Third-Party Data Sharing Register

Below is a list of every third-party integration that receives or may receive personal data, and what it receives.

Integration Status Data Shared
Payment Gateways (bKash, Nagad, Rocket, card/SSLCommerz) Configured via env (BKASH_*/NAGAD_*/ROCKET_*/SSLCOMMERZ_*). No live gateway is enabled on this deployment — fee/donation checkout falls back to manual/office recording until credentials are set. Payer name, phone number, amount, and payment reference only — never full student profile or academic data.
SMS Gateway Configurable via env (SMS_GATEWAY_*); enabled only when SMS_GATEWAY_ENABLED=true. Recipient phone number and message content only.
WhatsApp Business API Configurable via env (WHATSAPP_*). Recipient phone number and message content only.
Web Push (VAPID) Configurable via WEBPUSH_VAPID_* (php spark push:generate-vapid). Browser endpoints only; no phone numbers. Push subscription endpoint URL and notification title/body.
Live Class Video Platforms (Zoom, Google Meet) Link-only: a teacher/admin pastes a meeting URL created outside this system. No participant data (names, attendance) is transmitted to the platform via API. None automatically - the meeting link itself is the only data stored.
Plagiarism Checking Not integrated - plagiarism_score is a manually-entered field, not a live third-party API call. None - no submission content currently leaves the system for automated checking.

← Back to Privacy Policy

Live Chat