Pathshala by MJX Pathshala by MJX

Privacy Policy

Effective date: 23 September 2026

This Privacy Policy (the “Policy”) describes how MJX Technologies LLP (“MJX”, “we”, “us” or “our”) collects, uses, stores, discloses and otherwise processes personal data in connection with Pathshala by MJX, including its websites, the course and learner pages of the institutions that use it, and the mobile application MJX Learn (together, the “Service”).

This Policy is published in accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the rules made under them, and the policies of Google Play. By using the Service you acknowledge that you have read and understood this Policy.

1. Who We Are and Our Role

The Service is used by schools, coaching institutes, tutors and other educators (each an “Institution”) to manage enquiries, admissions, fees, courses and communication with their students, learners and parents. In respect of the records an Institution maintains about its own students, learners and parents, the Institution determines the purpose of processing and MJX processes that data on the Institution’s behalf. In respect of account security, fraud prevention, the MJX Learn application and the operation of the Service itself, MJX determines the purpose of processing.

2. Personal Data We Collect

2.1 Institutions and their staff

Institution name, address, subdomain, and the name, mobile number, email address and password of the owner and of each staff member the Institution adds. Where an owner completes identity verification (KYC), the documents submitted and the result of that verification (see section 2.6).

2.2 Enquiries, students and parents

Details entered by an Institution or submitted through an Institution’s enquiry forms, such as the name, mobile number and email address of a parent or enquirer, and the name, class and admission details of a student. This data belongs to the Institution.

2.3 WhatsApp communication

Messages exchanged between an Institution and its enquirers, parents or learners through the WhatsApp Business Platform, which are stored to maintain the conversation history, to send the replies and notifications the Institution has configured, and to meet the requirements of the WhatsApp Business Platform.

2.4 Learners using MJX Learn or the course pages

  • Identity and contact details: name, mobile number and, where provided, email address and profile photograph. The mobile number is verified by a one-time code delivered on WhatsApp.
  • Device information: a randomly generated device identifier and the device type (for example, “Android phone”), used to permit an account to be active on one device at a time.
  • Precise location: collected, with the device’s location permission, at each sign-in and approximately every ten minutes while the application is open on the screen. Location is not collected while the application is closed or running in the background. Location data is stored in encrypted form, is not displayed to the Institution, and is used solely for account security and the prevention of account sharing and fraud. On a bona fide safety request (for example, concerning a missing person), MJX may use the most recent location for that purpose.
  • Approximate location: an approximate city and country derived from the network address, which the Institution sees only as aggregated counts.
  • Contacts: MJX Learn does not access a learner’s contacts, call logs or messages.
  • Learning activity: the courses purchased or assigned, progress through their topics, quiz answers, questions (“doubts”) sent to teachers, assignments submitted, certificates earned, and notifications received.
  • Payment records: the course purchased, the amount and the payment status. Card, UPI and bank credentials are entered directly with the payment provider (Razorpay) and are not received or stored by MJX.

2.5 Educators and staff using MJX Learn

In addition to the account details in section 2.1, after an in-app notice and only with the corresponding device permissions: the device’s contacts (names and telephone numbers), so that the educator can find and select the people to whom the Institution sends messages from its own WhatsApp number; and the device’s precise location at sign-in and while the application is open, stored in encrypted form, for account security and so that MJX can understand where its customers are located. Call logs and messages are never accessed.

2.6 Identity verification through DigiLocker

An Institution owner may verify identity through DigiLocker (MeriPehchaan). The user authenticates on DigiLocker’s own page and selects the documents to share. MJX retains the name, date of birth, gender, the last four digits of the Aadhaar number (where shared), and, from the documents the user chooses to share, the PAN and driving-licence numbers (stored in encrypted form and shown to the Institution only in masked form) and the DigiLocker photograph. An address, where shared, is stored in encrypted form and is accessible only to MJX for the investigation of suspected fraud. MJX does not store the full Aadhaar number. The DigiLocker access token is used once and then revoked. A school may similarly verify a student’s APAAR ID through DigiLocker with the parent’s authentication; only the student’s name, date of birth, gender and APAAR ID are received.

2.7 Content you choose to upload

Photographs, PDF files and other documents that a user deliberately selects and uploads — for example a profile photograph, a KYC document, a photograph attached to a doubt, an assignment, a course cover or banner, or a signature and seal for certificates. Such files are selected through the device’s own file or photo picker; the application does not read the device’s photo library by itself. Where an Institution requires a learner’s own photograph with a doubt, the photograph is checked automatically, using an artificial-intelligence service, only to confirm that it shows one person’s face; this check does not identify the person, compare faces or create any biometric template, and nothing from the check is stored.

2.8 Google and Zoom accounts connected by an Institution

An Institution owner or administrator may connect their own Google or Zoom account so that live-class links are created on that account.

  • Access requested. For Google: permission to create one separate calendar named “Pathshala classes” and to create and delete events within that calendar only (scope calendar.app.created), together with the account’s email address (openid, email). The Service cannot read or modify any other calendar. For Zoom: permission to create and delete meetings and to read the account’s email address.
  • Use. One calendar event or one Zoom meeting is created for each live class scheduled with that provider and is deleted if the class is cancelled. No other events, meetings, emails, contacts or files are read, copied or modified.
  • Storage. The connected account’s email address (and, for Zoom, its user identifier), the identifier of the “Pathshala classes” calendar, and an access token stored in encrypted form. Nothing else is stored.
  • Disclosure. This data is not sold, not shared with any third party, not used for advertising and not used to train artificial-intelligence models.
  • Revocation. Selecting “Disconnect” in Settings → Setup deletes the stored token and revokes it with the provider. Access may also be revoked from the Google account’s security settings or the Zoom App Marketplace at any time.

The Service’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

2.9 Technical data

Network (IP) address, browser or device type, session timestamps and error reports, processed for security, fraud prevention and the diagnosis of faults.

3. Device Permissions Used by MJX Learn

  • Location (precise, foreground only): at sign-in and while the application is open, as described in section 2.4. Background location is not requested.
  • Contacts (read only): for educators and staff only, after an in-app notice, as described in section 2.5. Contacts are never modified.
  • Camera and microphone: only when the user joins a live class inside the application (Zoom or Google Meet) or chooses to take a photograph to upload. Nothing is recorded by MJX.
  • Notifications: to deliver messages from the Institution and course updates.

Every permission may be refused or later withdrawn in the device settings. Refusing the location permission prevents sign-in, because location is required for account security; refusing any other permission disables only the related feature.

4. Purposes of Processing

  • to provide and operate the Service, including courses, live classes, fees, payments, certificates and communication between Institutions and their learners and parents;
  • to authenticate users, secure accounts and prevent account sharing, fraud and misuse;
  • to generate automated or suggested replies and drafts using an artificial-intelligence service (Anthropic Claude), where the Institution has enabled such features;
  • to send transactional messages and notifications;
  • to maintain, diagnose and improve the Service; and
  • to comply with legal obligations and respond to lawful requests of authorities.

We do not sell personal data, and we do not use personal data for third-party advertising.

5. Consent

Personal data is processed on the basis of the consent given by the user (including consent given through the device’s permission dialogs and the in-app notices that precede them), for the legitimate uses permitted by law, or on the instructions of the Institution with which the user is associated. Consent may be withdrawn at any time in the manner described in sections 3 and 8; withdrawal does not affect processing carried out before it.

6. Disclosure to Service Providers

Personal data is disclosed only to the following categories of service providers, strictly for the purposes above and under obligations of confidentiality:

  • Meta Platforms (WhatsApp Business Platform) — message delivery;
  • Razorpay — payment processing;
  • Anthropic (Claude API) — artificial-intelligence features;
  • Google (Firebase Cloud Messaging) — delivery of push notifications;
  • Google Calendar / Google Meet and Zoom — live-class links, only where an Institution connects its own account (section 2.8);
  • DigiLocker / MeriPehchaan — identity and APAAR verification, only when the user initiates it (section 2.6);
  • Microsoft 365 — email delivery; and
  • cloud infrastructure providers — hosting in India.

Personal data may also be disclosed where required by law, court order or a lawful request of a government authority.

7. Storage, Security and Retention

  • Data is stored on servers located in India. Each Institution’s data is logically isolated from that of every other Institution.
  • All data is encrypted in transit (TLS). Location data, access tokens, identity-document numbers and verified addresses are additionally encrypted at rest.
  • Access is restricted to authorised personnel who require it for the purposes above.
  • Personal data is retained for as long as the associated account or the Institution’s subscription remains active and for up to 90 days thereafter, unless a longer period is required by law. Course files made available to a learner are removed within one month after the learner’s access ends. Issued certificates are retained as records of issue.

8. Your Rights and Deleting Your Account

Subject to applicable law, you have the right to access a summary of your personal data, to request its correction or completion, to request its erasure, to withdraw consent, to nominate another person to exercise these rights in the event of death or incapacity, and to seek redressal of grievances.

To delete your MJX Learn account and its data (including any location records and, for educators, any contacts collected from your device), send an email to privacy@mjxtechnologies.com from, or stating, the mobile number registered with your account, with the subject “Delete my account”. We will verify the request and complete the deletion within 30 days, except for records that we or the Institution are required by law to retain (such as payment and tax records and issued certificates), which will be retained only for the period so required.

Where your data is held on behalf of an Institution (for example, a student record kept by your school), we may refer your request to that Institution.

9. Children

MJX Learn is intended for users aged 18 years and above. Where the Service is used by a school to maintain the records of students under 18, that data is provided by the school or the parent, and the school is responsible for obtaining verifiable consent of the parent or lawful guardian. MJX does not knowingly use the data of children for tracking, behavioural monitoring or targeted advertising.

10. Cookies

The Service uses only the cookies necessary for its operation: session management, a device identifier that permits an account to be active on one device at a time, language preference and protection against request forgery. No tracking or third-party advertising cookies are used.

11. Changes to this Policy

We may amend this Policy from time to time. The amended Policy will be published on this page with a revised effective date and, where the change is material, notified to Institutions by email or within the Service. Continued use of the Service after the effective date constitutes acknowledgement of the amended Policy.

12. Contact and Grievance Officer

MJX Technologies LLP

Grievance Officer and privacy requests: privacy@mjxtechnologies.com

Support: info@mjxtechnologies.com

WhatsApp: +91 79968-37555

Grievances are acknowledged within 48 hours and resolved within the period prescribed by law. If you are not satisfied with the resolution, you may approach the Data Protection Board of India.