payment processors for adult or institutional transactions
- AI service providers where an AI feature is enabled
- Professional advisers
- Auditors
- Insurers
- Government authorities, regulators or law-enforcement bodies where legally required
Service providers acting on our behalf should receive only the information reasonably necessary for their role and should be subject to appropriate contractual and security obligations.
19. What We Do Not Do With Student Personal Data
nilo does not intend to:
- Sell student personal data
- Rent student personal data
- Trade student personal data
- Provide student lists to advertisers
- Use children's data for behavioural advertising
- Use children's data to market financial products
- Require children to connect bank accounts
- Require children to connect investment accounts
- Build commercial financial profiles about children
20. Cookies and Similar Technologies
Our public website may use essential and optional technologies.
Essential technologies
These may be necessary for:
- Login
- Security
- Session management
- Form protection
- Accessibility
- Basic preferences
- Service operation
Optional analytics or preference technologies
Where required, optional technologies should operate only after appropriate consent.
The student learning environment should avoid unnecessary advertising or cross-site tracking technologies.
nilo does not intend to place advertising trackers on student accounts.
Users should be provided with an accessible mechanism to manage optional cookie choices where applicable.
21. Data Security
We use reasonable technical and organisational safeguards appropriate to the nature of the information being processed.
These may include:
- Role-based access controls
- Authentication controls
- Access logging
- Password protection
- Encryption where appropriate
- Secure communications
- Controlled school-data access
- Backup procedures
- Security monitoring
- Vendor-management controls
- Employee and contractor access restrictions
- Incident-response procedures
- Need-to-know access
- Environment and credential separation
- Vulnerability-management practices
No internet-based service can promise absolute security.
Users, parents and schools must also protect their login credentials and promptly report suspected unauthorised access.
22. Security Logs
We may retain security, access and infrastructure logs where necessary to protect our systems, investigate incidents and meet applicable legal requirements.
Certain technical logs may be retained for periods required under Indian cybersecurity requirements, including applicable CERT-In directions.
Security logs will not be used for unrelated advertising purposes.
23. Personal Data Breaches
If nilo becomes aware of a personal-data or security breach, we will take appropriate steps to:
- Investigate the incident
- Contain the incident
- Reduce further risk
- Preserve necessary evidence
- Remediate affected systems
- Notify relevant schools, individuals, parents, guardians, authorities or regulators where required by applicable law
Information provided in breach notifications will depend on the nature of the incident and applicable legal requirements.
24. Data Retention
We do not intend to keep identifiable personal data indefinitely.
Retention depends on:
- The purpose for which information was collected
- School-contract requirements
- Whether the account remains active
- Certificate or learning-record requirements
- Security requirements
- Legal obligations
- Dispute-resolution requirements
As a general approach:
Student learning records
May be retained during the applicable school program or contractual relationship and for a limited period afterward where necessary for reporting, certificates, account transition, dispute resolution or legal requirements.
Parent and consent records
May be retained while relevant to the student's participation and for an appropriate period afterward to demonstrate consent, withdrawal, authorisation or compliance.
School and teacher records
May be retained while the school relationship or account remains active and for an appropriate period afterward.
Security records
May be retained for the period required for cybersecurity, security investigation and legal compliance.
When identifiable data is no longer reasonably required, it may be deleted, irreversibly anonymised or aggregated, subject to applicable law.
School agreements may establish more specific retention and return/deletion requirements.
25. When a Student Turns 18
A student's privacy rights change once the student reaches adulthood.
Where appropriate and technically feasible, nilo may:
- Verify that the student has reached adulthood
- Transfer account-control rights to the student
- Update parent-access permissions
- Seek the adult student's own choices or consent where required
- Allow the adult student to exercise applicable privacy rights directly
A parent's previous authority should not automatically continue indefinitely after the student becomes legally entitled to control their own personal data.
26. International Data Processing
Some technology providers used by nilo may operate infrastructure inside or outside India.
Where personal data is processed outside India, nilo will take reasonable measures to ensure the processing is permitted under applicable Indian law and subject to appropriate contractual, organisational and technical safeguards.
If the Government of India restricts transfers to a particular country or territory, nilo will comply with applicable restrictions.
27. Your Privacy Choices and Rights
Subject to applicable law and the circumstances of the request, eligible individuals may request:
- Information about personal data processed by nilo
- Correction of inaccurate information
- Updating of incomplete information
- Deletion or erasure where applicable
- Withdrawal of consent where processing depends upon consent
- Resolution of a privacy grievance
- Information about how their personal data is used
- Other rights available under applicable Indian law
For children, requests may normally be submitted through an authorised parent, lawful guardian or participating school, depending on the processing arrangement and applicable law.
Once a student is legally entitled to exercise their own privacy rights, those rights should be respected directly.
28. Withdrawal of Parental Consent
Where processing depends upon parental or guardian consent, that consent may be withdrawn using the available privacy-request process.
Withdrawal may mean that some student features can no longer be provided.
For example, nilo may need to:
- Stop further processing
- Restrict the student's account
- Remove the student from optional features
- Delete or return applicable information
- Ask the school to make alternative arrangements
Some information may still need to be retained where necessary for legal compliance, security, dispute resolution or another lawful purpose.
Withdrawal does not automatically invalidate processing that was lawfully carried out before withdrawal.
29. School Access and Parent Access
Teachers should see only information reasonably required for their authorised educational role.
School administrators should see only information appropriate to authorised school-management and reporting functions.
Parents or guardians should receive access only to the child or children they are authorised to represent.
nilo should implement reasonable controls designed to prevent:
- Cross-school access
- Unauthorised teacher access
- Parent access to another family's child
- Student access to another student's private records
- Unauthorised public disclosure
30. Child Safety and Legal Reporting
nilo is an educational platform and is not an emergency-response or child-protection service.
However, if nilo becomes aware of information that creates a serious concern about child exploitation, sexual abuse, child sexual abuse material, threats to safety or another matter that must be reported under applicable law, we may:
- Restrict access
- Preserve information where legally necessary
- Notify an appropriate school safeguarding contact
- Notify a parent or guardian where appropriate and lawful
- Report information to competent authorities where required by law
Nothing in this Privacy Policy prevents nilo from taking steps required under the Protection of Children from Sexual Offences Act, 2012 or other applicable child-safety laws.
31. Public Website Visitors
A person may generally browse public portions of nilofin.com without creating a student account.
If a visitor:
- Sends an enquiry
- Requests a school pilot
- Subscribes to communications
- Downloads gated material
- Contacts nilo
we may collect information reasonably necessary to respond to that request.
Public enquiry forms should not be used to submit confidential student information.
32. Communications
Schools, parents, teachers and adult users may receive:
- Account communications
- Security alerts
- Service notifications
- Pilot communications
- Support responses
- Important legal notices
Marketing communications to adults should provide appropriate choice mechanisms where required.
nilo does not intend to send behavioural marketing communications directly to children.
33. Research and Aggregate Insights
nilo may use appropriately anonymised or aggregated information to:
- Evaluate learning effectiveness
- Improve curriculum
- Improve educational experiences
- Understand platform adoption
- Produce school-level impact reporting
- Conduct internal research
Public reports should not identify individual children unless separate lawful permission has been obtained.
Anonymised information should not intentionally be re-identified.
34. Changes to This Policy
We may update this Privacy Policy where necessary because of:
- Changes in law
- Changes to the DPDP implementation framework
- New Services
- New school features
- Technology changes
- Security improvements
- Changes to our data practices
Material changes will be communicated through an appropriate method.
Where a change requires fresh consent under applicable law, we will seek that consent before relying on it for the new processing.
The latest version will display its effective date.
35. Legal Framework
Depending on the activity and effective legal provisions at the relevant time, nilo's privacy and security practices may be subject to Indian laws and regulatory requirements including:
- The Information Technology Act, 2000 and applicable rules
- The Digital Personal Data Protection Act, 2023 as its provisions come into force
- The Digital Personal Data Protection Rules, 2025 as their provisions come into force
- Applicable CERT-In directions
- The Consumer Protection Act, 2019, where applicable
- Applicable child-protection and school-safety requirements
- The Protection of Children from Sexual Offences Act, 2012, where relevant
- Other applicable Central, State or school-regulatory requirements
This Policy will be interpreted subject to the law actually in force at the relevant time.
36. Contact and Grievance Resolution
For privacy questions, consent requests, correction requests, deletion requests, grievances or concerns about student information, contact:
Privacy Contact / Grievance Officer
Sashidharan K
Nilofin Technologies Pvt Ltd
Operating brand: nilo
Email: hello@nilofin.com
Suggested subject: Privacy Request
Please provide only the information reasonably necessary for us to identify and address the request.
Do not send passwords, OTPs, PINs, card information or unnecessary government identity documents by email.
We may need to verify the identity or authority of a person making a privacy request before disclosing, modifying or deleting personal data.