Privacy Policy — Alvara Workspace

Privacy Policy

Alvara Workspace · Last updated: 16 August 2026

This policy is for staff, administrators and superadmins who use the Alvara workspace at an institute. If you are a student, the policy that applies to you is at alvara.education/privacy/student.

Alvara Education(“Alvara”, “we”) provides the Alvara platform to your institute. Contact: support@alvara.education · Privacy and data requests: grievance@alvara.education

1. You Wear Two Hats Here

As a user of Alvara, you have your own personal data in the platform — your account, your login records, your messages, your activity. Alvara is responsible for that data, and this notice tells you how we handle it.

As a member of your institute's staff, you handle students' personal data. Your institute is responsible for that data, and Alvara processes it on your institute's instructions. What your institute has agreed with us is set out in the agreement between us; below covers what that means for you day to day.

2. What We Hold About You

Your account

Your name, designation, your Alvara login identifier, your profile picture if you upload one, and the institute, and the parts of it, you have been given access to.

Your permissions

Which capabilities and which scope your superadmin has granted you, and a record of every change to them, including who made it and when.

Your login and security records

When you signed in, from which IP address and device, your browser details, the outcome of your login and two-factor verification attempts, and any lockouts. These are kept as a security and audit trail.

Your login codes

A one-time code sent for two-factor verification, stored only as a hash and valid for a short period.

Your notification subscription

If you allow browser notifications, the subscription your browser gives us so we can deliver them.

Your messages

The direct and group messages you send other staff inside the workspace, their attachments, and a snapshot of any message you edit.

Your work in the platform

The records you create or change about students, and a record of those changes; the spreadsheets you create or are given access to, and a log of actions on them; and your interface preferences.

Your queries to the assistant

See section 6.

3. Why We Hold It

To give you a working account and the right level of access · to keep the platform and your institute's data secure, and to be able to investigate if something goes wrong · to let you communicate with colleagues inside the platform · to maintain an audit trail your institute can rely on · to support you when you ask us for help · and to meet our legal obligations.

We do not use your data for advertising, we do not sell it, and we do not use it to build profiles about you.

4. Who Can See It

  • Your superadmin and staff granted the relevant permission can see your account, your designation and your permissions, and can change them.
  • Your institutecan see the audit trail of what you did in the platform. That is the point of an audit trail: your institute is accountable for its students' records, and it needs to know who changed what.
  • Colleagues you message see those messages. Group members see group messages.
  • Alvara can access your data where necessary to run the platform, to support you, to investigate a security incident, or to meet a legal obligation. Access to the live database is limited to the proprietor. There is no team access at present.
  • Students never see your login records, your messages to colleagues, or your queries to the assistant.
  • Authorities only against a lawful order, and we keep a record of every disclosure.

Note on profile pictures. Staff profile pictures are stored in a publicly readable location so they load quickly across the workspace. The address is not guessable, but anyone who has it can open the image without signing in.

5. Who We Share It With

ProviderWhat they doWhat they receiveWhere
SupabaseDatabase and file storageYour account, records and uploadsIndia (Mumbai)
Google (Firebase)Notification delivery and error diagnosticsNotification subscription; diagnosticsGlobal Google services
Google (Gemini)The Alvara assistant — see The text of your query and the data needed to answer itGoogle's services, which may be outside India
MSG91Sends verification codes by SMSThe mobile number on your account and the codeIndia

Nobody else. Each acts on our instructions and is bound by contract.

6. The Alvara Assistant

The workspace includes an AI assistant. It is built on Google's Gemini model — Alvara does not train or operate a model of its own.

What this means in practice

  • When you ask the assistant something, your query, and the data needed to answer it, are sent to Google. That may include information about your institute's students.
  • Your queries are logged. Every interaction is recorded as a permanent-style audit trail so that your institute and we can see what was asked and what was returned. Treat the assistant as a monitored tool, not a private one.
  • We use it only to answer what you ask. We do not use it to analyse your work or evaluate you.
  • Do not paste anything into it that is not needed to answer your question — and in particular do not paste students' identity documents, bank details or medical notes.

7. How Long We Keep It

DataHow long
Your account and permissionsWhile you have access, and for as long as your institute's records require afterwards
Login and security records90 days
Verification codesMinutes
Permission and lifecycle audit recordsWhile your institute's record of you exists
Your messages to colleaguesDirect messages are permanent and cannot be deleted, by design. Group conversations last as long as the group.
Spreadsheet action logs2 years
Assistant queries1 year
Notification subscriptionRemoved after a period of inactivity or repeated delivery failures

When our agreement with your institute ends, your data is returned or deleted along with your institute's, within 30 daysof the institute's written election.

8. Your Responsibilities with Students' Data

Because your institute is responsible for its students' data and we process it on its instructions:

  • Only look at what you need to. Your access is scoped, but scope is not permission to browse.
  • Do not export, copy or forward students' data outside the platform except where your institute has authorised it.
  • Enter only what is needed. Where a field asks for academic remarks, keep it to academic remarks. Do not record identity numbers, bank details, medical notes or caste in free-text fields.
  • Confirm consent before you admit a student. The confirmation on the admission screen is your institute's warranty that consent — including a parent's or guardian's where the student is under 18 — has been obtained and the signed form retained. Ticking it without that form leaves your institute exposed.
  • Your actions are logged, and your institute can see the log.
  • Tell us at once if you think an account has been misused or data has been exposed. Speed matters more than certainty.

9. How We Protect Your Data

All traffic encrypted in transit · access limited by capability and scope · two-factor verification required for sensitive actions · passwords and verification codes stored only as hashes · rate limiting on authentication · security logs retained for 90 days · records stored in India · multi-factor authentication on administrative access · regular backups.

No method of transmitting or storing information is completely secure. We work to protect your data but cannot guarantee absolute security.

10. Your Rights

You can ask to see the personal data we hold about you, to have it corrected, and to have it erased where we are not required to keep it. Some things we cannot erase on request, because they are your institute's audit record of who did what — we will tell you where that applies and why.

Write to grievance@alvara.education. We aim to resolve requests within 30 days.

Grievance Officer

Alvara Education · Pithampur, Indore, Madhya Pradesh 453001, India

grievance@alvara.education

If we do not resolve your complaint, you can approach the Data Protection Board of India.

Requests about students' data go to your institute, which is responsible for them. We will help your institute answer.

11. If Something Goes Wrong

If a security incident affects personal data, we will inform your institute without undue delay and within 48 hours of becoming aware of it, and will notify affected individuals and the Data Protection Board of India where the law requires.

12. Changes

We may update this notice. The date and version above change when we do, and we will tell your institute if the change is significant.