This Privacy Policy explains how Crazenators Technologies ("we") collects, uses, shares, secures, and deletes personal data in the EduManager Teacher Android application (package edu.manager.teacher) and the EduManager backend services it connects to.
EduManager Teacher is a school-management application for teaching and administrative staff. Accounts are created and issued by the school that has licensed EduManager. The app is not offered to the general public and is not directed at children.
By using the app you agree to this policy. If you do not agree, do not use the app.
Requests to change or delete a student record are decided by your school. Requests about your own staff account may be sent to us directly (see section 9).
We collect only the data listed below. We do not collect anything not listed here.
| Data | Purpose | Required? |
|---|---|---|
| Name, staff ID, role | Identifying you in the system and applying role permissions | Required |
| Work email address | Sign-in, password reset, service notices | Required |
| Work phone number | Account recovery and school communication | [Required / Optional] |
| Profile photo | Display on your staff profile | Optional |
| Assigned classes and subjects | Scoping which records you may access | Required |
Student attendance marks, exam and assessment marks, homework assignments, lesson plans, remarks, and notices. This data concerns students and is stored in your school's EduManager instance. It is used only to operate the school's own system.
Where your school has enabled location-verified attendance, the app reads your device's location at the moment you mark your own attendance (check-in and check-out) and sends it with that attendance record.
| What | Detail |
|---|---|
| What is collected | Latitude and longitude, accuracy radius, and the timestamp of the reading |
| Why | To confirm that staff attendance is marked at the school campus, and to prevent attendance being marked remotely on another person's behalf |
| When | Only while the app is open and only when you tap to mark attendance. There is no background, continuous, or periodic location collection, and no location trail between check-in and check-out |
| Whose location | Your own, as a staff user. The app never collects student location |
| Precision | Precise location is used because campus verification requires it. If only coarse location is available, the reading is stored with its accuracy radius and may be flagged for manual review by your school |
| Who sees it | Your school's administrators, as part of the staff attendance record. It is not shared with any other user, and not used for any purpose other than attendance verification |
| Retention | Stored with the attendance record for as long as your school retains staff attendance data (section 7) |
Your choice. The app asks for location permission the first time you mark attendance, and explains why before the Android prompt appears. You can decline, and you can revoke the permission later in Android Settings. If you decline, location-verified attendance is unavailable to you and your attendance must be marked or approved by your school administrator instead; every other feature of the app continues to work normally.
| Data | Purpose |
|---|---|
| App version, Android version, device model | Compatibility and support |
| Randomly generated install identifier | Linking crash reports to a session; not tied to advertising |
| IP address | Security, rate limiting, abuse prevention |
| Push notification token | Delivering notifications |
| Sign-in timestamps and session tokens | Authentication and session management |
| Crash logs and error diagnostics | Diagnosing and fixing failures |
We do not collect contacts, SMS messages, call logs, background location, continuous or passive location tracking, browsing history, health data, financial account or payment card details, or biometric templates. We do not use an advertising identifier. There is no advertising SDK in this app. Location is collected only as described in section 3.3.
Android asks your permission before each of these. You may decline any of them; the related feature becomes unavailable and the rest of the app continues to work.
| Permission | Why the app needs it |
|---|---|
POST_NOTIFICATIONS | Timetable changes, notices, leave approvals, messages |
ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION | Reading your location at the moment you mark attendance, to verify it is marked on campus. Foreground only — the app does not request ACCESS_BACKGROUND_LOCATION and cannot read your location while it is closed |
| Photo/media picker | Attaching a file to homework or a support request; access is limited to the file you select |
INTERNET, ACCESS_NETWORK_STATE | Communicating with your school's server and detecting offline mode |
We do not sell personal data. We do not share it with advertisers or data brokers. We do not use it to train machine learning models outside your school's own instance.
Data is shared only with:
| Recipient | Data shared | Purpose |
|---|---|---|
| Your school | Records within each user's role scope, staff attendance records including their location stamps, plus audit entries | Operating the school's system |
| [Hosting provider name] | All application data, encrypted in transit and at rest | Hosting the EduManager backend |
| Competent legal authority | As legally compelled | Compliance with a valid legal order |
Each provider processes data under contract, on our instructions only.
If a breach occurs that is likely to affect users' rights, we will notify the school without undue delay and support its response.
| Data | Retained for |
|---|---|
| Student and staff academic records | As long as the school instructs, per its record-keeping policy |
| Staff attendance records and their location stamps | As long as the school instructs, per its record-keeping policy; location stamps may be deleted earlier at the school's instruction without affecting the attendance record |
| Your staff account | Until the school deactivates it, then [90 days] before anonymisation |
| Authentication and session logs | [12 months] |
| Crash and diagnostic logs | [90 days] |
| Backups | [30 days] on a rolling cycle, then overwritten |
| All school data after licence ends | Exported to the school on request, then deleted within [60 days] |
You can request deletion of your account and associated personal data in either of these ways:
What is deleted: your profile, contact details, photo, device and push tokens, session records, and support correspondence.
What is retained: academic records you created (attendance, marks, homework) belong to your school and remain part of its institutional record. Staff attendance entries are retained on the same basis; the location stamp attached to them is deleted or detached from your identity as part of the same request unless your school is legally required to keep it. Your identity in the related audit entries is replaced with a non-identifying reference.
Requests are acknowledged within [7 days] and completed within [30 days], unless the school instructs otherwise or retention is legally required.
Subject to applicable law and your school's role as controller, you may request access to your data, correction of inaccurate data, deletion, restriction of or objection to processing, withdrawal of consent, and a portable copy of your data. Contact [email protected]. We verify identity before disclosing anything and respond within [30 days].
The app is intended for adult staff. Children do not hold accounts, and the app never collects a student's location. Teachers do, however, record information about students who are usually under 18. That data is used solely to operate the school's system, is never used for advertising, profiling, analytics, or model training, and is never sold or shared with data brokers. Consent for a student's record rests with the school and the student's parent or guardian under the school's admission policy.
EduManager data is hosted on servers in Malaysia. Where a provider processes data outside Pakistan, we require contractual safeguards at least equivalent to this policy. On-premise deployment is available for schools requiring in-country hosting.
Pakistan has no comprehensive personal data protection statute currently in force; the Prevention of Electronic Crimes Act 2016 (as amended) governs misuse and unauthorised transfer of personal data. We have written this policy against internationally recognised data protection principles so that our practices align with Pakistani legislation once enacted. This policy is governed by the laws of the Islamic Republic of Pakistan.
We may update this policy as the product or the law changes. The version and effective date above always reflect the current text. Material changes are notified to schools in advance and shown as an in-app notice before taking effect.