1. Definitions
“System” refers to the High Tech Child Safety Systems. “Personal Data” means any information relating to an identified or identifiable individual. “Processing” includes collection, recording, storage, use, disclosure, or deletion of data. “Institution” refers to the school or organization deploying the System.
2. Data Collection
We collect only data necessary for legitimate attendance tracking purposes.
- Name, Roll Number or Employee ID
- RFID Card Unique Identifier (UID)
- Class or Department details
- IP address and login activity
- Last login location (where enabled)
- System audit logs
We do not collect biometric data unless separately integrated through institutional authorization.
Passwords are stored in encrypted hashed format using industry standard cryptographic mechanisms.
3. Legal Basis for Processing
Processing of Personal Data is conducted in accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.
- Institutional authorization
- Legitimate interest in attendance management
- Explicit consent where legally required
4. Purpose of Processing
- Recording attendance via RFID authentication
- Generating compliance reports
- Monitoring punctuality
- Ensuring institutional security
- Maintaining audit logs
We do not sell, rent, lease, or trade Personal Data to third parties.
6. Data Retention
Attendance records are retained for 3–7 years as per institutional policy. System logs are retained for up to 12 months. Data is permanently deleted after the retention period expires.
7. Security Measures
- HTTPS (SSL/TLS) encryption
- Encrypted database storage
- Role-Based Access Control
- Firewall protection
- Device authentication controls
- Account lockout after repeated failed attempts
8. User Rights
- Right to access Personal Data
- Right to correction
- Right to erasure subject to legal retention
- Right to withdraw consent
- Right to grievance redressal
9. Children’s Data Protection
Where the System is deployed in schools, data of minors is processed strictly under institutional authorization and parental consent. No behavioral profiling or targeted advertising is conducted.
10. Data Breach Notification
In the event of a data breach, immediate containment measures will be undertaken. Investigation shall commence within 72 hours, and affected institutions and authorities shall be notified as required by law.
