Privacy Policy

Oxirgi yangilanish: 2026-09-02

This Privacy Policy describes how the 'M - IT UNO' mobile application and educational ERP platform collects, uses, and protects user data, including automated attendance tracking via physical on-premise Face ID terminals installed at learning center facilities. This document strictly complies with Google Play Developer Policies and Apple App Store Review Guidelines.

1. Information We Collect

To provide our educational services, we collect:
• Personal Identification: Full name, date of birth, contact phone number, and parent/guardian contact details.
• Profile Photo: Uploaded voluntarily for profile identification and synchronized with the center's attendance system.
• Academic Records: Assigned groups, class schedules, attendance logs, homework submissions, quiz results, and teacher evaluations.
• Billing Information: Monthly tuition records, applied discounts, and payment receipts.
• Device & Technical Data: Device model, operating system version, IP address, and Firebase Cloud Messaging (FCM) tokens for push notifications.

2. Physical Face ID Terminals & Biometric Attendance (Explicit Disclosure)

Important Note: The mobile application itself DOES NOT perform background facial recognition or scan biometric data using your smartphone's camera.

• On-Premise Hardware Terminals: Attendance tracking via facial recognition is handled exclusively by DEDICATED PHYSICAL FACE ID TERMINALS (hardware terminals / Hikvision devices) located at the physical entrance/exit of the learning center.
• Purpose of Processing: When a student physically enters or leaves the center, the hardware terminal logs the check-in/check-out timestamp.
• Parent Notifications: Attendance logs recorded by the physical terminal are automatically and securely dispatched to parents via Telegram.
• No Commercial Sharing: Facial biometric templates are strictly encrypted and never sold, rented, or shared with third-party advertisers or external services.

3. Mobile App Permissions

The application may request the following device permissions with explicit user consent:
• Camera: Used exclusively when the user chooses to take an avatar photo or capture a picture of completed homework assignments (e.g., workbook solutions).
• Storage / Media: Used to upload and download course materials and assignment files (PDF, ZIP, images).
• Push Notifications: Used to alert users regarding new assignments, timetable updates, fee reminders, and center announcements.

4. Data Security & Encryption

All communications between the mobile application and backend services are encrypted using industry-standard SSL/TLS 1.3 protocols. Data is stored in hardened cloud environments with strict role-based access control (RBAC).

5. Account and Data Deletion (Google & Apple Compliant)

In compliance with Google Play and Apple App Store mandates, users have the right to request complete deletion of their account and associated data at any time.

• How to Request Deletion: Users can initiate deletion via in-app Profile Settings or by submitting a written request to center administration / support.
• Retention Period: All personal profiles, photos, and hardware terminal identifiers are permanently purged within 14 business days of confirmation.

6. Children's Privacy (COPPA & GDPR-K Compliance)

When juvenile students are enrolled, accounts are linked with verified parent/guardian contacts. Parents retain full visibility and oversight over their child's academic progress, attendance history, and account data.