Privacy Policy — Alvara Access

Privacy Policy

Alvara Access · Last updated: 20 August 2026

1. Who we are

Alvara Access (“the app”) is provided by Alvara Education, a sole proprietorship based at Pithampur, Indore, Madhya Pradesh 453001, India. “Alvara”, “we” and “us” mean Alvara Education; “you” means the staff using the app.

2. Who this app is for

The app is for gate staff at campuses that use Alvara. There is no sign-up: your campus created and issued your account so you can do your job at a campus gate, and can change or withdraw your access at any time. You can only sign in if your campus has assigned you to a gate. It is not a personal account, and the app is not offered to the general public. You must be 18 or older to use it.

The app runs on Android, iOS and Windows. This policy covers all three.

3. Who answers for what

Your information falls into three groups, and a different party answers for each:

Your campus's record about you — your name, login ID, mobile number, designation, campus, the gate you are assigned to, what you are allowed to do in the app, and your profile photo. Your campus needs these to administer its staff and asked us to hold them; we act on its instructions.

Your Alvara account — your login ID, password, the code that secures your sign-in, and our security records. These exist so we can give you a secure account, and we answer for them.

The gate records you create — gate passes, entry scans, vehicle logs, and visitor arrivals and departures. Your campus needs these to run campus security. It answers for them; we process them on its instructions, for no purpose of our own.

This matters most for correction and deletion — see .

4. What we hold about you, and why

Identity and contact. Your name, login ID, mobile number, designation, campus, the gate you are assigned to, and your profile photo — to identify you, let you sign in, and send the code that secures your sign-in. Your mobile number is entered by your campus; the app shows it only masked, as the last four digits on the sign-in screen, and does not store it on your device.

Your account and security records. Your password and sign-in codes, in hashed form only; the record that a sign-in passed its code check; records of changes to your account; and our sign-in and security log. When you sign in, our servers see your IP address and the device and software details your device sends, as any internet service does, and we record these.

What you do in the app. The gate passes you create, the scans you make, the vehicle movements you log, the visitor arrivals and departures you mark, and any feedback you send. Every entry records which staff created it and when. A correction records who made it and when, without erasing who made the original entry.

The app sends nothing about your device. It creates no device identifier, and contains no analytics, crash-reporting, advertising or push-notification software.

5. The people you see in the app

To let you check identity at the gate, the app shows you the students and staff of your campus.

When a code is scanned, the app shows:

  • for a student — their name, photograph, institute name, academic year, class and batch;
  • for staff — their name, designation, photograph and institute name.

It shows no contact details, date of birth, family details, medical information, marks or attendance. The app holds none of that.

When a student or staff leaves campus on a gate pass and you scan that pass, the app also shows the reason recorded for the exit, who authorised it, and — for a student — the UID printed on their card, so you can check that the person in front of you is the person the pass was issued to.

The code on a UID card is a random identifier. It does not contain the person's name or any personal details.

Where staff has created a gate pass, or given a group permission to leave campus, the app shows you that person's name.

These are your campus's records. Students have their own notice, including a section for students under 18: Student Privacy Policy.

6. Scanning at the gate

A scan records which person's code was scanned, at which gate, at what time, and which gate staff scanned it.

Scanning at the gate does not mark academic attendance. It is a security record, kept separately.

Scans made while there is no network are held on your device until the app can send them.

When staff has given a group exemption, the app shows you which audience, and the name of the staff who gave it. It does not list the individual students.

7. Visitors

When you make a pass for a visitor, you record the visitor's name, the number of visitors, and the purpose of the visit. You may also record, if it applies: a contact number, an address, a vehicle number, who they are visiting, a student they are connected to, a photograph, and a remark.

A visitor's photograph is optional and can only be taken on a phone. It is kept privately and is visible only to authorised staff. The app tells you, at the point of taking it, not to photograph any government identity document.

A visitor pass is valid for one day and one scan. Once it has been scanned at a gate it cannot be used again.

A printed pass shows the campus name and address, the visitor's name, who they are meeting, the purpose, and — where given — the vehicle number, the connected student, and any remark, together with the pass code. Once printed, that paper is outside our systems.

These are your campus's records.Your campus decides that a visitor register is kept, and it is responsible for telling visitors what is recorded and why. We hold the records on its instructions and use them for no purpose of our own. A visitor's address and photograph are deleted 90 days after the visit; the rest of the pass is deleted after a year.

If you are a visitor and want to know what was recorded about your visit, or want it removed, please contact the campus you visited. If you contact us instead, we will pass your request to that campus and help it answer.

Hostel visits arranged in advance. For a hostel visit that a student has arranged through their campus, the app shows you the visitor's name, their relationship to the student, their contact number, the number of visitors, the identity document the student uploaded, the planned arrival and departure dates, and the student being visited. You mark the arrival and the departure. Those records belong to the campus's hostel system rather than to this app, and are covered by the Student Privacy Policy.

8. Printing a gate pass

The app prints to a thermal printer at your gate — over Bluetooth, Wi-Fi, local network, or USB, depending on the printer and the device you use. Nothing about the pass goes over the internet in order to print it. A pass is created on our servers and printed from your device to a printer you have set up.

9. What stays on your device

The app keeps a copy of the following on your device, so it opens quickly and works when the network is poor:

  • Who you are and which gate you are assigned to;
  • Your campus's student and staff names and photographs, so identity can be checked at the gate;
  • The day's gate passes for your campus;
  • Your campus's vehicle list;
  • Scans waiting to be sent;
  • Your printer settings — a Bluetooth address, a printer's Wi-Fi or local network address, or a USB printer name.

Names are copied automatically. Photographs are copied only when you choose to sync them, because that uses a lot of data.

This copy is encrypted with AES-256, kept in the app's storage area on your device, never copied to a cloud backup, and removed when you log out. On Android and iOS it is also removed if you uninstall the app. If your access is withdrawn or you log out of all devices, the copy is removed on any other device the next time it connects.

The app accesses your photo library only when you choose a profile photo. It uses the camera to scan codes at the gate and, on a phone, to take a visitor's photograph. It never accesses your microphone or your location.

Your profile photo is stored securely in cloud storage with an unguessable unique identifier and is never published publicly.

10. Who can see your information

  • You, in the app.
  • Staff at your campus with authorised access — the record your campus holds about you, and the gate records for the gates, groups and areas they can access, including which gate staff created or last changed each entry and when. Your campus decides who has that access; we do not.
  • Other gate staff at your campus can see the day's gate passes for the campus, including the ones you created, so that a visitor may leave from a different gate.
  • Your campus cannot see your sign-in, device or authentication history, and we do not provide it on request. We disclose it only where a lawful order requires it.
  • Feedback you send from the app goes only to Alvara. Your campus cannot see it, and it is not shown back to you in the app.
  • Inside Alvara, access to the live database is limited to the proprietor; there is no team access.
  • Nobody else. Authorities receive information only against a lawful order.

11. Who we share it with

ServiceWhat they doWhat they receiveWhere
Database and storage providerDatabase and file storageYour records, the gate records, and the files uploaded from the appIndia (Mumbai)
SMS delivery providerSends your sign-in code by SMSYour first name, mobile number and the codeIndia

Nobody else, other than your own campus — the party whose records they are — and where the law requires it against a lawful order. Each provider acts on our instructions and is bound by contract; neither may use your information for its own purposes.

Your records, and the files uploaded from the app, are stored in India, in the Mumbai region.

12. What we do not do

  • No ads. The app contains no advertisements, and no advertising identifier is tracked or transmitted.
  • We do not sell your personal data.
  • We do not use your details to send you marketing or promotional messages.
  • No analytics and no crash-reporting software in the app, and we do not study how staff use it.
  • No push notifications. The app does not send you notifications.
  • We create no device identifier.
  • We request no location permission, on any platform, and we do not collect your location.
  • We do not collect your email address.
  • This app uses no artificial-intelligence service, and nothing you do in it is sent to one.
  • We never read your messages. On Android your sign-in code can fill in by itself through a system feature that hands the app that one message only; the app has no permission to read your inbox. On iOS and Windows you type the code yourself.

13. How long we keep it

InformationHow long
Your account, and your campus's record of youWhile your campus keeps your access
Gate passes you create1 year
A visitor's address and photograph90 days after the visit
Vehicle movements you log1 year
Exception groups1 year
Entry scans6 months
Sign-in and security records90 days
Your sign-in codeValid 5 minutes; the stored record removed within an hour
Your profile photoUntil you or your campus replaces or removes it
Feedback you send usWhile we are acting on it
Arrivals and departures for a hostel visitKept in the campus's hostel system — see the Student Privacy Policy

14. How we protect it

  • All traffic between the app and our systems is encrypted in transit.
  • Your password and sign-in codes are stored only in hashed form. We never see your password, and a code works once.
  • Every fresh sign-in requires a code sent to your registered number. This app does not remember devices, so that step is never skipped.
  • Sign-in attempts and code requests are rate-limited, and repeated incorrect codes temporarily lock the account.
  • Changing or withdrawing your access, changing your password, or logging out of all devices signs you out everywhere.
  • The copy of your campus's records on your device is encrypted with AES-256, is never backed up to the cloud, and is removed when you log out.
  • We can require the app to be updated when a security fix is needed.
  • Security records are kept 90 days, so we can investigate if something goes wrong.
  • Records are stored in India; access to our own systems requires multi-factor authentication.
  • No method of transmitting or storing information is completely secure. We work to protect your information but cannot guarantee absolute security.

15. Your rights, and how to use them

You can ask to see the personal data we hold about you, to have it corrected, and to have it erased. Where the request goes depends on who answers for it ():

  • Your campus's record about you, and the gate records — your campus answers, and maintains them in its own Alvara workspace. Send the request to us and we will pass it on and help your campus answer it, or go to your campus directly. Gate records you created stay with your campus after your access ends: removing them would break its security record.
  • Your Alvara account and our security records — we answer directly. While your campus keeps your access, we cannot delete the account itself; that request goes to your campus.

How to make a request. Email grievance@alvara.education with your login ID. Because giving your data to the wrong person would itself be a breach, we confirm it is you by sending a code to the number on your record before we act. We aim to resolve requests within 30 days.

If we do not resolve it, you may complain to the Data Protection Board of India. Please raise it with us first.

16. If something goes wrong

If a security incident affects your personal data, we will tell you and inform the Data Protection Board of India, as the law requires. Where an incident affects a visitor's information, we will inform the campus that holds the visitor register so that it can tell the people affected.

17. Changes to this policy, and how to reach us

We may update this policy. When we do, the “Last updated” date at the top changes.

If our business is transferred to another entity — for example if we incorporate as a company, or are acquired — your data may transfer with it, and the new owner stays bound by this policy until it gives you notice of any change.

PurposeEmail
Privacy, data requests and complaintsgrievance@alvara.education
Help with the appstaffsupport@alvara.education
Feedback about the appfeedback@alvara.education

Alvara Education

Pithampur, Indore, Madhya Pradesh 453001, India

Governed by the laws of India. The courts at Indore, Madhya Pradesh have exclusive jurisdiction.