1. Scope and our roles
- For the Website, demo enquiries, billing and support, we decide why and how personal data is processed. Under the DPDP Act we are the Data Fiduciary for that data.
- For Institution Data inside the Service, the Institution decides what data to collect from its students, parents and staff and on what lawful basis. The Institution is the Data Fiduciary, and we act as its Data Processor, processing that data only on its documented instructions, which are our Terms & Conditions and the way the Institution configures the Service.
- Students, parents and staff whose data an Institution enters are Data Principals. They exercise their rights through their Institution, as explained in the section on your rights, and we help the Institution respond.
2. Data we collect on the Website
| Data | Where it comes from | Why we use it | How long we keep it |
|---|---|---|---|
| Demo enquiry: your name, institution, institution type, role, city, phone number, approximate student strength, preferred time and optional message | You, through the Book a Demo form or a WhatsApp or phone conversation | To respond to your enquiry, schedule the demo and follow up on the sale | 24 months from our last contact, or until you ask us to delete it |
| Usage analytics: a random visitor identifier, a session identifier, pages viewed, buttons clicked, referring site, campaign parameters, device and browser type | Your browser, stored only in its local storage; no cookies and no cross-site tracking | To understand which pages and features interest visitors and improve the Website | 12 months |
| Technical and security data: IP address and browser user agent | Your browser, when it requests a page or submits a form | Rate limiting, abuse prevention and diagnosing errors | Up to 30 days in security logs |
| Staff console: work email address and a session cookie | Our own staff signing in to the Website's administration console | Operating the console securely | For the browser session |
Our analytics are first-party and honour your browser's Do Not Track setting. The Website sets no advertising cookies, loads no third-party analytics or tracking pixels, and serves its fonts from our own domain.
3. Data processed in the Service on behalf of Institutions
Institutions collect and enter the following categories of personal data into the Service. We receive this data from the Institution rather than directly from the individuals concerned, except where a portal user enters or updates their own details.
- Students: identity details such as name, date of birth, gender, photograph, admission and roll numbers; government identifiers the Institution chooses to record, such as Aadhaar number and APAAR ID; contact details and address; category, religion and nationality where the Institution needs them for statutory returns; academic records, results and assignments; attendance; fee and payment records; documents and certificates; health information such as blood group, medical notes and nurse visits; and portal sign-in details.
- Parents and guardians: name, relationship, phone number, email address, occupation and portal sign-in details.
- Staff: identity and contact details, employment and qualification records, attendance and leave, payroll data including PAN, bank account, UAN, PF and ESI numbers, and portal sign-in details.
- Biometric data: face templates used for attendance, only where the Institution enables the Module and records consent (see the biometric section).
- Communications: messages and notifications the Institution sends through the Service by in-app notice, WhatsApp, SMS or push notification, and their delivery status.
- Logs: sign-in history and audit trails recording who created, changed or deleted a record and when.
4. Children's data
Most students whose data is processed in the Service are children. Under section 9 of the DPDP Act, the Institution, as Data Fiduciary, must obtain the verifiable consent of a parent or lawful guardian before processing a child's personal data, and must not use the Service for tracking, behavioural monitoring or advertising directed at children. The Service contains no advertising, and we process children's data only on the Institution's instructions for educational administration: admissions, attendance, academics, fees, health and safety, and communication with parents.
We do not knowingly collect children's personal data through the Website. If you believe a child has submitted the enquiry form, write to support@smartcampussai.com and we will delete the entry.
5. Biometric data
Face-based attendance is an optional Module. When an Institution enables it, the Service derives a mathematical template from an enrolment photograph and uses that template to recognise the person at an attendance kiosk. The template is encrypted at rest with a key held separately from the database, raw face images are not retained for matching, and templates are never sent back to browsers or devices. Each enrolment records whether consent was given and when, and can carry an expiry date after which fresh consent is required.
The Institution must obtain explicit, informed consent before enrolling anyone, from a parent or guardian in the case of a child, display a notice wherever a kiosk is used, and offer a non-biometric way to mark attendance. Deleting an enrolment in the Service deletes the template; the Institution can do this at any time on request.
6. Purposes and lawful basis
| Purpose | Lawful basis |
|---|---|
| Providing, securing and supporting the Service for an Institution | Performance of our contract with the Institution; the Institution's own lawful basis towards its students, parents and staff |
| Issuing invoices, collecting fees and complying with GST and income-tax law | Performance of a contract and compliance with legal obligations |
| Responding to demo enquiries and support requests | Your request, which is consent to be contacted about it |
| Keeping the Website and the Service secure and preventing abuse | Legitimate uses permitted by law and compliance with legal obligations |
| Improving the product using aggregated, anonymised statistics | No personal data is involved once aggregated |
| Telling you about SmartCampus updates and offers | Your consent, which you may withdraw at any time |
7. Payments
When you pay our invoices online, the payment is processed by our payment gateway partner, a certified payment service provider. Card numbers, CVV codes and banking credentials are entered on the gateway's secure pages and never reach our servers. We receive the transaction identifier, amount, status, the payer's name and a masked reference to the payment instrument, and we keep these with the invoice as tax law requires. For bank transfers we record the UTR and payer details shown on our bank statement.
Institutions that collect fees from parents through the Service do so through their own payment gateway account. In that case we process the transaction reference and status on the Institution's behalf and never hold the funds.
9. Where data is stored and transfers
The Website is hosted with Hostinger. The Service runs on Hostinger cloud servers located in Mumbai, India, and uploaded files and encrypted backups are stored with Cloudflare R2. Where personal data is stored in or accessed from a country outside India, we do so only as permitted by section 16 of the DPDP Act and protect it with contractual and technical safeguards. Institutions that require their data to remain in India should raise this with us before purchase.
10. How we protect data
- All traffic to the Website and the Service is encrypted in transit with TLS.
- Each Institution's data is kept in its own database, and row-level security enforced by the database itself prevents one Institution's users from reading another Institution's records.
- Highly sensitive fields, including biometric templates, medical notes and multi-factor authentication secrets, are additionally encrypted at the application layer, with support for key rotation.
- Access is controlled by roles and permissions set by the Institution, with optional multi-factor authentication, session expiry and automatic lockout after repeated failed sign-ins. Every change is written to an audit log, and deleted records can be restored by administrators.
- Institution Data is backed up every night. Backups are encrypted, kept for 14 days on our servers and 90 days off-site, checked for integrity, and restored in rehearsals.
- Our staff have least-privilege access to production systems, do not keep production data on personal devices, and security updates are applied regularly.
- If we confirm a breach affecting personal data, we notify the affected Institutions without undue delay and within 72 hours, with the information they need to notify Data Principals and the authorities as the law requires.
11. How long we keep data
| Data | Retention |
|---|---|
| Demo enquiries and sales correspondence | 24 months from last contact, or until you ask us to delete it |
| Website analytics | 12 months |
| Security and rate-limit logs | Up to 30 days |
| Institution Data during an active Licence | For the Term, as instructed by the Institution |
| Institution Data after expiry or termination | Retained for a 30-day export window, then deleted or anonymised within 90 days of expiry or termination, or earlier on request; backups age out within a further 90 days |
| Invoices, payments and tax records | Eight years, as required by GST and income-tax law |
| Support correspondence | 24 months |
12. Your rights
Under the DPDP Act you have the right to access a summary of the personal data being processed about you, to have inaccurate or incomplete data corrected or updated, to have data erased when it is no longer needed for the purpose it was collected for or the law does not require us to keep it, to have your grievances heard, and to nominate someone to exercise these rights on your behalf. You may withdraw consent to marketing communications at any time.
If you are a student, parent or staff member of an Institution, please make your request to the Institution, which is your Data Fiduciary. The Service gives Institutions the tools to view, correct, export and delete records, and we assist them so they can respond within the statutory time. If you contacted us through the Website, write to support@smartcampussai.com. We verify identity before acting on a request and respond within 30 days.
14. Changes to this Policy
We may update this Policy as the Service, our providers or the law change. Material changes are announced to Institutions by email or a notice in the Service at least 30 days before they take effect, and the date and version at the top of this page are updated. Earlier versions are available on request.
15. Grievance Officer
Our Grievance Officer under the Information Technology Rules and the DPDP Act is Mohammad Jani Basha, who can be reached at grievance@smartcampussai.com or at the postal address in the Contact section below. We acknowledge every grievance within two working days and aim to resolve it within 30 days. If you are not satisfied with our response, you may approach the Data Protection Board of India or any other authority designated under applicable law.
16. Contact
SmartCampus AI TechnologiesA sole proprietorship registered in India · Proprietor: Mohammad Jani BashaRamachandra Nagar, Kurnool, Andhra Pradesh 518002, India
GSTIN 37GPYPS4513H1Z3
Email: support@smartcampussai.com · Phone / WhatsApp: +91 90109 30360
Support hours: Monday to Saturday, 9:00 AM – 6:00 PM IST
Grievance Officer: Mohammad Jani Basha (grievance@smartcampussai.com)