Privacy Policy
This Privacy Policy applies to the ClassCheck mobile application (“App”) provided by
AGENA BILISIM VE SAVUNMA TEKNOLOJILERI ANONIM SIRKETI (“Company”, “Data Controller”).
1) Data we process
- User-provided: Name and email address.
-
Student list import data: Teachers may upload student lists in CSV or XLSX format. These files may contain personal data such as student names, email addresses, student numbers, and similar roster information. The uploaded file is processed for import, and the relevant student roster data extracted from the file may be stored in our database for course/class management and attendance-related operations.
- Notification technical data: Push notification token (FCM token) to deliver “class started” notifications.
-
Limited device integrity data for attendance security:
During attendance/check-in sessions, the App may use a device identifier provided by the mobile operating environment / plugin
and derive from it a lecture-scoped fingerprint that is limited to the relevant lecture/session.
This lecture-scoped fingerprint is used only to help detect suspicious behavior such as attempts to use multiple accounts
from the same device during the same lecture/session.
-
Limited technical logs: e.g., app version, OS version, security/diagnostic logs used to operate and secure the service.
-
Bluetooth (BLE): The App uses Bluetooth Low Energy (BLE) for attendance/check-in flows.
-
Location Permission: We do not collect location data (precise or approximate) and do not track users’ location.
On devices/OS versions (especially Android), the operating system may require a Location permission (e.g., Android ACCESS_FINE_LOCATION) to enable Bluetooth (BLE) scanning.
This permission is used only to support nearby Bluetooth device interactions for attendance/check-in. The App does not access GPS location and does not collect, store, or track location data.
For Google Play Data Safety purposes, this interaction is disclosed as 'Collected' and 'Processed Ephemerally' because the OS grants access to scanning, but the data is never transmitted to our servers or stored permanently.
2) Purposes
- Account creation, sign-in, and account management.
- Importing student lists uploaded by teachers in CSV/XLSX format.
- Creating, updating, and managing course/class rosters based on imported student list data.
- Attendance/check-in features (Bluetooth functionality).
- Delivering “class started” push notifications.
- Security, abuse prevention, service continuity, and protection of attendance/check-in integrity.
-
Detecting whether multiple different accounts attempt to participate in the same lecture/session from the same device.
- User support.
3) Third-party services & sharing
We do not integrate third-party advertising SDKs or third-party analytics services on our side.
However, the App may rely on Google Play Services components and Firebase Cloud Messaging (Google)
for push notification delivery and certain platform features. These services may process certain technical information
(e.g., service identifiers, device/app information, connection data, crash/diagnostic logs) according to Google’s own policies.
Google policies: policies.google.com/privacy
The Company does not sell or rent your personal data. We share data only as necessary to provide the service and to comply with legal obligations.
The lecture-scoped fingerprint described above is used only for attendance integrity, security, and anti-abuse purposes.
It is not used for advertising, marketing, profiling, or cross-app / cross-service tracking, and is not sold to third parties.
4) Storage & international transfers
Depending on infrastructure and notification services, data may be processed in Turkey or abroad. Where applicable, we apply legally required safeguards.
5) Security
We take reasonable technical and organizational measures to protect your data (access controls, authorization, encrypted transport/HTTPS, etc.).
6) Retention
Short retention notice
When you delete your account, your access to the App is disabled and your account is deactivated.
However, to preserve course record integrity and to allow teachers to identify the owner of attendance/check-in records,
attendance/check-in records and the identity/contact details necessary for that identification (such as name and email)
may be retained until the relevant course(s) are deleted.
- Name and email are retained while your account is active.
-
Student roster data imported from CSV/XLSX files may be retained in our database for as long as necessary to manage the relevant course/class, maintain attendance/check-in records, and preserve course/class record integrity, subject to legal obligations.
-
After you request account deletion, your account is deactivated and access is disabled. Certain data may be retained
until the relevant course(s) are deleted as described above, subject to legal obligations.
-
Lecture-scoped fingerprint data used for attendance integrity checks is retained only as long as needed for the relevant lecture/session.
Fingerprint data related to completed lectures is deleted during daily cleanup routines.
-
We do not keep a permanent cross-lecture device fingerprint for this feature. The fingerprint used for this control is limited to the relevant lecture/session context.
-
We may retain limited technical logs only if required by law or for security/abuse prevention, for the minimum period necessary.
7) Account deletion / data deletion
How to request deletion:
- In the App: Profile Info → Delete Account
- Without the App: Email
mobileSupport@agenabst.com
from your registered email address with subject
“ClassCheck – Account Deletion Request”.
Note
Deleting your account disables access and deactivates your account. To preserve course record integrity and to allow teachers to
identify the owner of attendance/check-in records, attendance/check-in records and the identity/contact details needed for that
identification (such as name and email) may be retained until the relevant course(s) are deleted. When the relevant course(s) are deleted,
these records are deleted/anonymized (subject to legal obligations).
What data is deleted / disabled:
- Push notification token (FCM token) associated with your account is deleted or disabled.
- Courses/classes created by the user, student roster data imported for those courses/classes, and the attendance/check-in records of those courses/classes are deleted.
- Join/leave requests and related process records are deleted.
-
Lecture-scoped fingerprint records associated with completed lectures are deleted in daily cleanup routines, and any remaining related records are deleted,
anonymized, or irreversibly disassociated when no longer required for security, abuse prevention, course/session integrity, or legal compliance.
Important
A user may act as both a teacher and a student. For courses the user joined (created by someone else), attendance/check-in records may be retained,
and the identity/contact details necessary for teachers to identify whose record it is (such as name and email) may be retained until the relevant
course(s) are deleted.
Retention / grace period:
- After you delete your account in the app, it is kept in a recoverable (soft-deleted) state for 30 days.
-
After 30 days, the account becomes non-recoverable (cannot be restored). However, certain data may still be retained
until the relevant course(s) are deleted for course record integrity, as described above.
- We may retain limited records only if required by law or for security/abuse prevention, for the minimum period necessary.
8) Children
The App is not directed to children under 13 and we do not knowingly collect personal information from children under 13.
9) Changes
We may update this policy from time to time. The current version will always be available on this page.
10) Contact
Email: mobileSupport@agenabst.com
Address:
Sanayi Mah. Teknopark Blv. Teknopark 2A No: 1/2A-103
Pendik - 34906
Türkiye (TR)