Legal
Privacy Policy
Last Updated: October 1, 2026
At InstituteOS, protecting the privacy and security of the educational institutions, administrators, teachers, parents, and students who rely on our School Management Software is our highest priority. This Privacy Policy details how we collect, use, and safeguard personal data.
1. Data Collection
We collect information necessary to provide and improve our ERP services. This includes:
- Account Information: Names, email addresses, phone numbers, and institutional affiliations when an account is created.
- Student Records: Academic performance, attendance records, health information (if provided by the institution), and disciplinary logs entered by administrators.
- Financial Data: Fee payment history and transaction records (note: payment processing is handled securely by third-party gateways; we do not store full credit card numbers).
- Usage Data: System interaction logs to monitor application performance and improve user experience.
2. How We Use Data
We act strictly as a data processor on behalf of the educational institution (the data controller). We use collected data solely to:
- Provide core ERP functionality (grading, fee alerts, attendance tracking).
- Send essential administrative notifications (e.g., WhatsApp or SMS fee reminders).
- Maintain system security and prevent unauthorized access.
- Provide customer support to authorized administrators.
We never sell student or institutional data to third-party advertisers or data brokers under any circumstances.
3. Data Security & Storage
InstituteOS employs enterprise-grade security measures to protect your data against unauthorized access, alteration, or destruction. We utilize industry-standard encryption protocols (SSL/TLS) for data in transit and AES-256 encryption for data at rest. Your data is stored on secure cloud databases with rigorous access controls.
4. Data Retention and Deletion
We retain institutional data only for as long as the institution maintains an active subscription with InstituteOS, or as required by applicable laws. Upon termination of service, all institutional records can be exported by the school administrators, after which the data will be permanently deleted from our primary servers within 90 days.
5. Contact Us
If you have questions about this Privacy Policy or our data handling practices, please contact your institution's administrator first, or reach out to our privacy team at privacy@instituteos.com.
Institute OS
Questions about our Security?
Unify your digital workflows and grow with confidence using our comprehensive management platform.