Privacy policy
Last updated 14 August 2026
KalaSangama is software that arts institutions use to run their own operations. This policy explains what we collect from the people who sign in, and what we hold on their behalf.
Two kinds of data
Account data is about the person signing in: their name, email address and password. We are the controller of this data.
Institute data is what an institution records in the product about its own students, classes, attendance and fees. The institution controls that data; we process it on their instructions and do not use it for any purpose of our own.
What we collect
- Name and email address, so you can sign in and we can contact you about your account.
- A one-way hash of your password. We never store or transmit the password itself.
- Institute records you enter: student names, guardian contact details, dates of birth, attendance, invoices and payments.
- Basic technical logs (IP address and timestamps), kept to detect abuse and diagnose faults.
We do not collect location, contacts, photos, device identifiers for advertising, or any biometric data. The app contains no advertising and no third-party analytics or tracking SDKs.
Children's data
Institutions record details of students who are often minors. That data is entered by the institution, not by the child, and is visible only to that institution's own staff. We do not knowingly allow children to create accounts, and the app is not directed at children.
How it is used
To operate the service: authenticate you, show your institute's records, send transactional email such as password resets and admission confirmations, and take payment for the subscription. We do not sell data, and we do not share it with advertisers.
Who we share it with
- Our hosting and database providers, who store the data on our behalf.
- Our email provider, to deliver transactional messages.
- Our payment provider, to process subscription payments. We never see full card details.
- Law enforcement, only where we are legally compelled.
Security
All traffic is encrypted in transit with HTTPS. Passwords are hashed with bcrypt. Every record is scoped to one institution, and access is re-verified on every request, so a change to someone's access takes effect immediately rather than when their session happens to expire.
Retention and deletion
Institute data is retained while the institution's subscription is active, and for 90 days after it lapses so nothing is lost during a late renewal.
You can delete your own account at any time, from the app or at /delete-account. Deleting your account removes your name, email and password. Records you created on behalf of an institution remain with that institution, with your name detached from them.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to privacy@kalasangama.com and we will respond within 30 days. If you are a student or guardian, contact your institution first. They hold that record and can act on it faster than we can.
Changes
We will post any change on this page and update the date above. Material changes are emailed to account holders before they take effect.