Security & data protection
A school’s data, treated like a school’s data.
Giiki holds children’s records, staff identities and money. The protections below are product mechanisms, not policy promises — each one is enforced by the software itself.
PAN, Aadhaar and salary bands show masked by default. Revealing one is an act on the record — logged against the person who revealed it.
Per-day attendance detail is auto-summarised after 3 years. We keep what a school needs, not everything we could.
Recruitment-call analysis runs on-premise — transcripts and sentiment are computed inside the school's own environment, DPDP-friendly by design.
A user cannot see or touch another school's data at all, and campus-scoped roles cannot reach another campus's records. Enforced on the server, on every query.
The menu hides what a person cannot open — and the server refuses it anyway. Roles are granted per screen, per campus.
When someone leaves, the clearance workflow deactivates every access they held — ordered, so nothing is missed between HR and IT.
Gate-vs-classroom discrepancies land in a log that only safeguarding roles can open.
Settings changes route through Approvals like everything else. The audit trail starts before the change, not after.
Backups are part of the hosting line on the published price ledger — not an add-on.
What we’ll say in writing. Data-processing terms, sub-processor lists and breach-notification commitments are part of every engagement contract. Ask for them on the demo call — the answer is a document, not a conversation.