Legal

Privacy Policy

Effective date: April 1, 2025

Learnova Technologies (Private) Limited ("Learnova", "we", "us", "our") is committed to protecting the personal data of everyone who uses our platform — including institution administrators, teachers, students, and parents. This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights in relation to it.

🇵🇰
Data stays in Pakistan
Primary data storage on servers located in Pakistan.
🔒
Encrypted at rest & in transit
TLS 1.3 in transit, AES-256 at rest.
👶
Children's data protected
Student data is never sold or used for advertising.

1Who We Are

The data controller for this Privacy Policy is Learnova Technologies (Private) Limited, a company incorporated in Pakistan. Our Data Protection Officer can be reached at privacy@learnova.pk.

For data processed on behalf of Institutions (including their students, teachers, and parents), the Institution is the data controller and Learnova acts as data processor under a data processing agreement incorporated into our Terms of Service.

2Data We Collect

From Institution Administrators

  • Name, email address, phone number
  • Institution name, type, city, and student count
  • Billing information (processed via payment gateway — card details are not stored by Learnova)
  • IP address and browser/device information for security purposes

From Teachers and Staff

  • Name, email address, phone number (if provided by the Institution)
  • Role and subject assignments
  • Attendance records and class activity logs

From Students

  • Name, class/grade, roll number (provided by the Institution)
  • Academic records: grades, attendance, assignments, and quiz results
  • Learning activity data (time on platform, feature usage) for analytics
  • Guardian/parent contact information (phone and email)

From Parents and Guardians

  • Name and WhatsApp/phone number (provided by the Institution)
  • Fee payment status and communication history

Automatically Collected

  • Log data: IP addresses, browser type, pages visited, timestamps
  • Device identifiers for offline sync purposes
  • Cookies and local storage (see Section 8)

3How We Use Your Data

  • Providing the Platform: Managing accounts, processing fees, generating reports, and delivering all Platform features.
  • WhatsApp Notifications: Sending automated fee reminders, attendance alerts, and notices to parents and students on behalf of the Institution. Only sent with Institution-confirmed consent.
  • Customer Support: Responding to queries, investigating issues, and providing onboarding assistance.
  • Platform Improvement: Analysing aggregated, anonymised usage patterns to improve features and performance. Individual student data is never used for this purpose without the Institution's permission.
  • Security: Detecting and preventing fraud, abuse, and unauthorised access.
  • Legal Obligations: Complying with applicable Pakistani laws, including tax obligations and lawful government requests.
  • Marketing (Administrators only): Sending product updates and relevant offers to Institution Administrators who have opted in. You can unsubscribe at any time.

We do not sell, rent, or trade personal data to third parties. We do not use student data for advertising purposes.

4Legal Basis for Processing

  • Contract performance: Processing necessary to provide the subscribed services.
  • Legitimate interests: Security, fraud prevention, and Platform improvement (always balanced against your rights).
  • Consent: Marketing communications to Administrators; WhatsApp notifications (via Institution-obtained consent from recipients).
  • Legal obligation: Compliance with Pakistani law.

5Data Sharing

We share personal data only with:

  • Infrastructure providers: Cloud hosting and database providers under strict data processing agreements.
  • Meta (WhatsApp Business API): To send notifications on behalf of Institutions. Governed by Meta's data processing terms.
  • Payment gateways (JazzCash, EasyPaisa — when integrated): To process fee payments. PCI-DSS compliant providers.
  • Analytics tools: Aggregated, anonymised data only — no individual student records.
  • Legal authorities: Only when required by a valid court order or applicable Pakistani law.

All third-party processors are bound by contractual obligations at least as protective as this policy.

6Children's Data

  • Students under 18 access the Platform only through their Institution. The Institution is responsible for obtaining parental or guardian consent.
  • We do not knowingly allow children to create individual accounts without Institution oversight.
  • Student data is used solely for educational purposes (academic records, attendance, learning analytics). It is never used for advertising, profiling, or sold to third parties.
  • Parents and guardians may request access to or deletion of their child's data through their Institution Administrator.

7Data Retention

  • Active account data is retained for the duration of the subscription.
  • After termination, Institution data is retained for 30 days (to allow export), then deleted within 90 days unless a longer retention period is required by law.
  • Anonymised, aggregated analytics data may be retained indefinitely.
  • Backup copies may persist for up to 30 additional days after deletion.

8Cookies and Local Storage

  • Essential cookies: Authentication tokens and session management. Required for the Platform to function.
  • Performance cookies: Anonymised analytics to understand how the Platform is used. You can opt out via your browser settings.
  • Offline storage: We use browser IndexedDB and service workers for offline functionality. This data stays on your device.

We do not use third-party advertising or tracking cookies.

9Your Rights

Subject to applicable Pakistani law, you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data (subject to legal retention requirements).
  • Portability: Request your data in a structured, machine-readable format.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Withdraw consent for marketing communications at any time.

End Users (students, teachers, parents) should exercise their rights through their Institution Administrator. Administrators and direct contacts may submit requests to privacy@learnova.pk. We will respond within 30 days.

10Data Security

  • TLS 1.3 encryption for all data in transit.
  • AES-256 encryption for sensitive data at rest.
  • Strict role-based access controls — Learnova staff access Customer Data only to resolve support issues, with full audit logging.
  • Regular security assessments and penetration testing.
  • Incident response plan: we will notify affected Institutions within 72 hours of becoming aware of a data breach.

11Pakistan Data Protection

We are committed to compliance with Pakistan's existing data protection framework and the forthcoming Personal Data Protection Bill. Our practices are designed to meet the requirements of both current regulations and anticipated future requirements, including:

  • Prevention of Electronic Crimes Act 2016 (PECA)
  • Pakistan Telecommunication Authority (PTA) regulations
  • Personal Data Protection Bill (when enacted)

12Changes to This Policy

We may update this Privacy Policy from time to time. We will notify Institution Administrators via email at least 14 days before material changes take effect. The updated policy will be posted on this page with a revised effective date.

13Contact Our Data Protection Officer

For any privacy-related questions, data requests, or concerns:

Data Protection Officer
Learnova Technologies (Private) Limited
Lahore, Punjab, Pakistan
privacy@learnova.pk
Chat with us