Blog · Licence guides
Data protection and privacy roles
Updated 5 September 2026 · Based on our Software Licence & Services model
You decide what student data to collect and why. LMS White processes data on your instructions for implementation and support — including DPDP considerations in India.
What this means for you
You determine what student/customer information is collected, why, who may access it and how long it is kept. Ordinarily you act as the primary data controller / data fiduciary for Client Data.
When LMS White accesses Client Data only on your documented instructions for implementation, troubleshooting or support, we act in the service-provider/processor role required by applicable law. You remain responsible for notices, consents, parental permissions where required, minimisation and user-rights handling for your students and staff.
We use reasonable confidentiality controls for data accessed during authorised work and do not use Client Data for unrelated commercial purposes. Both parties cooperate with applicable law, including India’s Digital Personal Data Protection Act, 2023 and its rules, to the extent they apply.
Why the institution leads on privacy
You choose the courses, enrolment forms, marketing lists and retention policies. A platform vendor cannot lawfully “own” those decisions for every academy. Clear controller/processor roles match how modern privacy statutes allocate duties.
Examples
- Your admissions form collects a parent phone number → you provide the privacy notice and lawful basis.
- During a bugfix you grant temporary Firebase access → we use that access only for the ticket, not for marketing.
What LMS White does: technical processing under your instructions during authorised work.
What you do: institutional privacy compliance for your learners and staff.