Privacy Policy โ€” iSCIMZ

How the iSCIMZ (Smart Campus & Institute Management System) mobile application collects, uses, and protects information.

Last updated: 23 July 2026

This Privacy Policy explains how the iSCIMZ mobile application (the “App”) collects, uses, discloses, and safeguards information.

iSCIMZ is a school and campus management application provided to an educational institution and used by its authorised users — parents / guardians of enrolled students, teachers, school guardians (mentors), and office staff. Accounts are created and managed by the institution; there is no public sign-up. By using the App, the authorised user acknowledges the practices described here.

Contents

1. Information we collect

a. Account information

When an authorised user signs in, we process their account details, including name, email address, phone number, assigned role (parent, teacher, guardian, or office staff), and the institution and campus they belong to. Sign-in credentials are transmitted securely to authenticate the session; authentication tokens are then stored in the device's secure storage.

b. Student and academic records

The App displays and manages records about enrolled students. Depending on the signed-in user's role and permissions, these may include:

A parent or guardian sees only the students linked to their account. Staff see only the classes, sections, and students their role and permissions allow.

c. Staff work records

For teacher, guardian, and office staff accounts, the App processes work-related records such as clock-in and clock-out times, attendance history, daily work logs, leave applications and their status, assigned classes and substitutions, and payslip summaries (period and net pay).

d. Photographs

The App can capture or select photographs — a class photograph used for attendance, and profile photographs. See Section 2, which explains face recognition separately because of its sensitivity.

e. Device and technical information

To operate reliably, the App processes limited technical information such as network requests to our server and the status of permissions you have granted. The App does not collect your location, does not read your contacts, call log, SMS, or microphone, and contains no third-party advertising or advertising-based tracking.

2. Photographs and face recognition

Please read this section carefully. Where the institution enables the optional “Photo AI” attendance feature, the App processes facial images, which are a form of sensitive personal data.

The Photo AI attendance feature works as follows:

The class photograph and the resulting detection data are stored on our backend server as the record supporting that attendance session. Facial templates for students are held by the institution to enable this matching.

This feature is optional and is enabled by the institution. If it is not enabled, or if a teacher does not use it, no facial image is captured or processed by the App and attendance is marked manually. Where required by applicable law, the institution is responsible for obtaining the necessary consent from students and their parents or guardians before facial recognition is used, and for honouring withdrawal of that consent.

To request deletion of a student's facial template, see our Account & Data Deletion page.

3. Device permissions and why we use them

The App requests only the Android permissions it needs. You may grant or deny these; the related features will not work without them, but the rest of the App will continue to function.

PermissionWhy the App uses it
CAMERA To capture a class photograph for Photo AI attendance, and to take profile or verification photographs. The camera is only activated when you tap a control that opens it.
READ_MEDIA_IMAGES (Android 13+)
READ_EXTERNAL_STORAGE (older Android)
To let you choose an existing photograph from your device instead of taking a new one.
WRITE_EXTERNAL_STORAGE (Android 12 and older only) To hold a captured or selected image temporarily on the device while it is being prepared for upload. Not requested on Android 13 and above.
INTERNET To securely send and receive data to and from our backend server.

The App does not request location, contacts, microphone, call log, or SMS permissions.

4. How we use information

We do not sell personal information, and we do not use it for third-party advertising or profiling.

5. How we share information

We share information only as needed to operate the service:

6. Fee payments

Where the institution enables online fee payment, selecting an invoice initiates a UPI payment request. The payment itself is completed in your own UPI application. The App does not collect, process, or store your card number, bank account credentials, UPI PIN, or any other payment credentials. We receive only the resulting payment status for the invoice, and the invoice is marked paid once the payment is verified.

7. Data retention

Student and institutional records are retained by the institution for as long as necessary for its educational, administrative, and legal purposes. Account records are retained while the account remains active. When information is no longer required, it is deleted or anonymised. See our Account & Data Deletion page for how to request deletion and what can and cannot be removed.

8. Security

Access to the App requires authentication, and communication with our server is encrypted in transit (HTTPS/TLS). Authentication tokens are stored in the device's secure storage (Android Keystore-backed encrypted storage), not in plain files. Access to records is restricted by role, so a user sees only what their role permits. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; users must keep their credentials confidential, sign out on shared devices, and use a secured device.

9. Data about students and minors

The App is used by adults — parents, guardians, and staff — and is not directed to children, who do not hold their own accounts. However, the records shown and managed in the App relate to enrolled students, most of whom are minors, and may include a student's photograph and, where the institution enables it, a facial template.

This information is processed on behalf of and under the instruction of the educational institution, in the course of its educational activities and in accordance with applicable law. A parent or guardian may contact the institution, or us at the address below, regarding the information held about their child.

10. Your rights and choices

Subject to applicable law, individuals whose personal data we process may request access to, correction of, or deletion of their information, may object to or restrict certain processing, and may withdraw consent where processing is based on consent (including for facial recognition). You may also deny or revoke any device permission from your device settings at any time.

Because records in the App belong to the educational institution, requests relating to student or academic records may be directed to the institution, or made to us using the contact details below and we will coordinate with the institution.

11. Third-party services

The App relies on our own backend server and its hosting infrastructure, and on our face-recognition service where that feature is enabled. The App does not embed third-party advertising or advertising-analytics SDKs. In addition:

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will post the updated policy here and revise the “Last updated” date above. Continued use of the App after changes take effect constitutes acceptance of the updated policy.

13. Contact us

If you have questions or requests regarding this Privacy Policy or your information, contact us at:

Email: itskillparkdbi@gmail.com