Sonet Microsystems

Privacy Policy

Privacy Policy

Sonet Microsystems Pvt. Ltd. ("Sonet", "we", "us", or "our") respects your privacy and is committed to protecting the personal data entrusted to us.

This Privacy Policy explains how Sonet collects, receives, uses, stores, processes, shares, protects and otherwise handles personal data when you visit our website, communicate with us, request a demonstration, enquire about our products or services, use our digital platforms where this Policy applies, or otherwise interact with us.

As an education technology company, Sonet may provide solutions used by universities, colleges, schools, preschools, educational groups and other institutions. Depending on the product, implementation and contractual arrangement, our platforms may process information relating to administrators, employees, faculty, students, parents/guardians, applicants, alumni, recruiters, vendors and other institutional users.

We seek to process personal data responsibly, transparently and only for legitimate and specified purposes.

1. Scope of This Privacy Policy

This Privacy Policy applies to personal data processed by Sonet in connection with:

  • Our websites and web pages;

  • Product and service enquiry forms;

  • Demo and consultation requests;

  • Communication with our sales, support and customer-success teams;

  • Marketing and communication activities;

  • Our software products and digital platforms, where this Privacy Policy applies;

  • Customer and partner interactions;

  • Recruitment or career-related interactions where applicable; and

  • Other online or offline interactions in which this Privacy Policy is expressly referenced.

Where an educational institution or other customer uses a Sonet platform to process personal data, the institution may determine the purposes for which certain data is collected and used. In such circumstances, the institution may act as the relevant data fiduciary/controller, while Sonet may process data on the institution's instructions as a service provider/data processor, subject to the applicable agreement and law.

This Privacy Policy should therefore be read together with applicable customer agreements, product-specific notices, terms and conditions, consent notices and other contractual documents.

2. Personal Data We May Collect

Depending on how you interact with Sonet, we may collect different categories of personal data.

A. Information You Provide Directly

This may include name, email address, telephone or mobile number, job title or professional designation, institution or organisation name, city, state or country, information provided through enquiry, demo, consultation or contact forms, information contained in messages, enquiries or correspondence, information supplied when communicating with our sales or support teams, information submitted through career or recruitment forms, where applicable; and other information that you voluntarily choose to provide.

We aim to collect information that is reasonably necessary for the relevant purpose.

B. Information Collected Through Our Platforms

Depending on the Sonet product and the customer's configuration, our education technology platforms may process information such as student identification and admission information, academic and course-related information, attendance records, examination, assessment and result information; faculty and employee information, parent or guardian information; fee and transaction-related records; learning activity and course information, communication and notification records, alumni and placement information, accreditation and quality-assurance information, institutional operational information, login, account and role information, system-generated activity and audit information; and other information configured by the customer for legitimate educational or administrative purposes.

The exact categories of data processed will depend on the particular Sonet product, the services purchased, the customer's configuration and the purpose for which the platform is used.

3. Information Collected Automatically

When you visit our website or use certain online services, some technical information may be collected automatically.

This may include IP address; browser type and version; device type; operating system; language and general regional settings; pages visited; referring pages or websites; date and time of access; general interaction information; diagnostic and performance information; and other technical information necessary for security, functionality and service improvement.

We may use this information to operate, secure, maintain and improve our website and services, understand website usage, identify technical issues and prevent fraudulent or unauthorised activity.

4. How We Use Personal Data

We may process personal data for legitimate and specified purposes, including to

  • Respond to enquiries and requests;

  • Schedule and conduct product demonstrations;

  • Provide information about our products and services;

  • Understand customer requirements;

  • Prepare proposals and quotations;

  • Provide customer and technical support;

  • Establish and manage business relationships;

  • Deliver contracted products and services;

  • Create and administer user accounts;

  • Authenticate users and manage access permissions;

  • Maintain platform security and integrity;

  • Monitor and troubleshoot technical performance;

  • Improve our products, services and user experience;

  • Communicate important service-related information;

  • Send marketing or promotional communications where permitted and, where required, based on consent;

  • Conduct analytics and business reporting;

  • Prevent fraud, misuse, security incidents and unauthorised access;

  • Meet legal, regulatory and contractual obligations;

  • Protect our legal rights and interests; and

  • Fulfil other purposes disclosed at the time information is collected or otherwise permitted by applicable law.

We do not use personal data for purposes that are incompatible with the purpose for which it was collected unless permitted or required by applicable law.

5. Legal Basis and Consent

Where applicable law requires consent for processing personal data, Sonet will seek consent in an appropriate manner.

Where processing is permitted or required without consent under applicable law, Sonet may process personal data on another lawful basis, including for performance of a contract, compliance with legal obligations, provision of requested services, security, fraud prevention or other purposes permitted by law.

Where consent is relied upon, you may withdraw that consent through the mechanism made available by Sonet. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.

The withdrawal of consent may affect our ability to provide certain products, features or services where the relevant processing is necessary for those services.

6. Education and Institutional Data

Sonet's platforms are designed to support educational and institutional operations. Accordingly, customers may configure our systems to process information required for admissions, academics, attendance, examinations, fees, learning management, accreditation, communication, administration, alumni engagement, placements and other institutional functions.

Where Sonet processes such information on behalf of an educational institution:

  • The institution is generally responsible for determining the purposes and requirements of the processing;

  • Sonet processes the information according to applicable contractual instructions and requirements;

  • Access to information may be controlled according to user roles and permissions configured by the institution;

  • The institution is responsible for ensuring that information supplied to the platform is collected and processed lawfully; and

  • Requests concerning institutional records may, where appropriate, need to be directed to the relevant educational institution.

7. Students' Data

We recognise that education technology services may involve information relating to children and students.

Where Sonet processes personal data relating to children, we will apply safeguards required by applicable law and contractual arrangements.

Where legally required, processing of a child's personal data will be subject to verifiable parental or lawful guardian consent and other applicable safeguards. We will not knowingly undertake processing that is prohibited by applicable law, including processing that is likely to cause a detrimental effect on a child's well-being.

Where applicable law restricts behavioural monitoring, tracking or targeted advertising involving children, Sonet will comply with those restrictions.

Educational institutions using Sonet platforms are also responsible for implementing appropriate consent, notices, permissions and safeguards for students and children within their respective legal and operational responsibilities.

The DPDP framework specifically provides enhanced protection for children's personal data, including requirements relating to verifiable parental consent and restrictions on certain forms of processing.

8. AI-Enabled Features

Certain Sonet products may include artificial intelligence, automation, analytics, recommendations or other intelligent features.

Where such features process personal data, Sonet will seek to use the information only for disclosed and legitimate purposes and in accordance with applicable law and contractual requirements.

Depending on the product, AI-enabled functionality may support activities such as:

  • Academic or institutional analytics;

  • Recommendations;

  • Assessment and examination workflows;

  • Reporting;

  • Content or learning assistance;

  • Administrative automation;

  • Placement or alumni intelligence; and

  • Other education-related use cases.

AI-generated outputs may require human review and should not automatically be treated as error-free, final, or a substitute for appropriate institutional or professional judgment.

Sonet will not use personal data to train general-purpose AI models or disclose personal data for unrelated AI-training purposes unless such processing is expressly permitted, appropriately disclosed, contractually authorised or otherwise lawful.

9. How We Share Personal Data

Sonet does not sell personal data.

We may disclose or provide access to personal data where reasonably necessary for legitimate business, contractual, operational, security or legal purposes, including to:

A. Customers and Educational Institutions

Where appropriate, information processed through a Sonet platform may be accessible to the educational institution or organisation that uses the relevant service, subject to its configured permissions and contractual arrangements.

B. Service Providers and Data Processors

We may engage trusted third-party service providers to support our operations, such as providers of:

  • Cloud hosting and infrastructure;

  • Data storage;

  • Website and application infrastructure;

  • Communication services;

  • Customer support;

  • Analytics;

  • Security;

  • Monitoring;

  • Email delivery;

  • Technical maintenance; and

  • Other business-support functions.

Such parties may process personal data only to the extent necessary for the services they provide and subject to appropriate contractual and security requirements.

C. Legal and Regulatory Authorities

We may disclose information where required or authorised by applicable law, regulation, court order, governmental request or lawful legal process.

D. Business Transactions

If Sonet is involved in a merger, acquisition, restructuring, financing, sale of assets or similar business transaction, relevant information may be transferred as part of that transaction, subject to applicable legal requirements and appropriate safeguards.

10. Data Security

Sonet takes reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, misuse or destruction.

Depending on the service and environment, security measures may include:

  • Access controls and role-based permissions;

  • Authentication mechanisms;

  • Encryption or other appropriate data-protection technologies;

  • Security monitoring;

  • System logging and audit mechanisms;

  • Backup and recovery measures;

  • Vulnerability management;

  • Secure development and maintenance practices;

  • Employee and authorised-user access controls; and

  • Incident detection and response procedures.

The precise safeguards applicable to a particular service may vary according to the nature of the data, product architecture, customer requirements and applicable contractual obligations.

No method of transmission or storage is completely secure. Accordingly, while we work to protect personal data, we cannot guarantee absolute security.

The DPDP Rules, 2025 expressly contemplate reasonable security safeguards, including measures relating to encryption, access controls, monitoring, backups, breach detection and response, and security obligations involving data processors.

11. Personal Data Breaches and Security Incidents

Sonet maintains processes for identifying, assessing, containing and responding to actual or suspected personal data breaches and security incidents.

Where a personal data breach occurs, Sonet will take reasonable steps to:

  • Assess the nature and extent of the incident;

  • Contain and mitigate the incident;

  • Investigate the cause;

  • Restore affected services where appropriate;

  • Take corrective and preventive measures; and

  • Provide notifications to affected individuals, customers, regulators or other parties where required by applicable law or contractual obligations.

The DPDP Rules, 2025 contain specific requirements concerning notification of personal data breaches, including information to be provided to affected individuals and reporting obligations to the Data Protection Board where applicable.

12. Data Retention

We retain personal data only for as long as reasonably necessary to fulfil the purpose for which it was collected, provide requested services, maintain business and contractual records, comply with legal obligations, resolve disputes, enforce agreements, protect our legitimate interests, or otherwise as permitted or required by applicable law.

When personal data is no longer required and there is no legal, contractual or legitimate reason to retain it, we will take appropriate steps to delete, anonymise or securely dispose of it.

For information processed on behalf of an educational institution, retention may be determined by the institution's instructions, contractual requirements and applicable law.

Certain records may need to be retained for longer periods where required by law, regulatory obligations, contractual requirements, dispute resolution or legitimate business purposes.

13. Accuracy of Personal Data

We seek to maintain accurate and reasonably up-to-date personal data appropriate to the purposes for which it is processed.

Where you provide personal data to us, you should ensure that the information is accurate and complete and notify us when relevant information changes.

Where Sonet processes information on behalf of an institution, requests to correct institutional records may need to be directed to the relevant institution.

14. Your Privacy Rights

Subject to applicable law and any limitations or conditions prescribed by law, you may have rights relating to your personal data, which may include:

  • The right to obtain information about processing of your personal data;

  • The right to access information relating to your personal data and its processing;

  • The right to correction or updating of inaccurate or incomplete personal data;

  • The right to request erasure of personal data where applicable;

  • The right to withdraw consent where processing is based on consent;

  • The right to raise a grievance regarding processing of your personal data; and

  • Other rights available under applicable data-protection law.

Requests may be subject to reasonable verification and applicable legal exceptions.

The DPDP Act provides Data Principals with rights concerning access to information, correction/erasure, grievance redressal and other matters, subject to the Act and applicable requirements.

15. Grievance Redressal and Privacy Contact

If you have questions, concerns, requests or complaints relating to this Privacy Policy or the processing of your personal data, you may contact us at:

Sonet Microsystems Pvt. Ltd.
Email: enquiry@sonetmicrosystems.com
Head Office: 407, H-221, Sector 63, Noida, Uttar Pradesh – 201301, India

For privacy-related matters, please include sufficient information to help us understand and address your request.

Where applicable, Sonet will provide the contact information of the person responsible for responding to questions relating to the processing of personal data.

16. Applicable Law

This Privacy Policy shall be interpreted in accordance with applicable laws and regulations governing privacy, data protection and electronic information in the jurisdictions in which Sonet operates or provides services.

For users and processing activities subject to Indian law, this may include the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, and other applicable laws, regulations and governmental requirements, as amended or replaced from time to time.

Nothing in this Privacy Policy is intended to limit any rights or protections that cannot lawfully be excluded or restricted.