Legal

Privacy policy

This policy explains what personal data we collect through this website, what we do with student and parent data inside our software, and what rights you have.

Last updated: 20 July 2026

1. Who we are

EnrollUp is a division of Kwickprep Education Services LLP, which also trades as Kwickprep. EnrollUp is not a separate company. In this policy, "we", "us" and "EnrollUp" mean Kwickprep Education Services LLP.

Our registered office is D 1009, Titanium City Centre, Near Sachin Towers, 100 Ft. Ring Road, Anandnagar, Satellite, Ahmedabad, Gujarat, India – 380015. You can reach us at grow@enrollup.in.

We work to the framework of India's Digital Personal Data Protection Act, 2023 (the DPDP Act). Under that Act, the party who decides why and how personal data is processed is the Data Fiduciary. A party who processes data on that fiduciary's instructions is a Data Processor.

2. The two hats we wear

This is the most important thing on this page, so we state it plainly.

We are the Data Fiduciary for two things

  • Enquiries you send us directly through this website, by email or by phone.
  • Account data for the administrators and staff of an institute that subscribes to our software: the login and contact details we need to set up and support the account, and our own billing records.

For those two categories we decide the purposes and means of processing, and this policy governs them.

We are the Data Processor for an institute's student and parent data

When an institute subscribes to the EnrollUp LMS or SPRM, the institute is the Data Fiduciary for the data of its students, parents and staff. The institute decides what is collected and why. We act only as its Data Processor, on its instructions, to host and operate the platform.

A student or a parent gives consent to their institute. They do not give consent to us, and we do not ask them for it. The institute's own privacy notice should disclose EnrollUp as one of its processors. If you are a student or a parent with a question about your data, contact your institute. It controls the record. We will help the institute answer you, but we cannot act on such a request without its instruction.

3. What we collect

From this website

  • Your name, institute name, email address and mobile number, when you submit an enquiry.
  • The topic you select and any message you write.
  • Basic technical data such as IP address, browser type, pages viewed and referring page, through website analytics. This is collected only after you accept analytics on the cookie banner.

From institute administrators

  • Names, work email addresses, mobile numbers and role, for the people who administer the account.
  • Login and activity records needed for access control and support.
  • Billing and invoicing records for the subscription.

As a processor, inside an institute's platform

  • Student records: name, contact details, batch and academic year, attendance, homework, test scores and results.
  • Parent or guardian records: name, mobile number, email address and messages exchanged with the institute.
  • Fee and invoicing records, and payment status.
  • Enquiry and follow-up records for prospective students.
  • Staff login and activity records needed for access control and audit.

We do not sell personal data. We do not use student or parent data from an institute's tenancy to market to those students or parents.

4. The free Toolkit

Our free Toolkit runs entirely in your own browser. When you enter an institute name, upload a logo, paste a list of students or build a document in one of the tools, that information stays on your device. It is not transmitted to us, it is not stored on our servers, and we never see it.

The only exception is the site-wide website analytics described above, which counts page visits. It records that a Toolkit page was viewed. It does not receive anything you type into a tool, and it runs only after you have given consent. If you save your work in a tool, it is saved in your own browser's local storage, which you can clear at any time.

5. Cookies

Our cookie policy lists every cookie and every piece of browser storage this site uses, what each one does, how long it lasts, and how to change or withdraw your consent at any time.

6. Lawful basis and consent

Under the DPDP Act we process personal data on consent, or for a legitimate use permitted by the Act.

  • Consent. When you submit an enquiry, you are asking us to get in touch, and we use your details for that. Website analytics runs only where you have accepted it. You may withdraw consent at any time, and withdrawing it is as easy as giving it.
  • Performance of our contract and legitimate use. Where an institute subscribes, we process administrator account data to deliver, support and bill for the service.
  • Legal obligation. We keep the accounting, tax and statutory records that Indian law requires us to keep.
  • On instruction. Student and parent data is processed on the institute's documented instructions, and the lawful basis for it is the institute's to establish.

We send marketing messages only where you have asked to hear from us or have an existing business relationship with us. Every marketing message carries a way to stop them.

7. Children's and students' data

Much of the data held on the platform belongs to students who are under 18.

The DPDP Act requires verifiable consent from a parent or lawful guardian before a child's personal data is processed. It also prohibits behavioural tracking of children and advertising targeted at them.

We do not run advertising, behavioural profiling or tracking of students at all, anywhere in our products.

Obtaining and recording that guardian consent is the institute's responsibility, because the institute is the Data Fiduciary and holds the relationship with the family. Our platform provides the mechanism to capture and record it. It does not transfer the responsibility to us, and using our platform does not by itself make an institute compliant with the DPDP Act. The platform is built to help an institute meet its obligations. Meeting them remains the institute's own responsibility.

8. Who we share data with

We use a small number of service providers, called sub-processors, who process data so that we can deliver the service. We share only what each one needs, and only for that purpose.

ProviderWhat it is used forWhere processed
MongoDB AtlasPlatform databaseBeing consolidated to an India region
Amazon Web Services (S3)File and document storageMumbai, India
Amazon Web Services (Bedrock)AI features, where enabledUnited States
OpenAIAI features, where enabledUnited States
Meta (WhatsApp Cloud API)WhatsApp messaging, where the institute enables itGlobal
RazorpayPayment processing. Card details are handled by Razorpay and never reach usIndia
ZeptomailTransactional emailIndia
Google (APIs)Contact synchronisation, where the institute enables itGlobal
Google AnalyticsWebsite analytics, only with your consentUnited States

AI features are optional and are switched on by the institute, not by us. Where an institute turns them on, the content sent to the AI provider is processed outside India.

We may also disclose data to professional advisers, or to an authority, where we are legally required to do so or need to establish or defend a legal claim.

9. Cross-border transfers

Some of the processing described above happens outside India. Our file storage sits in Mumbai and our database is being consolidated to an India region, but AI features, WhatsApp messaging, Google contact synchronisation and website analytics involve providers who process data outside India.

We tell you this openly because it matters. We do not claim that all data stays in India. Where data goes abroad, we rely on the transfer rules permitted under the DPDP Act and on the terms offered by each provider. An institute that does not want any processing outside India can leave the optional AI, WhatsApp and contact synchronisation features switched off.

10. How we protect data

We describe our security in terms of what is organisationally true today, rather than in terms that sound impressive.

  • Access to production systems is limited to named people who need it for their work.
  • Credentials for production systems are restricted and are not shared beyond that group.
  • Each institute's data sits in its own tenancy, so one institute cannot read another institute's data.
  • Access inside the platform is role based, so staff see only what their role requires.
  • Traffic between your browser and the platform runs over HTTPS.
  • We run an ongoing programme of security improvement, and we review these controls as the product grows.

No system is perfectly secure. If a breach affects data we hold, we will tell the affected institute and the relevant authority as the law requires, and explain what happened and what to do.

11. How long we keep data

We do not publish a fixed schedule of days and years, because we will not state as current practice something we do not yet enforce automatically. What we can tell you honestly is the principle we work to.

  • Data is kept while the account is active and while it is needed for the purpose it was given for.
  • Some records must be kept for longer because the law requires it. Accounting and tax records, for example, must be retained for several years under Indian law.
  • An institute's own agreement with us sets out the specific retention and deletion terms that apply to its data, including what happens on exit.
  • When data is no longer needed and no law requires us to hold it, we delete it or irreversibly anonymise it.

If you want to know how long we hold a specific record about you, ask us and we will tell you.

12. Your rights

Subject to the DPDP Act, you may ask us to:

  • Confirm what personal data of yours we hold and how it is being processed.
  • Correct data that is wrong, incomplete or out of date.
  • Erase data we no longer need, or that you gave us on a consent you now withdraw.
  • Withdraw consent for analytics or marketing at any time.
  • Nominate another person to exercise these rights on your behalf if you are unable to.

To exercise a right, email grow@enrollup.in with enough detail for us to identify your record. We will respond within a reasonable period, and we will tell you if we need to verify your identity first.

If your data sits inside an institute's tenancy, we are the processor and not the fiduciary. In that case we will pass your request to the institute, tell you that we have done so, and support the institute in answering it.

13. Grievance redressal

The Digital Personal Data Protection Act, 2023 requires us to give you a named person to complain to. Ours is:

  • Grievance OfficerMihir Joshi
  • Emailgrow@enrollup.in
  • PostKwickprep Education Services LLP, D 1009, Titanium City Centre, Near Sachin Towers, 100 Ft. Ring Road, Anandnagar, Satellite, Ahmedabad, Gujarat 380015, India

If you are unhappy with how we have handled your personal data or your request, write to him with "Grievance" in the subject line. We will acknowledge your complaint and work to resolve it, and we will tell you what we have done.

If your data sits inside an institute's tenancy, that institute is the fiduciary and has its own grievance contact, which appears in the notice it gave you. You may still write to us and we will pass it on rather than turn you away.

If you are still not satisfied, you may complain to the Data Protection Board of India.

14. Changes to this policy

We may update this policy as the law or our services change. The "last updated" date at the top always reflects the current version. Where a change materially affects a subscribing institute, we will notify it directly.

15. Contact us

  • Emailgrow@enrollup.in
  • Mobile+91 96015 75621
  • Office+91 79410 06697
  • HoursMonday to Saturday, 9 AM – 7 PM IST. We reply to email within one working day.
  • Post
    Kwickprep Education Services LLP
    D 1009, Titanium City Centre, Near Sachin Towers,
    100 Ft. Ring Road, Anandnagar, Satellite,
    Ahmedabad, Gujarat, India – 380015