Legal

Privacy Policy

We believe transparency earns trust. Here's exactly what data Genzzi collects, why we need it, and how we keep it safe.

Last updated: June 19, 2026

Overview

Genzzi ("we", "us", or "our") is a learning management platform that connects students with structured courses, assignments, and certifications. This Privacy Policy describes how we collect, use, and protect your personal data when you access or use our services.

By creating an account or using Genzzi, you agree to the practices described here. If you do not agree, please do not use our platform.

Short version: We collect only what we need to run the platform. We don't sell your data. We store it securely and give you control over it.

Data We Collect

We collect data in three ways: what you give us directly, what we record automatically when you use the platform, and what we derive from your activity.

👤Identity
  • ·Full name
  • ·Email address
  • ·Username
  • ·Profile picture
  • ·Phone number
  • ·Date of birth
🎓Academic
  • ·Student / Staff code
  • ·Batch & course data
  • ·Assignment submissions
  • ·Assessment marks
  • ·Certificate records
💻Device
  • ·Device fingerprint
  • ·IP address
  • ·Browser / OS
  • ·Approximate location
  • ·Session timestamps
🔐Auth
  • ·OAuth identity (sub)
  • ·Access token JTI
  • ·Refresh token hash
  • ·Login timestamps
  • ·Token expiry data

How We Use Your Data

We use your data for the following purposes:

  • ·Authentication & access controlverifying your identity, assigning your role (Student, Staff, or Admin), and protecting your account from unauthorised access.
  • ·Course deliveryenrolling you in courses, tracking progress, distributing assignments and projects, and recording grades.
  • ·Certificationgenerating and issuing verifiable certificates of completion tied to your student profile.
  • ·Platform notificationssending you alerts about enrollment updates, reviewed submissions, released marks, and certificate availability.
  • ·Security & auditdetecting suspicious device activity, maintaining audit logs, and revoking compromised sessions.
  • ·Platform improvementaggregated, anonymised usage analytics to improve features and performance.

We never use your data to build advertising profiles or sell targeting information to third parties.

Storage & Security

All data is stored in a PostgreSQL database managed on infrastructure with encryption at rest and in transit (TLS 1.2+).

  • ·Passwords are never stored — we use OAuth flows. Refresh tokens are stored as salted hashes, not raw values.
  • ·Device fingerprints are used solely to detect new and potentially fraudulent logins — not to track you across the web.
  • ·Sessions use short-lived access tokens (JWT) paired with rotating refresh tokens. Revoked tokens are flagged immediately.
  • ·File attachments (submission uploads, syllabus PDFs) are stored in a secured object store with per-object access keys.

In the unlikely event of a data breach affecting your personal information, we will notify affected users within 72 hours and report to the relevant authority where required by law.

Cookies & Sessions

Genzzi uses HttpOnly cookies to store session identifiers securely. These cookies are not accessible to JavaScript running in your browser, which protects against XSS attacks.

  • ·Session cookie — carries your refresh token. Expires when you log out or after 30 days of inactivity.
  • ·CSRF token cookie — a SameSite-protected token to prevent cross-site request forgery.

We do not use third-party tracking cookies or advertising pixels. There is no Google Analytics, Facebook Pixel, or similar tracking on the platform.

Sharing Your Data

We do not sell, rent, or trade your personal data. We share it only in these limited circumstances:

  • ·Within GenzziStaff assigned to a course can see the names and submission records of enrolled students in that course only.
  • ·Service providersInfrastructure vendors (database hosting, object storage) who are contractually bound not to use your data for their own purposes.
  • ·Legal obligationsIf required by law, court order, or government authority to disclose information.
  • ·Business transfersIn a merger or acquisition, your data may transfer to the new entity under the same protections.

Data Retention

We retain your data for as long as your account is active or as needed to provide services.

  • ·Account datakept until you request deletion, subject to a 30-day grace period.
  • ·Audit logsretained for 12 months to support security investigations and compliance.
  • ·Expired session tokenspurged within 7 days of expiry.
  • ·Certificatesretained indefinitely unless revoked, as they serve as verifiable credentials.
  • ·Deleted accountsa soft-delete flag is set immediately; hard deletion of personal data occurs within 30 days.

Your Rights

Depending on your location, you may have the following rights under applicable data protection law (including GDPR and similar frameworks):

AccessRequest a copy of the personal data we hold about you.
CorrectionAsk us to fix inaccurate or incomplete data.
DeletionRequest removal of your account and personal data ("right to be forgotten").
PortabilityReceive your data in a machine-readable format.
RestrictionAsk us to pause processing while a dispute is resolved.
ObjectionOpt out of processing where we rely on legitimate interests.

To exercise any of these rights, email support@genzzi.in. We will respond within 30 days.

Minors

Genzzi is intended for users aged 13 and above. We do not knowingly collect personal data from children under 13. If a parent or guardian believes their child has created an account without consent, contact us at support@genzzi.in and we will delete the account immediately.

For users between 13 and 18, we recommend parental oversight. Certain features — such as profile visibility to Staff — are limited for minor accounts.

Policy Changes

We may update this policy to reflect changes in our practices or applicable law. When we make material changes, we will:

  • ·Update the "Last updated" date at the top of this page.
  • ·Send a platform notification to all registered users at least 14 days before the change takes effect.
  • ·For significant changes, request re-acknowledgement at next login.

Continued use of Genzzi after the effective date constitutes acceptance of the updated policy.

Contact Us

Questions or concerns about this Privacy Policy? Reach us through any of these channels:

Email: support@genzzi.in

We aim to acknowledge all privacy requests within 2 business days and resolve them within 30 calendar days.