Natijaa Logo
Natijaa
Install App Home
Privacy Policy

Your Privacy Matters to Us

Last updated: September 2026  ·  Applies to: Natija School ERP Web Platform & Android App

This Privacy Policy explains how Natija collects, uses, and protects personal data of students, parents, teachers, and school administrators using the Natija School ERP system. By using Natija, you agree to this policy.

1 Who We Are

Natija is a cloud-based School ERP (Enterprise Resource Planning) software built specifically for Nepali schools. It is operated and maintained by the Natija development team. Natija provides school administration tools, student academic tracking, attendance management, result publication, and parent communication features.

Each school using Natija operates in a dedicated, isolated multi-tenant environment, meaning your school's data is never shared with or accessible by other schools on the platform.

2 What Data We Collect

We collect only the data necessary to provide school management services:

Student & Academic Data:

  • Full name, date of birth (BS and/or AD), gender, registration number, roll number
  • Student photograph (optional, uploaded by school admin)
  • Class, section, and academic session details
  • Attendance records (daily present / absent / leave status)
  • Terminal exam marks, grades, GPA, and result data
  • Continuous Assessment System (CAS) scores
  • Homework submissions (text and photo attachments)

Staff & Administrator Data:

  • Teacher full name, email address, and phone number
  • Assigned classes and subjects
  • Login credentials (passwords are stored as one-way cryptographic hashes — never in plain text)

School Data:

  • School name, address, phone number, and logo
  • Academic session configuration and exam settings

Usage Data (Automatically Collected):

  • IP address and browser/device type (for security and error logging)
  • App version and device model (Android app)
  • FCM (Firebase Cloud Messaging) push notification tokens

3 How We Use Your Data

Data is used exclusively for the following purposes:

  • Providing the school ERP services (attendance, marks entry, result generation, report cards)
  • Sending automated absence alerts to parents via FCM push notifications and SMS
  • Generating official NEB-compliant PDF report cards, grade ledgers, admit cards, and student ID cards
  • Enabling parents and students to check results through the public result portal
  • Broadcasting school announcements, notices, and event updates
  • Syncing student data from Nepal Government IEMIS Excel imports
  • Ensuring system security, preventing unauthorized access, and debugging application errors

We do not use your data for advertising, profiling, or sell it to any third party.

4 Third-Party Services We Use

Natija uses the following third-party services to deliver functionality:

  • Firebase Cloud Messaging (FCM) — Google LLC: Used to send real-time push notifications to the Android app for attendance alerts, announcements, and result notifications. FCM receives device tokens and notification payloads only.
  • SMS Gateway Provider: Used to send absence alert SMS messages to parent phone numbers registered in the system.
  • Cloud Hosting Provider: The application and database are hosted on a managed server. Data is stored within the hosting environment and subject to the hosting provider's data security practices.

These services are used solely to operate Natija and are bound by their own privacy policies. No personal data is shared with third parties beyond what is required for these services.

5 Data Storage & Security

  • All data is stored on secure cloud servers with encrypted connections (HTTPS/TLS).
  • Passwords are stored using industry-standard one-way cryptographic hashing (Django PBKDF2).
  • Authentication uses short-lived JWT (JSON Web Tokens) with secure refresh cycles.
  • Multi-tenant isolation ensures that each school's data is strictly scoped by a school_id and cannot be accessed by users of other schools.
  • Role-based access control (RBAC) ensures teachers can only access their own assigned classes.
  • Rate limiting and brute-force protection are applied to all login and public result lookup endpoints.
  • Daily automated backups are maintained to prevent data loss.
Parent and student login for the mobile app uses a zero-password system — authentication is done via Student Registration Number and Date of Birth (BS/AD). No passwords are stored for parents.

6 Data Retention

Student academic data (marks, results, attendance) is retained for the duration of your school's active subscription with Natija and for a reasonable archival period after. Schools may request data export or deletion by contacting us directly.

Server logs (IP addresses, request logs) are retained for a maximum of 90 days for security purposes and then automatically deleted.

7 Children's Privacy

Natija processes data of students who may be under 18 years of age. This data is provided by and under the authority of the school institution, which acts as the data controller. Parents and guardians may request access to or deletion of their child's data by contacting their school administrator.

Natija does not knowingly collect data from children directly — all student data is entered and managed by school administrators and teachers.

8 Your Rights

As a user of Natija (or as a parent of a student), you have the right to:

  • Access: Request a copy of the data we hold about you or your child.
  • Correction: Request correction of inaccurate data (typically done through your school administrator).
  • Deletion: Request deletion of your data, subject to the school's retention requirements.
  • Objection: Object to specific data processing activities.

For most requests, please contact your school's administrator first. For direct requests to Natija, use the contact information below.

9 Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to school administrators. Continued use of Natija after changes are posted constitutes acceptance of the updated policy.

10 Contact Us

If you have any questions, concerns, or data requests regarding this Privacy Policy, please contact us:

Natija Privacy Contact

For privacy inquiries, data requests, or concerns:
Submit a request via our Contact Form  ·  developer@natijaa.com

Back to Home Terms of Service
© 2026 Natijaa. All rights reserved.