Key Privacy Principles at a Glance
- •Customer Data Ownership: Educational institutions retain full ownership and control over the prospective student, applicant, and admission records they upload or manage within AdmitDrive.
- •No Sale of Student Data: AdmitDrive does not sell, rent, or trade student or institution personal data to third parties or cross-market data to other institutions.
- •90-Day Closure Retention: When an institution formally closes its workspace, data is preserved for a 90-day recovery and export window before permanent deletion eligibility.
- •Security Safeguards: AdmitDrive uses reasonable technical and organizational safeguards designed to protect customer data.
1. Introduction & About AdmitDrive
Welcome to AdmitDrive. AdmitDrive (“we”, “us”, or “our”) provides a multi-tenant Software-as-a-Service (SaaS) admissions customer relationship management (CRM) and lead orchestration platform for colleges, universities, and educational institutions.
This Privacy Policy describes our practices regarding the collection, use, disclosure, storage, and protection of personal data when institutions, administrators, staff members, prospective applicants, and visitors access our platform through admitdrive.com and associated web applications.
2. Scope of this Policy
This Privacy Policy applies to personal data processed through our website, application workspaces, invitation workflows, support channels, and platform APIs.
AdmitDrive operates primarily as a business-to-business (B2B) SaaS platform for educational institutions. In this capacity, there is a clear distinction between:
- Institution Customer Data: Information uploaded, imported, recorded, or managed by an educational institution regarding its prospective students, applicants, inquiries, tele-calling notes, and staff members.
- Account & Platform Data: Information we collect directly from institution administrators, authorized staff, and website visitors for account creation, authentication, security monitoring, billing readiness, and customer support.
3. Categories of Users & Data Subjects
We process personal data relating to the following categories of individuals:
Institution Administrators
Designated institutional representatives who create workspaces, manage roles, configure academic settings, and oversee subscription accounts.
Managers & Team Leads
Supervisory staff who oversee admissions campaigns, assign leads, monitor team performance, and review operational analytics.
Admissions Staff & Tele-callers
Counselors and staff who engage with prospective students, conduct calls, schedule follow-ups, and record admission outcomes.
Prospective Students & Applicants
Individuals whose inquiries, academic interests, or applications are entered or imported by educational institutions.
We also process limited technical data relating to Website Visitors who browse our public marketing pages.
4. Personal Data We May Process
Depending on how you interact with AdmitDrive, we may process the following categories of information:
A. Institution User Account Data
- Full name and institutional email address
- Institution/organization affiliation and assigned campus or department
- Assigned platform role (Administrator, Manager, or Staff)
- Authentication credentials and password hashes
- User activity logs, timestamps, and login session identifiers
B. Prospective Student & Admissions Data (Customer Data)
Supplied, uploaded, or generated by the educational institution:
- Student contact details: Full name, telephone/mobile number, email address, city/state
- Academic background: Previous school, qualifying examination, or entrance details
- Academic interests: Preferred departments, courses of interest, and interest levels
- Admissions provenance: Collection batch, campaign source, and referral attribution
- Operational interaction logs: Call outcomes, counselor notes, feedback, and scheduled follow-ups
- Admission lifecycle records: Enrollment status, admission confirmation, and milestone history
- Resource-sharing records: Logs of brochures or institution documents shared with candidates
C. Technical & Security Information
- Browser type, device classification, and operating system
- IP address and approximate network-level geolocation
- Security audit events, HTTP request timestamps, and system diagnostic telemetry
- Essential session cookies and authentication tokens
5. Purposes of Processing
We process personal data strictly for the following legitimate business and operational purposes:
- Operating, hosting, and maintaining the AdmitDrive CRM platform.
- Enabling lead intake, manual and bulk spreadsheet import, and verification workflows.
- Executing rule-based and manual lead assignment to designated admissions staff.
- Facilitating tele-calling operations, outcome logging, and automated follow-up reminders.
- Tracking student academic interests, course preferences, and admission confirmations.
- Enabling institutions to share admission brochures and information resources.
- Generating institution-level analytics, counselor productivity metrics, and admission conversion trends.
- Verifying user identity, managing role-based access, and preventing unauthorized workspace access.
- Providing technical support, diagnosing platform bugs, and responding to customer inquiries.
- Conducting disaster recovery, automated database backups, and maintaining platform data integrity.
- Fulfilling legal, statutory, regulatory, and audit obligations under applicable law.
6. Institution & AdmitDrive Responsibilities
AdmitDrive is designed to provide secure SaaS infrastructure. The respective responsibilities of the institution and AdmitDrive are established as follows:
The Institution’s Role
The educational institution decides what student and prospect data is entered, imported, or recorded within its workspace. The institution is responsible for ensuring that it possesses the requisite legal authority, provides appropriate privacy notices to candidates, and maintains all necessary consents.
AdmitDrive’s Role
AdmitDrive acts as a technology platform and service provider that processes Customer Data solely on behalf of the institution and according to its configuration and authorized instructions. AdmitDrive does not independently source, buy, or supply student prospect databases to institutions.
7. Lawful Processing & Consent
Institutions utilizing AdmitDrive represent and warrant that all prospective student information entered or uploaded into the platform has been collected through transparent, lawful means (such as student enquiry forms, college walk-ins, educational fairs, or authorized portal inquiries).
Where consent is required under applicable data protection laws for communications, SMS, or tele-calling, the institution is responsible for obtaining, verifying, and recording such consent prior to initiating outreach. Institutions must not upload unsolicited contact lists or unlawfully harvested data.
8. Children & Minors
College and higher education admissions frequently involve prospective applicants who are under 18 years of age (minors). Because institutions manage their own applicant data entry, the institution is responsible for complying with all applicable legal requirements regarding minors, including obtaining requisite parental or legal guardian consent where mandated by law.
AdmitDrive does not directly market its services to minors or provide open public enrollment portals to children without educational institution administration.
9. How Data May Be Shared or Disclosed
We do not disclose customer personal data except in the limited circumstances described below:
- Infrastructure & Cloud Hosting Providers: To host database systems, execute edge computations, and ensure reliable platform uptime.
- Authentication & Identity Services: To securely manage user login sessions and password verification.
- Transactional Email Delivery Services: To deliver system notifications, staff invitations, and administrative account alerts.
- Backup & Security Telemetry Providers: To maintain system backups, monitor security anomalies, and prevent fraudulent activity.
- Professional Advisers & Regulators: To legal counsel, auditors, or law enforcement authorities where strictly required to comply with binding court orders, applicable statutes, or to defend legal claims.
- Corporate Transactions: In connection with a merger, reorganization, financing, or sale of assets, subject to customary confidentiality protections.
No Sale of Personal Data
AdmitDrive does not sell institution, staff, or student personal data. Customer Data is never commercialized, rented, or repurposed for third-party advertising or cross-institution lead resale.
10. Data Security & Safeguards
AdmitDrive uses reasonable technical and organizational safeguards designed to protect customer data against accidental loss, unauthorized access, misuse, alteration, or disclosure.
Multi-Tenant Isolation
Database records are strictly partitioned by organization identifier, enforcing row-level security barriers between institutions.
Role-Based Access Control
Access is restricted according to verified user roles (Administrator, Manager, Staff), enforcing least privilege across operational views.
Encryption in Transit
All web traffic and API communications are transmitted using secure Transport Layer Security (TLS/HTTPS).
Personnel Access Controls
AdmitDrive personnel access customer data only when reasonably necessary for technical support, incident investigation, or system maintenance.
Please note: While we implement industry-standard safeguards, no method of transmission over the internet or electronic storage can be guaranteed to be completely secure.
11. Data Retention & 90-Day Account Closure Window
We retain personal data in accordance with the lifecycle of the customer’s subscription and account status:
Active Workspaces
Data is actively retained for the duration of the institution’s active pilot or subscription period to enable continuous operations.
Inactive or Suspended Subscriptions
An inactive or suspended subscription does not trigger immediate data deletion. Customer records remain safely preserved, and authorized roles may retain appropriate read-only access while the institution evaluates reactivation or export.
Formal Account Closure: 90-Day Retention Window
When an authorized institution Administrator formally requests workspace closure, a 90-day recovery and export window begins. During this 90-day window, the institution may retrieve its data or request workspace reactivation. Following the conclusion of the 90-day period, production tenant data becomes eligible for permanent deletion.
Backups and Legal Obligations
Residual copies may remain temporarily in backup or disaster-recovery systems and will age out according to applicable backup retention processes. Limited records may be retained longer if strictly necessary to satisfy statutory, tax, regulatory, security, or dispute resolution requirements.
12. Data Export, Portability & Deletion Requests
AdmitDrive is committed to customer data portability and preventing vendor lock-in:
A. Active Account Data Export & Portability
An authorized institution Administrator may request an export of their institution’s Customer Data at any time while the institution account is active. Export requests are strictly restricted to that institution’s own tenant data and may be provided in practical, common machine-readable formats (such as standard CSV or structured files) as supported by the platform.
B. Account Closure Recovery Window
During the 90-day retention window following a formal account closure request, the institution Administrator retains the right to retrieve and export the institution’s data prior to permanent deletion.
To initiate an active data export request or discuss data retrieval, an authorized Administrator may contact privacy@admitdrive.com.
Individual prospective students or applicants seeking to inspect, update, or delete records held in an institution workspace should submit their requests directly to the respective educational institution, as the institution controls that data. AdmitDrive will assist institutional administrators in fulfilling verifiable requests where appropriate.
13. Individual Privacy Rights & Grievance Redressal
Subject to applicable data protection laws, individuals may have the right to request:
- Access to information regarding the personal data processed about them.
- Correction or updating of inaccurate, incomplete, or out-of-date personal data.
- Erasure or deletion of personal data where no ongoing lawful basis for processing exists.
- Withdrawal of previously granted consent, without affecting the lawfulness of prior processing.
- Grievance redressal regarding personal data handling practices.
For privacy inquiries or grievance redressal, you may reach our designated privacy contact at: privacy@admitdrive.com.
14. Security Incidents & Breach Notification
In the event of a confirmed security incident affecting customer personal data, AdmitDrive will promptly initiate containment, investigation, and remediation measures. We will notify affected institution administrators and relevant authorities in accordance with applicable statutory timelines and requirements.
15. International & Cross-Border Processing
To deliver high availability and resilience, AdmitDrive relies on cloud infrastructure and subprocessor services that may operate data centers across multiple geographic locations. We ensure that any cross-border processing complies with applicable legal standards and is subject to appropriate technical and contractual protections.
17. Service Providers & Subprocessors
We engage vetted third-party vendors for cloud hosting, database management, transactional email delivery, and infrastructure monitoring. All service providers are bound by strict confidentiality and data protection obligations consistent with this Privacy Policy.
18. Changes to this Privacy Policy
We may revise this Privacy Policy periodically to reflect enhancements to our platform, changes in legal requirements, or operational practices. The updated version number and effective date will always be displayed at the top of this document.
For material changes affecting customer data handling, we will provide reasonable advance notice through the application interface or via email to registered institution Administrators.
19. Contact Information & Grievance Officer
If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact us:
AdmitDrive Privacy & Security Inquiries
- Privacy & Grievances: privacy@admitdrive.com
- Security Reports: security@admitdrive.com
- Customer Support: support@admitdrive.com
- General Inquiries: contact@admitdrive.com
