Our Privacy policy
Effective Date: 12/08/2026
Last Updated: 10/09/2026
This Privacy Policy explains how Zia international School (“Company,” “we,” “us,” or “our”) collects, uses, discloses, and protects information about you when you use our website(s), mobile application(s), and related services (collectively, the “Services”). It applies to visitors, registered users, and anyone who otherwise interacts with our Services.
By accessing or using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use our Services.
1. Scope of This Policy
This Policy applies to all information collected through our Services, including our website(s) at www.ziagroup.org, our mobile application(s) MCB, and any associated services, features, or content we own or control (collectively, the “Services”). It does not apply to third-party websites, products, or services, even if linked from our Services, or to information collected by third parties, including through any application or content (including advertising) that may link to or be accessible from the Services.
This Policy should be read together with our [Terms of Service] and, where applicable, our [Cookie Policy].
2. Information We Collect
We collect several categories of information depending on how you interact with our Services.
2.1 Information You Provide Directly
- Account information: name, email address, username, password, phone number, date of birth, profile photo.
- Identity/verification information: government-issued ID, date of birth, or other verification data (where required, e.g., for age verification or fraud prevention).
- Payment information: billing address, payment card details, transaction history (processed via our payment processors; we do not store full card numbers).
- Content you create or upload: posts, photos, videos, comments, messages, and other content you submit (“User Content”).
- Communications: information you provide when you contact customer support, respond to surveys, or participate in promotions.
- Preferences and settings: language, notification preferences, privacy settings.
2.2 Information Collected Automatically
- Device information: device type, operating system, unique device identifiers (IDFA, GAID, or similar), browser type, hardware model, mobile network information.
- Usage and log data: IP address, access times, pages viewed, features used, referring/exit pages, crash logs, and interactions with content and ads.
- Location information: approximate location derived from IP address; precise geolocation (GPS) only with your consent/permission.
- Cookies and similar technologies: see Section 6.
2.3 Information From Third Parties
- Social/login integrations: if you connect or log in via a third-party account (e.g., Google, Apple, Facebook), we may receive information from that provider as permitted by your settings with them (e.g., name, email, profile picture).
- Advertising and analytics partners: information about your interactions with our ads on other platforms.
- Data brokers and public sources: publicly available information, where permitted by law, used to supplement account or fraud-prevention data.
- Business partners: information shared by partners who co-offer products, services, or promotions with us.
2.4 Inferred Information
We may generate inferences about you—such as interests, preferences, or usage patterns—based on the information above, for purposes such as personalization and advertising.
2.5 Sensitive Information
We do not intentionally collect sensitive categories of information (e.g., health data, racial or ethnic origin, religious beliefs, sexual orientation, precise geolocation in some jurisdictions) unless you voluntarily provide it, it is required for a specific feature you choose to use, or applicable law otherwise permits it. Where collected, we apply heightened protections and only process it with your explicit consent where required.
3. How We Collect Information
- Directly from you when you create an account, use features, upload content, make purchases, or contact us.
- Automatically through cookies, SDKs, pixels, log files, and similar technologies when you use our Services.
- From third parties, including advertising partners, analytics providers, social login providers, and, where applicable, publicly available sources.
4. How We Use Your Information
We use the information we collect to:
- Provide and maintain the Services — create and manage accounts, enable core features, process transactions, and provide customer support.
- Personalize your experience — recommend content, customize feeds, and remember preferences.
- Communicate with you — send transactional messages, security alerts, updates, and (with consent where required) marketing communications.
- Improve and develop our Services — analyze usage trends, conduct research, debug and fix issues, and develop new features.
- Advertising — deliver, measure, and improve advertising, including personalized ads (see Section 7).
- Safety, security, and integrity — detect and prevent fraud, abuse, spam, and violations of our Terms of Service; protect the rights, property, and safety of our users and the public.
- Legal compliance — comply with applicable laws, regulations, legal processes, or government requests, and enforce our agreements.
- With your consent — for any other purpose disclosed to you at the time of collection, or otherwise with your consent.
5. Legal Bases for Processing (EEA/UK Users)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR/UK GDPR:
Legal Basis | Example Uses |
Contractual necessity | Providing the Services you sign up for, account management |
Legitimate interests | Product improvement, fraud prevention, security, certain analytics and non-intrusive advertising (balanced against your rights) |
Consent | Personalized advertising, marketing emails, precise location, certain cookies, sensitive data processing |
Legal obligation | Responding to law enforcement, tax and accounting requirements |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
6. Cookies and Tracking Technologies
We and our partners use cookies, web beacons, SDKs, pixels, and similar technologies (“Cookies”) to:
- Keep you logged in and remember your preferences.
- Understand how you use our Services (analytics).
- Deliver and measure the effectiveness of advertising.
- Detect and prevent fraudulent activity.
Types of Cookies We Use
- Strictly necessary — required for core functionality; cannot be disabled.
- Functional — remember choices and preferences.
- Analytics/performance — help us understand usage patterns (e.g., Google Analytics or similar).
- Advertising — used by us and third parties to build a profile of your interests and show relevant ads across sites/apps.
Your Choices
- Use our cookie consent banner/preference center at [link] to manage non-essential cookies.
- Adjust your browser settings to block or delete cookies (this may affect functionality).
- Opt out of interest-based advertising via industry tools such as the Digital Advertising Alliance, Network Advertising Initiative, or Your Online Choices (EU).
- Adjust device-level ad tracking settings (e.g., “Limit Ad Tracking” on iOS, “Opt out of Ads Personalization” on Android).
7. Advertising and Analytics Partners
We may work with third-party advertising and analytics companies (which may include companies such as Google, Meta, and others) to serve ads on our behalf across the internet and to provide analytics services. These partners may use cookies, SDKs, and similar technologies to collect information about your activity on our Services and other websites/apps to provide personalized advertising.
- We may share hashed or pseudonymized identifiers (e.g., hashed email addresses) with advertising partners for audience matching and measurement (e.g., “Custom Audiences,” “Enhanced Conversions”).
- Some of these partners act as independent controllers of the data they collect and are governed by their own privacy policies, including:
- Google: policies.google.com/privacy
- Meta: facebook.com/privacy/policy
- Where required (e.g., under GDPR or CCPA/CPRA), we obtain your consent or offer an opt-out before engaging in this sharing, and we enter into data processing agreements with our partners as required by law.
8. How We Share Your Information
We do not sell your personal information for money. We may share information as follows:
- Service providers/processors: hosting, cloud storage, payment processing, customer support, analytics, email delivery, and similar vendors, bound by contractual confidentiality and data protection obligations.
- Advertising partners: as described in Section 7.
- Affiliates: our corporate parent, subsidiaries, and affiliates, for purposes consistent with this Policy.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction.
- Legal and safety reasons: to comply with applicable law, regulation, subpoena, or legal process; to protect the rights, property, or safety of the Company, our users, or others; to detect, prevent, or address fraud, security, or technical issues.
- With your consent or at your direction:g., when you choose to share content publicly or connect a third-party integration.
- Aggregated or de-identified data: we may share data that has been aggregated or de-identified such that it no longer identifies you.
9. International Data Transfers
We are headquartered in India and may process and store information in other countries where we or our service providers operate. These countries may have data protection laws different from those in your jurisdiction.
Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- The UK International Data Transfer Addendum.
- Adequacy decisions, where applicable.
You may contact us for more information about the safeguards used for a specific transfer.
10. Data Retention
We retain personal information for as long as necessary to:
- Provide the Services and maintain your account;
- Comply with legal, tax, accounting, or reporting obligations;
- Resolve disputes and enforce our agreements;
- Support business operations such as analytics and security.
When information is no longer needed, we securely delete, anonymize, or aggregate it. Specific retention periods vary by data type; you may contact us at info@ziagroup.org for details relevant to your account.
11. Data Security
We implement technical and organizational measures designed to protect your information, including:
- Encryption of data in transit (TLS) and at rest, where appropriate.
- Access controls and role-based permissions.
- Regular security assessments and monitoring.
- Employee training and confidentiality obligations.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security, and you use the Services at your own risk. If we become aware of a security breach affecting your personal information, we will notify you and relevant authorities as required by applicable law.
12. Your Privacy Rights
Depending on your location, you may have some or all of the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you.
- Correction/Rectification — request correction of inaccurate or incomplete information.
- Deletion/Erasure — request deletion of your personal information, subject to legal exceptions.
- Portability — request a copy of your data in a structured, machine-readable format.
- Restriction — request that we limit processing of your information in certain circumstances.
- Objection — object to processing based on legitimate interests or for direct marketing, including profiling.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
- Opt-out of sale/sharing/targeted advertising — where applicable under laws like the CCPA/CPRA.
- Non-discrimination — we will not discriminate against you for exercising your privacy rights.
- Lodge a complaint — with your local data protection authority (see Section 13).
How to Exercise Your Rights
Submit a request via:
- Email: info@ziagroup.org
We may need to verify your identity before fulfilling your request. We will respond within the timeframe required by applicable law (e.g., 30 days under GDPR, 45 days under CCPA/CPRA).
You may also designate an authorized agent to submit requests on your behalf, subject to verification.
13. Region-Specific Disclosures
13.1 European Economic Area, UK, and Switzerland (GDPR/UK GDPR)
- Data Controller: Zia International School, Neeladri Nagar, Electronics city, Phase 1.
- EU/UK Representative (if applicable): NA
- Data Protection Officer (if applicable): NA
- You have the right to lodge a complaint with your local supervisory authority, if you believe our processing violates the GDPR.
13.2 California (CCPA/CPRA)
- Categories of personal information collected, in the past 12 months, may include: identifiers, commercial information, internet/network activity, geolocation data, audio/visual data, professional/employment information, inferences, and sensitive personal information (as described in Section 2).
- We may “share” personal information with advertising partners for cross-context behavioral advertising as defined under the CPRA. You can opt out via [our “Do Not Sell or Share My Personal Information” link] or by using the Global Privacy Control (GPC) signal, which we honor as an opt-out preference signal.
- California residents have the right to know, delete, correct, and opt out of sale/sharing, and to limit use of sensitive personal information, as described in Section 12.
- We do not knowingly sell or share the personal information of consumers under 16 years of age without opt-in consent.
13.3 Other U.S. States
Residents of states with comprehensive privacy laws (e.g., Virginia, Colorado, Connecticut, Utah, and others) may have similar rights to access, correct, delete, and opt out of targeted advertising, sale of personal data, and certain profiling. Contact us using the details in Section 19 to exercise these rights.
13.4 Brazil (LGPD)
Brazilian residents have rights of access, correction, deletion, portability, and information about data sharing under the Lei Geral de Proteção de Dados. Our contact for LGPD-related inquiries is info@ziagroup.org.
13.5 Other Jurisdictions
If you are located in a jurisdiction with data protection laws not explicitly addressed above (e.g., Canada’s PIPEDA, Australia’s Privacy Act, India’s DPDP Act), you may still have rights under local law. Contact us for jurisdiction-specific information.
14. Children’s Privacy
Our Services are not directed to children under the age of [13/16, per applicable law], and we do not knowingly collect personal information from children under that age. If we learn that we have collected personal information from a child under the applicable age without parental consent, we will take steps to delete such information promptly.
If you believe a child has provided us with personal information, please contact us at info@ziagroup.org.
For users in the EEA/UK, the age of consent for information society services may be as high as 16 depending on the member state.
15. Third-Party Links and Services
Our Services may contain links to third-party websites, plug-ins, and applications. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party sites and are not responsible for their privacy statements. We encourage you to read the privacy policy of every site you visit.
16. Automated Decision-Making and Profiling
We may use automated systems, including algorithms and machine learning, to:
- Personalize content and recommendations;
- Detect fraudulent or abusive behavior;
- Determine ad relevance.
Where such processing produces legal or similarly significant effects and is required by law, we will provide information about the logic involved, and, where applicable, a mechanism to request human review of the decision.
17. Do Not Track Signals
Some browsers offer a “Do Not Track” (DNT) signal. Because there is no common industry standard for DNT, our Services do not currently respond to DNT browser signals. However, we do honor the Global Privacy Control (GPC) signal as a valid opt-out request under applicable state laws (see Section 13.2).
18. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated Policy with a revised “Last Updated” date. Where required by law, we will provide additional notice (e.g., email notification or in-app notice) or obtain consent before material changes take effect.
We encourage you to review this Policy periodically.
19. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Zia international School
87/1, Neeladri Nagar,
Electronics City, Phase 1,
Bangalore, 560100
Email : info@ziagroup.org
Phone : +91 7676442915