Privacy Policy

Last updated 31 August 2026

IC ERP ("we", "us", "the Platform") is school-management software used by educational institutions ("Institutions") to manage admissions, students, staff, fees, attendance, transport, and related operations. Each Institution is a separate tenant on the Platform; its data is never visible to another Institution. This policy explains what personal data the Platform processes, on whose behalf, and how it's protected.

1. Who controls your data

Your Institution — the school, college, or academy you're enrolled at, employed by, or a guardian of a student at — is the data controller for the personal data described below. We act as the Institution's data processor: we host the Platform and process data on the Institution's instructions, but the Institution decides what data is collected and how it's used. Questions about your specific records should go to your Institution first; see Contact if you need to reach us directly.

2. What we collect

Depending on your role and which modules your Institution has enabled, this includes:

  • Identity & contact data — name, date of birth, CNIC/B-Form or other national ID, address, phone number, email, and photo, for students, guardians, and staff.
  • Academic records — enrollment, class/section, attendance, timetable, homework, exam results, and report cards.
  • Biometric attendance data — where an Institution enables biometric devices for staff or student attendance, a fingerprint template (not a raw fingerprint image) is stored to match future punches. This is processed only for attendance and is never used for any other purpose.
  • Financial data — fee challans, payment history, scholarships, and, for staff, payroll records.
  • Transport & location data — for Institutions using live bus tracking, a driver's phone reports GPS location only while they are signed in and on an active shift, so guardians can see the bus's real-time position. Location is not collected outside of an active shift, and is not collected from guardian, student, or non-driver staff devices at all.
  • Usage & device data — login activity, IP address, device/browser type, and app diagnostics, for security and support.

3. How data is isolated between institutions

The Platform enforces tenant isolation at the database level — every query is scoped so that one Institution's data is never returned to another, regardless of application-layer bugs. Staff access within an Institution is further restricted by role and branch: a capability-based permission system, not a hardcoded list, decides what each role can see and do, and every sensitive change is written to an audit trail.

4. Why we process this data

  • To operate the academic, financial, and administrative functions your Institution uses the Platform for.
  • To let guardians and students see attendance, results, fees, and transport status.
  • To secure accounts (authentication, fraud/abuse prevention) and maintain audit trails required for financial and academic record-keeping.
  • To provide support when your Institution or you contact us about an issue.

5. Who we share data with

We don't sell personal data. Data may be shared with: payment processors to complete a fee payment you initiate; SMS/email/WhatsApp providers to deliver notifications your Institution configures; and infrastructure providers who host the Platform under a confidentiality obligation. Any such processor only receives what's necessary to perform its function.

6. Data retention and deletion

Data is retained for as long as your Institution's account is active, plus any period required by academic or financial record-keeping obligations. Guardians and staff can request deletion of their own account or a linked child's record from within the app (Settings → Data & account deletion); a request goes through a grace period, during which it can be withdrawn, before the record is permanently anonymised.

7. Your rights

Depending on your jurisdiction, you may have rights to access, correct, or request deletion of your personal data, and to object to certain processing. For anything specific to your own record, start with your Institution or the in-app deletion request flow; for anything about the Platform itself, use the Contact page.

8. Changes to this policy

We'll update the "Last updated" date above whenever this policy changes materially. If a change meaningfully affects how we handle your data, we'll make a reasonable effort to notify Institutions in advance.