Legal information
Privacy Policy
What data we process —including that of the Google Workspace and Classroom integration—, for what purpose and how to exercise your rights.
Last updated: August 2026
01Data controller
ZAINDARI SMART NETWORKS S.L. is the controller of the personal data collected through this site and the Zaindari4Schools platform. We are committed to protecting the privacy of schools, their staff and their students, and to guaranteeing the security of the data.
02Data we collect
- Personal data: name, email address, position or contact details of school staff when they register or request the service.
- Browsing data: IP address, browser, pages visited and access dates/times.
- Cookies: to improve functionality and personalise the experience (see the Cookie Policy).
03Purpose of processing
We use the data to provide the filtering and monitoring services contracted by the school, manage the enrolment and organisation of students, improve the user experience, communicate with the school, comply with legal obligations and carry out internal analysis.
04Google data we access and why
The Zaindari4Schools integration with Google (sign-in, Google Workspace and Google Classroom) is used only by the school’s authorised staff to add and organise their students. The data accessed and its purpose are detailed below:
| Google data accessed | OAuth permissions (scopes) | What we use it for |
|---|---|---|
| Email address of the Google account (from the “Sign in with Google” ID token) | userinfo.email (via OpenID sign-in) |
Solely to verify the user’s identity and link it to a school staff account previously authorised on the Zaindari platform. We do not create accounts from Google data. |
| Google Workspace directory data: user ID, full name and primary email of users; names of organisational units | admin.directory.user.readonly, admin.directory.orgunit.readonly |
So that the school’s authorised staff (teachers, management, IT staff) can import their students into Zaindari and organise them by organisational unit (read-only). |
| Google Classroom data: course names, class rosters, and students’ names and emails | classroom.courses.readonly, classroom.rosters.readonly, classroom.profile.emails |
So that the school’s authorised staff can import Classroom courses as student groups and enrol the corresponding students (read-only). |
| Email of the staff user who connects the integration | userinfo.email |
To confirm which Google account the school staff used to authorise the integration and display it to them. |
05Sharing, protection, retention and deletion of Google data
| Aspect | Statement |
|---|---|
| Sharing, transfer and disclosure | We do not sell Google user data, do not use it for advertising purposes and do not share, transfer or disclose it to third parties. All infrastructure is self-hosted and operated by Zaindari —with no cloud providers or external sub-processors—, so Google user data never leaves our own servers. The only exceptions are: (a) the school that owns the data, which accesses it within its own workspace; and (b) the authorities when required by law. |
| Data protection | All data is encrypted in transit (TLS/HTTPS) and stored exclusively on Zaindari’s self-hosted, access-controlled infrastructure. Google OAuth tokens are never stored on our servers: they are kept only in the browser of the school staff member who connected the integration, as an encrypted (AES), HttpOnly and Secure cookie. Imported data is only accessible to the authenticated and authorised staff of the corresponding school, under role-based access control. |
| Data retention | OAuth credentials expire automatically after a maximum of 30 days (or when school staff disconnect the integration, whichever comes first). Data imported from the directory and from Classroom (names, emails, group membership) is kept only while the school maintains an active service agreement with Zaindari. |
| Data deletion | School staff can delete imported students, groups and tags from the Zaindari platform at any time, and can disconnect the Google integration whenever they wish (which immediately discards the credentials cookie). After the school’s agreement ends, or upon written request to [email protected], we delete all data derived from Google within 90 days. |
| “Limited Use” compliance | Zaindari’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. |
06Recipients
We do not sell or rent personal information. It is only shared with the school that owns the data and, when required by law, with the competent authorities. No cloud providers or external sub-processors are involved.
07Security
We apply technical and organisational measures, including encryption in transit and at rest, role-based access control and self-hosted infrastructure, although no transmission over the internet can be guaranteed to be completely secure.
08Your rights
You can exercise your rights of access, rectification, erasure, restriction, portability and withdrawal of consent by writing to [email protected].
09Links to third parties
ZAINDARI is not responsible for the privacy policies of linked external sites.
10Modifications
This policy may be modified, with notice given by email or by means of a notice on the website.