ZenScope Privacy Policy
1. Introduction
Zenscope Technologies Private Limited (“ZenScope”, “we”, “our”, “us”) operates an AI-powered school management platform (“Platform”) provided as a Software-as-a-Service (SaaS) to educational institutions across India. This Privacy Policy explains how data is collected, processed, stored, and protected through our Platform.
ZenScope acts solely as a secure technology infrastructure and data processing provider. We do not own, control, or claim rights over any institutional, student, or parent data processed through our Platform.
2. Data Ownership
Schools Own Their Data at All Times
All student, parent, staff, and institutional data uploaded or processed through ZenScope remains the sole property of the respective educational institution (“School”). ZenScope does not claim ownership over any institutional or student data. Schools retain full ownership and control at all times.
3. Data We Collect
To deliver high-fidelity management modules, ZenScope processes two core categories of information: Institutional Data provided by the school administrators, and Platform Operational Data generated during standard use.
Institutional Data (On behalf of Schools)
- Student Profiles: Name, admission number, photograph, class, section
- Parent and guardian contact information
- Attendance records
- Academic and certificate data
- Fee and financial records
- Bus route and GPS tracking data
- Staff profiles and roles
Platform Operational Data (Collected Directly)
- Account Credentials: Secure login credentials (encrypted)
- Device and browser information
- Platform usage logs and activity metadata
- Support communication records
We do not collect data beyond what is necessary to operate and deliver the Platform.
4. How We Use Data
Data is used exclusively to:
- Deliver contracted Platform services to Schools
- Generate reports, certificates, and communications as configured by the School
- Provide technical support when authorized by the School
- Maintain platform security and integrity
- Comply with applicable legal obligations
We do not use institutional or student data for advertising, profiling, analytics products, or any commercial purpose beyond contracted service delivery.
5. Data Access Policy
ZenScope personnel do not access institutional data except when:
- Explicitly authorized by the institution in writing or through authenticated support request
- Required for technical maintenance or bug resolution
- Required for security investigation of a reported incident
- Required by applicable Indian law or court order
6. Multi-Tenant Data Isolation
Strict Logical Separation
ZenScope uses enterprise-grade multi-tenant architecture. Each institution's data is logically isolated using Row-Level Security (RLS), tenant-scoped authorization, and encrypted storage. One institution cannot access, view, or interfere with another institution's data. ZenScope implements strict technical and organizational safeguards designed to prevent unauthorized cross-institution data access.
7.Children's Data Protection
ZenScope processes children's personal data solely under authorization from educational institutions, and where applicable, parents or guardians, in accordance with applicable Indian law.
- We do not sell, advertise to, or commercially exploit children's personal data.
- Children's data is processed strictly for institutional management purposes.
- Data access is restricted to authorized school staff and parents of the respective child only.
8. Government and Regulatory Access
Where applicable, government or regulatory bodies may be granted access to specific data through explicitly scoped, read-only APIs configured in accordance with institutional permissions and applicable legal frameworks. ZenScope does not permit unauthorized modification of institutional records by external entities.
9. Data Security
ZenScope implements industry-standard security practices. We design our systems to significantly reduce security risks through enterprise-grade architecture. No system can guarantee absolute security; however, we employ strong encryption and access controls aligned with industry best practices. Key protocols include:
AES-256 Encryption
For data at rest, and TLS 1.3 for data in transit.
JWT & MFA
JWT-based authentication with Multi-Factor Authentication.
RBAC Controls
Strict Role-Based Access Control and signed URLs for documents.
Audit Logging
Immutable audit logs, encrypted PII, and regular security reviews.
9A. Compliance Commitment
ZenScope is committed to complying with applicable Indian data protection laws, cybersecurity standards, and educational regulations, including evolving Digital Personal Data Protection (DPDP) requirements.
10. No Data Selling
Zero Commercialization of Data
ZenScope does not sell, rent, trade, monetize, or disclose institutional or student personal data to any third party for commercial purposes.
11. Data Retention
School data is retained for the duration of the active subscription agreement. Upon termination or non-renewal:
- Schools may request a full data export within 30 days of termination.
- Data is permanently deleted from ZenScope systems within 60 days of termination unless otherwise required by law.
- Certificate verification records may be retained in anonymized form for cryptographic integrity purposes.
12. Third-Party Services
ZenScope uses select third-party infrastructure providers (cloud hosting, storage, communications) under strict data processing agreements. These providers are prohibited from using your data for any purpose beyond contracted service delivery.
ZenScope may rely on third-party infrastructure providers, APIs, cloud services, and open-source components subject to their respective terms and operational availability.
13. School Responsibilities
Schools are responsible for:
- Obtaining all required consents from parents and guardians as required by applicable law.
- Ensuring accuracy and legality of uploaded data.
- Managing user access and permissions within their account.
- Notifying ZenScope promptly of suspected unauthorized access.
14. Your Rights
Institutions and individuals (through institutions) may request:
- Access to their stored data.
- Correction of inaccurate data.
- Deletion of data (subject to legal retention requirements).
- Data portability.
Requests can be submitted to: support@zenscope.in
15. Changes to This Policy
ZenScope will notify institutions of material changes to this Privacy Policy at least 30 days in advance via registered email. Continued use of the Platform after the effective date constitutes acceptance.
16.Backup & Recovery
ZenScope maintains periodic encrypted backups and disaster recovery procedures designed to support platform continuity and data recovery.
17. Contact
Entity: Zenscope Technologies Private Limited
Email: support@zenscope.in
Contact: +91 73825 35173
Website: www.zenscope.in
Registered Office: Khammam, Telangana – 507002, India