Presidency University is committed to protecting the privacy and security of personal information collected through its digital platforms and services, particularly during the admission process.
The University may collect information such as name, Aadhaar/PAN details, email ID and contact number to facilitate admissions, respond to queries, provide relevant information and improve its services.
The University may work with authorised third-party service providers, including Meritto (Nopaper Forms Solutions Private Limited) and its chatbot Prezy, to support application, enquiry and communication services. Such providers are required to maintain confidentiality and use information only for the intended purposes.
The University takes reasonable measures to protect personal information. However, no method of electronic transmission or storage can be guaranteed to be completely secure.
The University's digital platforms may contain links to third-party websites. The University is not responsible for the privacy practices or content of external websites and recommends reviewing their respective privacy policies.
This Privacy Policy may be updated periodically, with changes becoming effective once published on this page.
For privacy-related queries:
itsupport@presidencyuniversity.in
Privacy & Data Protection
Introduction and Purpose
Presidency University, Bengaluru ("University", "we", "us", or "our") is committed to protecting the privacy and personal data of its students, prospective students, alumni, faculty, staff, visitors, and other stakeholders (collectively, "you" or "Data Principals").
This Privacy Policy describes how the University collects, uses, discloses, stores, and protects personal data in the course of its academic, administrative, research, and operational activities, including through its website(s), learning management systems, mobile applications, and campus systems.
This Policy is issued in compliance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to the extent applicable, and other applicable laws and regulatory guidance issued by the UGC, AICTE, and other statutory bodies governing the University.
Scope and Applicability
This Policy applies to all personal data processed by the University, whether collected in physical or digital form, including but not limited to data collected through:
- • Admissions, enrolment, and registration processes
- • The University website, student and faculty portals, and learning management systems
- • Examination, evaluation, and academic record-keeping systems
- • Hostel, transport, library, and campus access/security systems, including CCTV and biometric access, where deployed
- • Placement, internship, and career services
- • Alumni relations, fundraising, and events
- • Research activities involving human participants, where governed additionally by Institutional Ethics Committee guidelines
- • Employment and human resources processes for faculty and staff
- • Third-party platforms integrated with University systems, such as payment gateways, video-conferencing tools, and cloud storage providers
This Policy does not apply to anonymised or aggregated data from which no individual can reasonably be re-identified.
Definitions
Personal Data means any data about an individual who is identifiable by or in relation to such data.
Data Principal means the individual to whom the personal data relates and, where such individual is a child or a person with disability, includes their lawful guardian.
Data Fiduciary means the University, either alone or jointly with others, which determines the purpose and means of processing personal data.
Data Processor means any entity that processes personal data on behalf of the University, such as a third-party service provider.
Processing means any operation performed on personal data, including collection, recording, storage, use, sharing, and erasure.
Consent Manager means a person registered with the Data Protection Board of India who enables a Data Principal to manage consent through an accessible, transparent, and interoperable platform, where applicable.
Sensitive Personal Data includes, without limitation, financial information, health records, biometric data, and other categories recognised as sensitive under applicable law.
Personal Data We Collect
Information You Provide Directly
The University may collect:
- • Identity and contact information including name, date of birth, gender, photograph, address, email address, phone number and government-issued identification such as Aadhaar, PAN or passport where legally required
- • Academic information including prior education records, entrance examination scores, transcripts, attendance, grades and disciplinary records
- • Financial information including fee payment details, bank account/UPI details, scholarship and financial aid information
- • Family and emergency contact information
- • Health information, including medical history, disability status and health records submitted for hostel, sports or medical accommodation purposes
- • Employment information for faculty and staff, including resumes, qualifications, employment history, salary and tax details and performance records
- • Biometric data, including fingerprint or facial recognition data used for attendance, examination authentication or campus access, where implemented
- • Other information voluntarily submitted through forms, applications, surveys or correspondence with the University.
Information Collected Automatically
When you access University websites, portals or applications, the University may collect:
- • IP address
- • Browser type
- • Device identifiers
- • Log data
- • Cookies and similar tracking technologies
- • CCTV footage captured within campus premises for security purposes
- • Access logs from Wi-Fi networks, ID card/biometric readers, and library or laboratory systems.
Information from Third Parties
The University may receive information from:
- • Previous educational institutions for admission verification
- • Background verification or reference-check agencies for employment
- • Payment gateways, banks and financial institutions processing fee payments
- • Government or regulatory databases where required for compliance, including UGC, AICTE and examination boards.
Purpose and Lawful Basis of Processing
The University processes personal data on the basis of consent obtained from the Data Principal, or where processing is a "certain legitimate use" recognised under the DPDPA, such as processing for a specified purpose for which the Data Principal has voluntarily provided personal data, compliance with a legal obligation, or purposes related to employment.
Personal data may be processed for purposes including:
- • Evaluating and processing admission applications
- • Administering academic programmes and examinations
- • Issuing certificates and transcripts
- • Managing hostel, transport, library and other campus facilities
- • Ensuring campus safety and security
- • Processing fee payments, scholarships and financial aid
- • Facilitating placement, internship and career-related activities
- • Communicating with students, parents/guardians, faculty, staff and alumni regarding University matters
- • Conducting research, subject to applicable ethics approvals and, where required, separate informed consent
- • Complying with statutory, regulatory and accreditation requirements
- • Managing employment relationships with faculty and staff.
Disclosure and Sharing of Personal Data
Personal data may be shared with the following categories of recipients, strictly on a need-to-know basis and, where required, under contractual confidentiality and data protection obligations:
- • Regulatory and statutory bodies, including UGC, AICTE, examination boards and government authorities, where required by law
- • Affiliated examination bodies and accreditation agencies
- • Third-party service providers engaged as Data Processors, including payment gateways, cloud hosting providers, LMS providers and background verification agencies, under written data processing terms
- • Placement partners and prospective employers, with the Data Principal's consent, for internship and placement purposes
- • Parents/legal guardians of students, particularly minors, in accordance with University policy
- • Law enforcement or judicial authorities where required under applicable law or in response to a valid legal process
- • Successors or assignees in the event of a merger, restructuring or transfer of University operations, subject to equivalent privacy protections
The University does not sell personal data to third parties for marketing purposes.
Cross-Border Transfer of Personal Data
Personal data is primarily stored and processed within India.
Where the University engages service providers or platforms that store or process personal data outside India, such transfers will be made in accordance with the DPDPA and any restrictions notified by the Central Government from time to time, and subject to appropriate contractual safeguards.
Data Storage, Security and Retention
The University implements reasonable technical and organisational security measures, including access controls, encryption where appropriate, network security and staff training, designed to protect personal data against unauthorised access, alteration, disclosure or destruction.
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, regulatory or accreditation record-keeping requirements.
Academic records may be retained on a long-term or permanent basis in accordance with University record-retention schedules and UGC guidance.
Upon expiry of the applicable retention period, personal data will be securely deleted, destroyed or anonymised, unless further retention is required by law.
Rights of Data Principals
Subject to applicable law, Data Principals have the following rights:
- • Right to access a summary of personal data processed by the University and the processing activities undertaken
- • Right to correction and updating of inaccurate or incomplete personal data
- • Right to erasure of personal data that is no longer necessary for the purpose for which it was collected, subject to legal retention requirements
- • Right to withdraw consent where processing is based on consent
- • Right to nominate another individual to exercise these rights in the event of death or incapacity
- • Right to grievance redressal, including approaching the University's Grievance Officer/Data Protection Officer and thereafter the Data Protection Board of India, if unresolved
Requests to exercise these rights may be submitted to the University's Grievance Officer using the contact details provided below. The University will respond within the timelines prescribed under applicable law.
Consent and Withdrawal
Where processing is based on consent, the University will seek free, specific, informed, unconditional and unambiguous consent through a clear affirmative action, with the option to access the consent request in English or other languages as applicable.
Consent may be withdrawn at any time through the mechanism by which consent was given or by contacting the Grievance Officer.
Withdrawal of consent will not affect the lawfulness of processing based on consent prior to withdrawal. The University may continue to retain certain data where required for legal or contractual purposes.
Data of Minors and Students Requiring Special Protection
Where the University processes personal data of a Data Principal below the age of 18 years or a person with disability who has a lawful guardian, the University will obtain verifiable consent from the parent or lawful guardian before processing such personal data, except where processing is for purposes exempted under the DPDPA, such as certain educational or health-related processing recognised by law.
The University does not undertake tracking, behavioural monitoring of children or targeted advertising directed at children, except where strictly necessary for permitted purposes such as safety or educational functions.
Cookies and Website Tracking Technologies
The University's websites and portals may use cookies and similar technologies to enhance user experience, remember preferences and analyse website traffic.
Users may control or disable cookies through their browser settings. Disabling cookies may affect the functionality of certain University online services.
Details of specific cookies used, where applicable, are set out in a separate Cookie Notice accessible on the relevant website.
Third-Party Links and Integrated Services
University websites and platforms may contain links to or integrations with third-party websites and services, such as payment gateways, video-conferencing platforms and social media.
This Policy does not apply to such third-party services. Users are encouraged to review the privacy policies of third-party services before providing personal data.
Personal Data Breach Notification
In the event of a personal data breach, the University will take prompt remedial action and notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines prescribed under the DPDPA and applicable rules.
Grievance Officer / Data Protection Officer
For questions, concerns or requests relating to this Policy or the processing of personal data, or to exercise rights as a Data Principal, please contact:
Grievance Officer / Data Protection Officer
Name: [Insert Name and Designation]
Email: [Insert Email Address]
Phone: [Insert Phone Number]
Postal Address: Presidency University, Itgalpura, Rajanakunte, Yelahanka, Bengaluru, Karnataka [Insert PIN Code]
If a grievance is not resolved to the satisfaction of the Data Principal within the timeline prescribed under applicable law, a complaint may be filed with the Data Protection Board of India.
Amendments to this Policy
The University may update this Policy from time to time to reflect changes in legal requirements, University practices or technology.
Material changes will be notified through the University website and/or other appropriate communication channels, along with the updated Effective Date.
Continued engagement with the University's services after such changes constitutes acknowledgment of the revised Policy.
Governing Law and Jurisdiction
This Policy shall be governed by the laws of India.
Subject to the grievance redressal and regulatory mechanisms described above, the courts at Bengaluru, Karnataka shall have exclusive jurisdiction over disputes arising out of or in connection with this Policy.
Who This Notice Covers
This Notice applies to all students enrolled in any programme offered by Presidency University, Bengaluru, including undergraduate, postgraduate, doctoral, and exchange/visiting students, for the duration of their association with the University and, in relevant respects, thereafter as alumni.
Personal Data We Collect About You
The University may collect:
- • Identity and contact details including name, date of birth, gender, photograph, address, phone number, email and government ID where required
- • Academic records including prior qualifications, entrance scores, enrolment details, attendance, internal assessments, examination results, transcripts and disciplinary records
- • Family and emergency contact information
- • Financial data including fee payment records, scholarship/financial aid applications and bank/UPI details for refunds
- • Health data including medical history and disability information submitted for hostel, sports or examination accommodation
- • Biometric/access data including fingerprint or facial recognition data for attendance or examination authentication, hostel and library access logs, campus Wi-Fi and ID card logs
- • CCTV footage recorded on campus and in hostels for safety and security
- • Placement and career data including resumes, skills, internship and placement records shared with recruiters with consent
- • System usage data including LMS activity, portal login records and IT usage logs.
Why We Process Your Data
Student personal data may be processed:
- • To administer admission, registration and academic progression
- • To conduct examinations and evaluations and issue certificates/transcripts
- • To manage hostel, transport, library, canteen and campus facilities
- • To ensure campus safety and security
- • To process fees, scholarships and refunds
- • To communicate academic and administrative information to students and, where appropriate, parents/guardians
- • To facilitate placements, internships and alumni engagement, with consent where required
- • To comply with UGC, AICTE, examination board and other statutory/regulatory requirements.
Sharing of Your Data
Student data may be shared with examination boards and regulatory/accreditation bodies, hostel and transport service providers, placement partners and prospective employers with consent, payment gateways for fee processing, and parents/guardians, particularly where the student is a minor or where University policies require such communication.
The University does not sell your personal data.
Minor Students
Where a student is below 18 years of age, the University will, where required under applicable law, obtain verifiable consent from the parent or lawful guardian for processing personal data.
The University will not use student data for tracking, behavioural monitoring or targeted advertising.
Retention
Academic records are retained in accordance with University record-retention schedules and UGC guidance, which may require long-term or permanent retention of core academic records such as transcripts and degree records.
Other categories of data are retained only as long as necessary for the purposes described above or as required by law.
Your Rights
Subject to applicable law, students may:
- • Access a summary of the personal data held by the University
- • Request correction or updating of inaccurate or incomplete data
- • Request erasure of data that is no longer required, subject to academic record-keeping obligations
- • Withdraw consent for optional processing activities, such as sharing a resume with placement partners
- • Raise a grievance with the University's Grievance Officer and thereafter with the Data Protection Board of India.
Who This Notice Covers
This Notice applies to permanent, contractual and visiting faculty, administrative and support staff, and other personnel engaged by the University for the duration of their employment or engagement and, in relevant respects, thereafter for legal and record-keeping purposes.
Personal Data We Collect About You
The University may collect:
- • Identity and contact details including name, date of birth, gender, photograph, address, phone number, email and government ID
- • Passport information for international faculty
- • Employment records including offer and appointment letters, qualifications, prior employment history, employment contracts, designation and department
- • Payroll and financial data including bank account details, salary, tax declarations, Provident Fund/ESI details and reimbursement claims
- • Performance data including appraisal records, feedback, disciplinary and grievance records and training records
- • Health and insurance data including medical fitness certificates, group health/life insurance enrolment and leave records related to medical conditions
- • Biometric/access data including fingerprint or facial recognition data for attendance, campus and building access logs and vehicle/parking records
- • IT and communications data including official email and system usage logs
- • Background verification data including references, educational and criminal record verification conducted at the time of hiring, where applicable
- • CCTV footage recorded within campus premises for security purposes.
Why We Process Your Data
Employee data may be processed:
- • To manage recruitment, onboarding and the employment relationship
- • To process payroll, statutory deductions, benefits and reimbursements
- • To conduct performance appraisals and manage training and development
- • To ensure workplace safety, security and compliance with internal policies
- • To comply with labour, tax, social security and other statutory obligations, including Provident Fund, ESI, professional tax and UGC/AICTE faculty reporting requirements
- • To manage internal communications and IT systems
- • To defend or pursue legal claims where necessary.
Sharing of Your Data
Employee data may be shared with statutory and regulatory authorities such as Provident Fund and tax authorities, UGC/AICTE, payroll and insurance service providers, background verification agencies and, where required, professional bodies for accreditation of faculty qualifications.
Data may also be shared internally with reporting managers and Human Resources on a need-to-know basis.
The University does not sell your personal data.
Workplace Monitoring
The University may monitor official email accounts, IT systems and campus premises, including through CCTV and access control systems, for security, compliance and operational purposes in accordance with its internal IT and security policies.
Such monitoring is conducted proportionately and, where required, notified to employees separately.
Retention
Employment-related records, including payroll and statutory compliance records, are retained for the duration of employment and thereafter for the period required under applicable labour, tax and social security laws or as necessary to defend legal claims.
Your Rights
Employees may:
- • Access a summary of the personal data held by the University
- • Request correction or updating of inaccurate or incomplete data
- • Request erasure of data no longer required, subject to statutory retention obligations
- • Withdraw consent for optional processing activities, where applicable
- • Raise a grievance with the University's Grievance Officer and thereafter with the Data Protection Board of India.
Purpose
This Policy sets out how long Presidency University, Bengaluru retains personal data and institutional records across its academic, administrative, financial and IT systems, and the manner in which such data is securely deleted or disposed of once no longer required.
It is issued in furtherance of the Digital Personal Data Protection Act, 2023, the University's Regulations for Information Technology and applicable UGC/AICTE record-keeping norms.
Scope
This Policy applies to personal data and institutional records processed or stored by the University across:
- • ERP system
- • Learning Management Systems
- • Linways Academic Management System
- • Tally financial software
- • KOHA Library Management System
- • Biometric and CCTV systems
- • Network and backup infrastructure
- • Other systems operated directly by the University
- • Systems operated by Data Processors/vendors on behalf of the University
It covers data relating to students, employees, applicants, alumni and other stakeholders.
Retention Principles
- • Personal data shall not be retained longer than necessary for the purpose for which it was collected, except where a longer period is required by law, regulation or accreditation norms.
- • Where a specific retention period is not prescribed by law, the default retention period shall be determined by the originating department in consultation with the Data Protection Officer/Grievance Officer, applying the principle of data minimisation.
- • Backups and disaster-recovery copies are retained on rolling cycles determined by the relevant system/vendor and are not treated as an extension of the primary retention period.
- • A right-to-erasure request will be given effect in the live system immediately, with corresponding backup copies purged on their normal rotation cycle.
- • Where data is subject to an ongoing legal proceeding, audit or regulatory inquiry, the applicable retention period is automatically extended until the matter is concluded.
Student and Academic Data
Admission Application Data
Enrolled applicants: Becomes part of the student's academic record on enrolment.
Unsuccessful/non-joining applicants: Retained for 1 year from decision, followed by secure deletion or anonymisation.
Academic Records
Marksheets, transcripts and degree registers are retained permanently, with access restricted.
Examination Answer Scripts
Evaluated answer scripts are retained for 6 months from result declaration, or until the revaluation window closes, whichever is later, followed by secure shredding or certified digital deletion.
Attendance Records
Class, library and hostel attendance records are retained for 3 years from the date of recording, followed by secure deletion.
Hostel Records
Hostel accommodation records are retained for the duration of stay + 1 year, followed by secure deletion.
Library Records
Library circulation and OPAC history are retained for the duration of active membership + 1 year, followed by secure deletion.
Placement / Internship Records
Placement and internship records are retained for 3 years from graduation or withdrawal of consent, whichever is earlier, followed by secure deletion.
Alumni Data
Alumni data is retained until consent withdrawal and reviewed every 3 years for continued relevance.
Employee Data
Recruitment Records
Records of unsuccessful candidates are retained for 1 year from closure of recruitment, unless retained with consent for future openings.
Employment Records
Offer letters, contracts and appraisals are retained for the duration of employment + 7 years from separation.
Payroll and Statutory Compliance Records
Payroll and statutory compliance records are retained for 8 years from the relevant financial year.
Biometric Attendance / Access Data
Employee biometric attendance and access data are retained for the duration of association + 1 year, followed by secure overwrite/deletion.
Official Email Accounts
Official email accounts are deactivated on exit. Mailbox content is retained for 90 days for handover and then deleted.
Performance and Disciplinary Records
Performance appraisal and disciplinary records are retained for the duration of employment + 3 years.
Financial, IT and Security Data
Financial and Accounting Records
Financial and accounting records are retained for 8 years from the relevant financial year, followed by secure deletion.
Backup Data
Backup retention periods are determined by the relevant backup and vendor configurations, including rolling backup cycles for Tally, Linways AMS and cloud snapshots.
CCTV Footage
CCTV footage is retained for 90 days by default.
Footage relevant to a reported incident is preserved for the duration of the investigation or proceeding.
Firewall, Network and System Access Logs
Firewall, network and system access logs are retained for 12 months, followed by automatic purge.
IT Helpdesk / Service Request Tickets
IT helpdesk and service request tickets are retained for 2 years from ticket closure, followed by secure deletion.
E-Waste and Physical IT Hardware
Physical IT hardware is stored for a maximum of 180 days after decommissioning and disposed of through an approved e-waste contractor.
Secure Deletion and Disposal
Electronic records in University-managed databases such as ERP, Linways AMS, Tally and KOHA shall be deleted using the delete/purge functions provided by the respective systems.
Where anonymisation is used instead of deletion, the University shall ensure that the data can no longer reasonably identify an individual.
Physical documents shall be destroyed through secure shredding or pulping through an authorised vendor, with a destruction log maintained by the concerned department.
Physical IT hardware and storage media shall be securely wiped or physically destroyed prior to disposal and disposed of only through an approved e-waste contractor, with a Certificate of Destruction/Disposal obtained and retained by DIT.
Where third-party vendors or Data Processors hold University data, contracts shall require deletion or return of University data upon termination of services or expiry of the applicable retention period.
Data Principal Erasure Requests
Students, employees, applicants and other Data Principals may request erasure of their personal data in accordance with the rights described in the master Privacy Policy.
On receipt of a verified request, DIT and the concerned department shall delete relevant data from live systems within the timeline prescribed under applicable law, unless the University is required or permitted to retain the data under statutory retention, legal hold or an ongoing academic/employment relationship.
Where a request cannot be fully honoured, the University shall inform the Data Principal of the specific ground for continued retention.
Roles and Responsibilities
Department of Information Technology
Implements technical deletion and backup-purge mechanisms across ERP, Linways AMS, network and security systems; maintains e-waste and destruction logs; and executes erasure requests referred by the Grievance Officer.
Grievance Officer / Data Protection Officer
Owns the Policy, reviews and approves retention periods, receives and coordinates data-erasure requests, and liaises with the Data Protection Board of India where required.
Registrar's Office
Custodian of academic and examination records and determines retention for physical academic files.
Finance Department
Custodian of Tally-based financial and payroll records and ensures statutory retention compliance.
Human Resources
Custodian of employee lifecycle records and applies the retention schedule at separation.
Librarian
Applies the retention schedule to KOHA circulation and membership data.
Respective Vendors
Vendors including Linways, Mahatvaa/Tally hosting, ERP providers and surveillance/biometric vendors apply applicable backup and system-level retention periods and honour deletion instructions from DIT.
Review
This Policy shall be reviewed at least annually and additionally whenever:
- • A new IT system or vendor is onboarded
- • Applicable law changes
- • The University's Auto Backup/Disaster Recovery solution is implemented
Amendments require approval of the Director IT and the Grievance Officer/Data Protection Officer. Material changes affecting Data Principals shall be reflected in the master Privacy Policy and relevant Privacy Notices.


Rajanukunte, Yelahanka, Bengaluru, Karnataka, Pin: 560119, India
+91 9022092222