eduSis Kolej Mobile

Privacy Policy

Last updated: 2026-02-05

Roles, processed data types, security approach and retention principles within eduSis Kolej Mobile.

1) Scope and Roles

This policy explains the principles regarding the processing of parent and student data within the eduSis Kolej Mobile App.

In this service, the data controller is the relevant school or institution. Veridizayn acts as the data processor on behalf of the school or institution.

Data is processed and stored on the servers of the relevant school or institution.

The app includes student-related records for parental supervision purposes. The school or institution provides the required notices within its own procedures and policies.

2) Account Management and Authentication

For security purposes, user identity and session activity may be written to technical logs.

Passwords should not be stored in plain text and should be processed using appropriate security methods only for verification.

  • No in-app account creation. Accounts are created and managed by the school or institution.
  • Authentication is performed using school code, username and password.

3) Types of Data Processed

Depending on the app features, the following types of data may be processed:

Location data is not processed. Camera and gallery permissions are not used. No push notification token is processed.

  • Balance information: card or account balance and balance transactions
  • Entry or turnstile records: date-time and entry-exit point information
  • Spending limits and restricted item records: definitions, restrictions and related enforcement records
  • Technical data: app version, device and operating system information, IP address or device identifiers

4) User Actions

The app may allow users not only to view data but also to update certain settings or take actions.

Records related to these actions, such as managing spending limits or restrictions, may be retained for security and audit purposes.

5) Biometric Data

The mobile app does not collect or store biometric data.

If biometric authentication exists, it is handled within the school or institution’s own devices and infrastructure.

6) Payments / Balance Top-Up

For accounting and chargeback purposes, transaction data such as bank name, order number, date and amount may be retained.

The payment service provider is Payten.

  • Balance top-up is performed by redirecting to a payment page via an in-app WebView.
  • Card details are not transmitted to Veridizayn servers and are not processed by the app. Payments are completed on the secure infrastructure of the payment service provider.

7) Third Parties and Transfers

No third-party SDKs are used for analytics, crash reporting or advertising.

For payment transactions, data may be transferred to service providers such as Payten only to the extent required by the transaction.

No other third-party data sharing is intended.

8) Retention Periods

  • Backups may be retained as required by system operations.
  • Operational records may be stored for certain periods due to legal obligations.
  • Other data is retained in line with the agreement with the school or institution and its policies.

9) Account Deletion and Data Requests

The app may not include a direct account deletion initiation feature.

Account deletion and data requests are handled through the relevant school or institution or through support channels.

For details, review the account deletion and privacy choices pages.

10) Security

Access control, encryption and logging mechanisms are used to prevent unauthorized access.

Technical records such as IP address, device identifiers and user identity may be retained for operational security.

11) Contact

For privacy-related requests, you may write to [email protected].

For general support, please use the support page.