Contents
- 1. Introduction
- 1.1 Our Commitment to Privacy
- 1.2 Purpose of this Privacy Policy
- 1.3 Relationship with Other Privacy Documents
- 1.4 Acknowledgement of this Privacy Policy
- 2. Scope
- 2.1 Services Covered
- 2.2 Persons Covered
- 2.3 Schools Covered
- 2.4 Geographic Scope
- 2.5 Public Cortex IOS Website
- 3. About Cortex IOS and the Educational Data Environment
- 3.1 Cortex IOS as a School Operating System
- 3.2 Nature of Educational Information
- 3.3 Government and Educational Reporting Information
- 3.4 Multi-Tenant Environment
- 4. Roles and Responsibilities
- 4.1 The Role of the School
- 4.2 The Role of Aionpixel
- 4.3 The Role of Parents and Guardians
- 4.4 The Role of Students
- 4.5 The Role of Teachers and School Staff
- 5. Information We Process
- 5.1 General Principle
- 5.2 Student Identity and Profile Information
- 5.3 Student Demographic and Background Information
- 5.4 Parent, Guardian and Family Information
- 5.5 Admission and Enrolment Information
- 5.6 Academic and Learning Information
- 5.7 Attendance and Leave Information
- 5.8 Financial and Fee Information
- 5.9 Health, Welfare and Support Information
- 5.10 Transport Information
- 5.11 Staff and Employment Information
- 5.12 Communications and Collaboration Information
- 5.13 Device and Technical Information
- 5.14 Security and Audit Information
- 5.15 Mobile Application Information
- 5.16 Device Permissions
- 6. Why Information Is Processed
- 6.1 General Processing Purposes
- 6.2 Student Administration
- 6.3 Academic and Educational Purposes
- 6.4 Attendance and School Operations
- 6.5 Parent and Guardian Engagement
- 6.6 Fee, Payment and Accounting Administration
- 6.7 Human Resource and Staff Administration
- 6.8 Communications and Notifications
- 6.9 Regulatory, Educational and Government Reporting
- 6.10 Security, Fraud Prevention and Platform Integrity
- 6.11 Technical Support and Service Delivery
- 6.12 Product Improvement
- 7. Sensitive and Higher-Risk Information
- 7.1 Nature of Sensitive Information
- 7.2 School Responsibility for Sensitive Information
- 7.3 Access to Sensitive Information
- 7.4 Use of Demographic Information
- 7.5 Health and Welfare Information
- 8. Children's and Student Information
- 8.1 Our Approach to Children's Information
- 8.2 Information Collected Through Schools
- 8.3 Parent and Guardian Involvement
- 8.4 Student Access
- 8.5 Student Privacy Notices
- 8.6 Advertising and Commercial Profiling
- 8.7 Student Safety and School Responsibilities
- 9. How Information Is Collected or Received
- 9.1 Information Provided by Schools
- 9.2 Information Provided by Parents and Guardians
- 9.3 Information Provided by Students
- 9.4 Information Provided by Teachers and School Staff
- 9.5 Information Collected Automatically
- 9.6 Information from Integrations and Service Providers
- 9.7 Information from Government or Educational Sources
- 10. Web Portal and Mobile Application Processing
- 10.1 Web Portal Access
- 10.2 Account Creation and Provisioning
- 10.3 Mobile Application Access
- 10.4 Role-Based Mobile Experience
- 10.5 Information Submitted Through Mobile Features
- 10.6 Privacy Policy Acknowledgement
- 10.7 Platform Terms Agreement
- 10.8 Policy Version Changes
- 10.9 Account Access Termination
- 10.10 Privacy and Data Requests
- 11. Sharing and Disclosure of Information
- 11.1 General Principle
- 11.2 Access by the School
- 11.3 Access by Parents, Guardians and Students
- 11.4 Aionpixel Personnel
- 11.5 Service Providers and Subprocessors
- 11.6 Payment Service Providers
- 11.7 Communication Service Providers
- 11.8 School-Enabled Integrations
- 11.9 Educational and Government Authorities
- 11.10 Legal and Safety Disclosures
- 11.11 Corporate Transactions
- 12. Location and International Processing of Information
- 12.1 Cloud and Service Infrastructure
- 12.2 Cross-Border Processing
- 12.3 School Requirements
- 13. Data Retention and Deletion
- 13.1 Retention Principle
- 13.2 School-Controlled Records
- 13.3 Technical and Security Information
- 13.4 Backups
- 13.5 Account Access and Data Retention
- 13.6 Deletion Requests
- 13.7 Tenant Termination
- 14. Security and Protection of Information
- 14.1 Security Commitment
- 14.2 Security by Design
- 14.3 Encryption
- 14.4 Role-Based Access Control
- 14.5 Tenant Isolation
- 14.6 Authentication and Session Security
- 14.7 Monitoring and Auditability
- 14.8 Security Incident Response
- 14.9 User and School Responsibilities
- 15. Artificial Intelligence and Automated Features
- 15.1 AI-Assisted Capabilities
- 15.2 AI Does Not Automatically Process All Cortex IOS Data
- 15.3 Purpose Limitation
- 15.4 Third-Party AI Service Providers
- 15.5 AI Training Claims
- 15.6 Human Responsibility and Educational Decisions
- 15.7 Automated Processing and Transparency
- 15.8 Future AI Features
- 16. Privacy Rights and Privacy Requests
- 16.1 General Principle
- 16.2 Access to Personal Information
- 16.3 Correction of Information
- 16.4 Deletion of Eligible Personal Information
- 16.5 Restriction or Review of Processing
- 16.6 Objection to Processing
- 16.7 Withdrawal of Consent
- 16.8 Communication Preferences
- 16.9 Data Export and Portability
- 16.10 Privacy Requests Relating to Children
- 16.11 Identity Verification
- 16.12 Response to Privacy Requests
- 16.13 How to Submit a Privacy Request
- 17. Cookies and Similar Technologies
- 17.1 Browser-Based Services
- 17.2 Essential Technologies
- 17.3 Non-Essential Technologies
- 17.4 Mobile Applications
- 17.5 Further Information
- 18. Third-Party Services and Integrations
- 18.1 Use of Third-Party Services
- 18.2 Information Shared with Service Providers
- 18.3 Service Provider Responsibilities
- 18.4 School-Selected or School-Enabled Services
- 18.5 Third-Party Privacy Practices
- 18.6 Transparency Regarding Providers
- 19. Changes to this Privacy Policy
- 19.1 Policy Updates
- 19.2 Material Changes
- 19.3 Policy Versioning
- 19.4 Non-Material Changes
- 20. Contact Information
- 20.1 Privacy Enquiries
- 20.2 School-Related Requests
- 20.3 Security Concerns
- 20.4 Product Support
1. Introduction
1.1 Our Commitment to Privacy
Cortex IOS is a cloud-based School Operating System developed, owned and operated by Aionpixel Technologies Private Limited. Throughout this document, references to "Aionpixel", "we", "our", or "us" mean Aionpixel Technologies Private Limited, the legal owner and operator of Cortex IOS.
Cortex IOS is designed to support educational institutions in managing academic, administrative, financial, operational, communication, human resource, and learning activities through integrated digital services.
Schools may use Cortex IOS to process information relating to students, parents and guardians, teachers, non-teaching staff, school management, administrators, finance personnel, and other authorised members of the school community.
We recognise that educational technology involves a significant responsibility, particularly where information relating to children and students is concerned.
Aionpixel is committed to responsible data handling, transparency, privacy by design, security by design, purpose-based processing, and appropriate protection of personal information processed through Cortex IOS.
This Product Privacy Policy ("Privacy Policy") explains how personal information is collected, received, accessed, used, processed, stored, shared, protected, retained, and otherwise handled in connection with Cortex IOS.
1.2 Purpose of this Privacy Policy
The purpose of this Privacy Policy is to explain:
- the types of personal information that may be processed through Cortex IOS
- why such information may be required
- how information may be collected or received
- the respective roles of Schools and Aionpixel
- how authorised users may access information
- when information may be shared with third parties
- how information is protected
- how retention and deletion are approached
- how privacy-related requests may be submitted
- how privacy practices apply across Cortex IOS web and mobile services
This Privacy Policy is intended to provide a transparent overview of Cortex IOS privacy practices.
It does not replace privacy notices, consent requirements, policies, or statutory obligations that may independently apply to a School.
1.3 Relationship with Other Privacy Documents
This Privacy Policy is the principal product-level privacy document for Cortex IOS.
Depending on your relationship with a School and your use of Cortex IOS, additional notices or documents may apply, including:
- Parent & Guardian Privacy Notice
- Student Privacy Notice
- School Staff Privacy Notice
- Platform Terms of Service
- Cookie & Similar Technologies Policy
- Data Governance Statement
- Information Security Statement
- privacy notices or policies issued directly by your School
- feature-specific notices or consent requests where applicable
Where a more specific privacy notice applies to a particular user category or processing activity, that notice supplements this Privacy Policy.
1.4 Acknowledgement of this Privacy Policy
Authorised users accessing the Cortex IOS web portal or mobile application may be requested to acknowledge that they have been provided with an opportunity to read and understand this Privacy Policy.
Acknowledgement of this Privacy Policy is a record of privacy notice and awareness.
It should not automatically be interpreted as blanket consent for every processing activity conducted by a School or through Cortex IOS.
Where consent is specifically required for a particular processing activity, feature, communication, or optional use of personal information, an appropriate consent or choice mechanism may be presented separately.
Cortex IOS may record the version of this Privacy Policy acknowledged by an authorised user, together with relevant acceptance or acknowledgement information for audit and compliance purposes.
2. Scope
2.1 Services Covered
This Privacy Policy applies to personal information processed in connection with Cortex IOS services, including, where enabled:
- Cortex IOS web portals
- Parent Portal
- Student Portal
- Teacher Portal
- School Administration Portal
- Management dashboards
- Finance and Accounts functions
- Human Resource Management functions
- Learning Management services
- communication services
- reporting and analytics functions
- Android mobile applications
- iOS mobile applications
- authorised APIs
- approved integrations
- related technical and support services
The availability of individual modules, features, and services may vary between Schools depending on their subscription, configuration, policies, educational requirements, and enabled integrations.
2.2 Persons Covered
This Privacy Policy may apply to information relating to:
- prospective students
- enrolled students
- former students where records remain lawfully retained
- parents
- legal guardians
- authorised family contacts
- teachers
- non-teaching staff
- school administrators
- principals and academic leaders
- school management
- finance and accounts personnel
- human resource personnel
- transport personnel
- library personnel
- authorised School representatives
- applicants
- vendors or service contacts where relevant to School operations
- other authorised users of Cortex IOS
Not every category of information described in this Privacy Policy is processed for every individual.
The information processed depends upon the individual's relationship with the School, the Cortex IOS modules enabled by the School, and the functions used.
2.3 Schools Covered
Cortex IOS may be used by different types of educational institutions, including K–12 Schools and School groups.
Schools may follow different:
- educational boards
- curricula
- statutory requirements
- administrative practices
- internal policies
- reporting requirements
- data retention requirements
Accordingly, the information requested by one School may differ from the information requested by another School.
2.4 Geographic Scope
Cortex IOS is primarily designed to support educational institutions operating in India.
Where Cortex IOS is made available to organisations or individuals in other jurisdictions, additional legal or privacy requirements may apply.
Aionpixel and the subscribing School may implement additional notices, contractual safeguards, or processes where required by applicable law.
2.5 Public Cortex IOS Website
The Cortex IOS public website may process limited information relating to website visitors, product enquiries, demonstration requests, and website interactions.
Public website use is also subject to the Cortex IOS Website Terms of Use and applicable cookie disclosures.
Information submitted through product enquiries or demonstration requests may also be processed by Aionpixel for customer relationship, sales, support, and business administration purposes.
3. About Cortex IOS and the Educational Data Environment
3.1 Cortex IOS as a School Operating System
Cortex IOS provides a digital platform through which Schools may manage multiple educational and institutional functions.
Depending on the modules enabled, these functions may include:
- admissions and enrolment
- student information management
- parent and guardian records
- academic administration
- curriculum and subject management
- attendance
- timetable management
- examinations and assessments
- gradebooks and progress reporting
- learning management
- assignments and learning activities
- fee administration
- payment records
- accounting
- library management
- transport management
- human resource management
- staff attendance and administration
- communication and notifications
- school governance workflows
- regulatory reporting
- institutional reporting and analytics
- other School-configured operational processes
Cortex IOS does not independently determine the educational curriculum, academic decisions, admission criteria, student grades, School policies, or statutory reporting obligations of a School.
These matters remain subject to the authority and responsibility of the School and applicable educational requirements.
3.2 Nature of Educational Information
The information processed through a School Operating System may differ from information typically processed by a general consumer application.
Schools may be required to maintain detailed records relating to students and their educational journey.
Depending upon School requirements and applicable law, these records may include identity, family, demographic, academic, attendance, assessment, financial, welfare, transport, and other educational information.
Certain information may be requested because it is required for:
- student admission
- maintenance of School records
- educational administration
- government reporting
- education department reporting
- board-related requirements
- scholarship administration
- student support
- inclusion or accessibility requirements
- statutory compliance
- other legitimate School purposes
Cortex IOS provides the technology through which authorised Schools may collect and manage such information.
3.3 Government and Educational Reporting Information
Schools in India may be required or expected to maintain information for educational administration, government reporting, statutory records, or schemes applicable to students.
Depending on the School and applicable requirements, information processed through Cortex IOS may include:
- gender
- date of birth
- nationality
- religion
- caste, category, or community information
- mother tongue
- socio-economic information
- family income or income category
- scholarship-related information
- disability or special support information
- government-issued or educational identifiers
- information relevant to government schemes
- other information required for authorised educational reporting
The inclusion of a data field within Cortex IOS does not, by itself, mean that every School is required to collect that information.
The School is responsible for determining whether information is required, appropriate, and lawfully collected for its educational and administrative purposes.
Where Cortex IOS supports configurable data fields, Schools should collect only information appropriate to their requirements and applicable obligations.
3.4 Multi-Tenant Environment
Cortex IOS is designed as a multi-tenant SaaS platform.
Different subscribing Schools or School groups operate within authorised tenant environments.
Cortex IOS uses logical access controls and platform design measures intended to restrict users to the tenant, School, role, and information they are authorised to access.
A user authorised by one School is not automatically entitled to access information belonging to another School.
Where a School group operates multiple Schools, access may be configured according to the governance and authorisation structure established for that School group.
Further information regarding our security approach is available in the Cortex IOS Information Security Statement.
4. Roles and Responsibilities
4.1 The Role of the School
In most educational processing activities conducted through Cortex IOS, the School determines:
- what student, parent, or staff information is required
- why the information is required
- which School processes use the information
- who within the School may access the information
- which Cortex IOS modules are enabled
- which communications are sent
- which educational or administrative records are created
- whether optional features are enabled
- applicable School-level retention requirements, subject to law and contractual arrangements
The School is responsible for ensuring that its collection and use of personal information is appropriate for its educational, administrative, statutory, and operational purposes.
Schools are also responsible for managing authorised user access and assigning appropriate roles and permissions within the scope of available Cortex IOS controls.
4.2 The Role of Aionpixel
Aionpixel develops, operates, hosts, maintains, and supports Cortex IOS.
For School-controlled information, Aionpixel generally processes information to:
- provide Cortex IOS
- host and store authorised information
- execute School-configured workflows
- make information available to authorised users
- maintain platform functionality
- provide technical support
- maintain platform security
- detect and investigate technical or security events
- perform authorised backups and recovery activities
- support integrations enabled by the School
- meet applicable contractual and legal obligations
Aionpixel does not sell student personal information.
Aionpixel does not use student educational information to create commercial behavioural advertising profiles.
Aionpixel may separately determine the purposes and means of processing certain limited information required for its own legitimate corporate, security, contractual, billing, support, fraud-prevention, and legal compliance activities.
4.3 The Role of Parents and Guardians
Parents and guardians may use Cortex IOS to access information and services made available by their School.
Depending on School configuration, parents or guardians may:
- view student information
- provide or update authorised information
- submit documents
- review attendance
- view academic information
- receive School communications
- access fee information
- make or review payments
- communicate with authorised School personnel
- manage applicable communication preferences
- review privacy information
- submit privacy-related requests
Parents and guardians are responsible for providing accurate information to the best of their knowledge and for notifying the School where relevant information requires correction.
Where a parent or guardian provides information relating to a student, they should do so only where they are authorised to provide that information.
4.4 The Role of Students
Students may access Cortex IOS according to their School, grade, age, assigned role, and enabled features.
Depending on School configuration, students may:
- view academic information
- access learning content
- submit assignments
- participate in authorised learning activities
- view attendance or timetable information
- receive School communications
- use other student-facing features
Students should use Cortex IOS only for authorised educational purposes and should not attempt to access information relating to other users without permission.
Age-appropriate privacy information and parental or guardian involvement may be provided where applicable.
4.5 The Role of Teachers and School Staff
Teachers, administrators, finance personnel, School management, and other authorised staff may access information according to their assigned roles and responsibilities.
School personnel are expected to:
- access information only for authorised purposes
- protect account credentials
- maintain confidentiality
- use information in accordance with School policies
- avoid unauthorised disclosure
- report suspected security or privacy incidents
- comply with applicable legal and professional obligations
Access to Cortex IOS does not grant unrestricted authority to access all information held by a School.
5. Information We Process
5.1 General Principle
The categories of information processed through Cortex IOS depend on:
- the School using Cortex IOS
- the modules enabled by the School
- the user's role
- the educational or administrative process involved
- information submitted by authorised users
- applicable statutory or regulatory requirements
- integrations enabled by the School
Cortex IOS does not necessarily process every category listed below for every School or user.
5.2 Student Identity and Profile Information
This may include:
- full name
- preferred name
- photograph
- date of birth
- gender
- student admission number
- student identifier
- roll number
- class
- grade
- division or section
- academic year
- admission date
- nationality
- mother tongue
- other School-defined student profile information
5.3 Student Demographic and Background Information
Where required or configured by the School, information may include:
- religion
- caste
- category or community classification
- socio-economic information
- family income or income category
- scholarship eligibility
- minority status where applicable
- disability or accessibility information
- special educational support information
- rural or urban classification where relevant
- government scheme eligibility
- other demographic information required for authorised School or educational reporting purposes
Because some of this information may be sensitive, Schools should collect and use such information only where appropriate for their authorised purposes and applicable requirements.
5.4 Parent, Guardian and Family Information
This may include:
- parent or guardian name
- relationship to the student
- contact number
- email address
- residential address
- occupation
- employer information where required
- educational information where collected by the School
- family information
- emergency contact information
- authorised pickup information
- custody or guardianship-related information where lawfully recorded
- communication preferences
5.5 Admission and Enrolment Information
This may include:
- admission applications
- enquiry information
- previous School information
- previous academic records
- transfer information
- certificates
- identification documents
- photographs
- declarations
- admission decisions
- application status
- submitted documents
- School-defined admission information
5.6 Academic and Learning Information
This may include:
- subjects
- curriculum information
- academic plans
- assessments
- examination records
- marks
- grades
- competencies
- learning outcomes
- teacher observations
- progress information
- report cards
- assignments
- submitted learning work
- learning activity records
- learning management activity
- other educational records
5.7 Attendance and Leave Information
This may include:
- student attendance
- staff attendance
- presence or absence status
- late arrival information
- leave applications
- leave reasons
- attendance corrections
- attendance history
- authorised attendance-related remarks
5.8 Financial and Fee Information
Depending on the modules enabled, Cortex IOS may process:
- fee structures
- fee assignments
- invoices
- payment status
- receipts
- concessions
- scholarships
- refunds
- outstanding balances
- transaction references
- payment gateway references
- accounting records
Cortex IOS may integrate with payment service providers where enabled.
Payment card, banking, or payment credential information may be processed directly by applicable payment service providers depending on the payment flow and integration used.
5.9 Health, Welfare and Support Information
Where enabled and lawfully used by the School, information may include:
- health-related information provided to the School
- allergies
- medical conditions relevant to student support
- emergency health information
- disability information
- accessibility requirements
- student welfare information
- authorised counselling or support-related records
- incident-related information
Cortex IOS does not require every School to collect such information.
The School determines whether these functions are used and what information is appropriate for its responsibilities.
5.10 Transport Information
Where transport functions are enabled, information may include:
- assigned route
- vehicle information
- pickup point
- drop-off point
- transport contact information
- boarding information
- transport attendance
- route-related notifications
- location-related information where a specific transport feature requires and supports such processing
5.11 Staff and Employment Information
Where Cortex IOS HR or staff administration functions are enabled, information may include:
- staff identity information
- contact information
- employment information
- department
- designation
- qualifications
- attendance
- leave
- payroll-related records
- professional development information
- assigned responsibilities
- performance or administrative records where configured
- other School employment information
Staff information is further addressed in the School Staff Privacy Notice.
5.12 Communications and Collaboration Information
Cortex IOS may process communications sent through enabled platform features, including:
- announcements
- notices
- messages
- chats
- circulars
- communication acknowledgements
- support communications
- comments
- notifications
- attachments submitted through communication features
Users should not use Cortex IOS communication features to share information that is unrelated to legitimate School, educational, or authorised operational purposes.
5.13 Device and Technical Information
When Cortex IOS is accessed, we may process technical information such as:
- device type
- device model
- operating system
- operating system version
- browser type
- browser version
- application version
- IP address
- session information
- authentication information
- network-related information
- technical error information
- diagnostic information
This information may be used for security, authentication, compatibility, troubleshooting, support, and platform performance purposes.
5.14 Security and Audit Information
Cortex IOS may create or process records relating to:
- login attempts
- successful authentication
- failed authentication
- session activity
- administrative actions
- role or permission changes
- significant configuration changes
- security events
- data-related actions where audit logging is supported
- support access
- system events
- other activities required for security or accountability
The nature and retention of audit information may vary according to the event, platform function, School requirements, security requirements, and applicable obligations.
5.15 Mobile Application Information
The Cortex IOS mobile application is intended for existing authorised users.
The mobile application does not provide a general public user-registration process and does not independently create Cortex IOS user accounts.
User accounts are created, provisioned, or authorised through applicable School or web-platform workflows.
When an existing authorised user signs in to the mobile application, Cortex IOS may process:
- authentication information
- user role
- School or tenant association
- authorised profile information
- application version
- device and operating system information
- notification information
- session information
- information submitted through enabled mobile features
Depending on the user's role and School configuration, mobile features may allow authorised users to perform actions such as:
- view educational or administrative information
- receive notifications
- send authorised communications
- submit assignments
- mark or manage attendance
- upload documents or photographs
- access learning features
- perform other role-authorised platform activities
The mobile application does not provide an instant self-service function for deleting a Cortex IOS account.
Privacy, access, correction, or deletion-related requests may be submitted through available privacy request channels and may require review by the School or Aionpixel, depending on the nature of the information and applicable retention requirements.
5.16 Device Permissions
Certain mobile features may require access to device capabilities.
Depending on the feature used, Cortex IOS may request permission to access:
- camera
- microphone
- photographs or media
- files or document storage
- notifications
- location where a specifically enabled feature requires location-related functionality
Permissions are requested through the device operating system where applicable.
The availability of a device permission does not mean Cortex IOS continuously accesses that capability.
Access should occur in connection with the relevant feature and applicable permission settings.
Users may manage device permissions through their operating system settings, although disabling a permission may prevent the associated feature from functioning correctly.
6. Why Information Is Processed
6.1 General Processing Purposes
Personal information processed through Cortex IOS is used to support authorised educational, administrative, operational, financial, communication, security, and technology-related activities.
The specific purpose for which information is processed depends on:
- the School's requirements
- the individual's relationship with the School
- the Cortex IOS modules enabled by the School
- the feature being used
- applicable educational or statutory requirements
- the actions of authorised users
Aionpixel does not independently require every category of information described in this Privacy Policy from every School or user.
6.2 Student Administration
Information may be processed to:
- create and maintain student records
- manage admissions and enrolment
- assign admission numbers or student identifiers
- maintain class, grade, division, and academic-year information
- manage student progression
- maintain student profiles
- manage transfers or withdrawals
- generate authorised School records
- support general student administration
6.3 Academic and Educational Purposes
Information may be processed to:
- manage subjects and curricula
- maintain academic plans
- create and administer assessments
- record marks and grades
- monitor competencies and learning outcomes
- prepare report cards and progress reports
- record teacher observations
- manage assignments
- deliver learning content
- monitor authorised learning activities
- support academic review
- assist Schools in managing teaching and learning processes
Academic decisions remain the responsibility of the School and its authorised academic personnel.
6.4 Attendance and School Operations
Information may be processed to:
- record attendance
- manage absence and leave
- identify attendance patterns
- communicate attendance-related information
- manage School calendars
- manage timetables
- support transport operations
- manage library activities
- support School events
- administer operational workflows
- maintain School records
6.5 Parent and Guardian Engagement
Information may be processed to:
- associate authorised parents or guardians with students
- provide access to relevant student information
- send School communications
- provide attendance information
- provide academic information
- display fee and payment information
- support authorised parent–School communication
- receive documents or information from parents
- manage communication preferences where available
- provide access to privacy and compliance information
Access to student information is subject to the relationship and authorisation records maintained by the School.
6.6 Fee, Payment and Accounting Administration
Information may be processed to:
- configure fee structures
- assign fees
- generate invoices or demands
- record payments
- generate receipts
- manage concessions or scholarships
- process refunds
- maintain payment references
- reconcile transactions
- maintain accounting records
- support financial reporting
- meet applicable financial or record-keeping requirements
Where payment gateways or financial service providers are used, information necessary to initiate, verify, or reconcile a transaction may be exchanged with the applicable provider.
Aionpixel does not use student financial information for unrelated commercial profiling.
6.7 Human Resource and Staff Administration
Where HR or staff administration modules are enabled, information may be processed to:
- maintain staff records
- manage employment-related information
- assign departments and roles
- administer attendance and leave
- support payroll-related processes
- manage professional development
- manage assigned responsibilities
- maintain administrative records
- support School workforce operations
6.8 Communications and Notifications
Information may be processed to enable authorised School communications, including:
- emergency notifications
- attendance alerts
- School closure notices
- examination information
- timetable changes
- fee-related communications
- transport notifications
- academic notices
- assignments
- announcements
- circulars
- student welfare communications
- other authorised School messages
Certain communications may be considered necessary for School operations, educational administration, student safety, or the delivery of services.
Where communication preferences are available, they may distinguish between essential School communications and optional communications.
The ability to disable a particular communication channel does not necessarily prevent the School from using another authorised channel to send essential information.
6.9 Regulatory, Educational and Government Reporting
Information may be processed to assist Schools in preparing records, reports, or submissions required or requested by:
- education departments
- educational boards
- competent government authorities
- statutory bodies
- authorised education programmes
- scholarship programmes
- other applicable regulatory or educational processes
Cortex IOS provides technology and reporting functionality.
The School remains responsible for determining whether a particular report or disclosure is required and for verifying the accuracy and appropriateness of information submitted to an authority.
6.10 Security, Fraud Prevention and Platform Integrity
Information may be processed to:
- authenticate users
- protect accounts
- manage sessions
- enforce access controls
- detect suspicious activity
- investigate security events
- prevent unauthorised access
- diagnose technical problems
- protect platform availability
- maintain audit records
- investigate misuse
- support incident response
Security-related processing may occur independently of individual user preferences where necessary to protect Cortex IOS, Schools, users, or information processed through the platform.
6.11 Technical Support and Service Delivery
Information may be processed to:
- respond to support requests
- investigate reported problems
- reproduce technical errors
- diagnose application behaviour
- resolve integration issues
- support School administrators
- maintain platform functionality
- improve service reliability
Support personnel should access customer information only where authorised and necessary for the applicable support or operational purpose.
6.12 Product Improvement
Aionpixel may use appropriately controlled technical, operational, performance, and usage information to:
- improve Cortex IOS
- identify application errors
- improve performance
- improve user experience
- evaluate feature reliability
- strengthen security
- plan platform improvements
Where possible and appropriate, aggregated or de-identified information may be used for analysis.
Aionpixel does not use student educational records to create behavioural advertising profiles.
7. Sensitive and Higher-Risk Information
7.1 Nature of Sensitive Information
Certain information processed through Cortex IOS may require a higher level of care because of its nature, the individual concerned, or the potential impact of misuse.
Depending on School configuration and requirements, this may include:
- information relating to children
- caste or category information
- religion
- disability information
- health information
- socio-economic information
- family income information
- scholarship information
- student welfare information
- financial records
- government or educational identifiers
- photographs
- counselling or support-related information
- other information considered sensitive under applicable law or School policy
The terminology and legal classification applicable to such information may differ between jurisdictions.
7.2 School Responsibility for Sensitive Information
Schools should collect sensitive or higher-risk information only where it is appropriate for an authorised educational, administrative, welfare, statutory, or legal purpose.
The availability of a configurable data field within Cortex IOS does not require a School to use that field.
Schools are responsible for determining:
- whether the information is required
- the purpose for collecting it
- whether an applicable notice is required
- whether consent or another lawful basis is required
- which users may access the information
- how the information should be handled under applicable School policies and law
7.3 Access to Sensitive Information
Cortex IOS is designed to support role-based access controls.
Access to sensitive information should be limited according to:
- user role
- assigned responsibility
- School configuration
- operational necessity
- available platform permissions
Not every teacher, staff member, parent, administrator, or other user is automatically entitled to access every category of information held within Cortex IOS.
7.4 Use of Demographic Information
Demographic information such as religion, caste, category, community, socio-economic status, or family income may be processed where required by the School for authorised purposes.
These purposes may include:
- maintenance of School records
- educational reporting
- government reporting
- scholarship administration
- eligibility assessment
- inclusion programmes
- regulatory requirements
- other authorised educational purposes
Aionpixel does not use student demographic information for behavioural advertising or unrelated commercial profiling.
7.5 Health and Welfare Information
Where a School enables features that process health, welfare, accessibility, or support-related information, such information should be accessed only by authorised persons for legitimate School purposes.
Cortex IOS is not a substitute for professional medical diagnosis, treatment, emergency medical services, or independent clinical record systems unless expressly configured and lawfully used for a specific authorised purpose.
Schools remain responsible for their student welfare, medical, safeguarding, and emergency procedures.
8. Children's and Student Information
8.1 Our Approach to Children's Information
Cortex IOS is specifically designed for educational environments and may process information relating to children and students.
We recognise that children's information requires particular care.
Our approach is guided by principles including:
- transparency
- purpose limitation
- appropriate access control
- security by design
- privacy by design
- responsible data use
- appropriate parental or guardian involvement where required
8.2 Information Collected Through Schools
In most circumstances, student information is collected, entered, uploaded, or maintained through processes established by the School.
Information may be provided by:
- parents or guardians
- students
- teachers
- authorised School staff
- School administrators
- previous School records
- authorised integrations
- other lawful School sources
Aionpixel does not independently approach children to build consumer profiles or collect student information for advertising purposes.
8.3 Parent and Guardian Involvement
Depending on the student's age, applicable law, School policy, and the processing activity involved, a parent or guardian may:
- provide information relating to the student
- review privacy notices
- acknowledge privacy information
- provide specific consent where required
- access authorised student information
- request correction of information
- submit privacy-related requests
- manage applicable optional communication or processing preferences
A parent's acknowledgement of this Privacy Policy is not treated as unlimited consent for every present or future processing activity.
Where specific consent is required, Cortex IOS or the School may present a separate consent mechanism.
8.4 Student Access
Students may be provided with Cortex IOS access by their School.
Student access is limited according to the user's authorised account, School, tenant, role, and enabled functionality.
Cortex IOS mobile applications do not provide a general public registration process through which a child independently creates a Cortex IOS account.
Student accounts are created, provisioned, or authorised through applicable School or web-platform workflows.
8.5 Student Privacy Notices
Cortex IOS may provide a Student Privacy Notice designed to explain privacy practices in a more focused and understandable manner.
Schools may also provide their own student privacy notices.
Where appropriate, privacy information may be presented using language suited to the age and understanding of the intended users.
8.6 Advertising and Commercial Profiling
Aionpixel does not sell student personal information.
Aionpixel does not use student educational records to deliver behavioural advertising.
Aionpixel does not build commercial advertising profiles of students based on their academic performance, attendance, demographic information, or learning activity.
8.7 Student Safety and School Responsibilities
Cortex IOS may provide features supporting communication, attendance, transport, reporting, student welfare, or other School activities.
The use of such technology does not replace the School's legal, professional, safeguarding, supervision, or student safety responsibilities.
Schools remain responsible for establishing and implementing appropriate policies and procedures for their students.
9. How Information Is Collected or Received
9.1 Information Provided by Schools
Schools may provide information to Cortex IOS through:
- School onboarding
- data migration
- administrative data entry
- bulk uploads
- authorised imports
- integrations
- School-configured forms
- ongoing School operations
This may include historical records required for continued School administration.
9.2 Information Provided by Parents and Guardians
Parents or guardians may provide information through:
- admission or enrolment workflows
- profile update forms
- document uploads
- School forms
- fee or payment workflows
- leave applications
- communications
- privacy requests
- consent workflows
- other enabled parent-facing features
Information submitted by a parent or guardian may relate both to the parent or guardian and to the student.
9.3 Information Provided by Students
Students may provide information through authorised features such as:
- assignment submissions
- learning activities
- forms
- communications
- document uploads
- feedback
- assessments where applicable
- other School-enabled student functions
The availability of these features depends on the School and the student's authorised access.
9.4 Information Provided by Teachers and School Staff
Teachers and authorised School personnel may create or enter information including:
- attendance
- marks
- grades
- observations
- assessment information
- learning records
- administrative records
- communications
- fee or accounting records
- staff records
- other information associated with their authorised responsibilities
9.5 Information Collected Automatically
Certain technical information may be collected or generated when Cortex IOS is accessed.
This may include:
- IP address
- authentication events
- session information
- device type
- operating system
- browser information
- application version
- error information
- diagnostic information
- security events
- platform activity required for audit or service operation
Automatically generated information is used for purposes such as security, authentication, service delivery, troubleshooting, performance, and accountability.
9.6 Information from Integrations and Service Providers
Where a School enables an integration, Cortex IOS may receive information from authorised third-party services.
Examples may include:
- payment status or transaction references
- authentication information
- messaging delivery status
- communication service information
- integration synchronisation information
- other data required for the enabled integration
The information received depends on the specific integration and the service configured by the School or Aionpixel.
9.7 Information from Government or Educational Sources
Where lawfully authorised and technically supported, Schools may import or maintain information associated with government, educational board, or authorised reporting processes.
Cortex IOS does not independently represent that every government or educational database is directly integrated with the platform.
The existence and nature of any integration should be determined based on the actual service enabled for the School.
10. Web Portal and Mobile Application Processing
10.1 Web Portal Access
Cortex IOS provides browser-based portals for authorised users.
Depending on role and School configuration, web portal users may include:
- School management
- administrators
- teachers
- accountants
- human resource personnel
- non-teaching staff
- parents
- guardians
- students
The web portal may support account administration, data entry, configuration, reporting, educational activities, communications, and other authorised functions.
10.2 Account Creation and Provisioning
Cortex IOS accounts are created, provisioned, or authorised through applicable School or web-platform workflows.
The School or its authorised administrators generally determine which individuals are provided access to Cortex IOS and the roles assigned to those individuals.
Account creation may be associated with:
- student enrolment
- parent or guardian association
- staff onboarding
- administrative authorisation
- other School-managed processes
Users must not create, access, or use accounts for which they are not authorised.
10.3 Mobile Application Access
The Cortex IOS Android and iOS applications are intended for existing authorised Cortex IOS users.
The mobile applications:
- do not provide general public registration
- do not independently create Cortex IOS user accounts
- do not independently enrol students
- do not provide an instant self-service account deletion function
- require an existing authorised Cortex IOS account for access
An authorised user may sign in using the authentication process supported for their School and account.
10.4 Role-Based Mobile Experience
The information and functionality available through the mobile application depend on the user's authorised role.
For example:
- a parent may access information relating to an associated student
- a student may access authorised learning or academic information
- a teacher may access teaching and School functions
- an administrator may access authorised administrative functions
- an accountant may access authorised finance functions
- other School personnel may access features relevant to their assigned responsibilities
The availability of a feature within Cortex IOS does not automatically grant every user access to that feature.
10.5 Information Submitted Through Mobile Features
Although the mobile application does not create user accounts, authorised users may submit or create information while using enabled features.
Examples may include:
- messages or chats
- assignment submissions
- attendance actions
- photographs
- document uploads
- leave requests
- comments
- form submissions
- acknowledgements
- communication preferences
- other role-authorised activities
Information submitted through the mobile application may become part of the relevant School or platform record.
10.6 Privacy Policy Acknowledgement
Users accessing Cortex IOS through the web portal or mobile application may be requested to acknowledge the applicable version of this Privacy Policy.
The acknowledgement may be recorded together with information such as:
- user identifier
- School or tenant
- document identifier
- document version
- acknowledgement date and time
- access channel
- audit reference
- other technical evidence appropriate for compliance and security purposes
The acknowledgement records that the user was presented with or provided access to the applicable Privacy Policy and acknowledged having had the opportunity to review it.
It does not convert every processing activity described in this Privacy Policy into consent-based processing.
10.7 Platform Terms Agreement
Users may separately be required to agree to the Cortex IOS Platform Terms of Service.
Agreement to the Platform Terms of Service is recorded separately from acknowledgement of this Privacy Policy.
Where a material version of the Platform Terms is introduced, users may be required to review and agree to the updated version before continuing to use Cortex IOS.
10.8 Policy Version Changes
Where this Privacy Policy is materially updated, Cortex IOS may:
- notify authorised users
- display an update notice
- make the revised Policy available through the Trust & Privacy Centre
- record the version presented to users
- request renewed acknowledgement where appropriate
Not every editorial, formatting, or non-material change will necessarily require renewed acknowledgement.
10.9 Account Access Termination
Access to Cortex IOS may be suspended, disabled, or terminated by an authorised School administrator or through applicable platform administration processes.
Examples may include:
- student withdrawal
- completion of schooling
- staff separation
- role change
- account security concerns
- suspected misuse
- School instruction
Termination of account access does not necessarily result in immediate deletion of the information associated with the individual.
Educational, financial, statutory, security, or other records may need to be retained in accordance with applicable requirements and the Cortex IOS Data Governance Statement.
10.10 Privacy and Data Requests
Users may submit privacy-related requests through available Cortex IOS, School, or Aionpixel channels.
Requests may include:
- access to personal information
- correction of inaccurate information
- review of account access
- privacy questions
- withdrawal of optional consent where applicable
- review of optional processing preferences
- deletion of eligible personal information
A request to delete information does not guarantee immediate deletion of all School or educational records.
The School or Aionpixel, as applicable, may need to assess:
- the nature of the information
- the purpose for which it is held
- School requirements
- educational record requirements
- financial or accounting obligations
- security requirements
- legal obligations
- applicable retention periods
The requester will be informed of the applicable process or outcome in accordance with relevant requirements.
11. Sharing and Disclosure of Information
11.1 General Principle
Cortex IOS processes information to support authorised School, educational, administrative, operational, security, and platform purposes.
Aionpixel does not sell student personal information.
Aionpixel does not disclose student educational information to third parties for behavioural advertising or unrelated commercial profiling.
Information may be shared or made available only where appropriate for the relevant purpose, School configuration, service delivery, legal requirement, or authorised integration.
11.2 Access by the School
Information processed through Cortex IOS may be accessed by authorised School personnel according to their roles, responsibilities, and available platform permissions.
Depending on School configuration, authorised users may include:
- School management
- principals and academic leaders
- School administrators
- teachers
- finance and accounts personnel
- human resource personnel
- counsellors or student support personnel
- transport personnel
- library personnel
- authorised IT personnel
- other School personnel assigned an appropriate role
The School is responsible for assigning user roles and managing School-level access according to its responsibilities and policies.
11.3 Access by Parents, Guardians and Students
Parents and guardians may access information associated with students to whom they are lawfully and appropriately linked within the School's records.
Students may access information and functions made available to their authorised student account.
Access may differ according to:
- School configuration
- user role
- student relationship
- age or grade
- enabled modules
- available access controls
A parent, guardian, or student is not automatically entitled to access information relating to another student or family.
11.4 Aionpixel Personnel
Authorised Aionpixel personnel may access limited customer information where necessary to:
- provide technical support
- investigate reported issues
- maintain platform services
- investigate security events
- support data migration
- perform authorised operational activities
- support recovery processes
- comply with legal obligations
- protect Cortex IOS and its users
Access should be based on authorised responsibilities and operational necessity.
Aionpixel does not provide unrestricted customer-data access to all employees.
Administrative, support, or technical access may be subject to applicable access controls, logging, and internal procedures.
11.5 Service Providers and Subprocessors
Aionpixel may engage service providers to support the delivery and operation of Cortex IOS.
Depending on the service, these providers may support:
- cloud infrastructure
- data storage
- messaging
- email delivery
- push notifications
- payment processing
- application monitoring
- error diagnostics
- security
- authentication
- customer support
- other technical functions
A service provider receives or processes only information relevant to the service it performs, subject to applicable contractual, technical, and organisational safeguards.
Further information may be provided through the Cortex IOS Data Governance Statement or applicable third-party service disclosures.
11.6 Payment Service Providers
Where a School enables online payments, Cortex IOS may integrate with an authorised payment gateway or financial service provider.
Information necessary to initiate, identify, verify, or reconcile a transaction may be exchanged with the relevant provider.
This may include:
- payer information
- transaction amount
- payment reference
- invoice or fee reference
- transaction status
- other information required for the payment workflow
Sensitive payment credentials may be collected and processed directly by the applicable payment service provider depending on the integration.
Aionpixel does not represent itself as a bank or payment card network.
11.7 Communication Service Providers
Cortex IOS may use third-party communication services to deliver:
- SMS
- push notifications
- messaging
- other enabled communications
Information necessary to deliver the communication may be provided to the applicable service provider.
This may include a recipient identifier, contact detail, device notification token, message delivery information, or message content where required for delivery.
11.8 School-Enabled Integrations
A School may enable approved integrations with third-party services.
Where an integration is enabled, information may be exchanged to perform the relevant function.
The School should assess whether the integration is appropriate for its requirements.
The categories of information exchanged depend on the integration and the authorised workflow.
11.10 Legal and Safety Disclosures
Information may be disclosed where reasonably necessary to:
- comply with applicable law
- respond to a valid legal process
- comply with a lawful order
- protect the rights or security of Aionpixel
- investigate fraud or misuse
- respond to a security incident
- address an immediate and serious safety concern where disclosure is permitted or required by law
Legal and government data requests are further addressed in the Cortex IOS Legal & Transparency Statement.
11.11 Corporate Transactions
If Aionpixel is involved in a merger, acquisition, restructuring, financing, or transfer of business assets, information may be transferred as part of that transaction where legally permitted.
Appropriate confidentiality and data protection considerations will be applied to such transfers.
12. Location and International Processing of Information
12.1 Cloud and Service Infrastructure
Cortex IOS is a cloud-based service.
Information may be processed using cloud infrastructure and technical service providers selected to support platform operation, security, availability, communication, and related services.
The location of processing may depend on:
- infrastructure configuration
- School contractual requirements
- enabled integrations
- service-provider architecture
- applicable legal requirements
12.2 Cross-Border Processing
Certain service providers or technical services may process information outside the location in which a user or School is based.
Where cross-border processing occurs, Aionpixel will seek to apply appropriate contractual, technical, and organisational measures relevant to the nature of the processing and applicable legal requirements.
Cortex IOS will not represent that all information remains within a particular country unless such data-location commitment is expressly supported by the applicable service architecture and contractual arrangement.
12.3 School Requirements
Where a School has specific data-location or processing requirements, those requirements should be addressed through the applicable subscription agreement, data processing terms, or enterprise arrangements.
Public statements regarding Cortex IOS data location should be read together with any specific contractual commitment provided to the School.
13. Data Retention and Deletion
13.1 Retention Principle
Personal information should not be retained indefinitely without an appropriate purpose.
Information processed through Cortex IOS may be retained according to:
- the purpose for which it was collected
- the nature of the School record
- the School's requirements
- educational record requirements
- financial or accounting obligations
- statutory requirements
- contractual requirements
- security requirements
- dispute or investigation needs
- applicable law
Different categories of information may therefore have different retention periods.
13.2 School-Controlled Records
Many records maintained through Cortex IOS form part of the School's educational, administrative, financial, or employment records.
Examples may include:
- admission records
- student profiles
- academic records
- attendance records
- assessment records
- report cards
- fee records
- financial transactions
- staff records
- School communications
The School may determine applicable retention requirements for these records, subject to law and the services provided by Cortex IOS.
Aionpixel does not independently delete School-controlled records merely because a user stops using the mobile application or loses access to their account.
13.3 Technical and Security Information
Technical, diagnostic, session, security, and audit information may be retained for periods appropriate to:
- security monitoring
- incident investigation
- fraud prevention
- troubleshooting
- platform reliability
- audit requirements
- legal or contractual obligations
Retention periods may differ according to the type and significance of the record.
Detailed retention categories may be described in the Cortex IOS Data Governance Statement.
13.4 Backups
Information may remain in protected backup systems for a limited period after deletion or removal from active systems.
Backup information is maintained for resilience, recovery, and continuity purposes.
Information contained in backups is not intended to be restored for ordinary user access after valid deletion from active systems, except where restoration is required for legitimate recovery, security, or continuity purposes.
Backup retention and deletion processes are managed according to applicable operational procedures.
13.5 Account Access and Data Retention
Disabling or terminating a Cortex IOS account does not necessarily delete the underlying information associated with the user.
For example, a student's account may be disabled after leaving a School while academic, attendance, or financial records remain subject to School or legal retention requirements.
Similarly, termination of a staff member's access does not necessarily require immediate deletion of all employment or School records.
13.6 Deletion Requests
A request to delete personal information will be assessed according to:
- the identity of the requester
- the requester's authority
- the category of information
- the School's role and instructions
- the purpose of processing
- applicable educational requirements
- financial or accounting obligations
- legal retention requirements
- security requirements
- other lawful grounds for continued retention
Where information is eligible for deletion, reasonable steps may be taken to delete or de-identify it in accordance with the applicable process.
Where information must be retained, the requester may be informed that deletion cannot immediately be completed or that only certain categories of information can be deleted.
13.7 Tenant Termination
Where a School terminates its use of Cortex IOS, the handling of School data will be governed by:
- the applicable agreement with Aionpixel
- applicable data processing terms
- School instructions
- agreed transition or export arrangements
- legal obligations
- applicable deletion and backup processes
A School's termination of Cortex IOS does not automatically authorise an individual user to obtain or delete all School records.
14. Security and Protection of Information
14.1 Security Commitment
Aionpixel recognises the importance of protecting information processed through Cortex IOS.
We implement administrative, technical, and organisational safeguards designed to protect the confidentiality, integrity, and availability of information.
No technology platform can guarantee absolute security.
Our objective is to apply safeguards appropriate to the nature of Cortex IOS, the information processed, and reasonably identifiable security risks.
14.2 Security by Design
Security considerations are incorporated into the design, development, deployment, and operation of Cortex IOS.
Our security approach may include:
- secure application design
- access controls
- role-based permissions
- authentication controls
- encryption
- secure communication protocols
- audit logging
- application monitoring
- controlled deployment processes
- dependency management
- backup and recovery processes
- incident response procedures
14.3 Encryption
Cortex IOS is designed to use appropriate encryption and secure communication technologies to protect information.
Measures may include:
- encryption of information transmitted between supported clients and platform services
- encryption of information stored within supported infrastructure where implemented
- secure handling of authentication credentials
- controlled management of cryptographic services or keys
Specific cryptographic implementations may evolve as technology and security requirements change.
14.4 Role-Based Access Control
Access to Cortex IOS functionality and information is based on authorised roles and permissions.
Examples of roles may include:
- parent
- student
- teacher
- School administrator
- accountant
- human resource personnel
- principal
- management
- other authorised School roles
Role assignment does not remove the responsibility of the School to ensure that users receive appropriate access.
Schools should regularly review user accounts, roles, and permissions.
14.5 Tenant Isolation
Cortex IOS is designed to support multiple School tenants.
Platform controls are intended to prevent users from accessing another tenant's information unless access is expressly authorised through an applicable School group or administrative structure.
Tenant association and access permissions form part of the platform's access-control model.
14.6 Authentication and Session Security
Security measures may include:
- individual user accounts
- password controls
- secure authentication processes
- session management
- token-based authentication
- inactivity or session controls
- additional authentication measures where supported
Users are responsible for protecting their credentials and should not share passwords or authentication information.
14.7 Monitoring and Auditability
Cortex IOS may log security, administrative, authentication, and other significant platform events.
Logging may support:
- security monitoring
- investigation
- accountability
- troubleshooting
- compliance
- operational review
Audit capabilities vary according to the platform function and event type.
14.8 Security Incident Response
Aionpixel maintains processes intended to support the identification, assessment, containment, investigation, recovery, and review of information security incidents.
Where a confirmed incident affects School information, Aionpixel will assess notification and response obligations according to:
- the nature of the incident
- applicable law
- contractual obligations
- the role of the School
- the information affected
14.9 User and School Responsibilities
Security is a shared responsibility.
Schools and users should:
- protect credentials
- use authorised accounts
- assign appropriate roles
- promptly remove unnecessary access
- maintain appropriate device security
- report suspicious activity
- avoid unauthorised sharing of information
- follow applicable School security policies
Further information is available in the Cortex IOS Information Security Statement.
15. Artificial Intelligence and Automated Features
15.1 AI-Assisted Capabilities
Cortex IOS may provide artificial intelligence, machine learning, recommendation, automation, or other computationally assisted features.
These capabilities may evolve as Cortex IOS develops.
Examples may include features intended to assist with:
- content generation
- educational workflows
- observations or narrative assistance
- reporting
- analytics
classification;
recommendations;
administrative productivity; or
other authorised School functions.
The availability of an AI-assisted feature may depend on the School's subscription, configuration, and product release.
15.2 AI Does Not Automatically Process All Cortex IOS Data
The presence of AI functionality within Cortex IOS does not mean that all student, parent, staff, academic, or School information is automatically submitted to an AI model.
The information processed by an AI-assisted feature depends on:
- the specific feature
- the action initiated by the user or system
- the data required for that function
- School configuration
- applicable technical architecture
- relevant privacy or contractual requirements
15.3 Purpose Limitation
Information used by an AI-assisted feature should be limited to information relevant to the authorised purpose of that feature.
Aionpixel does not use student educational information to create commercial advertising profiles through AI systems.
Where an AI-assisted feature introduces materially different processing, Cortex IOS may provide additional information, feature-specific notices, controls, or contractual terms.
15.4 Third-Party AI Service Providers
Where an AI-assisted feature uses a third-party model or AI service provider, information necessary to perform the requested function may be transmitted to that provider.
The nature of the information transmitted depends on the feature and technical implementation.
Aionpixel will seek to assess applicable providers and implement appropriate contractual, technical, or organisational safeguards relevant to the service.
Applicable third-party processing may be identified through the Cortex IOS Data Governance Statement or related service disclosures.
15.5 AI Training Claims
Aionpixel will not state that customer or student information is never retained by, or never used to improve, a third-party AI service unless that claim is supported by the applicable service configuration and contractual terms.
Where Cortex IOS provides an AI-assisted feature, the applicable data handling practices should reflect the actual technical implementation and provider terms.
Aionpixel will seek to provide appropriate transparency regarding material AI data handling practices.
15.6 Human Responsibility and Educational Decisions
AI-assisted outputs may be incomplete, inaccurate, or unsuitable in a particular context.
Unless expressly stated otherwise, AI-assisted features are intended to support authorised users and not replace professional educational judgement.
Teachers, School administrators, and other authorised personnel remain responsible for reviewing AI-assisted outputs before relying on them for significant educational, administrative, welfare, disciplinary, or other decisions.
Cortex IOS should not be used to make a significant decision affecting a student solely on the basis of an unreviewed AI-generated output.
15.7 Automated Processing and Transparency
Where Cortex IOS introduces automated processing that materially affects individuals, Aionpixel and the School may assess whether additional transparency, controls, or human review mechanisms are appropriate.
Users may be provided with additional information where required by applicable law or the nature of the processing.
15.8 Future AI Features
As Cortex IOS develops, new AI-assisted capabilities may be introduced.
Where a new feature materially changes how personal information is processed, Aionpixel may:
- update this Privacy Policy
- update the Data Governance Statement
- provide a feature-specific notice
- update applicable third-party disclosures
- introduce School-level configuration controls
- request specific consent or acknowledgement where required
The introduction of an AI-assisted feature does not provide unrestricted authority to use Cortex IOS information for unrelated AI purposes.
16. Privacy Rights and Privacy Requests
16.1 General Principle
Individuals may have rights relating to their personal information under applicable law.
The rights available to an individual may depend on:
- the applicable jurisdiction
- the individual's relationship with the School
- the nature of the information
- the purpose for which the information is processed
- the role of the School and Aionpixel
- statutory or educational record requirements
- applicable legal exceptions
Cortex IOS supports processes through which privacy-related requests may be raised and reviewed.
16.2 Access to Personal Information
An individual may request access to personal information relating to them.
Parents or guardians may request access to information relating to a student where they are appropriately authorised to act for the student.
Access requests may be subject to:
- identity verification
- relationship verification
- School review
- protection of information relating to other individuals
- applicable legal restrictions
- educational or safeguarding considerations
Where the information forms part of a School-controlled record, the request may be referred to or coordinated with the School.
16.3 Correction of Information
Individuals may request correction of personal information they believe is inaccurate or incomplete.
Certain information may be directly editable through authorised Cortex IOS features.
Other information may require School approval or administrative review.
Examples may include:
- student identity records
- date of birth
- parent or guardian relationships
- academic records
- attendance records
- financial records
- statutory information
Aionpixel may not independently alter School-controlled educational records without appropriate School authorisation.
16.4 Deletion of Eligible Personal Information
Individuals may request deletion of eligible personal information.
Deletion rights are not absolute.
Information may need to be retained where required for:
- educational records
- academic history
- attendance records
- financial or accounting obligations
- School administration
- statutory reporting
- legal compliance
- dispute resolution
- fraud prevention
- security investigations
- other lawful purposes
Where information is eligible for deletion, reasonable steps may be taken to delete, anonymise, or de-identify the information according to the applicable process.
16.5 Restriction or Review of Processing
Where applicable, an individual may request review or restriction of a particular processing activity.
The School or Aionpixel may assess:
- the processing purpose
- whether the activity is necessary
- applicable legal requirements
- School obligations
- contractual requirements
- the rights and interests of the individual
A request to restrict processing may affect the availability of certain Cortex IOS or School services.
16.6 Objection to Processing
Where applicable law provides a right to object to particular processing, an individual may submit an objection through the available privacy request channels.
The objection will be reviewed according to the nature and purpose of the processing.
Processing required for School operations, educational administration, security, statutory obligations, or other lawful purposes may continue where permitted by applicable law.
16.7 Withdrawal of Consent
Where a processing activity is specifically based on consent, the individual or authorised parent or guardian may withdraw that consent through an available mechanism or by submitting a request.
Withdrawal of consent:
- applies to the relevant consent-based processing activity
- does not automatically affect processing conducted for another valid purpose
- does not necessarily require deletion of records that must lawfully be retained
- does not affect the lawfulness of processing undertaken before withdrawal, where applicable
Privacy Policy acknowledgement is distinct from specific consent.
Withdrawal of an optional consent does not constitute withdrawal of acknowledgement of this Privacy Policy.
16.8 Communication Preferences
Where available, users may manage preferences relating to optional communications.
Cortex IOS or the School may distinguish between:
- essential School communications
- optional communications
Essential communications may include information relating to student safety, attendance, School operations, examinations, fees, transport, or other important educational and administrative matters.
Users may be permitted to select preferred communication channels.
The School may continue to send essential communications through an authorised available channel where necessary for legitimate School purposes.
16.9 Data Export and Portability
Where applicable and technically supported, an individual may request a copy or export of eligible personal information.
The format and scope of an export may depend on:
- the information requested
- the role of the requester
- School authorisation
- technical feasibility
- applicable law
- the rights of other individuals
A request for data portability does not provide unrestricted access to the School's complete database, internal records, confidential information, or information relating to other users.
16.10 Privacy Requests Relating to Children
Requests relating to a student may require verification of:
- the identity of the requester
- the relationship between the requester and student
- parental or guardian authority
- the student's age
- School records
- other relevant circumstances
Where appropriate, the School may be involved in responding to the request.
16.11 Identity Verification
Before responding to certain privacy requests, the School or Aionpixel may take reasonable steps to verify the identity and authority of the requester.
Additional information should only be requested where reasonably necessary for verification.
This process is intended to protect personal information from unauthorised disclosure, alteration, or deletion.
16.12 Response to Privacy Requests
Privacy requests will be assessed and responded to in accordance with applicable legal requirements and the nature of the request.
Where additional time is reasonably required because of complexity, verification, School coordination, or the volume of information involved, the requester may be informed where required.
If a request cannot be fully completed, the requester may be provided with an explanation where appropriate and legally permitted.
16.13 How to Submit a Privacy Request
Privacy-related requests may be submitted through:
- the Trust & Privacy Centre within Cortex IOS, where available
- the applicable School
- the School's authorised privacy or administrative contact
- the Aionpixel Privacy Team
Contact details are provided in Section 20 of this Privacy Policy.
17.1 Browser-Based Services
The Cortex IOS public website and web portal may use cookies and similar browser technologies.
These technologies may support:
- authentication
- secure sessions
- security
- user preferences
- application functionality
- performance
- diagnostics
- website analytics
17.2 Essential Technologies
Certain cookies or browser technologies are necessary for Cortex IOS to operate securely.
Examples may include:
- session cookies
- authentication technologies
- CSRF protection
- security controls
- load-balancing or service continuity technologies
Disabling essential technologies may prevent a user from securely accessing the applicable service.
17.3 Non-Essential Technologies
Where non-essential analytics, preference, or similar technologies are used, appropriate information or preference mechanisms may be provided where required.
Aionpixel does not use student educational information collected through cookies to build behavioural advertising profiles.
17.4 Mobile Applications
The Cortex IOS Android and iOS applications generally use application technologies rather than traditional browser cookies.
These may include:
- authentication tokens
- secure application storage
- session identifiers
- push notification tokens
- application preferences
- operating-system permission mechanisms
The specific technologies used may evolve as the mobile applications are updated.
17.5 Further Information
Additional information is available in the Cortex IOS Cookie & Similar Technologies Policy.
That Policy should be reviewed together with the actual cookies, SDKs, analytics services, and mobile technologies implemented within Cortex IOS.
18. Third-Party Services and Integrations
18.1 Use of Third-Party Services
Cortex IOS may rely on third-party services to support specific technical or operational functions.
These services may include:
- cloud infrastructure
- payment processing
- communication delivery
- push notifications
- authentication
- application monitoring
- diagnostics
- analytics
- customer support
- integrations
- AI-assisted services where enabled
The use of a service may vary according to the School, Cortex IOS configuration, product version, or enabled module.
18.3 Service Provider Responsibilities
Aionpixel seeks to use service providers appropriate to the services they perform.
Where applicable, service-provider arrangements may include requirements relating to:
- confidentiality
- information security
- permitted processing
- data protection
- incident handling
- return or deletion of information
The safeguards applicable to a provider may vary according to the nature of the service and contractual arrangement.
18.4 School-Selected or School-Enabled Services
Certain integrations may be selected, requested, or enabled by a School.
Where a School directs Cortex IOS to integrate with a third-party service, the School should assess the service's suitability and applicable privacy requirements.
Aionpixel may provide technical integration capabilities without independently controlling all processing conducted by the third-party service.
18.5 Third-Party Privacy Practices
Third-party services may maintain their own privacy policies and terms.
Where an individual directly interacts with a third-party service, that provider's privacy practices may independently apply.
Cortex IOS does not control the independent privacy practices of third parties acting for their own purposes.
18.6 Transparency Regarding Providers
Information regarding material categories of third-party services and data processing may be provided through the Cortex IOS Data Governance Statement.
Where appropriate, Aionpixel may maintain a public list of material subprocessors or third-party service categories.
Such information may be updated as Cortex IOS services and infrastructure evolve.
19. Changes to this Privacy Policy
19.1 Policy Updates
Aionpixel may update this Privacy Policy from time to time.
Changes may be made to reflect:
- changes in Cortex IOS functionality
- new modules or services
- changes in data processing activities
- changes in third-party services
- legal or regulatory developments
- security improvements
- changes in AI-assisted features
- improvements to privacy practices
19.2 Material Changes
Where a change materially affects how personal information is processed, Aionpixel may take appropriate steps to inform affected users or Schools.
These steps may include:
- publishing an updated Privacy Policy
- displaying an in-platform notice
- sending a notification
- informing the School
- updating the Trust & Privacy Centre
- requesting renewed acknowledgement where appropriate
19.3 Policy Versioning
Cortex IOS maintains version information for this Privacy Policy.
The Policy may display:
document identifier;
version number;
effective date;
last updated date; and
version history.
Where Cortex IOS records user acknowledgement, the acknowledgement may be associated with the applicable Policy version.
19.4 Non-Material Changes
Minor corrections, formatting improvements, clarification of existing wording, or other non-material changes may not require renewed user acknowledgement.
Aionpixel will assess whether renewed acknowledgement is appropriate based on the nature of the change.
20. Contact Information
20.1 Privacy Enquiries
Questions regarding this Privacy Policy or Cortex IOS privacy practices may be directed to:
- Privacy Team Aionpixel Technologies Private Limited
- Email: privacy@cortexios.com
- Website: [Aionpixel Website]
- Cortex IOS Trust, Privacy & Security Centre: [Trust Centre URL]
20.3 Security Concerns
Suspected information security concerns relating to Cortex IOS may be reported to:
- Security Team Aionpixel Technologies Private Limited
- Email: security@cortexios.com
- Users should not send passwords, authentication credentials, or unnecessary sensitive personal information through ordinary email
20.4 Product Support
Technical or product support requests may be directed through the applicable Cortex IOS support channel or to:
- Email: support@cortexios.com
- Privacy requests should be directed to the Privacy Team rather than ordinary product support wherever possible
Annexure A – Data Inventory Summary
The following table provides a high-level summary of categories of information that may be processed through Cortex IOS.
The actual information processed depends on School configuration, enabled modules, user role, and applicable requirements.
| Data Category | Examples | Primary Processing Purposes |
|---|---|---|
| Student Identity | Name, date of birth, student ID, photograph | Student administration and identification |
| Student Demographics | Gender, religion, caste/category, nationality, mother tongue | School records, authorised educational and regulatory purposes |
| Socio-Economic Information | Family income, income category, scholarship eligibility | Scholarship, support, School or authorised reporting |
| Parent & Guardian Information | Name, relationship, contact details, address | Guardian records, communication and authorised student access |
| Admission Information | Applications, previous School records, documents | Admission and enrolment |
| Academic Information | Subjects, marks, grades, competencies, report cards | Teaching, assessment and academic administration |
| Learning Information | Assignments, submissions, learning activities | Learning management and educational delivery |
| Attendance Information | Attendance, absence, leave, late arrival | Attendance administration and School operations |
| Health & Welfare Information | Allergies, support needs, disability information | Student support, welfare and accessibility where enabled |
| Fee Information | Fee assignment, invoices, concessions, balances | Fee administration |
| Payment Information | Payment status, transaction reference, gateway reference | Payment processing and reconciliation |
| Accounting Information | Financial records, ledger-related information | School accounting and financial administration |
| Transport Information | Route, pickup point, vehicle assignment | School transport management |
| Staff Information | Identity, employment, department, designation | HR and School workforce administration |
| Payroll Information | Salary-related and payroll records | Payroll administration where enabled |
| Communications | Messages, notices, chats, circulars | School communication and collaboration |
| Uploaded Documents | Certificates, photographs, forms, attachments | Authorised School workflows |
| Device Information | Device type, OS, browser, application version | Compatibility, security and support |
| Network Information | IP address and session-related information | Security and fraud prevention |
| Authentication Information | Login events, tokens, session information | Account access and security |
| Audit Information | Administrative actions, changes, security events | Accountability, security and investigation |
| Support Information | Support requests and troubleshooting information | Technical support |
| AI Feature Information | Feature-specific inputs and outputs where enabled | Authorised AI-assisted functionality |
Annexure B – Processing Activity Summary
| Processing Activity | Information Typically Involved | Primary Purpose | Typical Responsible Party |
|---|---|---|---|
| Student Enrolment | Identity, demographic and admission information | Student administration | School |
| Parent Association | Parent and student relationship information | Authorised guardian access | School |
| User Provisioning | Identity, role and School association | Platform access | School / Cortex IOS |
| Academic Administration | Academic and student information | Teaching and School operations | School |
| Assessment | Marks, grades and learning records | Academic evaluation | School |
| Attendance | Student or staff attendance | Attendance administration | School |
| Fee Administration | Student, fee and payment records | Fee management | School |
| Payment Processing | Transaction and payment information | Payment execution and reconciliation | School / Payment Provider / Cortex IOS |
| Communication | Contact and message information | School communication | School |
| Mobile Authentication | Account, device and session information | Secure mobile access | Cortex IOS |
| Security Monitoring | IP, authentication and security events | Security and fraud prevention | Aionpixel |
| Technical Support | Account and issue-related information | Troubleshooting | Aionpixel |
| Data Backup | School and platform information | Resilience and recovery | Aionpixel |
| Regulatory Reporting | Student and School information | Authorised reporting | School |
| AI-Assisted Feature | Feature-specific information | User-requested or School-enabled assistance | School / Aionpixel, depending on feature |
| Privacy Request | Identity and request information | Privacy rights management | School / Aionpixel |
Privacy
Parent & Guardian Privacy Notice
Student Privacy Notice
School Staff Privacy Notice
Data Governance
Cortex IOS Data Governance Statement
Security
Cortex IOS Information Security Statement
Terms and Technologies
Cortex IOS Website Terms of Use
Cortex IOS Platform Terms of Service
Cortex IOS Cookie & Similar Technologies Policy
Legal and Transparency
Cortex IOS Legal & Transparency Statement
Cortex IOS Privacy & Security FAQ
Version History
| Version | Date | Description |
|---|---|---|
| 1.0 | 29th June 2026 | Initial Cortex IOS Product Privacy Policy |
| 2.0 | 16th July 2026 | Comprehensive revision covering data inventory, School and Aionpixel responsibilities, children's information, web and mobile processing, privacy rights, retention, AI-assisted features, third-party services, and expanded transparency disclosures |