1. Scope and roles
This Privacy Policy applies to CampusOne AI websites, marketing pages, institution workspaces, hosted institution websites, mobile or web interfaces, and related support. In most cases, an institution decides the purpose of processing for the records it enters into its workspace. CampusOne operates that platform as a service provider or processor for the institution. For account, billing, security, and marketing information about the institution’s relationship with CampusOne, CampusOne may act as the organisation responsible for that processing.
2. Information we collect
- Account and institution information: name, institution type, contact details, domain, address, administrator details, plan, and configuration.
- ERP information: student, guardian, staff, admission, attendance, timetable, academic, fee, examination, communication, leave, and website content entered by the institution.
- Usage and device information: login records, IP address, browser, device, approximate location, pages or features used, audit events, and security signals.
- Support and transaction information: messages, attachments, payment status, invoices, integration settings, and correspondence. Payment providers generally provide transaction references and status rather than full payment credentials.
3. How we use information
We use information to provide and secure CampusOne; create and administer workspaces; authenticate users; apply roles and tenant isolation; operate websites and ERP modules; process payments; send service and workflow notifications; provide support; diagnose errors; prevent fraud and abuse; maintain audit trails; improve reliability; and comply with legal obligations.
We may send essential service messages such as login, security, billing, leave, admission, or workflow notifications. Marketing messages can be controlled through the available unsubscribe option.
4. Institution-controlled records
Institution records belong to the institution that submitted them. CampusOne does not sell student, guardian, staff, or institutional records. The institution is responsible for informing its users, obtaining required permissions, setting appropriate access, and handling requests concerning those records.
Because CampusOne serves education organisations, the institution may enter information about children or other sensitive categories. Institutions should collect only what they need, configure least-privilege access, and avoid placing unnecessary sensitive information in AI prompts or uploaded files.
6. AI and uploaded files
If an institution uses Puffy AI or another CampusOne AI feature, the user’s prompt, selected workspace context, uploaded file, and relevant records may be processed to return an answer or prepare an authorised workflow. AI interactions may be recorded in the institution’s workspace and audit history so the institution can review usage.
Where an external AI provider is used, the relevant request is transmitted to that provider. CampusOne aims not to use institution data to train public models unless expressly agreed. Institutions should review AI-generated results before acting on them and should not use the service as a substitute for professional advice.
7. Choices and data requests
You may update account information through the product or contact us. You may request access, correction, deletion, export, or restriction where available under applicable law. For student, guardian, staff, or other records controlled by an institution, contact that institution first because it determines the purpose and retention of those records. We will assist the institution with a verified request where required.
You can withdraw optional marketing consent, request help with account closure, and ask questions about processing by contacting info@campusoneai.com. We may need to verify identity and authority before completing a request.
8. Security and retention
We use access controls, tenant isolation, encryption in transit, audit logging, backups, monitoring, and operational safeguards designed to protect information. No online service can guarantee absolute security, so institutions must also protect credentials, devices, integrations, and exported files.
We retain information for as long as needed to provide the service, meet contractual and legal obligations, resolve disputes, maintain security records, and enforce agreements. Retention may vary by data type, institution settings, plan, backup cycle, and applicable law. When data is no longer required, we delete, anonymise, or securely isolate it according to our retention process.
9. Cookies and education users
CampusOne may use essential cookies or similar technologies for sessions, security, preferences, and product functionality. We may use limited analytics to understand reliability and feature usage. You can control cookies through your browser, but disabling essential cookies may affect sign-in or workspace functionality.
CampusOne is provided to institutions, not as a direct social service for children. Institutions remain responsible for determining whether collection and use of a student’s information is permitted, providing notices, obtaining consent where required, and configuring access for parents, guardians, students, and staff.
10. Updates and contact
We may update this policy when our service, providers, or legal obligations change. We will publish the revised policy and update the effective date. For privacy questions or a verified request, contact info@campusoneai.com or write to CampusOne AI, Rajkot, Gujarat, India.