SmartCampusInstitute ERP
HomePricingTermsRefunds
Talk to us

SmartCampus · Legal

Privacy Policy

Last updated 3 September 2026 · Version 1.0

SmartCampus AI Technologies (“SmartCampus”, “we”, “us” or “our”) respects the privacy of everyone whose personal data it handles. This Privacy Policy explains what personal data we collect through our website at https://smartcampussai.com (the “Website”), what personal data institutions process inside the SmartCampus institute ERP (the “Service”), how we protect it, whom we share it with, how long we keep it and the rights you have.

It is written to comply with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), the Information Technology Act, 2000 and the rules made under it, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. This Policy forms part of our Terms & Conditions.

Contents

  1. Scope and our roles
  2. Data we collect on the Website
  3. Data processed in the Service on behalf of Institutions
  4. Children's data
  5. Biometric data
  6. Purposes and lawful basis
  7. Payments
  8. Sharing and sub-processors
  9. Where data is stored and transfers
  10. How we protect data
  11. How long we keep data
  12. Your rights
  13. Cookies and local storage
  14. Changes to this Policy
  15. Grievance Officer
  16. Contact

1. Scope and our roles

  • For the Website, demo enquiries, billing and support, we decide why and how personal data is processed. Under the DPDP Act we are the Data Fiduciary for that data.
  • For Institution Data inside the Service, the Institution decides what data to collect from its students, parents and staff and on what lawful basis. The Institution is the Data Fiduciary, and we act as its Data Processor, processing that data only on its documented instructions, which are our Terms & Conditions and the way the Institution configures the Service.
  • Students, parents and staff whose data an Institution enters are Data Principals. They exercise their rights through their Institution, as explained in the section on your rights, and we help the Institution respond.

2. Data we collect on the Website

DataWhere it comes fromWhy we use itHow long we keep it
Demo enquiry: your name, institution, institution type, role, city, phone number, approximate student strength, preferred time and optional messageYou, through the Book a Demo form or a WhatsApp or phone conversationTo respond to your enquiry, schedule the demo and follow up on the sale24 months from our last contact, or until you ask us to delete it
Usage analytics: a random visitor identifier, a session identifier, pages viewed, buttons clicked, referring site, campaign parameters, device and browser typeYour browser, stored only in its local storage; no cookies and no cross-site trackingTo understand which pages and features interest visitors and improve the Website12 months
Technical and security data: IP address and browser user agentYour browser, when it requests a page or submits a formRate limiting, abuse prevention and diagnosing errorsUp to 30 days in security logs
Staff console: work email address and a session cookieOur own staff signing in to the Website's administration consoleOperating the console securelyFor the browser session

Our analytics are first-party and honour your browser's Do Not Track setting. The Website sets no advertising cookies, loads no third-party analytics or tracking pixels, and serves its fonts from our own domain.

3. Data processed in the Service on behalf of Institutions

Institutions collect and enter the following categories of personal data into the Service. We receive this data from the Institution rather than directly from the individuals concerned, except where a portal user enters or updates their own details.

  • Students: identity details such as name, date of birth, gender, photograph, admission and roll numbers; government identifiers the Institution chooses to record, such as Aadhaar number and APAAR ID; contact details and address; category, religion and nationality where the Institution needs them for statutory returns; academic records, results and assignments; attendance; fee and payment records; documents and certificates; health information such as blood group, medical notes and nurse visits; and portal sign-in details.
  • Parents and guardians: name, relationship, phone number, email address, occupation and portal sign-in details.
  • Staff: identity and contact details, employment and qualification records, attendance and leave, payroll data including PAN, bank account, UAN, PF and ESI numbers, and portal sign-in details.
  • Biometric data: face templates used for attendance, only where the Institution enables the Module and records consent (see the biometric section).
  • Communications: messages and notifications the Institution sends through the Service by in-app notice, WhatsApp, SMS or push notification, and their delivery status.
  • Logs: sign-in history and audit trails recording who created, changed or deleted a record and when.

4. Children's data

Most students whose data is processed in the Service are children. Under section 9 of the DPDP Act, the Institution, as Data Fiduciary, must obtain the verifiable consent of a parent or lawful guardian before processing a child's personal data, and must not use the Service for tracking, behavioural monitoring or advertising directed at children. The Service contains no advertising, and we process children's data only on the Institution's instructions for educational administration: admissions, attendance, academics, fees, health and safety, and communication with parents.

We do not knowingly collect children's personal data through the Website. If you believe a child has submitted the enquiry form, write to support@smartcampussai.com and we will delete the entry.

5. Biometric data

Face-based attendance is an optional Module. When an Institution enables it, the Service derives a mathematical template from an enrolment photograph and uses that template to recognise the person at an attendance kiosk. The template is encrypted at rest with a key held separately from the database, raw face images are not retained for matching, and templates are never sent back to browsers or devices. Each enrolment records whether consent was given and when, and can carry an expiry date after which fresh consent is required.

The Institution must obtain explicit, informed consent before enrolling anyone, from a parent or guardian in the case of a child, display a notice wherever a kiosk is used, and offer a non-biometric way to mark attendance. Deleting an enrolment in the Service deletes the template; the Institution can do this at any time on request.

6. Purposes and lawful basis

PurposeLawful basis
Providing, securing and supporting the Service for an InstitutionPerformance of our contract with the Institution; the Institution's own lawful basis towards its students, parents and staff
Issuing invoices, collecting fees and complying with GST and income-tax lawPerformance of a contract and compliance with legal obligations
Responding to demo enquiries and support requestsYour request, which is consent to be contacted about it
Keeping the Website and the Service secure and preventing abuseLegitimate uses permitted by law and compliance with legal obligations
Improving the product using aggregated, anonymised statisticsNo personal data is involved once aggregated
Telling you about SmartCampus updates and offersYour consent, which you may withdraw at any time

7. Payments

When you pay our invoices online, the payment is processed by our payment gateway partner, a certified payment service provider. Card numbers, CVV codes and banking credentials are entered on the gateway's secure pages and never reach our servers. We receive the transaction identifier, amount, status, the payer's name and a masked reference to the payment instrument, and we keep these with the invoice as tax law requires. For bank transfers we record the UTR and payer details shown on our bank statement.

Institutions that collect fees from parents through the Service do so through their own payment gateway account. In that case we process the transaction reference and status on the Institution's behalf and never hold the funds.

8. Sharing and sub-processors

We do not sell personal data and we do not share it for third-party advertising. We share personal data only with the providers below, who process it on our or the Institution's behalf, with professional advisers and auditors under confidentiality, and with authorities where the law requires. If our business is transferred, personal data may pass to the successor under this Policy.

RecipientWhat is sharedWhy
Hostinger International Ltd.All Website and Service dataCloud servers and web hosting for the Website and the Service
Cloudflare, Inc. (R2 object storage)Uploaded files such as photographs and documents, and encrypted backupsFile storage and off-site backups
Meta Platforms, Inc. (WhatsApp Business Platform)Recipient phone number and message contentDelivering messages an Institution sends through its own WhatsApp Business account
The SMS gateway chosen by the Institution, such as Fast2SMS, MSG91, Twilio or SpearUCRecipient phone number and message textDelivering SMS an Institution sends through its own gateway account
Google LLC (Firebase Cloud Messaging)Device push tokens and notification contentPush notifications to the mobile application
Our payment gateway partnerPayer name and transaction detailsCollecting our licence fees online

9. Where data is stored and transfers

The Website is hosted with Hostinger. The Service runs on Hostinger cloud servers located in Mumbai, India, and uploaded files and encrypted backups are stored with Cloudflare R2. Where personal data is stored in or accessed from a country outside India, we do so only as permitted by section 16 of the DPDP Act and protect it with contractual and technical safeguards. Institutions that require their data to remain in India should raise this with us before purchase.

10. How we protect data

  • All traffic to the Website and the Service is encrypted in transit with TLS.
  • Each Institution's data is kept in its own database, and row-level security enforced by the database itself prevents one Institution's users from reading another Institution's records.
  • Highly sensitive fields, including biometric templates, medical notes and multi-factor authentication secrets, are additionally encrypted at the application layer, with support for key rotation.
  • Access is controlled by roles and permissions set by the Institution, with optional multi-factor authentication, session expiry and automatic lockout after repeated failed sign-ins. Every change is written to an audit log, and deleted records can be restored by administrators.
  • Institution Data is backed up every night. Backups are encrypted, kept for 14 days on our servers and 90 days off-site, checked for integrity, and restored in rehearsals.
  • Our staff have least-privilege access to production systems, do not keep production data on personal devices, and security updates are applied regularly.
  • If we confirm a breach affecting personal data, we notify the affected Institutions without undue delay and within 72 hours, with the information they need to notify Data Principals and the authorities as the law requires.

11. How long we keep data

DataRetention
Demo enquiries and sales correspondence24 months from last contact, or until you ask us to delete it
Website analytics12 months
Security and rate-limit logsUp to 30 days
Institution Data during an active LicenceFor the Term, as instructed by the Institution
Institution Data after expiry or terminationRetained for a 30-day export window, then deleted or anonymised within 90 days of expiry or termination, or earlier on request; backups age out within a further 90 days
Invoices, payments and tax recordsEight years, as required by GST and income-tax law
Support correspondence24 months

12. Your rights

Under the DPDP Act you have the right to access a summary of the personal data being processed about you, to have inaccurate or incomplete data corrected or updated, to have data erased when it is no longer needed for the purpose it was collected for or the law does not require us to keep it, to have your grievances heard, and to nominate someone to exercise these rights on your behalf. You may withdraw consent to marketing communications at any time.

If you are a student, parent or staff member of an Institution, please make your request to the Institution, which is your Data Fiduciary. The Service gives Institutions the tools to view, correct, export and delete records, and we assist them so they can respond within the statutory time. If you contacted us through the Website, write to support@smartcampussai.com. We verify identity before acting on a request and respond within 30 days.

13. Cookies and local storage

NameTypePurposeDuration
sc-vidBrowser local storageAnonymous visitor identifier for first-party analyticsUntil you clear browser storage
sc-sid, sc-last-activity, sc-session-ctxBrowser session storageGroups page views into one visit; a visit ends after 30 minutes of inactivityUntil the tab is closed
sc-themeBrowser local storageRemembers your light or dark theme choiceUntil you clear browser storage
sc_adminCookie (HttpOnly, Secure, SameSite=Lax)Sign-in session for our staff's Website consoleBrowser session
Service sign-in tokensBrowser session storage in the Service applicationKeeps you signed in to the Service; cleared when the application is closedUntil the application is closed

We use no advertising or third-party cookies. You can block or clear browser storage at any time; the Website continues to work, although your theme choice and visit grouping will reset.

14. Changes to this Policy

We may update this Policy as the Service, our providers or the law change. Material changes are announced to Institutions by email or a notice in the Service at least 30 days before they take effect, and the date and version at the top of this page are updated. Earlier versions are available on request.

15. Grievance Officer

Our Grievance Officer under the Information Technology Rules and the DPDP Act is Mohammad Jani Basha, who can be reached at grievance@smartcampussai.com or at the postal address in the Contact section below. We acknowledge every grievance within two working days and aim to resolve it within 30 days. If you are not satisfied with our response, you may approach the Data Protection Board of India or any other authority designated under applicable law.

16. Contact

SmartCampus AI TechnologiesA sole proprietorship registered in India · Proprietor: Mohammad Jani Basha
Ramachandra Nagar, Kurnool, Andhra Pradesh 518002, India
GSTIN 37GPYPS4513H1Z3
Email: support@smartcampussai.com · Phone / WhatsApp: +91 90109 30360
Support hours: Monday to Saturday, 9:00 AM – 6:00 PM IST
Grievance Officer: Mohammad Jani Basha (grievance@smartcampussai.com)
SmartCampusModern institute ERP
Terms & ConditionsPrivacy PolicyRefund & Cancellation Policy

© 2026 SmartCampus AI Technologies · GSTIN 37GPYPS4513H1Z3