FeeDesk · Codeworth
Data processing agreement
Last updated 30 September 2026
In short
When your institute uses FeeDesk, you decide what personal data is collected about your students, their parents and your staff; Codeworth processes it only to run FeeDesk for you. This agreement sets out how, as the Digital Personal Data Protection Act, 2023 requires. It applies to every institute on FeeDesk. To have a signed copy, print this page, fill in the details at the end, and send it to codeworth.official@gmail.com; we sign and return it.
1Parties and roles
The institute using FeeDesk (the “Institute”) is the Data Fiduciary. Codeworth, a business run by Swayam Bhalotia and Keshav Mishra as partners (not yet registered), West Bengal, India (“Codeworth”) is the Data Processor. This agreement forms part of the terms of service; where they differ on personal data, this agreement prevails.
2What is processed, and why
- People: the Institute’s students (most of them children), their parents and guardians, and the Institute’s staff.
- Data: names, dates of birth, gender, photos and documents the Institute uploads, phone numbers, consent records, batches, fees, discounts, payments, receipts, attendance, messages and replies, staff roles and activity.
- Purpose: only to provide FeeDesk to the Institute (managing admissions, fees, receipts, reminders, attendance and reports) for as long as the Institute uses it.
3Codeworth’s commitments
- Process the data only on the Institute’s documented instructions, which are its use and settings of FeeDesk, and never for any other purpose. Codeworth does not sell the data, use it for advertising, or combine it with other data.
- Never track, behaviourally monitor or target advertising at children.
- Keep the data confidential; only Codeworth’s partners, who are bound by confidentiality, can access it, and only as needed to run and support FeeDesk.
- Protect the data with at least the measures in Annex A.
- Help the Institute answer requests from students, parents and staff (access, correction, erasure, withdrawing consent, nomination) and grievances; FeeDesk lets the Institute correct records, export a student’s data, record withdrawn consent and anonymise a student who has left.
4Personal data breaches
If Codeworth becomes aware of a breach affecting the Institute’s data, it will tell the Institute without undue delay and within 24 hours, with what is known (what happened, what data and people are affected, what is being done), and keep the Institute informed. This lets the Institute inform the Data Protection Board of India and the people affected within the time the DPDP Rules require. Codeworth will take reasonable steps to contain the breach and prevent it recurring.
5Other companies (sub-processors)
The Institute agrees to the sub-processors in Annex B. Codeworth will email the Owner at least 15 days before adding or replacing one; if the Institute objects, it may close its account before the change. Codeworth requires each sub-processor to protect the data at least as well as this agreement, and remains responsible for them. Services the Institute connects with its own accounts (WhatsApp, SMS, Razorpay) are the Institute’s own processors, not Codeworth’s.
6Where the data is
FeeDesk’s servers are in Germany or Finland; encrypted backups are stored with Cloudflare. Transfers outside India are permitted by the DPDP Act except to countries the Government of India restricts.
7Retention, return and deletion
- Message contents are removed after 180 days (who, when, template and delivery status remain); report files and exports after 24 hours.
- The Owner can download all the Institute’s data at any time, including when the Institute is read-only.
- When the Institute closes its account (or the service ends), all its data is deleted 30 days later, after the Institute has had the chance to export it. Encrypted backups containing it expire within 6 months and are restored only to recover the whole service from a failure.
8Information and audits
Codeworth will give the Institute the information reasonably needed to show it meets this agreement, and answer reasonable security questionnaires. Once a year, with 30 days’ notice, the Institute may review Codeworth’s compliance at its own cost, in a way that does not expose other institutes’ data.
9Contact
Codeworth’s contact for data protection: Swayam Bhalotia, codeworth.official@gmail.com.
AAnnex A: security measures
- Each institute’s records are separated by the database itself (row-level security on every table), tested against every route of the application.
- All connections use HTTPS (TLS), with HSTS; the website and application send strict security headers.
- Passwords are stored only as salted scrypt hashes and checked against known breaches when set; sign-in attempts are rate-limited, with increasing delays.
- Owners must use two-factor sign-in; the institute can require it for admins and accountants.
- Staff see only what their role and branches allow; teachers never see parents’ phone numbers; sensitive actions need the password again.
- Payment and messaging credentials are encrypted (AES-256-GCM).
- Every change to records is written to an audit log that cannot be edited or deleted from the application.
- Application logs redact personal details such as names, emails and phone numbers.
- Nightly backups are encrypted on the server before they leave it, with a key held only by Codeworth, and restore-tested.
- Servers accept SSH keys only, run a firewall and install security updates automatically; only Codeworth’s partners have access.
- Report files and full exports are deleted 24 hours after they are made; message contents after 180 days.
BAnnex B: sub-processors
- Hetzner Online GmbH (Germany / Finland): Servers that run FeeDesk and hold its database and uploaded files.
- Cloudflare, Inc. (Global network): Stores the nightly backups (encrypted before they leave our server, with a key only Codeworth holds); hosts this website and counts its visits without cookies.
- Resend, Inc. (United States): Sends FeeDesk’s emails: sign-in and invitation codes, security notices, invoices.
- Have I Been Pwned (Troy Hunt) (Global): Checks new passwords against known data breaches. Only the first 5 characters of a hash of the password are sent; never the password or who it belongs to.
Connected by the Institute with its own accounts (the Institute’s processors):
- Meta Platforms (WhatsApp Business Platform): Fee reminders, receipts and absence alerts on WhatsApp.
- MSG91 (Walkover Web Solutions Pvt Ltd): SMS reminders and alerts.
- Razorpay Software Pvt Ltd: Online fee payments, paid into the institute’s own account.
For the Institute
Institute name
Address
Name and role
Signature
Date
For Codeworth
Name
Address
Signature
Date