ZentorLast updated: 22 July 2026
Zentor ("we", "us") provides attendance management for universities. This policy explains what personal data we collect, why, how we protect it, and your rights. By using Zentor you agree to the practices described here.
| Account & sign-in | Your name, matriculation number, school email, phone, department, level and semester — provided when your account is set up or drawn from your institution's records. How you sign in: students and lecturers use their school email/matriculation number and a password they set; parents create an account with their own email and a password they set, linked to their ward by the ward's matriculation number and a parent access code. Passwords are never stored in readable form — only as a secure one-way hash (see §5). |
| Attendance records | Sessions you attend (in-person and online), timestamps, and the course involved. |
| Online classes | For virtual classes, the join link your lecturer shares, and — when attendance is recorded — the attendance code you enter and the device you enter it from. The class itself takes place on an external platform (e.g. Zoom, Google Meet, Microsoft Teams, Telegram) governed by that provider's own privacy policy. |
| Photos & face data | A selfie captured when you scan in class, plus a reference photo, shown to your lecturer so they can confirm it is really you (anti-proxy). Online classes do not capture a selfie. This is biometric data and is treated as sensitive. |
| Location | Approximate GPS coordinates at scan time, used only to confirm you are physically present in class. |
| Device signals | A device/browser fingerprint used to detect proxy attendance and account sharing. |
| Passkey (device biometric) | Where enabled, attendance is confirmed with a passkey on your device — your phone or computer's own fingerprint/Face ID. Your biometric never leaves your device; we only store a public key that verifies it's really your enrolled device. We cannot read your fingerprint or face from it. |
| Communications | Feedback, absence requests, and messages you send through the app. |
| Usage analytics | Basic product-usage events — sign-ups, logins, attendance submissions and timetable saves — recorded in our own database to understand and improve the app. We use no third-party analytics service, and this data never leaves our infrastructure. |
Your attendance and reports are visible to your lecturers, your school's administrators, and — for students who enable it — a linked parent/guardian. We do not sell your data or use it for advertising. We use trusted infrastructure providers (e.g. database hosting and email delivery) who process data on our behalf under contract.
Face images and location are collected solely to confirm presence and prevent fraud. They are not used to track you outside of attendance scans. Where the law — including the Nigeria Data Protection Act / Regulation (NDPR) — requires consent for biometric processing, your use of the scan/check-in feature constitutes that consent, and you may ask your institution about manual alternatives (for example, a lecturer marking you present).
Data is stored on managed cloud infrastructure. Passwords are hashed (never stored in plain text), face images are encrypted at rest and served only to your lecturer through short-lived, expiring links, traffic is encrypted in transit, and access is restricted by role. Passkeys store only a public key on our side — never your actual fingerprint or face. No system is perfectly secure, but we take reasonable measures to protect your information.
We practise data minimisation — we keep sensitive media only as long as it serves its purpose:
| Scan selfies | Automatically deleted about 30 days after the class (the lecturer's review window). The attendance record itself is kept; only the photo is removed. |
| Reference (enrolment) photo | Kept while you are an active student so future scans can be verified, and deleted when you leave or on an erasure request. |
| Passkey credentials | Kept while active; removed when you reset your device or request erasure. |
| Attendance & account records | Kept for as long as your institution requires them for academic records, then deleted or anonymised. |
You may request access to, correction of, or deletion of your personal data, and you may object to certain processing. In particular, you may ask us to erase your biometric data (face images and passkeys) — your institution's administrator can action this, after which you simply re-enrol on next use. Academic attendance records may be retained even after biometric erasure, in line with your school's record-keeping obligations. To exercise these rights, contact us at support@zentor.ink or speak to your school administrator.
Zentor is intended for university students and staff. Where a user is under the age of majority, a parent/guardian's involvement (via the parent portal) is supported.
We may update this policy. Material changes will be communicated in-app or by email. Continued use after an update means you accept the revised policy.
Questions about this policy or your data: support@zentor.ink · +234 812 228 7703 · +234 703 237 3712.