GDPR
GDPR and Data Protection
Effective Date: October 10, 2026
Last Updated: October 10, 2026
1. Introduction
At Nisaab360, we recognize that protecting personal information is an essential part of building trustworthy educational technology.
Founded on August 14, 2026, Nisaab360 is an independent Pakistani Software as a Service (SaaS) platform designed to help schools and colleges manage their academic and administrative operations digitally.
Our platform supports the management of information relating to educational institutions, students, parents, teachers, and employees.
This document explains our approach to data protection and the requirements of the European Union's General Data Protection Regulation (GDPR), where applicable.
This document does not constitute a certification or declaration that Nisaab360 has achieved full GDPR compliance.
2. Applicability of the GDPR
Nisaab360 is based in Pakistan and initially focuses on educational institutions operating within Pakistan.
The GDPR may apply to organizations outside the European Union when their processing activities fall within its territorial scope, including certain circumstances involving offering goods or services to individuals located in the European Union or monitoring their behavior there.
The applicability of GDPR depends on the specific processing activities, organizational relationships, and relevant legal circumstances.
Nisaab360's availability through an internationally accessible website does not, by itself, establish that all processing activities are subject to GDPR.
Where GDPR applies, the relevant requirements must be addressed before and during the processing of covered personal information.
3. Our Approach to Data Protection
Nisaab360 aims to support responsible handling of educational and institutional information.
Our approach is guided by the principles of lawful processing, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.
These principles require personal information to be processed for appropriate purposes, protected against unauthorized access, and retained only for justified periods.
Institutions using Nisaab360 remain responsible for their own data collection practices and applicable legal obligations.
4. Data Controller and Data Processor Responsibilities
Under GDPR, organizations may have different responsibilities depending on whether they determine the purposes and means of processing personal data or process it on another organization's behalf.
Educational Institutions
Schools and colleges generally determine the purposes for collecting and using their student, parent, teacher, and employee information.
Where an institution makes these decisions, it generally acts as a data controller for the relevant processing activities.
Institutions are responsible for identifying an appropriate lawful basis, providing required privacy notices, responding to applicable individual rights requests, and determining appropriate retention requirements.
Nisaab360
When Nisaab360 processes institutional information on behalf of an educational institution and under its documented instructions, Nisaab360 may act as a data processor.
Nisaab360 may separately act as a data controller for certain information processed for its own purposes, such as business inquiries, account administration, and subscription management, depending on the circumstances.
The actual responsibilities of each party must be determined according to its processing activities and applicable agreements.
5. Categories of Personal Data
Nisaab360's educational management functionality may involve the following categories of information.
Institutional Information
Institution names, campus details, administrative contact information, subscription records, and institutional account details.
Student Information
Student names, admission identifiers, roll numbers, enrollment records, class assignments, attendance, examination marks, academic results, and fee-related information.
Parent and Guardian Information
Names, contact information, relationships to students, and institutionally maintained communication records.
Teacher and Employee Information
Names, contact information, institutional roles, assigned responsibilities, and relevant administrative records.
Account Information
User identifiers, authentication-related data, account permissions, and information necessary for managing access to the Services.
Technical Information
Information generated through the operation of an online system, potentially including IP addresses, device information, browser details, request timestamps, and application activity.
The information actually processed depends on the institution's configuration and use of the platform.
6. Lawful Basis for Processing
Where GDPR applies, personal data must be processed under an appropriate lawful basis.
Depending on the circumstances, these may include contractual necessity, compliance with legal obligations, legitimate interests, consent, or another basis recognized under applicable law.
Educational institutions are responsible for identifying appropriate lawful bases for processing the personal information under their control.
Nisaab360's processing of institutional information must remain consistent with its contractual responsibilities and applicable legal requirements.
Consent must not be assumed to be the appropriate basis for every educational processing activity.
Where consent is required, applicable standards for obtaining and managing that consent must be satisfied.
7. Purpose Limitation and Data Minimization
Personal information should be collected and processed for specified, explicit, and legitimate purposes.
Institutions should avoid collecting information that is unnecessary for educational or administrative operations.
Nisaab360's platform is intended to support defined institutional workflows rather than unrestricted collection or use of personal information.
Any additional processing purposes must be assessed against applicable legal and contractual requirements.
8. Institutional Data Ownership
Educational institutions retain ownership of their Institutional Data in accordance with the Nisaab360 Institutional Agreement.
The use of Nisaab360 does not transfer ownership of institutional records to the Provider.
Institutions are responsible for managing the information they submit and determining how it is used within their authorized educational operations.
Data ownership does not override applicable individual privacy rights.
Nisaab360's processing of institution-controlled information must remain consistent with the applicable agreement, authorized instructions, and legal requirements.
9. Individual Data Protection Rights
Where GDPR applies, individuals may exercise relevant rights regarding their personal information, subject to legal conditions and exceptions.
Right to Be Informed
Individuals have the right to receive appropriate information about how their personal data is processed.
Right of Access
Individuals may request confirmation of whether their personal data is being processed and access to information covered by the applicable legal requirements.
Right to Rectification
Individuals may request correction of inaccurate personal information or completion of incomplete records.
Right to Erasure
Individuals may request deletion of personal information where the applicable legal conditions are satisfied.
The right to erasure is not absolute and may be subject to legitimate retention requirements.
Right to Restriction of Processing
Individuals may request restrictions on particular processing activities where GDPR provides that right.
Right to Data Portability
Where the relevant legal conditions are met, individuals may request certain personal information in a structured, commonly used, machine-readable format.
Right to Object
Individuals may object to certain processing activities where an applicable right of objection exists.
Rights Relating to Automated Decision-Making
Where legally applicable, individuals have protections concerning certain decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects.
Requests concerning institution-controlled educational records should ordinarily be directed to the relevant school or college.
For privacy concerns involving Nisaab360 directly, individuals may contact [email protected].
10. Handling Data Protection Requests
Where GDPR applies, requests must be assessed and addressed within the relevant legal deadlines.
The GDPR generally requires a response to applicable individual rights requests within one month, subject to legally permitted extensions and exceptions.
Nisaab360 may need to verify the identity or authority of a requester before disclosing or modifying personal information.
Where Nisaab360 acts as a processor, it may need to assist the relevant institution in fulfilling its obligations rather than independently deciding the outcome of a request.
11. Protection of Children's Information
Nisaab360 processes educational information that may relate to children and students under the age of 18.
Institutions are responsible for determining appropriate collection and processing practices for student information.
Where GDPR applies, processing involving children requires consideration of relevant safeguards and applicable legal requirements.
The GDPR contains specific requirements concerning children's consent for certain information society services when consent is the lawful basis for processing.
Those requirements do not mean that every educational record requires the same form of parental consent.
Nisaab360's handling of student information remains subject to applicable institutional responsibilities, contractual obligations, and relevant law.
12. Security of Personal Information
Nisaab360 recognizes the importance of protecting personal information against unauthorized access, disclosure, alteration, destruction, or loss.
The platform is designed around authenticated accounts, institutional separation, and role-based permissions.
Appropriate security measures must be evaluated according to the nature of processing, potential risks, and applicable legal requirements.
Such measures may include suitable access controls, credential protection, encryption, logging, vulnerability management, backup controls, and incident response procedures.
The presence and effectiveness of particular security measures must be established through technical verification.
No online service can guarantee absolute security.
Users and institutions must protect their credentials and report suspected unauthorized account activity.
Security Contact: [email protected]
13. Personal Data Breaches
A personal data breach may involve accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access to personal information.
Where GDPR applies, Nisaab360 must fulfill the breach management and notification obligations relevant to its role.
When acting as a data processor, Nisaab360 is required to notify the relevant controller without undue delay after becoming aware of a personal data breach.
A controller must notify the competent supervisory authority within 72 hours after becoming aware of a breach, where feasible, when the relevant GDPR reporting threshold is met.
Notification to affected individuals may also be required where a breach is likely to result in a high risk to their rights and freedoms, subject to applicable exceptions.
Security incidents should be reported to [email protected].
14. International Data Transfers
Nisaab360 operates from Pakistan and uses online infrastructure to provide its Services.
Personal information may be processed outside the country in which an individual or educational institution is located, depending on the infrastructure and services involved.
Where GDPR applies to international transfers, relevant transfer requirements must be satisfied.
These may involve an applicable adequacy decision, Standard Contractual Clauses, supplementary safeguards, or another legally recognized transfer mechanism.
An institution's subscription to Nisaab360 does not independently establish a lawful international transfer mechanism.
Specific transfer arrangements must be assessed according to the relevant data flows and service providers.
15. Third-Party Service Providers
Operating an online educational platform may require infrastructure, hosting, communications, payment processing, and other supporting services.
Where third parties process personal information on behalf of Nisaab360, their responsibilities must be evaluated according to the applicable contractual and legal requirements.
For processing subject to GDPR, the use of subprocessors may require appropriate contractual safeguards and controller authorization.
Nisaab360 does not represent that every external provider has independently obtained a particular privacy certification.
Information about relevant processing arrangements may be requested through the official contact channels.
16. Data Processing Agreements
Where GDPR requires a controller-processor agreement, an appropriate Data Processing Agreement (DPA) must govern the relevant processing.
Such an agreement should address documented processing instructions, confidentiality, appropriate security measures, subprocessors, assistance with individual rights, breach assistance, deletion or return of personal information, and necessary compliance information.
Nisaab360's standard Institutional Agreement establishes data ownership and general confidentiality obligations.
It should not automatically be treated as a complete GDPR Article 28 Data Processing Agreement.
Additional contractual provisions may be required where GDPR applies.
17. Data Retention and Deletion
Personal information should not be retained longer than necessary for the purposes for which it is processed, subject to applicable legal and contractual obligations.
Institutional data handling is governed by the applicable subscription agreement, Privacy Policy, and legitimate operational requirements.
Nisaab360's Institutional Agreement provides for online data export functionality.
Institutions should arrange necessary exports before their subscription access ends.
Deletion requests, retention schedules, backup handling, and post-termination processing must be assessed according to the applicable legal requirements and operational arrangements.
These provisions do not establish a specific deletion period or guarantee immediate removal from all backups.
18. Cookies and Online Tracking
Nisaab360 may require browser storage or cookies to support authenticated sessions and platform functionality.
Any analytics, advertising, or additional tracking technologies must be assessed according to their actual implementation and the applicable privacy and electronic communications requirements.
Where consent is legally required, relevant tracking must not be activated before obtaining valid consent.
This document does not claim that Nisaab360 currently uses any particular analytics or advertising provider.
19. Privacy by Design and Default
Nisaab360 aims to incorporate privacy considerations into its software development and institutional management functionality.
Privacy by design and by default involve evaluating data collection, permissions, accessibility, retention, and security throughout the development and operation of a system.
Institutions should assign permissions according to legitimate responsibilities and avoid granting unnecessary access.
Where GDPR applies, additional technical and organizational measures may be required to satisfy Article 25.
This section expresses the intended privacy approach and does not substitute for a technical compliance assessment.
20. Data Protection Impact Assessments
Certain processing activities may require a Data Protection Impact Assessment (DPIA) where they are likely to result in a high risk to individuals' rights and freedoms.
Educational institutions may need to assess whether their particular use of Nisaab360 requires such an evaluation.
Where Nisaab360 acts as a processor, it may have obligations to assist the relevant institution with an applicable DPIA.
No universal conclusion about the necessity of a DPIA can be made without examining the actual processing activities.
21. Complaints and Supervisory Authorities
Where GDPR applies, individuals may have the right to lodge complaints with a competent European data protection supervisory authority.
They may also have other remedies available under applicable law.
Nisaab360 encourages individuals to raise privacy concerns through its official contact email so that the relevant processing activity and institutional responsibilities can be identified.
Nothing in this document limits an individual's right to contact a competent supervisory authority.
22. Relationship With Other Nisaab360 Policies
This document should be read alongside the applicable Nisaab360 Privacy Policy, Terms of Service, and Institutional Agreement.
The Privacy Policy explains Nisaab360's information-handling practices.
The Terms of Service govern general access and acceptable use.
The Institutional Agreement establishes the contractual relationship between Nisaab360 and subscribing educational institutions.
Where necessary, a separate Data Processing Agreement should establish the specific controller-processor obligations required by GDPR.
This document does not override mandatory legal requirements or create an independent certification of compliance.
23. Updates to This Document
Nisaab360 may update this document to reflect developments in its platform, processing arrangements, contractual commitments, or applicable data protection requirements.
Changes will be reflected in the published effective and last updated dates.
Where applicable law or contractual arrangements require additional notification or consent, those obligations must be respected.
24. Contact Information
For questions concerning personal information, privacy rights, or GDPR-related matters, contact Nisaab360 through the following channels.
General and Privacy Inquiries: [email protected]
Technical Support and Security Reports: [email protected]
Support Days: Monday to Friday
Location: Dunyapur, Lodhran, Pakistan
Official Website: https://nisaab360.app
25. Our Commitment
Nisaab360 was founded with the vision of helping Pakistan's educational institutions move beyond traditional paper-based administration and toward more connected digital systems.
We believe that modern education technology must be accompanied by responsible information management and respect for individual privacy.
As Nisaab360 develops, data protection will remain an important consideration in how the platform is designed, operated, and improved.
Nisaab360
Moving Education Beyond Registers.
Founded August 14, 2026
Dunyapur, Lodhran, Pakistan
https://nisaab360.app