Legal

Privacy Policy

How we collect, use, and protect your information across all DigiRoad platforms

Last updated: June 30, 2025
Contents
01Introduction 02Company Information 03Scope of Services 04Information We Collect 05How We Use Your Information 06Cookies & Analytics 07Third-Party Services 08Data Sharing & Disclosure 09Data Retention 10Data Security 11Your Rights & Choices 12Children's Privacy 13International Transfers 14Updates to This Policy 15Contact Us

1. Introduction

DigiRoad Inc. ("DigiRoad," "we," "our," or "us") operates digiroad.co and a suite of related digital platforms designed to serve universities, higher education institutions, and the students they educate. Our mission is to unify the fragmented digital infrastructure of higher education — and doing so responsibly means treating the personal data you share with us with the highest degree of care.

This Privacy Policy explains what information we collect, why we collect it, how we use and share it, how long we retain it, and the rights available to you as a user or an institutional partner. It applies to all DigiRoad products and services, including eCampus, Connect, UniPay, associated mobile applications, web portals, and API integrations.

By using any DigiRoad service, you acknowledge that you have read and understood this Privacy Policy. If you are using DigiRoad services on behalf of an institution, you confirm that the institution has authorised such use and that you have the authority to bind the institution to the terms herein.

If you have questions or concerns about this policy or our data practices at any time, please contact us at legal@digiroad.co.

2. Company Information

The data controller for personal information processed through DigiRoad platforms is:

Data Controller
DigiRoad Inc.
Website digiroad.co
General Enquiries laith@digiroad.co
Privacy & Legal legal@digiroad.co
Jurisdiction To be updated upon formal registration

Where DigiRoad processes personal data on behalf of a university or institution, DigiRoad acts as a data processor and the institution acts as the data controller for that data. The institution's own privacy policies and data agreements will apply in addition to this policy.

3. Scope of Services

This Privacy Policy applies to the full range of DigiRoad products and services, including but not limited to:

  • eCampus — A unified digital student experience platform integrating student services, notifications, timetables, assessments, and institutional communication tools.
  • DigiRoad Connect — API infrastructure enabling institutions to integrate DigiRoad services with their existing student information systems, identity providers, and third-party platforms.
  • UniPay — Cross-border student payment rails facilitating tuition, accommodation, and institutional fee payments across currencies and jurisdictions.
  • Virtual Student Credentials — Digital identity and credentialing solutions in partnership with HID Global, allowing institutions to issue and manage digital student ID cards.
  • Mobile Applications — iOS and Android applications for students and institutional administrators.
  • Web Portals — Institution-facing and student-facing web dashboards.
  • API Integrations — Services accessed programmatically by institutional partners via authenticated API keys.
  • Communication Tools — In-app messaging, push notifications, and transactional email services.

Where third-party services are embedded within DigiRoad platforms (such as payment processors or analytics providers), those third parties may have their own privacy policies. We recommend reviewing those policies directly — see Section 7 for a full list.

4. Information We Collect

We collect information in a number of ways depending on how you interact with our services:

4.1 Information You Provide Directly

  • Identity & Contact: Full name, email address, phone number, date of birth (where required for verification), and profile photograph.
  • Institutional Affiliation: University or institution name, student or staff identification number, enrolled programme, academic year, and campus.
  • Account Credentials: Username and hashed password. We never store your password in plaintext.
  • Payment Information: Payment details are collected and processed exclusively by our third-party payment processors (e.g., Stripe). DigiRoad does not store full card numbers or bank account details.
  • Communications: Messages, feedback, and support enquiries submitted through our platforms.

4.2 Information Collected Automatically

  • Usage Data: Pages and features accessed, actions taken, time spent, navigation paths, and error logs.
  • Device Information: Device type, operating system, browser type and version, screen resolution, and unique device identifiers.
  • Network Information: IP address, general geographic location (derived from IP, not GPS), and internet service provider.
  • Cookies & Tracking Technologies: As described in Section 6.

4.3 Information from Institutional Partners

  • Student Records: Enrolment status, module registrations, assessment schedules, and institutional email addresses may be shared with DigiRoad by your institution for the purposes of providing services under a contractual agreement.
  • Access Control Data: Permissions, roles, and campus access records associated with digital credentials.

4.4 Location Data

Precise location data (GPS) is only collected through mobile applications and only with your explicit consent. You may revoke location permissions at any time through your device settings. Approximate location derived from your IP address may be used for security, fraud prevention, and service regionalisation.

4.5 Information We Do Not Collect

We do not intentionally collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or sexual orientation, except where strictly necessary for a specific service feature (such as accessibility accommodations) and only with your explicit consent.

5. How We Use Your Information

We use personal data for the following purposes, relying on the legal bases noted in parentheses where applicable under GDPR and equivalent frameworks:

5.1 Service Delivery & Account Management

To create and manage your account, authenticate your identity, provide access to the features you are enrolled for, process transactions, and deliver the core functionality of DigiRoad platforms. (Legal basis: Performance of a contract.)

5.2 Communications

To send transactional notifications (account changes, payment receipts, security alerts), important service updates, and institutional communications on behalf of your university. We may also send you information about new DigiRoad features or related services where you have opted in. (Legal basis: Legitimate interests / Consent for marketing.)

5.3 Analytics & Product Improvement

To understand how users interact with our platforms, identify bugs and performance issues, and make data-driven improvements to the user experience. Analytics data is aggregated and de-identified wherever possible. (Legal basis: Legitimate interests.)

5.4 Security & Fraud Prevention

To monitor for suspicious activity, detect and prevent unauthorised access, investigate security incidents, and protect the safety and integrity of our platforms and users. (Legal basis: Legitimate interests / Legal obligation.)

5.5 Legal Compliance

To comply with applicable laws, regulations, court orders, and requests from public authorities, including data protection laws, financial regulations, and export control requirements. (Legal basis: Legal obligation.)

5.6 Institutional Reporting

To provide universities with aggregated and/or individual usage reports, credential issuance records, and payment reconciliation data as required under our institutional service agreements. (Legal basis: Performance of a contract with the institution.)

6. Cookies and Analytics

DigiRoad uses cookies and similar tracking technologies (including local storage and session storage) to operate our services, remember your preferences, and understand how our platforms are used.

6.1 Types of Cookies We Use

  • Essential Cookies: Required for the platform to function. These include authentication session tokens, CSRF protection tokens, and security cookies. You cannot opt out of these without stopping use of the service.
  • Functional Cookies: Store your preferences such as language selection, region, and UI settings to personalise your experience across sessions.
  • Analytics Cookies: Used by Google Analytics and Firebase Analytics to collect aggregated data about how users navigate our platforms. This helps us identify usability issues and measure feature adoption. You may opt out via the cookie settings panel or by using a browser extension such as the Google Analytics Opt-out Add-on.
  • Marketing Cookies (Optional): Only placed with your explicit consent. Used to understand the effectiveness of DigiRoad's institutional outreach campaigns. These are not used for student-facing platforms.

6.2 Third-Party Analytics

We use Google Analytics 4 and Google Firebase for usage analytics. Data collected by these services is subject to Google's Privacy Policy. We have enabled IP anonymisation and have configured data retention periods consistent with our obligations.

6.3 Managing Your Cookie Preferences

You can manage your cookie preferences at any time by adjusting your browser settings or using the cookie settings interface available in your DigiRoad account. Note that disabling non-essential cookies will not affect the core functionality of the platform.

7. Third-Party Services & Providers

DigiRoad integrates with carefully selected third-party providers to deliver a secure, scalable, and full-featured platform. Each provider has been evaluated for their security practices and compliance posture. Where required, we have executed Data Processing Agreements (DPAs) with these providers.

Supabase Database

Open-source PostgreSQL database and backend infrastructure provider. Handles data storage, real-time subscriptions, and user authentication services for DigiRoad platforms.

Resend Email

Transactional email delivery service used to send account notifications, password reset emails, payment confirmations, and institutional communication on behalf of DigiRoad.

Google Firebase Hosting & Analytics

Used for web and mobile app hosting, push notification delivery, and in-app usage analytics. Subject to Google's terms and privacy policies.

Cloudflare CDN & Security

Content delivery network, DDoS mitigation, DNS management, and web application firewall. All traffic to DigiRoad platforms is routed through Cloudflare's global network for performance and protection.

HID Global Credentials

Industry-leading physical and digital identity credentialing provider. Powers DigiRoad's virtual student ID card issuance, mobile credential management, and NFC/Bluetooth access control integration.

Microsoft 365 Integration

Institutional email integration enabling DigiRoad platforms to authenticate against Microsoft Entra ID (formerly Azure AD), synchronise calendars, and interact with university Microsoft 365 tenants.

Stripe Payments

Third-party payment processing infrastructure used for card and bank payment transactions within UniPay. DigiRoad does not store card data. All payment data is processed under Stripe's PCI DSS-compliant environment.

Intercom Support

Customer support and live chat platform. Used for in-app support, onboarding guidance for institutional administrators, and helpdesk ticket management.

Google Analytics Analytics

Web and mobile usage analytics service by Google. Collects anonymised interaction data to help DigiRoad understand user behaviour, session flows, and feature engagement. IP anonymisation is enabled.

Amazon Web Services Infrastructure

Cloud infrastructure provider used for certain backend compute, storage, and media processing workloads. Data processed on AWS is subject to applicable AWS data residency configurations and the AWS Data Processing Addendum.

Each third-party provider operates under its own privacy policy and terms of service. We encourage you to review these directly. DigiRoad is not responsible for the privacy practices of external services. Where a provider is located outside your jurisdiction, data transfers are governed by appropriate safeguards as described in Section 13.

8. Data Sharing and Disclosure

DigiRoad does not sell your personal data. We do not trade, rent, or monetise your information to third parties. We share data only in the following limited circumstances:

8.1 With Your Institution

Where you access DigiRoad services through a university or institution, that institution has authorised access to data relating to their students and staff members. This may include usage records, credential activity, and payment status reports. The institution's privacy policy governs how they handle data they receive from us.

8.2 With Service Providers

We share data with the third-party service providers listed in Section 7 to the extent necessary for them to provide services on our behalf. All providers operate under contractual obligations that restrict their use of your data to the specified purposes.

8.3 For Legal Requirements

We may disclose your information if we are required to do so by law, court order, or governmental authority. We will notify you of such requests where legally permitted to do so.

8.4 Business Transfers

In the event of a merger, acquisition, reorganisation, or sale of assets, your data may be transferred to the successor entity. We will notify you via email or prominent notice on our platforms before any such transfer occurs, and your data will remain subject to the commitments made in this Privacy Policy.

8.5 With Your Consent

In any other circumstances not listed above, we will seek your explicit consent before sharing your personal data with third parties.

9. Data Retention

We retain your personal data for as long as your account is active, or as long as necessary to provide you with our services. Specifically:

  • Account Data: Retained for the duration of your account and for up to 3 years following account closure, to support dispute resolution, legal compliance, and institutional audit requirements.
  • Transaction Records: Payment and transaction records are retained for a minimum of 7 years in accordance with applicable financial and tax regulations.
  • Analytics Data: Aggregated and de-identified analytics data may be retained indefinitely. Individual-level analytics data is retained for no longer than 26 months.
  • Support Communications: Support tickets and related communications are retained for 3 years after closure.
  • Credential Data: Digital identity and credentialing records are retained in accordance with the institutional agreement and applicable accreditation requirements.
  • Legal Holds: In cases involving litigation, regulatory investigation, or legal obligation, data may be retained beyond the standard periods described above until the matter is resolved.

Upon expiry of the applicable retention period, data is securely deleted or anonymised. You may request earlier deletion subject to the exceptions noted in Section 11.

10. Data Security

DigiRoad implements a comprehensive set of technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. Our security practices include:

  • Encryption in Transit: All data transmitted between clients and DigiRoad servers is encrypted using TLS 1.2 or higher. We enforce HTTPS across all endpoints.
  • Encryption at Rest: Sensitive data stored in our databases is encrypted at rest using AES-256.
  • Access Controls: Access to personal data is restricted on a strict need-to-know basis using role-based access control (RBAC). All internal access is logged and audited.
  • Authentication: Multi-factor authentication (MFA) is available and encouraged for all accounts. Institutional administrators are required to use MFA.
  • Vulnerability Management: We conduct regular security assessments, penetration tests, and code reviews. Critical vulnerabilities are remediated within defined SLA windows.
  • SOC 2-Aligned Practices: Our internal controls are aligned with the SOC 2 Type II framework, covering security, availability, and confidentiality.
  • Incident Response: We maintain a formal incident response plan. In the event of a data breach that poses a risk to individuals, we will notify affected users and relevant authorities within the timescales required by applicable law.
  • Subprocessor Security: All third-party providers are required to maintain security standards commensurate with the sensitivity of data they process.

While we take all reasonable steps to protect your data, no system is completely infallible. We encourage users to choose strong, unique passwords and to report any suspected security incidents to legal@digiroad.co immediately.

11. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights with respect to your personal data. We honour these rights in accordance with the General Data Protection Regulation (GDPR), the UK GDPR, and equivalent frameworks in other jurisdictions.

  • Right of Access: You have the right to request a copy of the personal data we hold about you, along with information about how it is used and shared.
  • Right to Rectification: If any of your personal data is inaccurate or incomplete, you have the right to request correction.
  • Right to Erasure ("Right to be Forgotten"): You may request deletion of your personal data where there is no compelling legal reason for its continued processing. Note that some data may be retained to fulfil legal obligations or institutional requirements.
  • Right to Data Portability: You may request that we provide your personal data in a structured, commonly used, and machine-readable format for transfer to another service.
  • Right to Restriction of Processing: You may request that we restrict the processing of your data in certain circumstances, such as while a dispute about accuracy is resolved.
  • Right to Object: You may object to the processing of your data based on legitimate interests, including profiling and direct marketing.
  • Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing that occurred prior to withdrawal.
  • Right to Lodge a Complaint: If you believe your data rights have been violated, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction.

To exercise any of these rights, please submit a request to legal@digiroad.co. We will respond within 30 days. Where requests are complex or numerous, we may extend this period by a further 60 days and will notify you accordingly. We may ask you to verify your identity before processing your request.

12. Children's Privacy

DigiRoad services are designed for use by university students, academic staff, and institutional administrators. Our services are not intended for individuals under the age of 16.

We do not knowingly collect personal data from children under 16. In certain jurisdictions or institutional contexts where DigiRoad services are used by students under 16 (such as vocational colleges or further education institutions), use must be authorised and supervised by the institution, and the institution must have obtained appropriate parental or guardian consent in accordance with applicable law.

If you become aware that a child under 16 has provided us with personal data without appropriate authorisation, please contact us immediately at legal@digiroad.co and we will take steps to delete such information promptly.

13. International Data Transfers

DigiRoad operates globally and serves institutions across multiple regions. As a result, your personal data may be transferred to, processed in, and stored in jurisdictions outside your country of residence, including but not limited to the European Union, the United States of America, and Southeast Asia.

Where such transfers involve countries that do not provide an equivalent level of data protection to your home jurisdiction, we implement appropriate safeguards, which may include:

  • Standard Contractual Clauses (SCCs): EU-approved contractual clauses for transfers from the EEA to third countries.
  • UK International Data Transfer Agreements (IDTAs): For transfers from the UK to third countries post-Brexit.
  • Adequacy Decisions: Where the European Commission or UK Information Commissioner's Office has determined that a recipient country provides an adequate level of protection.
  • Data Processing Agreements: Executed with all sub-processors to ensure consistent data protection obligations regardless of processing location.

You may request a copy of the safeguards we have put in place for international transfers by contacting legal@digiroad.co.

14. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements, or best practices. We are committed to keeping you informed of any material changes.

When we make significant changes to this policy, we will notify you by:

  • Sending a notification to the email address associated with your account;
  • Displaying a prominent notice within the DigiRoad platform or app upon your next login;
  • Updating the "Last updated" date at the top of this policy.

Your continued use of DigiRoad services after the effective date of any updated policy constitutes your acceptance of the revised terms. If you do not agree with the changes, you should discontinue use of the affected services and contact us to close your account.

We encourage you to review this policy periodically. Previous versions of this policy are available upon request by contacting legal@digiroad.co.

15. Contact Us

If you have questions, concerns, or requests relating to this Privacy Policy or our data practices, our team is here to help. Please do not hesitate to reach out through any of the channels below.

Privacy & Legal Contact
DigiRoad Privacy Team
Legal Enquiries legal@digiroad.co
General Contact laith@digiroad.co
Website digiroad.co
Response Time Within 30 days for data subject requests

You also have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction if you believe we have not handled your personal data lawfully. In the UK this is the Information Commissioner's Office (ICO); in the EU, it is the supervisory authority in the member state of your residence, place of work, or the place of the alleged infringement.

These terms are also available in our Terms & Conditions.

DigiRoad
Solutions
  • eCampus
  • DigiRoad Connect
  • UniPay
Company
  • About Us
  • Newsroom
  • Jobs
  • Contact
  • Pricing
Resources
  • Documentation
  • Security
  • Get Support
  • Become a Partner
© 2026 DigiRoad Inc. All rights reserved.
Privacy Policy · Terms & Conditions