Privacy Policy
Last updated: October 5, 2026
This Privacy Policy explains how Pedinno Private Limited (“Pedinno”, “we”, “us”) collects, uses, shares and protects personal data when you use our website, the Pedinno AI ERP platform (including School ERP, AI HRMS, Payroll, Accounting, CRM, WhatsApp and Pedinno AI modules), and our apps — Pedinno AI — My Login (Staff), Pedinno Student & Parent, Transport — Pedinno, Pedinno Gatepass and Pedinno Time Tracker (together, the “Services”). It is published in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
1. Scope and Who We Are
Pedinno Private Limited is a company incorporated in India with its registered office at Shop No. 111/62, Sec-11 JCC, Near India Post Office, Pratap Nagar, Jaipur, Rajasthan 302033, India. This policy covers visitors to our website, people who request a demo or contact us, and every user of the Services — including administrators, staff and employees, candidates, students, parents and guardians, drivers, security guards, visitors recorded at a gate, clients, vendors and channel partners of organisations that use Pedinno.
2. Our Role: Data Fiduciary and Data Processor
Website and sales enquiries. For information you give us through our website, demo requests, chat assistant or direct communication, Pedinno decides how the data is used and acts as the Data Fiduciary.
Customer data in the platform. When a school, college, company or other organisation (“Customer”) uses Pedinno, the Customer decides what personal data is entered and why. The Customer is the Data Fiduciary and Pedinno processes that data on the Customer’s behalf as a Data Processor, under our agreement with the Customer. If you are a student, parent, employee or other user of a Customer’s account, please contact that organisation first about your data; we will support them in responding to you.
3. Information We Collect
3.1 Information you give us
- Enquiries and demos: name, work email, phone number, organisation, role, and details of your requirement submitted through our contact form, demo request form or chat assistant.
- Account and registration: organisation details, branch details, administrator names, mobile numbers, email addresses, GSTIN and billing information.
3.2 Information Customers enter or generate in the platform
- Students and guardians: admission and profile details, class and section, attendance, leave, fees and receipts, RTE details, homework, exam marks, results and certificates, ID card photos, transport route and stop, library and hostel records, and parent contact details.
- Staff and candidates: profile and contact details, resumes, interview responses and AI-generated interview reports, offer and appointment letters, pre-boarding documents, attendance, leave, tasks, performance records, assets allotted, appeals and exit records.
- Payroll and finance: salary structure, bank account details, PAN and statutory identifiers required for PF, ESI, Professional Tax, TDS, LWF and Form 16, payslips, claims, advances and loans, and accounting entries.
- Business records: leads, clients, vendors, quotations, invoices, purchase orders, contracts, feedback and survey responses.
- Gate and visitor records: visitor name, mobile number, purpose, host, photo, and check-in and check-out times.
3.3 Information collected automatically
- Device and log data: IP address, device model, operating system, app version, browser type and crash data.
- Usage and security data: login activity, actions performed, audit logs and pages or features used.
- Cookies and similar technologies on our website (see section 17).
4. Biometric, Face and Location Data
Some features process data that Indian law treats as sensitive. These features are enabled by the Customer, and are used only for the purpose shown:
- Face recognition attendance and face identification: the Staff and Gatepass apps compute a numerical face template from a camera image to mark attendance or identify a registered person at a gate. Templates stored on a device are encrypted using the device’s secure keystore. Face data is used only for attendance and identification — never for advertising or profiling.
- Biometric attendance machines: when a Customer connects a fingerprint or face machine, the machine sends punch records (employee or student code, time and verification type) to Pedinno. Raw fingerprints remain on the machine.
- Location: where a Customer enables GPS or geofence attendance, staff tracking or transport tracking, the relevant app collects device location while marking attendance, during tracked duty, or during an active transport trip, as configured by the Customer.
Customers are responsible for informing users and obtaining any consent required before enabling these features. Users can contact their organisation to ask for an alternative attendance method.
5. Children’s and Students’ Data
Our education modules process data about students, many of whom are under 18. Schools and institutions enter and control this data and are responsible for obtaining verifiable consent from parents or lawful guardians as required by the DPDP Act. Pedinno does not use children’s data for behavioural monitoring, tracking for advertising, or targeted advertising, and does not sell it. The Student & Parent app is intended to be used by students under the supervision of their parents or guardians.
6. Time Tracker Data
When an organisation uses Pedinno Time Tracker on Windows or macOS, the following applies while an employee’s timer runs:
- Always recorded: timer events (start, pause, break, stop, sleep and wake), a periodic heartbeat, and per-minute counts of seconds with keyboard or mouse input.
- Recorded only if the organisation enables it: screenshots at the chosen interval, the name of the application in front, and (on Windows) window titles.
- Never collected: typed text, key sequences, passwords, clipboard contents, URLs or browsing history, camera, microphone or location, or anything while the timer is paused, stopped or idle-locked.
Employees can see in the app what is being recorded at any time, in the Timer and Privacy tabs.
7. How We Use Information
- To provide, operate, secure and support the Services as instructed by Customers.
- To respond to enquiries, schedule demos, and send information you asked for.
- To send service notifications such as OTPs, alerts, reminders and account messages.
- To maintain security, detect fraud and misuse, and keep audit trails.
- To improve the reliability and quality of the Services using aggregated or de-identified usage data.
- To bill Customers and meet legal, tax and regulatory obligations.
We do not sell personal data, and we do not use Customer data for advertising.
8. AI Features and Processing
Pedinno AI and other AI features (resume parsing, AI interviews, PDF question extraction, smart insights, feedback insights and document processing) process the data needed to answer a request or complete a task.
- Pedinno AI reads data only through permission-checked product services and only within the user’s role and branch.
- Some AI processing uses third-party AI model providers. We send only the text needed for the request, under terms that do not permit the provider to use it to train its models, wherever such terms are available.
- We do not use Customer data to train general-purpose AI models.
- AI outputs, including interview analysis and scores, support human decisions and are not the sole basis for decisions about people.
9. Mobile App Permissions
Our apps request device permissions only when a feature needs them, and you can change them in your device settings:
- Camera: face attendance, face identification, QR scanning, and photos or documents you choose to upload.
- Location: GPS or geofence attendance, staff tracking and transport trip tracking, when enabled by your organisation.
- Notifications: alerts about attendance, fees, homework, approvals and trips.
- Storage / files: downloading payslips, receipts and reports, and uploading documents.
10. Sharing and Sub-processors
We share personal data only as needed to provide the Services, and with:
- The Customer organisation that controls the account, and authorised users within it according to their roles.
- Service providers (sub-processors) for cloud hosting and storage, content delivery, email and SMS delivery, push notifications, maps, video meetings, AI model processing and payment processing, bound by confidentiality and data protection obligations.
- Authorities, where required by law, court order or to protect rights, safety and security.
- A successor entity in a merger, acquisition or restructuring, subject to this policy.
A current list of sub-processors is available to Customers on request.
11. WhatsApp and Communications
When a Customer uses our WhatsApp module, messages are sent through the official WhatsApp Business Platform (Cloud API) operated by Meta, using the Customer’s own business account. Customers are responsible for obtaining opt-in consent from recipients and for honouring opt-outs. Meta’s processing is governed by its own terms and policies.
12. Payments
Online fee and subscription payments are processed by authorised payment gateways. Card, UPI and net-banking credentials are entered on the gateway’s secure pages and are not stored by Pedinno. We receive payment status and reference details to issue receipts and update ledgers.
13. Data Retention and Deletion
- Customer data is retained for the duration of the Customer’s subscription and as instructed by the Customer.
- After a subscription ends, Customers may request an export of their data; we then delete or anonymise it within a reasonable period, except where law requires us to keep it (for example, tax and accounting records).
- Enquiry and demo data is kept for as long as needed to respond and follow up, and then deleted.
- Security and audit logs are kept for a limited period needed to protect the Services.
14. Security
We use reasonable security practices including encryption in transit, encrypted storage of secrets and device tokens, role-based and branch-level access control, OTP-based sign-in, instant device logout and disable, login activity logs and audit trails. More detail is on our Data Security page. No system is completely secure; if a personal data breach occurs, we will notify affected Customers and, where required, the Data Protection Board of India and affected individuals.
15. Your Rights
Subject to applicable law, you have the right to:
- Access a summary of your personal data and how it is processed.
- Correct, complete, update or erase your personal data.
- Withdraw consent where processing is based on consent (this does not affect prior processing).
- Have your grievance addressed, and nominate another person to exercise your rights in case of death or incapacity.
For data in a Customer’s account, please contact your school or employer first. For other requests, contact our Grievance Officer below. If you are not satisfied with our response, you may approach the Data Protection Board of India.
16. Storage and Cross-Border Transfers
Data is primarily processed and stored on cloud infrastructure. Some service providers may process data outside India; any such transfer is made in compliance with the DPDP Act and any restrictions notified by the Government of India.
17. Cookies
Our website uses essential cookies, and, with your consent, analytics and preference cookies. You can change your choice at any time. See our Cookie Policy.
18. Changes to This Policy
We may update this policy as the Services or the law change. We will post the updated version here with a new “Last updated” date and, for material changes, notify Customers.
19. Grievance Officer and Contact
Grievance Officer
Pedinno Private Limited
Shop No. 111/62, Sec-11 JCC, Near India Post Office, Pratap Nagar, Jaipur, Rajasthan 302033, India
Email: info@pedinno.com
Phone: +91 8239999353
We address grievances expeditiously and in any case within one month of receipt.