Last updated 21 August 2026
Your school is the data controller for the student, guardian, and staff records it enters — the same way it would be if that information sat in a paper register in the school office. Groflex is the data processor: we host the infrastructure and provide the software your school uses to manage that data, but we do not use it for our own purposes.
From the school (account holder): owner and staff name, email, phone, and login credentials.
Entered by the school, about students and guardians: name, father's name, class, roll number, date of birth, guardian name and phone number, address, admission details, fee and payment records, attendance, exam results, and homework. This is entered and controlled entirely by the school, not collected by Groflex directly.
We do not collect: payment card numbers, bank account details, or any online payment information — the Service has no payment gateway. School subscription payments are settled offline, directly with Groflex.
Solely to operate the Service: displaying dashboards, generating fee challans and receipts, tracking attendance and results, sending fee and attendance notifications, and the platform-level work of running your school's subscription (activation, renewal, and support).
Data is stored on Google Cloud infrastructure via Firebase (Google's cloud platform), the same infrastructure used by a very large share of the internet's applications. Access is restricted by tenant — one school's data is walled off from every other school's by the platform's access rules, enforced both in the application and at the database level.
A school's own records are visible only to that school's owner and the staff the owner grants access to, plus Groflex staff strictly for support and platform operation (for example, diagnosing a reported problem). Groflex's own super admin access does not extend to browsing a school's student data as a matter of course — see our architecture notes if you'd like the technical detail.
If a school turns on the parent portal, a guardian can see their own child's fees, attendance, results, and homework — nothing about any other student.
Fee reminders, attendance alerts, payment receipts, and announcements are delivered as push notifications to a parent's Groflex app and stored in an in-app inbox, so nothing is lost if the push itself doesn't arrive. Groflex operates this notification system directly — no message content is shared with a third-party messaging provider.
Records are kept for as long as the school's account is active, and after a subscription lapses, are retained rather than deleted — access is locked, not the data itself. A school can request full export or deletion of its data at any time by contacting Groflex.
Most records in this system are about students, many of whom are minors. That data is entered and controlled by the school, under the school's own relationship with its students' families — Groflex's role is providing the platform, not independently collecting or using children's data for its own purposes (no advertising, no profiling, no sale of data, ever).
A school can access, correct, export, or delete the data it holds directly within the Service. A parent or guardian with a question about their own child's data should contact their school directly, since the school controls that record; Groflex will support the school in fulfilling such a request.
We may update this policy as the product changes. Material changes will be communicated directly where practical.
Questions about this policy or a data request: groflex.co@gmail.com.