BaseCode Labs Pvt. Ltd.

Privacy Policy

Product: BCL OneCampus ERP
Effective Date: 10 July 2026
Last Updated: 10 July 2026
Website: https://basecodelabs.com

BaseCode Labs does not sell personal information. Institutions own and manage their student and staff data. Online payments are processed by third-party payment gateways. Passwords are protected using industry-appropriate hashing, and data transmission uses HTTPS.

1. Introduction

1.1. BaseCode Labs Pvt. Ltd. (“BaseCode Labs”, “we”, “us”, or “our”) develops and operates BCL OneCampus ERP (“OneCampus”, “Platform”, or “Service”), a cloud-based Campus Management System for schools, colleges, universities, and other educational institutions.

1.2. This Privacy Policy explains how we collect, use, store, share, and protect information when you access OneCampus through our web portals, Android application, iOS application (when available), institution login pages, or related services.

1.3. By accessing or using OneCampus, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.

1.4. This Policy is provided for informational purposes and is intended to meet transparency expectations for educational software, mobile app stores (including Google Play), and institutional deployments. It does not constitute legal advice.

2. Scope of Policy

2.1. This Privacy Policy applies to the BCL OneCampus ERP web application and institution portals; the Android mobile application; the iOS mobile application (when released); related APIs, notifications, and support channels operated by BaseCode Labs; and links to this Policy from Google Play Console, App Store listings, and institution ERP login pages.

2.2. OneCampus is typically deployed for an educational institution (“Institution”). The Institution is the primary controller of student, staff, and academic records entered into its tenant environment. BaseCode Labs acts as a technology service provider / processor for such institutional data, except where we process limited account, billing, support, or product analytics data as an independent controller.

2.3. This Policy does not apply to third-party websites, payment gateways, or services that we do not control, even if linked from OneCampus.

3. Information We Collect

Depending on your role (student, parent, faculty, staff, administrator) and the modules enabled by your Institution, we may process the following categories of information.

3.1 Personal Information

3.2 Academic Information

3.3 Financial Information

We do not store full card numbers, UPI PINs, or banking passwords. Online payments are processed by third-party payment gateway providers.

3.4 Device Information

3.5 Usage Information

3.6 Information Provided by Institutions

Institutions may upload or configure master data, documents, notices, and operational records. BaseCode Labs processes such information to deliver the Service as configured by the Institution.

4. Cookies and Tracking Technologies

4.1. Our web portals may use cookies, local storage, and similar technologies to maintain authenticated sessions, remember preferences, protect against fraud and abuse, and measure product performance and reliability.

4.2. You may control cookies through your browser settings. Disabling certain cookies may affect login or portal functionality.

4.3. We do not use advertising trackers to sell personal information or build advertising profiles from institutional academic data.

5. Camera, Storage and Notification Permissions

5.1. Mobile applications may request device permissions only as needed for features enabled by your Institution, including:

5.2. Permissions are optional where the underlying feature is optional. You may deny or revoke permissions in device settings; some features may then be unavailable.

5.3. We do not access device content beyond what is required to perform the user-initiated action.

6. How We Use Information

We use information to:

  1. provide, operate, and maintain OneCampus modules;
  2. authenticate users, enforce role-based access, and maintain audit trails;
  3. process fee-related workflows and display payment status returned by payment gateways;
  4. send service, security, and institutional notifications;
  5. provide customer support and resolve technical issues;
  6. improve reliability, performance, security, and user experience;
  7. generate institutional reports and analytics for authorised users of the Institution;
  8. operate optional AI Assistant features subject to institutional configuration and access controls;
  9. comply with applicable law, enforce our Terms, and protect the rights, safety, and security of users and BaseCode Labs.

BaseCode Labs does not sell personal information.

7. Legal Basis for Processing

Where applicable data protection principles apply, we process information on one or more of the following bases:

  1. Contract / service delivery — to provide OneCampus under agreements with Institutions and authorised users;
  2. Legitimate interests — to secure, improve, and support the Platform in ways that do not override user rights;
  3. Consent — where required for optional features, notifications, or device permissions;
  4. Legal obligation — where processing is required to comply with applicable laws or lawful requests.

Institutions are responsible for ensuring they have a lawful basis to collect and process student and staff data within their OneCampus environment.

8. Data Sharing

8.1. We may share information only as described below:

8.2. We do not sell personal information to third parties for marketing or advertising purposes.

8.3. Aggregated or de-identified information that cannot reasonably identify an individual may be used for product improvement and operational reporting.

9. Third-Party Service Providers

9.1. BaseCode Labs may engage trusted third-party providers for infrastructure, communications, monitoring, and related services.

9.2. Such providers are permitted to process data only to perform services on our behalf and are expected to implement appropriate security measures.

9.3. Third-party websites or apps linked from OneCampus have their own privacy practices. We encourage you to review those policies separately.

10. Payment Gateway Providers

10.1. Online fee payments and similar transactions are processed by third-party payment gateway providers selected and configured for the Institution (for example, Razorpay, NTT DATA Payment Services, Cashfree, BillDesk, or other supported providers).

10.2. When you make a payment, you may interact with the payment provider’s checkout experience; payment credentials are handled by the payment provider according to their terms and privacy policy; and OneCampus may receive confirmation details such as transaction reference, amount, and status for reconciliation and receipts.

10.3. BaseCode Labs does not control the payment provider’s systems and is not responsible for their independent data practices. Please review the applicable payment provider’s privacy policy and terms.

11. Data Security

11.1. We implement administrative, technical, and organisational measures designed to protect information against unauthorised access, alteration, disclosure, or destruction. These measures may include role-based access controls, secure hosting and network protections, monitoring and incident response practices, and regular software updates.

11.2. No method of transmission or storage is completely secure. While we strive to protect information, we cannot guarantee absolute security.

11.3. Institutions and users must also protect credentials, devices, and access rights under their control.

12. Encryption and Authentication

12.1. Data transmission between supported clients and OneCampus servers uses HTTPS/TLS.

12.2. Passwords are stored using industry-appropriate one-way hashing / encryption practices and are not stored in plain text.

12.3. Sensitive configuration secrets (such as payment gateway credentials) are protected using encryption and access controls where implemented in the Platform.

12.4. Authentication may include session controls, role permissions, and additional security features configured for the Institution.

13. User Rights

Subject to applicable law and institutional policies, you may have rights to access personal information; request correction of inaccurate information; request deletion subject to legal, academic, financial, and audit retention requirements; withdraw consent where processing is based on consent; and raise concerns with your Institution and/or BaseCode Labs.

Because Institutions control most student and staff records, many requests are most effectively handled by your Institution’s administrator. BaseCode Labs will reasonably assist Institutions in responding to valid requests.

14. Data Retention

14.1. We retain information for as long as needed to provide the Service, fulfil contractual obligations with Institutions, resolve disputes, enforce agreements, and meet legal, accounting, and audit requirements.

14.2. Institutional academic, fee, and examination records may be retained according to the Institution’s retention policies and applicable education regulations.

14.3. When an Institution’s subscription ends, data handling (export, archival, or deletion) will follow the applicable service agreement and reasonable technical timelines.

15. Children's Privacy

15.1. OneCampus is designed for educational institutions and may process information about students, including minors, under the direction of the Institution.

15.2. We do not knowingly market OneCampus directly to children or collect children’s data for independent commercial purposes outside institutional use.

15.3. Parents or guardians with questions about a student’s information should contact the Institution first. BaseCode Labs will support Institutions in addressing legitimate requests.

15.4. This approach is intended to align with Google Play and educational app expectations regarding transparency and institutional accountability for student data.

16. International Data Transfers

16.1. OneCampus may be hosted on cloud infrastructure that stores or processes data in India and/or other jurisdictions depending on deployment configuration.

16.2. Where data is transferred across borders, we take steps designed to ensure appropriate safeguards consistent with applicable law and contractual commitments.

16.3. Institutions are responsible for confirming that their chosen deployment and data residency arrangements meet their regulatory and policy requirements.

17. AI Assistant Usage

17.1. Where enabled, the OneCampus AI Assistant may process user prompts and relevant institutional context to generate responses, summaries, or guided insights.

17.2. AI outputs may be incomplete or inaccurate and should not be treated as the sole basis for academic, financial, disciplinary, or legal decisions without human verification by authorised personnel.

17.3. AI features are subject to role-based permissions. Institutions should configure access carefully and avoid submitting unnecessary sensitive personal data into free-text prompts.

17.4. BaseCode Labs may use de-identified or aggregated interaction patterns to improve reliability and safety of AI features, consistent with this Policy and institutional agreements.

18. Institutional Responsibility

18.1. Institutions own and manage their student, staff, academic, and operational data within their OneCampus tenant.

18.2. Institutions are responsible for obtaining any required consents and providing privacy notices to their users; configuring roles, permissions, and retention practices; ensuring accuracy of uploaded records; responding to student, parent, and staff privacy requests; and selecting and configuring payment gateways and third-party integrations.

18.3. BaseCode Labs provides the software platform and related support; it does not replace the Institution’s obligations as an educational data steward.

19. Account Deletion Requests

19.1. Users who wish to delete a mobile or portal account should first contact their Institution’s administrator, because accounts are institution-managed.

19.2. Institutions may request account deactivation or deletion through supported administrative workflows or by contacting BaseCode Labs support.

19.3. For Google Play and app-store compliance, users may also email contact@basecodelabs.com with the subject line “Account Deletion Request – BCL OneCampus ERP”, including full name, registered mobile/email, Institution name, user role, and optional reason.

19.4. We will coordinate with the Institution where required. Certain records may be retained where necessary for legal, fee, examination, audit, or security purposes.

20. Changes to Privacy Policy

20.1. We may update this Privacy Policy from time to time to reflect product, legal, or operational changes.

20.2. The “Last Updated” date at the top of this Policy will be revised when changes are published.

20.3. Material changes may be communicated through the website, in-app notice, Institution administrators, or other reasonable means.

20.4. Continued use of OneCampus after the effective date of an updated Policy constitutes acceptance of the updated Policy, to the extent permitted by law.

21. Contact Information

For privacy questions, data requests, or concerns regarding BCL OneCampus ERP, contact:

BaseCode Labs Pvt. Ltd.
Your Technology Growth Partner

Website: https://basecodelabs.com
Email: contact@basecodelabs.com
Phone: +91 95663 63655

If you are a student, parent, faculty member, or staff user, please also contact your Institution’s ERP administrator for account-specific requests.