1. Introduction and Scope
Pixa Consulting LLP (“we,” “our,” or “us”) operates the Pixa Smart Attendance mobile application and associated web/cloud platform (collectively, the “App”). We are committed to respecting privacy and protecting personal data processed through our platform.
This Privacy Policy outlines our practices regarding the collection, storage, processing, transfer, and deletion of information when you interact with our App and associated services.
Role of Pixa and Educational Institutions
Pixa Smart Attendance is provided as an enterprise platform to educational institutions, including schools, colleges, universities, and training organizations (“Institution”).
- Pixa as Data Processor: Where Pixa processes student, faculty, or staff personal data on behalf of an Institution, the Institution determines the purposes and legal grounds for processing. In such cases, the Institution acts as the Data Fiduciary (Data Controller), and Pixa Consulting LLP acts as a Data Processor under strict contractual instructions and applicable laws (including the Digital Personal Data Protection Act, 2023).
- Pixa as Data Fiduciary: Pixa acts as a Data Fiduciary only for information independently collected for our direct business operations, such as administrative user accounts, billing details, customer support interactions, and direct app telemetry.
This Privacy Policy should be read alongside any privacy notice, consent form, institutional policy, or agreement provided by your applicable Institution.
2. Information We Collect
We collect information necessary to provide a secure, accurate, and fraud-resistant attendance management system:
A. Information Provided Directly
- Identity Data: Full Name, Date of Birth, Gender
- Contact Details: Email Address, Mobile/Phone Number
- Institutional Identifiers: Student Enrollment Number, Roll Number, Employee ID, Faculty ID
- Academic Context: Class, course, section, semester, batch, or department details
- Profile Media: Profile photographs provided during onboarding or enrollment
B. Biometric and Camera Data (Face Recognition)
The App requests permission to access the device camera to capture images for identity verification and attendance marking. Depending on features enabled by the Institution, the App may process:
- Facial photographs captured via the camera
- Facial embeddings, vectors, or mathematical templates derived from images
- Facial comparison result logs (match/no-match status with confidence scores)
C. Automatically Collected Technical Data
- Device hardware model, operating system version, and App build version
- Network details, IP address, and connection logs
- Session timestamps, login/logout events, crash reports, and audit logs
3. Biometric & Face Data Usage Policy
What Face Data We Collect
To enable face-based attendance functionality, the App collects facial images through your device’s camera and generates facial templates for identity verification and attendance matching.
Usage Restrictions
Facial images and generated templates are strictly processed to verify identity during attendance events. Pixa explicitly guarantees that Face Data is NEVER:
- Used for commercial advertising, marketing, or behavioral tracking
- Sold, rented, licensed, or traded to third parties or data brokers
- Transferred to third parties for general-purpose AI, Generative AI, or LLM training
- Retained for background surveillance or non-attendance tracking
Storage and Encryption
- All facial images and templates are transmitted over encrypted networks (TLS / HTTPS).
- Biometric templates at rest are encrypted using AES-256 encryption within restricted database instances hosted on Amazon Web Services (AWS). The applicable hosting region may depend on the deployment selected by the Institution.
Retention & Deletion Schedule
- Temporary Attendance Capture Images: Purged automatically once the facial template is generated or verified, unless the Institution requires retention for administrative audit compliance.
- Enrolled Facial Templates: Retained only while the student or faculty member remains active with the Institution. Once an account is deactivated, facial templates will be deleted from active systems in accordance with the Institution’s retention requirements and Pixa’s applicable data-deletion procedures.
4. How We Use Your Information
- Authenticate attendance using facial recognition
- Maintain institutional attendance records
- Provide, operate, and improve App performance, reliability, and security
- Prevent fraud and unauthorized access
- Send system and service notifications
- Maintain operational security and audit logs
- Respond to technical support requests
Pixa does NOT use student or faculty personal data for advertising or targeted marketing.
5. How We Share Data & AI Policy
Personal data is shared strictly on a need-to-know basis:
- Educational Institutions: Attendance reports, timestamps, and verification logs are accessible to authorized administrators or faculty.
- Infrastructure Service Providers (AWS): Hosted on Amazon Web Services (AWS). AWS processes encrypted data solely under our technical direction and does not possess rights to independently access student face data.
- Legal Requirements: Disclosed if legally compelled by court order, regulatory mandate, or legal process under Indian law.
- Business Transfer: If Pixa undergoes a merger or acquisition, user data remains bound by this policy.
Third-Party AI Services Policy
Pixa Smart Attendance does not use or integrate with external third-party Generative AI platforms (such as OpenAI, Anthropic, Google Gemini, or Azure OpenAI) for processing face data or student records.
Facial recognition algorithms operate solely through infrastructure managed directly by Pixa. User data is not transmitted to external AI model providers.
6. Data Security
We enforce multi-layered administrative, technical, and physical security controls, including:
- Encryption via HTTPS/TLS in transit and AES-256 at rest for sensitive data and biometric templates
- Role-Based Access Control (RBAC) and strict IAM authorization policies
- Isolated Virtual Private Clouds (VPCs) on AWS with automated intrusion detection
- Regular security monitoring, access auditing, and vulnerability management
7. User Rights and Data Deletion
In compliance with the Digital Personal Data Protection Act, 2023 (DPDP), users (or their legal guardians) possess the following rights:
- Right to Access & Summary: Request a summary of personal data held and processing activities.
- Right to Correction & Erasure: Request correction of inaccurate details or erasure of personal data no longer required for attendance.
- Right to Withdraw Consent: Consent for biometric processing may be withdrawn at any time. (Note: Withdrawing consent may affect face-based attendance functionality, requiring alternative institutional attendance mechanisms).
How to Request Deletion
- Via Institution: Deletion requests should primarily be submitted to your Institution’s administrative office as the Data Fiduciary.
- Direct Contact / In-App: You may submit a request directly via in-app support or by emailing support@pixaconsulting.com. Eligible requests will be handled within the timeframe required by applicable law and the applicable institutional or contractual arrangements.
8. Children’s Personal Data
Where Pixa Smart Attendance is deployed for students under 18 years of age:
- The educational Institution is responsible for establishing lawful grounds, including obtaining Verifiable Parental Consent where required under the DPDP Act 2023 and DPDP Rules 2025, or applying applicable institutional exemptions. The specific requirements may vary depending on the nature of the Institution, the purpose of processing, and any exemption or other provision applicable under law.
- Pixa provides technical functionality (e.g., parent portal consent flags) to support Institutions in managing consents.
- We do not build commercial profiles on minor students or serve targeted advertisements to children.
9. Policy Updates
We may update this Privacy Policy to reflect technical updates, legal amendments, or operational changes. Material changes will be communicated through the App, website notices, or direct email communication.
10. Grievance Redressal and Contact Information
If you have questions, concerns, or grievances regarding the processing of your personal data or biometric information, please contact our designated Grievance Officer:
- Company: Pixa Consulting LLP
- Grievance Officer: Pixa Consulting LLP
- Email: support@pixaconsulting.com
- Website: https://pixaconsulting.com/
