Legal
Privacy Policy
Last updated: June 2026
LyraDiary is operated by Lyra Tech Private Limited. This policy explains how we collect, process, and protect personal data across all users of the platform.
1.Company Identity & Data Controller
LyraDiary is a Software-as-a-Service (SaaS) platform developed and operated by Lyra Tech Private Limited, a company incorporated under the laws of India (“Lyra Tech”, “we”, “us”, or “our”).
For the purposes of applicable data protection legislation:
- Lyra Tech Private Limited is the data processor — we operate the platform and process personal data on behalf of schools.
- Each music school that subscribes to LyraDiary is the data controller for the personal data of their students, parents, and teachers. Schools are responsible for their own compliance obligations towards their users.
2.What Data We Collect
We collect the minimum data necessary to deliver the platform’s functionality. Data is organised by category:
School Information
- School name, trading name, and registration details provided at sign-up
- Business contact information (email, phone number, billing address)
- Location details for multi-location schools
- Subscription tier, billing history, and invoice references
- Platform configuration preferences (programs, instruments, fee structures)
User Account Data
- School Owners / Administrators — full name, email, role, and hashed authentication credentials
- Teachers — full name, email, phone (optional), assigned programs and locations
- Parents / Guardians — full name, email, phone, and relationship to enrolled student(s)
Student Data
- First and last name, date of birth (for age verification and COPPA compliance)
- Email address (optional for minors; required for adult students)
- Enrolled program(s), instrument(s), and current curriculum grade
- Lesson attendance records, homework assignments, and progress notes
- Data consent records — whether consent was obtained, when, and by whom (required for minors)
Platform Usage Data
- Lesson content uploaded by teachers (practice videos, audio files, sheet music) — stored securely within the relevant school tenant only
- Technical logs (IP address, browser type, access timestamps) for security monitoring — retained for 90 days
3.Payment Data — What We Store and What We Don't
What LyraDiary stores
- Transaction ID (issued by the school’s payment provider)
- Payment status (e.g. pending, completed, failed, refunded)
- Invoice amount and currency
- Payment date and associated student/invoice reference
What LyraDiary does NOT store
- Credit or debit card numbers, expiry dates, or CVV/CVC codes
- Bank account numbers, sort codes, or IBAN/routing numbers
- UPI handles, digital wallet credentials, or net banking login details
- Any sensitive authentication data related to financial accounts
All payment processing is performed directly by the school’s chosen third-party payment provider (e.g. Stripe, Razorpay). Payments flow directly between the school and the parent/student. Lyra Tech is not a payment aggregator, payment gateway, or financial institution under any applicable regulation.
4.How We Use Your Data
Platform Functionality
- Creating and managing user accounts and school tenants
- Delivering lesson scheduling, attendance tracking, and curriculum management
- Facilitating communication between teachers, students, and parents
- Generating progress reports, grade certificates, and attendance summaries
- Enabling the student portal for self-service access to schedules and materials
Payment Tracking and Reconciliation
- Recording invoice status against student enrolment records
- Providing schools with a payment history dashboard for fee reconciliation
- Alerting schools and parents to overdue or failed payments
Platform Security and Improvement
- Detecting and preventing unauthorised access, fraud, or abuse
- Diagnosing technical errors and maintaining platform stability
- Producing anonymised, aggregated usage statistics to improve the platform (no individual is identifiable)
Legal and Compliance
- Complying with applicable laws in India and in jurisdictions where our school customers operate
- Responding to valid legal requests from competent authorities
- Enforcing our Terms of Service
5.Data Sharing
We do not sell your personal data. We do not share personal data with third parties for advertising, profiling, or commercial purposes. Data is shared only in the following limited circumstances:
Payment Providers
When a school configures a payment integration, the school’s chosen provider receives payment-related data directly from the payer. LyraDiary receives only the resulting payment metadata (transaction ID, status, amount) via webhook or API callback. No personal financial credentials pass through LyraDiary systems.
Cloud Infrastructure
LyraDiary is hosted on Microsoft Azure. Lyra Tech has data processing agreements in place with all infrastructure providers. Infrastructure providers do not access customer data except as required for platform operation.
Legal Requirements
We may disclose personal data if required by applicable law, court order, or regulatory authority. We will, where lawful, notify the relevant school before complying with such a request.
Within Your School
Within a school tenant, data is visible only to authorised users of that school. Multi-tenant architecture ensures complete isolation between schools — one school cannot access another school’s data.
6.Children and Parental Consent
LyraDiary is frequently used with students who are minors. We take our obligations regarding children’s data seriously.
- Student profiles for minors are created by the school and linked to a parent or guardian account — minors do not self-register.
- Schools are required to obtain appropriate parental consent before adding a minor student to the platform. The platform provides a digital consent tracking mechanism (consent date and source recorded per student).
- Parents can view, correct, and request deletion of their child’s data through the Parent Portal or by contacting the school administrator.
- Schools operating in jurisdictions with specific child data laws (e.g. COPPA in the US, GDPR Article 8 in the EU, DPDPA in India) are responsible for compliance with those requirements as data controllers.
7.Security Practices
Lyra Tech implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure.
Encryption
- In transit — All data transmitted between users and the LyraDiary platform is encrypted using TLS 1.2 or higher (HTTPS). Unencrypted HTTP connections are rejected.
- At rest — Database storage and file storage are encrypted at rest using AES-256 or equivalent encryption provided by Microsoft Azure.
- Passwords — User passwords are hashed using bcrypt / Argon2. Plaintext passwords are never stored or logged.
Access Control
- Role-based access control (RBAC) restricts data access to the minimum necessary for each user role.
- API endpoints require valid JWT authentication tokens. Tokens are short-lived and scoped to the authenticated user’s tenant.
- Multi-tenant isolation is enforced at the database query level — every query is filtered by TenantId, preventing cross-school data access.
- Internal administrative access to production data is restricted to authorised Lyra Tech personnel and is logged.
Operational Security
- Regular security reviews and vulnerability assessments
- Automated dependency scanning for known CVEs in platform libraries
- In the event of a data breach likely to affect user rights, we will notify affected schools within 72 hours of becoming aware, in line with GDPR Article 33 practices and analogous obligations under applicable Indian law.
8.International Data Transfers
Lyra Tech is incorporated in India and our primary data processing infrastructure is hosted in the Microsoft Azure cloud, with data residency in the region selected during school onboarding.
If your school is based outside India, your personal data may be transferred to and processed in India or in the Azure region hosting your tenant. We ensure such transfers are subject to appropriate safeguards, including:
- Data Processing Agreements (DPAs) with cloud infrastructure and service providers
- Standard contractual clauses or equivalent mechanisms where required by applicable law (e.g. EU Standard Contractual Clauses for EU-origin data)
- Schools serving users in regulated jurisdictions (EU/UK, Canada, Australia) should contact us to confirm applicable data residency options.
9.Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to perform our contractual obligations, or to comply with legal requirements.
| Data category | Retention period |
|---|---|
| Active user accounts and student records | Duration of school subscription + 90 days grace period |
| Soft-deleted student records (PII) | 2 years from deletion, then automatically anonymised |
| Payment metadata and invoices | 7 years (statutory financial record-keeping requirement) |
| Access and security logs | 90 days |
| Uploaded media (videos, audio, images) | Duration of school subscription + 30 days after termination |
| Data consent records | 7 years (compliance audit trail) |
| Anonymised/aggregated analytics | Indefinitely (no individual is identifiable) |
Subscribers may request early deletion of their data by contacting info@lyradiary.com. Early deletion requests are processed within 30 days, subject to any legal hold obligations.
10.Your Rights
Depending on your location and applicable law, you may have the following rights in relation to your personal data:
- Right of Access — Request a copy of the personal data we hold about you.
- Right to Rectification — Request correction of inaccurate or incomplete personal data.
- Right to Erasure — Request deletion of your personal data where there is no overriding legal basis for continued processing.
- Right to Restriction — Request that we restrict processing in certain circumstances.
- Right to Data Portability — Where processing is based on consent or contract, request your data in a structured, machine-readable format.
- Right to Object — Object to processing based on legitimate interests.
- Right to Withdraw Consent — Consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of prior processing.
- Right to Lodge a Complaint — You may lodge a complaint with your national Data Protection Authority. For India, this is the Data Protection Board of India (when constituted under the DPDPA).
To exercise any of these rights, contact us at info@lyradiary.com. We will respond within 30 days and may request identity verification before processing a request.
11.Cookies and Tracking
LyraDiary uses a minimal set of cookies and session tokens required for platform operation:
- Authentication tokens — Short-lived JWT tokens stored in session storage to maintain your logged-in session. These are not persistent tracking cookies.
- Preference cookies — Used to remember user interface preferences (e.g. language, theme) within a session.
We do not use third-party advertising cookies, cross-site tracking pixels, fingerprinting, or analytics services that share data with advertising networks.
12.Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the “Last updated” date at the top of this page
- Notify school administrators via email and an in-app notification at least 30 days before changes take effect
- For changes that materially affect how we process student data, we will provide a more prominent notice and, where required by law, seek fresh consent
13.Contact Us
Lyra Tech Private Limited
Data Privacy Team
Email: info@lyradiary.com
Company: lyra-tech.in
We aim to respond to all privacy-related correspondence within 5 business days.
