§ 13 · Legal

Legal documentation.

Comprehensive legal policies governing the use of Infocing SaaS Platform. We prioritize transparency, security, and user control.

Privacy Policy

Last updated: 01/01/2026Version 3.1GDPR CompliantEncryptedUser Controlled

Executive Summary

This Privacy Policy governs how Infocing ("we", "our", "us") collects, processes, stores, and protects institutional data through our institute management platform. We operate on a principle of minimum necessary access, user-controlled encryption, and complete transparency in all data handling operations.

01

Data Collection Framework & Categories

Core Institutional Data (All may not be mandatory)

  • Complete organizational structure
  • Academic hierarchies and departments
  • Infrastructure and facility details
  • Financial and operational policies
  • Academic, learning and examination details

Personnel & Student Data (All may not be mandatory)

  • Staff records (academic & non-academic)
  • Student demographic information
  • Guardian/emergency contact details
  • Employment and enrollment history
  • Documentations and certificates
ApplicationData collectedPermissions requiredPurpose
Infocing Mate (Student)• Academic records • Assignment submissions • Student demographics based on the available data • Examinations data • Academic activities and structure data • Finance data • User-submitted data • All records based on the data submitted by the institute administration • No location tracking • No background data collection• Camera (optional) • Notifications • Gallery access (documents submission only)Academic management, assignment submission, academic lifecycle management, schedule management, communication, learning management
Infocing Pilot (Staff)• Location data (geo-fenced attendance) • Background location verification • Staff photos for attendance • All records based on the data submitted by the institute administration • Professional records• Camera (optional, required for attendance) • Location (premises verification) • Notifications • Background location (attendance validation)Staff attendance verification, professional management, learning management, student tracking, student finances, staff lifecycle management
Infocing Admin• Administrative access only • All records based on the data submitted by the institute administration • System configuration data• Standard administrative permissions • NotificationsSystem administration and management

In summary

In summary, our data collection framework is designed to ensure complete transparency, security, and compliance with institutional requirements. We collect a range of core institutional data, personnel, and student information, only as necessary to support the specific academic, administrative, and operational needs of the institution. For application-specific data, each platform collects only the information required to fulfill its designated purpose, such as academic management, attendance tracking, professional lifecycle management, and administrative operations. All data collection practices are clearly communicated to the institution, and permissions are explicitly requested when sensitive resources such as cameras, location services, or document access are involved. We prioritize data minimization and limit collection strictly to what is essential for functionality. By implementing these practices, we ensure that institutions retain full control over their data, with our role being strictly confined to secure processing, storage, and authorized integration. This approach underscores our commitment to being a trustworthy partner, safeguarding institutional and individual privacy while enabling efficient and reliable management of educational and administrative processes.

02

Data Migration & SecureLink Platform

A · Company Dependent Migration

  • Complete user control over data upload
  • Available training provided
  • Zero external data exposure
  • We take the responsibility of adding the data to our platform
  • Save institute's time and effort

B · Self-Service Migration

  • Complete user control over data upload
  • Available training provided
  • Zero external data exposure
  • Guidance on how to migrate the data

C · SecureLink Assisted Migration

  • Complete user control over data access and upload
  • End-to-end encrypted data submission
  • Complete access logging and audit trails
  • Real-time access revocation capability
  • Automated access revocation compatibility

D · Partial Migration

  • Complete user control over data upload
  • Available training provided
  • Zero external data exposure
  • Slow migration procedure
  • Use our platform with minimal data, build trust, then migrate to full data
  • Provide partial data to us or the SecureLink platform, progression on the administration's pace

SecureLink Platform Protocol

Data Security
All data submitted through SecureLink is encrypted in transit and at rest using multi-layered encryption. We only have the read-only capability for the data even if migration not done through SecureLink. We respect and ensure user's data safety.
Data Handling
Any misconduct done on the data after we have successfully migrated the data to our platform, we will not be held responsible for it. Users are solely responsible for the data they submit, how they manage it and work with it.
Transient Data Access
During assisted migration, our engineers access data only for structuring purposes. Data is never saved locally or retained beyond the migration window. All access is logged in real-time within the SecureLink portal.
Access Revocation Protocol
Users can instantly revoke access at any time via SecureLink. If revoked during active migration, our team will contact you to understand concerns and discuss alternative solutions. Revocation triggers immediate access termination and data deletion from our temporary workspaces.
Migration Procedure
The data migration procedure might take some time depending on the size of the data and the institution. We work with you to ensure that the migration is done as quickly as possible. We may need to get connected to the institute's appropriate team / staff to work on the migration process.

In summary

In summary, our Data Migration and SecureLink Platform are designed to provide maximum security, transparency, and institutional control throughout the migration process. We offer four distinct migration pathways—Company Dependent, Self-Service, SecureLink Assisted, and Partial Migration—each providing complete user control over data upload and access while minimizing risk of external exposure. Our platform ensures that all data submitted is end-to-end encrypted, and all access is strictly logged and auditable. During assisted migration, engineers access data only for structuring purposes and never save it locally or retain it beyond the migration window. Users can instantly revoke access at any time, triggering immediate termination of access and deletion from temporary workspaces. We provide comprehensive training and guidance to support institutions through every stage of the migration, ensuring a smooth transition while preserving data integrity and privacy. Our approach prioritizes zero external data exposure and institutional autonomy, meaning that once the migration is complete, institutions have full control over their data and bear sole responsibility for its management. The migration process may take time depending on the data volume, and our team works collaboratively with institutional staff to ensure efficient, secure, and reliable integration into our platform. By implementing these robust protocols, SecureLink underscores our commitment to trust, accountability, and the protection of institutional and individual data, allowing educational institutions to migrate and manage their information confidently and securely.

03

Encryption Architecture & Security Protocols

User-Controlled Encryption Framework

Encryption Key Management
Institutions maintain exclusive control over encryption keys. We provide zero-knowledge architecture where we cannot decrypt your data without your explicit key provision.
Real-time Re-encryption
Users can initiate re-encryption cycles at any time. This process generates new encryption keys and re-encrypts all stored data without service interruption.
Multi-Layer Encryption
Database-level encryption combined with application-layer encryption and transport layer security (TLS 1.3) ensures comprehensive data protection.
ControlDetailStatus
Multi-Factor Authentication (MFA)Required for all administrative accountsMandatory
Email OTP VerificationFor all login attempts and sensitive operationsAlways Active
Login AuditA comprehensive system to inform about logins and audit themAlways Active
Multi Layered EncryptionOur system follows multi layered encryption to ensure that your data is safeMandatory
Rate LimitsOur system uses rate limiting to prevent abuse and ensure fair usageMandatory
Abuse MonitoringWe may monitor aspects to prevent abuse, protect our systems and our usersNon Mandatory

In summary

Our Encryption Architecture and Security Protocols are designed to provide industry-leading protection for all institutional and user data. At the core of our framework is a user-controlled encryption system, where institutions maintain exclusive ownership of encryption keys, ensuring a zero-knowledge architecture in which we cannot decrypt any data without explicit key provision. All stored data is secured through multi-layer encryption, combining database-level encryption, application-layer encryption, and transport-layer security (TLS 1.3), creating a comprehensive and resilient defense against unauthorized access. Our platform supports real-time re-encryption, allowing institutions to regenerate encryption keys and re-secure all data without service interruption, thereby guaranteeing continuous data protection and operational availability. Authentication and access control protocols are equally robust. All administrative accounts require multi-factor authentication (MFA), and all login attempts and sensitive operations are verified using email OTP. A comprehensive login audit system provides full visibility into access events, while rate limiting and abuse monitoring mechanisms safeguard against misuse and ensure fair platform usage. Data access is strictly governed by principle of least privilege, and our system enforces instant access revocation to terminate privileges immediately if required. Collectively, these measures ensure that our platform not only protects data during storage and transit but also enables transparent, accountable, and user-controlled security, giving institutions the confidence that their information is fully safeguarded at every stage of management, migration, and operational use.

04

Data Processing, Storage & Third-Party Services

Data is processed in accordance with the migration methods defined by the institution's specific requirements. Once the data has been processed, control over the data is fully transferred to the institution, and they manage it directly through our platform. After successful onboarding, we do not access, modify, or interfere with the institution's data in any manner, and the institution assumes full responsibility for its management and use. We do not sell, distribute, or share any data with unknown, unauthorized, or unethical third parties. Any third-party integrations or services are implemented only after being clearly communicated and approved by the institution's administration. All data is securely stored using MongoDB Atlas with multi-layered encryption to protect the institution's information. Our cloud infrastructure is hosted via Google Cloud Console, ensuring additional security and reliability. Once the institution's data is stored, our role is limited to maintaining its security, integrity, and proper integration within our platform. All other responsibilities related to the data remain solely with the institution.

On-Demand Integrations — integrated only when requested by the institution and governed by separate Data Processing Agreements (DPAs)

  • Razorpay — Payment Processing
  • MSG91 — SMS & Communication
  • Twilio — SMS & Communication
  • Any other third-party service providers on demand

In summary

Our platform ensures that all data processing, storage, and third-party interactions are governed by strict privacy and security standards. Data is handled according to the institution's defined requirements, and control is always retained by the institution throughout the process. Once the data is onboarded, we never access, modify, or use it without explicit institutional consent. Our cloud infrastructure leverages Google Cloud Console's secure architecture alongside MongoDB Atlas with multi-layer encryption, providing a highly resilient environment that safeguards data against unauthorized access, accidental loss, or corruption. Any integrations with third-party services occur strictly on demand and only after explicit institutional approval, with each integration governed by separate Data Processing Agreements (DPAs). This ensures that no data is shared, sold, or exposed to unauthorized parties. Institutions can confidently leverage payment processing, SMS, communication, or other specialized services while retaining full oversight of data flow and access control. Our platform is designed to provide transparent, accountable, and secure management of data, ensuring that institutions retain complete responsibility and autonomy over their information, while our role remains limited to maintaining security, integrity, and seamless integration within the platform.

05

Data Retention, Deletion & User Rights

Our platform follows strict data retention policies designed to minimize unnecessary storage while maintaining operational functionality. Institutions have full control over the retention schedules for their data, including automated archival, purging, or long-term storage. Any data retained beyond active usage is encrypted, isolated, and only accessible to authorized institutional personnel. Users can initiate deletion requests at any time, and such requests are executed without delay, in accordance with GDPR and CCPA regulations.

Deletion Protocol

Immediate Deletion
User-deleted data is immediately removed from active databases and cannot be recovered unless the trash mechanism is used.
Trash Mechanism
Some modules employ a "trash" system for accidental deletion recovery. Data in trash is not automatically purged and must be manually deleted.

User Rights Under GDPR & CCPA

  • Right to Access — Complete data export capability
  • Right to Rectification — Real-time data correction
  • Right to Erasure — Immediate deletion requests
  • Right to Restrict Processing — Temporary processing halt
  • Right to Data Portability — Standard format exports
  • Right to Object — Opt-out of specific processing

In summary

All retention and deletion policies are fully configurable by the institution. Our platform ensures secure erasure of backups, logs, and archived data in accordance with regulatory compliance. Users and institutions retain full transparency and control over the lifecycle of their data, including the ability to review, export, or permanently remove any information at any time. This approach guarantees maximum privacy, accountability, and operational integrity while maintaining the flexibility required for institutional workflows.

06

Cookies, Tracking & Compliance

Cookie typePurposeDurationEssential
Session AuthenticationSecure login session maintenanceSessionYes
CSRF ProtectionCross-site request forgery preventionSessionYes
PreferencesUser interface settings1 YearOptional

We use essential cookies only to maintain security, authentication, and session management. No tracking cookies are deployed for marketing or analytics purposes. All cookies are transmitted over encrypted HTTPS connections for maximum security.

Our platform actively monitors server logs and system activity to prevent abuse, detect suspicious accounts, and ensure fair usage. Monitoring is primarily automated using our AI-driven security intelligence, which operates without human intervention, but allows human review when necessary to mitigate detected issues.

Users retain control over cookie acceptance via browser settings; however, essential cookies are mandatory for core platform functionality, including secure login, session maintenance, and fraud prevention.

In summary

Essential cookies enable platform security, session functionality, and automatic abuse prevention mechanisms.

07

Policy Updates & Contact Information

Modification Protocol

30-Day Notification Period
Material changes to this policy will be communicated to all institutional administrators 30 days prior to implementation via registered email and phone number.
Version Control & Archive
All policy versions are archived and inaccessible. Current version: 3.1 (Effective 01/06/2026)

Data Protection Contact Points

General Inquiries — connect@infocing.com
For general questions, feature requests, and platform support.
Data Protection & Software Enquiries — connect@infocing.com
For privacy concerns, data subject requests, and security incidents.

Aryavart Creations

Privacy Policy Version 3.1 | Effective 01/06/2026

© 2026 Aryavart Creations. INFOCING is a product of Aryavart Creations. All rights reserved. For questions regarding these policies, contact connect@infocing.com.

Write to legal