Privacy Policy
Protecting your data is our highest priority.
What We Collect
To provide a high-fidelity experience, Semipass collects limited but necessary information:
- Identity Details: Full name, email address, and profile photo for your Global Identity Passport.
- Operational Data: Attendance logs, class enrollment history, and institute-specific identifiers.
- Financial Metadata: Transaction records (amount, method, and date) for receipt generation.
Where Data is Stored
We utilize world-class infrastructure to ensure your data is secure and always available. Our primary sub-processors include:
Data Portability & Export
We believe in data freedom, not vendor lock-in. Registered Institute Administrators can request or generate a comprehensive export of their institute's data (students, classes, and records) at any time. We provide these exports in standardized formats like CSV or JSON to ensure your data remains your own.
Child Data Protection
As an educational platform, we take the privacy of minors seriously:
- Parental Control: Our "Parent Link" system ensures that only authorized parents can view a child's attendance and financial history.
- Institute Responsibility: Educational institutes are required to obtain parental consent before enrolling students under the age of 16.
- Minimal Exposure: We do not include "social" features that expose child data to uninvited third parties.
Breach Notification
In accordance with the Sri Lanka Personal Data Protection Act (PDPA), we maintain strict security monitoring. In the unlikely event of a data breach, we will notify affected institutes and users within 72 hours of discovery.