On this page
This Privacy Policy describes how Zenithsystems Private Limited, operating under the brand name Zenith Systems ("Zenith Systems", "Zenith", "we", "us" or "our"), collects, uses, stores, discloses and protects personal data.
This Policy applies to our websites, applications, platforms, products and services, including our Software-as-a-Service products, school management and ERP platforms, Curriculo, academic and curriculum-management tools, artificial intelligence features, mobile applications, web applications, APIs and related implementation, support and technology services (collectively, the "Services").
Scope
This Privacy Policy applies when personal data is processed through our websites, Zenith Systems web and mobile applications, Curriculo, school ERP and education-management products, AI-powered features, customer accounts, product demonstrations and enquiries, customer onboarding, technical support, subscriptions, authorised integrations and other Services provided by Zenith Systems.
Additional contractual provisions may apply where a school, business or other organisation uses our Services, including the Data Processing Terms incorporated into our Terms and Conditions.
Our Role in Processing Personal Data
Where Zenith Systems determines the purpose and means of processing — for example, for website enquiries, customer accounts, billing, security, product administration and customer support — Zenith Systems may act as the Data Fiduciary or equivalent controller under applicable law.
Schools and other organisations may use our Services to process information concerning students, parents, guardians, teachers, employees and other users. Where the customer determines why such personal data is processed and instructs Zenith Systems to process it in connection with the Services, the customer will generally act as the Data Fiduciary and Zenith Systems will act as a Data Processor on the customer's behalf.
Individuals whose information has been provided to us by a school or other organisation should ordinarily contact that organisation regarding the use of their information.
Information We May Process
The information processed depends upon the Services and modules used, and may include the following categories:
- Identity and profile information — name, profile photograph, user ID, employee or student ID, role, class/section/grade, department, organisational affiliation.
- Contact information — email address, mobile or telephone number, parent or guardian details, communication information associated with an account.
- Educational information — enrolment, class and section, subjects and curriculum, timetables, attendance, assignments, examinations, marks and grades, academic performance, lesson plans, student reports and certificates, teacher information and guardian relationships.
- Administrative and employee information — staff records, attendance, department information, organisational roles, schedules, leave information and other administrative records.
- Account and security information — usernames, authentication credentials, hashed passwords, login activity and session data, permissions and roles, audit logs and security events.
- Financial and transaction information — fee records, invoice information, payment status, transaction references, subscription and billing information.
- Technical information — IP addresses, browser and operating-system information, device identifiers, application versions, timestamps, diagnostics, error logs and usage information.
- Communications and support — emails, support requests, issue reports, chat history, feedback and other information voluntarily provided.
- AI interactions — prompts and instructions, questions, documents supplied to an AI feature, context required to provide authorised answers, generated responses, and institutional data the requesting user is authorised to access.
Payment-card or banking information may be processed directly by third-party payment providers. Zenith Systems does not intend to store complete payment-card credentials where payment processing is handled by an authorised payment provider, and does not intend to store user passwords in readable plaintext form.
Sources of Personal Data
We may obtain personal data:
- directly from the individual
- from a school or organisation
- from authorised administrators
- through account registration
- through data imports
- through authorised integrations
- through use of our Services
- through customer-support interactions
- automatically through operation of our applications and security systems
Purposes of Processing
Personal data may be processed to:
- operate and deliver the Services
- create and administer accounts
- authenticate users and apply role-based permissions
- provide school-management and academic-planning functionality
- process authorised educational information
- generate reports, documents and analytics
- provide AI-powered features
- enable authorised communications
- process subscriptions, billing and payments
- provide implementation, maintenance and support
- maintain service security and prevent unauthorised access
- maintain audit and security logs
- diagnose technical issues and improve reliability
- fulfil customer contracts
- comply with legal obligations and investigate misuse
- protect our customers, users and systems
Lawful Processing and Consent
Zenith Systems processes personal data only for lawful purposes and in accordance with applicable law. Where consent is required, appropriate consent should be obtained before the relevant processing occurs.
Where Zenith Systems processes information on behalf of a customer, the customer is responsible for establishing the appropriate lawful basis for providing the information to Zenith Systems and instructing us to process it.
Students and Children's Personal Data
Our educational Services may process information concerning individuals under the age of eighteen. We recognise that children's personal data requires additional protection.
Where a school provides student personal data to Zenith Systems, the school is responsible for:
- determining the purposes for which student information is processed
- providing appropriate privacy notices
- establishing a lawful basis for processing
- obtaining parental or lawful-guardian consent where required
- ensuring its instructions to Zenith Systems comply with applicable law
Zenith Systems will process student information only for authorised educational, administrative, security, operational and service-related purposes. Zenith Systems does not sell children's personal data, does not use student personal data for targeted advertising, and does not intentionally conduct behavioural advertising profiling of students.
Artificial Intelligence
Certain Zenith Systems products contain artificial intelligence or machine-learning functionality. AI features may assist with curriculum planning, lesson planning, academic planning, reports, summaries, document generation, recommendations, analysis, educational content, administrative assistance and natural-language interaction with authorised information.
AI-generated output can contain errors, omissions or inaccuracies and should be appropriately reviewed by a human before being relied upon for consequential decisions.
Access to institutional information through AI features remains subject to applicable user permissions and customer configuration. Zenith Systems may use third-party AI infrastructure or model providers to perform AI operations, and information necessary to fulfil an AI request may therefore be transmitted to such providers subject to applicable contractual, privacy and security safeguards. Customers and users must not submit personal data to AI features unless authorised to process that information.
Disclosure and Service Providers
We may engage service providers including:
- cloud infrastructure providers
- database and storage providers
- AI and machine-learning providers
- email, SMS and messaging providers
- authentication providers
- payment processors
- security and monitoring providers
- analytics providers
- technical-support providers
- professional advisers
Such providers receive only the information reasonably necessary to perform the relevant service and are expected to process information subject to appropriate contractual or legal safeguards. Information may also be disclosed to courts, law-enforcement agencies, regulators, government authorities or other persons where disclosure is required by applicable law.
Corporate Transactions
Information may be transferred in connection with a merger, acquisition, restructuring, financing, investment, sale of business or transfer of assets. Where required, appropriate safeguards will apply to such a transfer.
No Sale of Personal Data
Zenith Systems does not sell personal data as part of its business model. Our business model is based upon software subscriptions, implementation, technology services, support and related products and services.
International Processing and Hosting
Our Services may use cloud and technology infrastructure located in India or other jurisdictions. Where information is processed outside India, such processing will be performed as permitted by applicable law and applicable customer agreements.
Customer-specific hosting or data-residency requirements may be specified separately in an Order Form, Statement of Work or enterprise agreement.
Data Retention
Personal data is retained only for as long as reasonably necessary for the purpose for which it was processed — providing the Services, fulfilling a customer contract, security, audit requirements, legal compliance, dispute resolution, fraud prevention, backup and disaster recovery, and enforcement of agreements.
Where Zenith Systems processes personal data for a customer, retention is also governed by the customer's lawful instructions and our contractual obligations. After termination of a customer account, customer information may be returned, exported, deleted or anonymised in accordance with the applicable agreement and law. Certain information, including security records, transaction records, audit records, logs and backups, may be retained for longer periods where required for security or compliance with law.
Security
Zenith Systems maintains reasonable technical and organisational measures designed to protect personal data. Depending upon the Service, measures may include:
- encryption where appropriate
- access controls
- role-based permissions
- authentication mechanisms
- logging and monitoring
- secure cloud infrastructure
- backup systems
- network security
- vulnerability management
- incident response
- restricted administrative access
No technology system can be guaranteed to be completely secure. Users are responsible for protecting their credentials and promptly reporting suspected account compromise.
Personal Data Breaches
Zenith Systems maintains procedures for investigating suspected security incidents. Where Zenith Systems becomes aware of a personal-data breach, we will take reasonable measures to investigate, contain, mitigate and remediate the incident and make notifications required under applicable law.
Where Zenith Systems acts as a Data Processor, we will notify the relevant customer without undue delay after becoming aware of a confirmed breach materially affecting that customer's personal data.
Individual Privacy Rights
Depending upon applicable law and our role in relation to the information, individuals may have rights including:
- obtaining information about processing
- requesting correction of inaccurate information
- requesting completion or updating of information
- requesting erasure where applicable
- withdrawing consent where processing relies on consent
- submitting a grievance or complaint
- exercising other rights provided by applicable law
Where information is controlled by a school or organisation, requests should generally be directed to that organisation. Requests concerning information controlled directly by Zenith Systems may be sent to support@zenithsystems.org.in. We may verify the identity or authority of the requester before completing a request.
Institutional Administrators
Where a Zenith Systems product is provided through an institution, authorised administrators may be able to create or remove accounts, reset access, assign roles, view institutional records, manage modules, configure permissions and perform other administrative actions. The organisation is responsible for determining which individuals receive administrative privileges.
Third-Party Services
Our Services may contain links to or integrations with services operated independently by third parties. Independent third-party services are governed by their own privacy policies and contractual terms. Zenith Systems is not responsible for independent processing undertaken by third parties outside our control.
Changes to this Policy
We may periodically update this Privacy Policy because of changes to our Services, technology, processing activities, applicable law or operational practices. The revised Policy will display an updated "Last Updated" date. Material changes will be communicated where required by law.
Governing Law
This Privacy Policy is governed by applicable laws of India, including applicable data-protection and information-technology laws. Nothing in this Policy limits rights that cannot legally be excluded or restricted.
Privacy and Grievance Contact
Questions, complaints, privacy requests and grievances may be submitted to:
We will endeavour to review and respond to legitimate requests within the period required by applicable law.
