1. Introduction
This Privacy Policy explains how Zenexis Solutions Private Limited (“Zenexis”, “we”, “us”, or “our”), a company registered and operating from Bidar, Karnataka, India, collects, uses, discloses, stores and protects personal data when you use our products and services - including our ZenSchool WebApp, the Zen ERP Android and iOS mobile applications, server-hosted services, and our IoT attendance terminal devices (collectively, the “Services”).
This Policy applies to data collected from users (employees, students, parents, visitors, administrators and others) using our ERP and related products including attendance, leave, payroll, fee and receipt management, visitor management, mobile apps, web portal and IoT terminals.
This document is written for public display on our website and to be linked in Play Store / App Store listings. It is intended to be clear and actionable.
2. Who we are (Data Controller)
Data Controller: Zenexis Solutions Private Limited
Registered office: #581, 1ˢᵗ floor, 5ᵗʰ cross, Gandhi Nagar North, Mailoor, Bidar, Karnataka, India 585403.
Company identifiers: MCA-registered (CIN: U47413KA2024PTC195517) - MSME & Startup India certified.
Contact / Privacy Officer: [email protected], +91-6363740943
This Privacy Policy specifically governs the Zen ERP Mobile Application (Android Package ID: com.zenexistech.zen_erp) and the ZenSchool ERP Web Platform. Under applicable Indian data protection law (including the Digital Personal Data Protection Act, 2023), Zenexis acts as the Data Controller (Data Fiduciary) for all personal data processed through the Services and is committed to responsible data handling.
3. Key Takeaways
- We collect contact, identity, device, usage, attendance images, and biometric-derived face embeddings to operate ERP services.
- Biometric processing is used only for attendance, identity verification, and fraud prevention with explicit consent.
- We display advertisements using Google AdMob (in our Zen ERP mobile app) and Google AdSense (on our WebApp), which use cookies and device identifiers to serve and personalize ads.
- Users can request complete account and data deletion at any time.
- Users have rights including access, correction, erasure, portability, consent withdrawal, and grievance redressal.
4. Information We Collect
We collect the following categories of personal data depending on the services and features used.
A. Identity & Contact Information
Full name, job/role, employee or student ID, photograph, email address, phone/mobile number, address, organization/institution affiliation.
B. Authentication & Account Data
Login credentials (hashed), authentication tokens, account settings, multi-factor authentication data (if enabled).
C. Biometric & Sensor Data (Face Recognition)
Photographs or video stills, derived face embeddings or templates. Used only for attendance and authorised verification. Processed strictly with explicit consent.
D. Attendance, Time & Location
Time-stamped attendance logs, device or terminal identifiers, check-in and check-out timestamps, geo-location (only when enabled and consented).
E. Payroll, Financial & Fee Data
Salary components, bank account details for payroll, fee payment records and receipts, transaction IDs and billing metadata.
F. Device & Technical Data
IP address, browser and operating system details, mobile device identifiers (including Android Advertising ID / Google Advertising ID (AAID)), IoT terminal logs, diagnostic and performance logs.
G. Visitor & Access Records
Visitor name and ID, visitor photograph, purpose of visit, host details.
H. Cookies & Analytics
Cookies and session identifiers, usage analytics and aggregated metrics.
5. How we collect data
- Directly from users during registration, configuration, and usage of apps and devices.
- From authorised representatives of organisations or institutions.
- Automatically through devices, applications, servers, logs, and telemetry.
- From third-party subprocessors such as payment, analytics, or notification services.
6. Why we collect data - purposes and legal basis
We process personal data only for lawful, specific, and explicit purposes. Primary purposes include:
- Operating ERP services such as attendance, leave, payroll, fees, and visitor management.
- Performing face-based identity verification with explicit informed consent.
- Processing payroll, payments, and statutory compliance.
- Improving system reliability, analytics, security, and fraud prevention.
- Displaying ads to support free/trial tiers (via Google AdMob in mobile app, and Google AdSense on the web portal).
- Responding to support requests, grievances, and legal obligations.
Biometric processing is strictly limited to attendance and authorised verification and is never sold or reused for unrelated purposes.
7. Consent, children & minors
- Explicit consent is required for biometric processing.
- Consent is recorded and can be withdrawn at any time.
- Withdrawal of consent may disable face-based features.
- For minors (under 13 in the US/EU, or under 18 in India), parental or guardian consent is mandatory.
- In compliance with COPPA (Children's Online Privacy Protection Act), India's DPDP Act, and Google Publisher Policies, we do not serve personalized or interest-based ads to users known to be children or minors. If the user account is identified as belonging to a student under the age of 18, we restrict ad serving to non-personalized, contextual advertisements only.
- Data collected from minors without valid consent will be deleted unless legally required.
8. Advertising, Analytics & Diagnostics (AdMob, AdSense & Firebase)
We use third-party advertising, analytics, and diagnostics services to support our services, analyze usage, and improve application stability. Specifically, we use Google AdMob and Google Firebase (Analytics & Crashlytics) in our mobile application and Google AdSense on our web portal.
A. Google AdMob (Mobile Application)
We integrate the Google Mobile Ads SDK (AdMob) in the Zen ERP Android application. Google and its partner advertising networks may collect and use device information, IP addresses, Google Advertising ID (AAID), device type, network carrier, and app interaction data to deliver personalized or contextual advertisements, measure ad performance, and prevent fraud.
B. Google AdSense (Web Application)
On our web portal, we use Google AdSense to serve advertisements. Google uses cookies to serve ads based on your prior visits to our website or other sites on the Internet. Google's use of advertising cookies enables it and its partners to serve ads to our users based on their visit to our site and/or other sites on the Internet.
C. Google Firebase (Analytics & Crashlytics)
We integrate the Google Firebase SDK in our Zen ERP mobile application and web portal to analyze app usage, track performance metrics, and collect crash logs. These tools collect device identifiers, crash data, and user interaction details to help us troubleshoot errors, monitor app stability, and improve overall service quality.
D. Opting Out of Personalized Advertising & Tracking
- Web Portal: You can opt out of Google's personalized advertising by visiting Google Ads Settings (https://www.google.com/settings/ads).
- Mobile App: You can opt out of personalized/interest-based ads in the Zen ERP app by adjusting the advertising settings on your Android device (Settings -> Google -> Ads, and select "Opt out of Ads Personalization").
9. Data Security
We implement appropriate technical and organisational safeguards:
- Encryption in transit and at rest for sensitive data.
- Role-based access control and audit logging.
- Secure IoT device authentication and firmware controls.
- Regular backups and disaster recovery planning.
In case of a confirmed data breach, affected users and regulators will be notified as required by law.
10. Data retention
- Account and contact data is retained while accounts remain active and for limited periods after deactivation.
- Attendance logs and biometric templates follow configurable customer retention policies.
11. Account & Data Deletion
Google Play Store and our user trust policies require a clear mechanism for account and data deletion. Users have the right to request deletion of their account and all associated personal data at any time.
A. How to Request Deletion
- Web Request: Visit our online Request page at https://zenexistech.com support (or contact your institution administrator).
- Email Request: Contact our Privacy Officer directly at [email protected] with the subject line "Account Deletion Request".
B. What Data is Deleted
Upon receiving a valid deletion request: Your account credentials, profile details, and personal settings will be permanently erased. Any biometric templates/embeddings used for attendance will be permanently deleted from our servers. General school ERP records might be archived/retained by your school administration in accordance with local regulations, but your direct personal login access and linked mobile identifiers will be fully deleted.
C. Data Processing Time
We will process your deletion request within 15 business days. Once processed, the data is deleted permanently and cannot be recovered. We only retain backup logs for up to 30 days or as required by law for statutory compliance.
12. Your rights and how to exercise them
You may have the following rights under applicable law: Access your personal data, correct inaccurate or outdated information, request erasure where legally permitted (including account deletion), obtain a portable copy of your data, withdraw consent at any time, or lodge a grievance with the Grievance Officer.
13. Legal & Compliance Note
This policy is designed for compliance with Indian data protection law (DPDP Act 2023), GDPR, COPPA, and Google Play Store/Publisher policy requirements.