← Back to Zentor
ZentorZentor

Privacy Policy

Effective 22 July 2026 · Version 1.4 · Revised 6 September 2026

Zentor is operated by Zensence Technologies Limited, a private company limited by shares registered in the Federal Republic of Nigeria ("Zensence", "we", "us"), which provides attendance management for universities under the Zentor brand. This policy explains what personal data we collect, why, how we protect it, and your rights. By using Zentor you agree to the practices described here.

1. Information we collect

Account & sign-inYour name, matriculation number, school email, phone, department, level and semester — provided when your account is set up or drawn from your institution's records. How you sign in: students and lecturers use their school email/matriculation number and a password they set; parents create an account with their own email and a password they set, linked to their ward by the ward's matriculation number and a parent access code. Passwords are never stored in readable form — only as a secure one-way hash (see §5).
Attendance recordsSessions you attend (in-person and online), timestamps, and the course involved.
Online classesFor virtual classes, the join link your lecturer shares, and — when attendance is recorded — the attendance code you enter and the device you enter it from. The class itself takes place on an external platform (e.g. Zoom, Google Meet, Microsoft Teams, Telegram) governed by that provider's own privacy policy.
Photos & face dataA selfie captured when you scan in class, plus a reference photo, shown to your lecturer so they can confirm it is really you (anti-proxy). Online classes do not capture a selfie. This is biometric data and is treated as sensitive.
LocationApproximate GPS coordinates at scan time, used only to confirm you are physically present in class.
Device signalsA device/browser fingerprint used to detect proxy attendance and account sharing.
Passkey (device biometric)Where enabled, attendance is confirmed with a passkey on your device — your phone or computer's own fingerprint/Face ID. Your biometric never leaves your device; we only store a public key that verifies it's really your enrolled device. We cannot read your fingerprint or face from it.
CommunicationsFeedback, absence requests, and messages you send through the app.
Usage analyticsBasic product-usage events — sign-ups, logins, attendance submissions and timetable saves — recorded in our own database to understand and improve the app. We use no third-party analytics service, and this data never leaves our infrastructure.

2. How we use your data

3. Who we share it with

Your attendance and reports are visible to your lecturers, your school's administrators, and — for students who enable it — a linked parent/guardian. We do not sell your data or use it for advertising. We use trusted infrastructure providers (e.g. database hosting and email delivery) who process data on our behalf under contract.

4. Sensitive data: face & location

Face images and location are collected solely to confirm presence and prevent fraud. They are not used to track you outside of attendance scans. Where the law — including the Nigeria Data Protection Act / Regulation (NDPR) — requires consent for biometric processing, your use of the scan/check-in feature constitutes that consent, and you may ask your institution about manual alternatives (for example, a lecturer marking you present).

5. Storage & security

Data is stored on managed cloud infrastructure. Passwords are hashed (never stored in plain text), face images are encrypted at rest and served only to your lecturer through short-lived, expiring links, traffic is encrypted in transit, and access is restricted by role. Passkeys store only a public key on our side — never your actual fingerprint or face. No system is perfectly secure, but we take reasonable measures to protect your information.

6. Cookies & browser storage

Zentor uses one cookie, and it exists only to keep you signed in. We do not use advertising or marketing cookies, and there are no third-party analytics or tracking scripts on this site — no Google Analytics, no advertising pixels, nothing that follows you to other websites.

ae_rtSet when you sign in, so you stay signed in without retyping your password. It cannot be read by JavaScript (HttpOnly), is only sent over HTTPS, is restricted to our sign-in address, and expires after 30 days or as soon as you sign out.

Because this cookie is strictly necessary to provide the service you asked for, it does not require your consent, and we do not show a cookie banner. We would ask first before adding any cookie that is not essential.

The app also keeps a few things in your browser's own storage on your device, so it opens quickly and behaves the way you left it:

Your sessionWho you are signed in as, and your role, so the app knows what to show you.
PreferencesLight or dark mode, and whether you have dismissed prompts or finished the guided tour, so they are not repeated.
Passkey referenceThe identifier of the passkey held on your device. This is a reference only — your fingerprint or face never leaves your device and is never sent to us.
Cached listsRecent courses, notifications and attendance, so the app still works when the network drops.

Clearing your browser data removes all of it and signs you out. Nothing here is used to profile you or to advertise to you.

7. Retention

We practise data minimisation — we keep sensitive media only as long as it serves its purpose:

Scan selfiesAutomatically deleted about 30 days after the class (the lecturer's review window). The attendance record itself is kept; only the photo is removed.
Reference (enrolment) photoKept while you are an active student so future scans can be verified, and deleted when you leave or on an erasure request.
Passkey credentialsKept while active; removed when you reset your device or request erasure.
Attendance & account recordsKept for as long as your institution requires them for academic records, then deleted or anonymised.
Backup copiesBackups exist so your school's records survive a failure, and they are never edited in place — they expire and are replaced. Database backups are kept 14 days; the separate backup of absence evidence is kept 30 days. When something is deleted, it is removed from the live service immediately and disappears from backups as those copies expire, within 30 days at most. Backups are encrypted and are never used to make decisions about you.

8. Your rights

You may request access to, correction of, or deletion of your personal data, and you may object to certain processing. In particular, you may ask us to erase your biometric data (face images and passkeys) — your institution's administrator can action this, after which you simply re-enrol on next use. Academic attendance records may be retained even after biometric erasure, in line with your school's record-keeping obligations. Erasure takes effect in the live service straight away; backup copies holding the same data expire on the schedule in Section 6, within 30 days at most, and we re-apply your erasure if a backup ever has to be restored. To exercise these rights, contact us at support@zentor.ink or speak to your school administrator.

9. Children & students

Zentor is intended for university students and staff. Where a user is under the age of majority, a parent/guardian's involvement (via the parent portal) is supported.

10. Changes

We may update this policy. Material changes will be communicated in-app or by email. Continued use after an update means you accept the revised policy.

11. Contact

Questions about this policy or your data: support@zentor.ink · +234 812 228 7703 · +234 703 237 3712.

The data controller is Zensence Technologies Limited (RC 9778748, trading as Zentor), a company registered in the Federal Republic of Nigeria. Where we process data on behalf of your institution, your institution is the controller and we act as its processor.