Data Policy
Effective Date: July 7, 2026
This Data Policy outlines the principles and practices governing the management, processing, security, and compliance of data within the ONLIVE School Transport & Parent Platform. This policy complements our Privacy Policy and Terms & Conditions.
1. Data Ownership
1.1 Customer Data: All data uploaded, submitted, or generated by Schools, Parents, Drivers, and Bus Attendants remains the property of the respective School or individual user. ONLIVE acts as a data processor on their behalf.
1.2 ONLIVE Data: Data generated by ONLIVE for operating, maintaining, and improving the Service (e.g. aggregated and anonymized usage statistics, system logs, metadata) is owned by ONLIVE and does not contain personally identifiable information.
2. Data Processing
- Purpose of Processing: ONLIVE processes Customer Data solely to provide the Service, as instructed by Schools or individual users.
- Lawful Basis: Processing is conducted on a lawful basis — user consent, contractual necessity, legal obligation, or legitimate interests.
- Data Minimization: We collect and process only the data necessary for the intended purpose.
- Data Accuracy: We rely on users to provide accurate, up-to-date data and to correct any inaccuracies.
3. Data Security
ONLIVE employs comprehensive security measures to protect Customer Data from unauthorized access, disclosure, alteration, and destruction:
- Technical Safeguards: Encryption (in transit and at rest), firewalls, intrusion detection systems, and secure coding practices.
- Administrative Safeguards: Access controls, employee background checks, regular security training, and incident response plans.
- Physical Safeguards: Secure data centers with restricted access, surveillance, and environmental controls.
4. Data Backup and Recovery
ONLIVE performs regular backups of Customer Data to prevent loss, maintains a disaster recovery plan for continuity and rapid restoration, and designs backup and recovery processes to maintain data integrity and availability.
5. Data Retention and Deletion
5.1 Retention Periods: Customer Data is retained only as long as necessary to fulfill its purposes, provide the Service, and comply with legal obligations. Specific periods are detailed in our Privacy Policy.
5.2 Secure Deletion: Upon expiration of the retention period or upon a valid request, Customer Data will be securely deleted or anonymized in a manner that prevents its reconstruction.
6. Confidentiality
All ONLIVE employees and contractors are bound by strict confidentiality agreements and trained on data protection principles. Any third-party service providers are contractually obligated to maintain the confidentiality and security of Customer Data.
7. Compliance
ONLIVE is committed to complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) for the EU, the California Consumer Privacy Act (CCPA) for California, the Digital Personal Data Protection Act (DPDP Act), 2023 for India, and other relevant local and international laws.
8. Data Breach Notification
In the event of a data breach affecting Customer Data, ONLIVE will notify affected Schools and relevant regulatory authorities in accordance with applicable laws and our incident response plan.
9. Changes to This Data Policy
We may update this Data Policy from time to time. Your continued use of the Service after such modifications constitutes your acknowledgment of the modified Data Policy.
10. Contact Us
If you have any questions about this Data Policy or our data practices, please contact us.