Privacy Policy
Privacy Policy
Please read this Privacy Policy carefully before using our Services.
This Privacy Policy explains how NoPaperForms Solutions Limited (“NoPaperForms”, “we”, “us” or “our”), through its Collexo products and services (“Collexo”), collects, uses, stores, shares and otherwise processes personal data.
Collexo is a software and technology platform purpose-built for educational organisations to manage fee structures, fee collection workflows, student payment records, reconciliation, reporting and related financial operations.
Certain payment-related features available through Collexo are provided or processed in collaboration with banks, payment gateways, payment aggregators, prepaid payment instrument issuers, card or payment networks, financing partners and other regulated or authorised third-party service providers.
NoPaperForms does not operate as a bank, non-banking financial company or payment aggregator. Payment processing, settlement, issuance of payment instruments and other regulated financial activities are undertaken by the applicable authorised third-party providers.
This Privacy Policy should be read together with the applicable Collexo Terms and Conditions and, where relevant, the privacy notice or terms of the educational organisation, payment provider or other third party through which a service is provided.
1. Who We Are
Collexo is owned and operated by:
NoPaperForms Solutions LimitedUnit No. 4, First Floor,
Plot No – 242 & 243, AIHP Palms,
Udyog Vihar, Phase IV, Palam Road,
Gurugram – 122015
Depending on the context in which personal data is processed, NoPaperForms may act:
- on behalf of an educational organisation or another organisation that determines why and how personal data is processed;
- independently in relation to personal data required to operate, secure and administer Collexo and our business; or
- as a technology or service provider supporting an authorised bank, payment provider, PPI issuer or other regulated service provider.
2. Scope of This Privacy Policy
This Privacy Policy applies where you:
- visit Collexo websites or digital properties;
- submit a demo, enquiry, contact or support request;
- use a Collexo application, dashboard, portal, API or other interface;
- access Collexo as an employee or authorised representative of an educational organisation;
- make or manage fee payments through a Collexo-enabled workflow;
- interact with Collexo in connection with Pixi;
- receive communications relating to a Collexo service;
- attend an event, webinar or programme organised by us; or
- otherwise interact directly with NoPaperForms in connection with Collexo.
This Privacy Policy does not replace the privacy policy of an educational organisation or an independent payment or financial service provider where that entity independently determines how your personal data is processed.
3. Our Role When Educational Organisations Use Collexo
Educational organisations use Collexo to configure and manage workflows relating to fees and payments.
These may include student fee structures, invoices, payment schedules, reminders, transaction status,
reconciliation records, ledgers and reports.
Where an educational organisation determines the purposes for which student, parent, payer or other personal
data is processed through Collexo, the educational organisation generally acts as the relevant Data Fiduciary
or Data Controller, and NoPaperForms processes such personal data on its behalf in accordance with its
instructions and our contractual arrangements.
- create fee structures or payment schedules;
- maintain student-wise fee ledgers;
- issue invoices and receipts;
- send fee-related reminders;
- facilitate payment through an integrated third-party payment provider;
- reconcile transaction information received from payment providers;
- track unpaid, failed or pending payments; or
- prepare financial or operational reports.
In these circumstances, queries relating to the purpose for which your personal data was collected, correction of institutional records or deletion of data controlled by the educational organisation should ordinarily be directed to that organisation.
Our processing of such data may also be governed by a separate Data Processing Addendum with the relevant customer.
Collexo serves as the financial system of record for fee collection and payment workflows in the Company’s current business positioning.
4. When NoPaperForms Processes Personal Data Independently
NoPaperForms may independently determine the purposes for which certain limited categories of personal data are processed where necessary to operate and manage Collexo and our business.
This may include processing for:- user and account administration;
- authentication and access management;
- service security;
- detection of misuse, fraud or suspicious activity involving our systems;
- troubleshooting and technical support;
- system diagnostics and performance monitoring;
- product reliability and service improvement;
- maintenance of audit and security logs;
- contractual administration;
- billing and invoicing relating to our customers;
- legal and regulatory compliance;
- responding to lawful requests from authorities; and
- communications relating to Collexo products and services.
Where applicable law requires consent for a particular activity, such consent will be sought separately.
5. Payment and Regulated Service Providers
Certain Collexo features depend on independent third parties that provide regulated or specialised payment and financial services.
These may include:- banks;
- payment gateways;
- RBI-authorised payment aggregators;
- prepaid payment instrument issuers;
- card and payment networks;
- mandate and AutoDebit providers;
- KYC or identity-verification providers;
- lenders and financing providers;
- other authorised financial or technology service providers.
NoPaperForms does not operate as a bank, non-banking financial company or payment aggregator. Payment
processing, settlement, issuance of payment instruments and other regulated financial activities are
undertaken by the applicable authorised third-party. These providers may independently collect or process
personal data or transaction information in accordance with applicable law, their contractual arrangements
and their own privacy notices.
Where a payment is initiated through Collexo, the payment itself may be processed by the applicable payment
provider. NoPaperForms provides the technology and workflow layer connecting the educational organisation,
payer and relevant provider.
Where another provider independently determines the purposes and means of processing personal data,
NoPaperForms does not control that provider’s independent processing practices.
6. Information We May Process
The information processed through Collexo depends on the relevant service and how you interact with us.
Website visitors and prospective customers- name;
- business email address;
- phone number;
- organisation name;
- designation or professional information;
- information submitted through forms;
- correspondence with us;
- IP address;
- browser and device information;
- website interaction and usage information; and
- cookie and similar technology information.
We use this information to respond to enquiries, provide requested information, understand interest in our services, improve our websites, maintain security and, where permitted, communicate about Collexo.
Customer representatives and authorised users We may process:- name;
- official email address;
- phone number;
- organisation and designation;
- user credentials and authentication information;
- access permissions;
- login and session information;
- device and browser information;
- IP address;
- user activity and audit logs;
- support correspondence; and
- administrative actions undertaken within Collexo.
This information is used to provide and secure access to Collexo, administer customer accounts, maintain auditability, provide support and protect the platform.
Student, parent and payer informationWhere Collexo is used by an educational organisation, information processed may include:
- name;
- contact details;
- student or application identifier;
- programme, course or campus information;
- fee category;
- fee structure;
- amount payable;
- due dates;
- discounts, scholarships or concessions;
- invoice information;
- payment status;
- transaction reference information;
- settlement or reconciliation information; and
- other information configured or supplied by the relevant educational organisation.
The educational organisation ordinarily determines the purpose for which this information is processed.
Transaction-related informationTo facilitate reconciliation, reporting, payment status and related functionality, Collexo may receive limited transaction information from payment providers.
Depending on the service, this may include:- transaction identifier or reference;
- transaction amount;
- date and time;
- payment method category;
- transaction status;
- settlement information;
- failure or response codes;
- refund information; and
- other information necessary to reconcile the relevant payment.
Payment credentials and sensitive authentication information may be collected and processed directly by the applicable payment service provider rather than by NoPaperForms.
7. Pixi
Pixi is a Collexo offering that combines student identification and campus functionality with payment
functionality provided in collaboration with third-party providers.
The Company’s current business disclosure describes Pixi as a unified student ID card for campus identity,
access, payments and transit and states that the PPI functionality is issued by an RBI-licensed PPI issuer,
with NoPaperForms acting as co-branded partner.
Different parties may therefore process different categories of information in connection with Pixi.
An educational organisation may provide information necessary to configure or issue a student identity or related campus service, including:
- name;
- student identifier;
- photograph;
- programme or course;
- campus information;
- eligibility or entitlement information; and
- other institution-defined attributes.
Where the institution determines the purpose of this processing, NoPaperForms processes such information on its behalf.
PPI and regulated payment functionalityWhere Pixi includes a prepaid payment instrument or other regulated payment functionality, such functionality is provided in collaboration with the applicable RBI-authorised issuer and other relevant regulated participants.
The issuer or other authorised provider is responsible for regulatory activities falling within its role, which may include:- PPI issuance;
- applicable KYC requirements;
- AML/CFT checks;
- regulatory record retention;
- transaction authorisation;
- payment processing; and
- other obligations imposed upon it under applicable law.
Where information is required for KYC or identity verification, Collexo may provide the technology through
which such information is submitted or securely transmitted to the applicable issuer or verification provider.
Such information may include information prescribed by the applicable authorised provider or law.
NoPaperForms processes KYC-related information only to the extent necessary to enable the relevant service,
comply with its contractual obligations or applicable law, and does not use such information for unrelated
advertising or marketing purposes.
Retention of KYC information is determined by the relevant data flow, applicable contractual arrangements and
legal requirements.
NoPaperForms may receive limited card status, wallet, transaction or service information necessary to display
functionality within Pixi, provide customer support, administer applicable programmes or enable reconciliation
and related services.
Sensitive card credentials and authentication information are processed in accordance with the architecture
and controls of the relevant authorised provider.
8. How We Use Personal Data
Depending on the service and our role, personal data may be processed to:
- provide, operate and maintain Collexo;
- configure fee and payment workflows;
- create and maintain student ledgers;
- facilitate payment initiation through integrated providers;
- display payment and transaction status;
- undertake reconciliation and reporting;
- generate invoices or receipts;
- send transaction and fee-related notifications;
- administer Pixi-related functionality;
- provide customer support;
- authenticate users;
- maintain audit trails;
- monitor system performance;
- detect misuse or security incidents;
- protect our systems and users;
- administer contracts and customer relationships;
- comply with applicable legal obligations;
- improve the reliability and performance of our products;
- understand use of our websites and services; and
- communicate about our products where permitted by applicable law.
9. Analytics, Product Improvement and Artificial Intelligence
We may process service telemetry, diagnostic information, usage information and other information necessary to
understand, secure and improve the operation of Collexo.
Where we process personal data on behalf of an educational organisation, we do so in accordance with the
customer’s instructions and applicable contractual arrangements.
Where information is aggregated, anonymised or de-identified such that it no longer identifies an individual,
we may use it to understand service performance, usage trends, operational patterns and product effectiveness,
subject to applicable law and contractual restrictions.
Personal data processed by Collexo is not used to train general-purpose artificial intelligence models unless
such processing is expressly permitted under the applicable contractual arrangement and applicable law.
10. Cookies and Similar Technologies
Our websites and digital services may use cookies, pixels, tags, SDKs and similar technologies.
These may include:Essential technologies, required for login, authentication, security and operation of the Services.
Performance and analytics technologies, used to understand service performance and how users interact with our websites.
Preference technologies, used to remember settings or improve the user experience.
Marketing technologies, used to measure campaigns or provide relevant communications where permitted by law.
Where consent is required for non-essential cookies or similar technologies, such technologies will be used only after obtaining the required consent.
Users can manage applicable preferences through the cookie settings made available on our website or through browser or device settings.
11. Children’s Personal Data
Collexo is designed primarily for use by educational organisations and may therefore process personal data
relating to students who are minors.
Where we process a child’s personal data on behalf of an educational organisation, the educational
organisation is responsible for establishing the appropriate lawful basis and obtaining parental or guardian
consent where required.
Where personal data relating to a child is processed in connection with a regulated payment or Pixi service,
additional eligibility, consent or verification requirements may be determined by the relevant authorised
provider and applicable law.
Privacy consent alone does not determine a minor’s eligibility to obtain or use a payment instrument.
NoPaperForms does not knowingly use children’s personal data for targeted advertising or behavioural profiling
in circumstances prohibited by applicable law.
12. Sharing of Personal Data
We may share personal data where necessary with:
Our customersWhere necessary to provide Collexo and the customer is entitled to access such information.
Service providers and subprocessors We may engage providers supporting:- cloud hosting;
- communications;
- monitoring and diagnostics;
- security;
- customer support;
- data storage;
- identity verification;
- document processing; and
- other infrastructure required to provide Collexo.
Where they process personal data on our behalf, we impose appropriate contractual obligations relating to confidentiality, processing and security.
Payment and regulated providersInformation may be exchanged with banks, payment gateways, payment aggregators, PPI issuers, payment
networks, KYC providers or other authorised providers where necessary for the applicable service.
Their independent processing may be governed by their own privacy policies and applicable regulatory
requirements.
Professional advisers
We may share information with auditors, consultants, legal advisers and other professional advisers where reasonably necessary and subject to appropriate confidentiality obligations.
Corporate transactionsPersonal data may be disclosed in connection with an actual or proposed restructuring, financing, investment, merger, acquisition or transfer of all or part of our business, subject to appropriate confidentiality and legal safeguards.
Legal requirementsWe may disclose information where required by applicable law, regulation, court order or a valid request from
a competent authority.
Where we process data on behalf of a customer and legally permissible, we may refer such request to the
relevant customer.
13. International Transfers
NoPaperForms operates a cloud-based technology platform and may use service providers or
infrastructure located in more than one jurisdiction.
Where personal data is transferred across national borders, we implement appropriate safeguards in accordance
with applicable data protection law.
Depending on the relevant jurisdiction, these may include contractual protections, approved transfer
mechanisms, security controls and other safeguards required by applicable law.
Cross-border processing is also subject to any restrictions applicable under Indian law and other relevant
regulatory frameworks from time to time.
14. Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was processed,
subject to applicable contractual, security, accounting and legal requirements.
Retention periods may differ according to the relevant data and processing role.
Customer-controlled data
Data processed on behalf of educational organisations is retained and deleted in accordance with applicable
contractual arrangements and customer instructions, subject to legal requirements.
Account and administrative data
Customer account and administrative information may be retained for the duration of the customer relationship
and for an appropriate period thereafter where required for legal, contractual, accounting or
dispute-resolution purposes.
Security and audit information
Security, authentication and audit information may be retained for periods reasonably necessary to investigate
incidents, maintain system integrity and comply with security requirements.
Payment and regulated records
Records required to be retained by payment providers, PPI issuers, banks or other regulated entities are
retained by those entities in accordance with their legal and regulatory obligations.
Where personal data is no longer required, it is deleted, anonymised or otherwise securely disposed of in
accordance with applicable processes.
15. Security
We maintain administrative, organisational and technical safeguards designed to protect personal data from unauthorised access, alteration, disclosure or destruction.
These include measures relating to:-
encryption;
- authentication and access controls;
- role-based permissions;
- network security;
- security logging and monitoring;
- vulnerability management;
- secure software-development practices;
- backup and recovery;
- independent security assessments; and
- incident-management processes.
NoPaperForms maintains a dedicated Information Security function and undertakes independent reviews of its
infrastructure, applications and cloud environments.
No method of storage or transmission is completely secure, and absolute security cannot be guaranteed.
Additional information regarding our security programme and certifications is available on our Security and
Compliance page.
16. Data Breaches
We maintain processes intended to identify, investigate, contain and respond to personal data and
information-security incidents.
Where NoPaperForms becomes aware of a personal data breach, we will take action in accordance with our role,
applicable contractual obligations and applicable law.
Where we process personal data on behalf of a customer or other controller, we will provide notifications and
assistance to the relevant controller as required under our contractual arrangements and applicable law.
17. Your Privacy Rights
Depending on your location, relationship with Collexo and the law applicable to the relevant processing, you may have rights relating to your personal data.
These may include rights to:- obtain information about processing;
- access personal data;
- request correction or updating;
- request deletion or erasure;
- withdraw consent where processing relies upon consent;
- object to or restrict certain processing where applicable;
- request portability where applicable;
- nominate another person where provided under applicable law;
- seek grievance redressal.
These rights apply only to the extent available and in force under applicable law.
Where NoPaperForms processes personal data solely on behalf of an educational organisation or another controller, requests relating to such data should ordinarily be submitted to that organisation. We will provide reasonable assistance to the relevant organisation in responding to valid requests in accordance with applicable law and our contractual obligations.
We may need to verify identity before acting upon a request.
18. Your Choices
- unsubscribe from marketing communications using the unsubscribe mechanism provided;
- manage cookies through our cookie preference controls;
- change device permissions through your device settings;
- withdraw consent where the applicable processing is based on consent.
Withdrawal of consent does not affect processing lawfully undertaken before withdrawal and may affect our
ability to provide a feature where that information is necessary for the feature.
Operational, security, billing or transaction-related communications may continue where necessary to provide
the Services or comply with applicable obligations.
19. Duties of Data Subject/Data Principal (DPDPA)
Under the Digital Personal Data Protection Act, 2023 (DPDPA), a Data Principal shall perform the following duties:
- Comply with applicable laws while exercising rights under the provisions of the Act.
- Not impersonate another person while providing personal data for a specified purpose.
- Not suppress any material information while providing personal data for obtaining any document, unique identifier, proof of identity, or proof of address issued by the State or any of its instrumentalities.
- Not register a false or frivolous grievance or complaint with a Data Fiduciary or the Data Protection Board.
- Furnish only verifiably authentic information while exercising the right to correction or erasure under the provisions of the Act or the rules made thereunder.
20. India Digital Personal Data Protection Framework
Where the Digital Personal Data Protection Act, 2023 and rules issued thereunder apply and the relevant provisions are in force, NoPaperForms processes digital personal data in accordance with the obligations applicable to its role.
Where an educational organisation determines the purpose and means of processing personal data through Collexo, the educational organisation is ordinarily responsible for obligations applicable to it as the Data Fiduciary, while NoPaperForms processes such data in accordance with the applicable contractual arrangement.
Where NoPaperForms independently determines the purpose and means of processing personal data, it will comply with obligations applicable to it as a Data Fiduciary.
References in this Privacy Policy to rights or obligations under the DPDP framework apply to the extent the relevant statutory provisions are applicable and in force from time to time.
21. GDPR and Other International Privacy Laws
Where the European Union General Data Protection Regulation or similar laws apply, processing may be based on one or more lawful grounds including:
- consent;
- performance of a contract;
- compliance with a legal obligation;
- legitimate interests, where permitted; or
- processing undertaken on behalf of another controller.
Where NoPaperForms acts as processor, the relationship with the relevant customer may additionally be governed
by a Data Processing Addendum.
Where other privacy laws, including the UAE Personal Data Protection Law, apply, we process personal data in
accordance with the obligations applicable to our role under those laws.
22. Third-Party Websites and Services
Collexo may contain links or integrations with websites, applications or services operated by third parties.
NoPaperForms does not control the independent privacy practices of such third parties.
Users should review the relevant provider’s privacy notice before supplying personal information directly to
that provider.
23. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, data-processing
practices, technology or applicable law.
When we update the Policy, we will revise the “Last Updated” date.
Where required by applicable law, we will provide appropriate notice of material changes.
An update to this Privacy Policy does not by itself constitute consent to any processing activity for which
separate consent is legally required.
24. Contact and Grievance Redressal
If you have questions, want to exercise your rights, or wish to raise concerns, you can contact us as follows:
General Privacy EnquiriesEmail: infosec@meritto.com
Registered Address
NoPaperForms Solutions Limited,
Unit No. 4, First Floor, Plot No – 242 & 243, AIHP Palms, Udyog Vihar, Phase IV, Palam Road,
Gurugram – 122015
Grievance Redressal (DPDP — India)
- Data Principals may submit grievances regarding the processing of their personal data through our Trust Center: https://trustcenter.nopaperforms.com/your-data https://trustcenter.nopaperforms.com/your-data