Skip to content
InstiPilot
FeaturesContact
Log in

INSTIPILOT / POLICIES

Data Retention Policy

How InstiPilot retains records, handles archives and backups, and processes requests for correction, deletion, or account closure.

Last updated: 5 October 2026

ON THIS PAGE

Who can make a requestHow to contact usVerification and responseWhat deletion can includeWhatsApp and Meta-related requestsAttendance and device recordsRetention, archives, and backupsQuestions and related policies

1. Who can make a request

You can request correction or deletion of information associated with InstiPilot. For student, guardian, staff, admission, attendance, or fee records maintained by an institute, contact that institute first. Its authorised administrator generally needs to approve changes to operational records.

You may also contact InstiPilot if you need help directing a request, have contacted us directly about a demo, or are an authorised administrator requesting account or integration closure. No InstiPilot login is needed to send a request.

2. How to contact us

Email admin@instipilot.com with the subject “InstiPilot data request”. State whether you want correction, deletion, integration disconnection, or complete account closure.

  • Your name and a contact address where we can reply.
  • The institute or organisation involved, if applicable.
  • Your relationship to the account or record.
  • A registered email, phone number, enrollment reference, or other limited identifier that helps locate the record.
  • Which information you want changed or removed.

You do not need to justify a deletion request. Do not send passwords, access tokens, NFC secrets, full financial documents, or identity-document scans in your initial email. If verification is needed, we will explain what is necessary.

3. Verification and response

We verify identity and authority before disclosing, altering, or deleting information. We may contact the institute administrator or ask for limited additional information. A student’s request does not authorise deletion of another student’s records or of an entire institute account.

We will review the request, explain any verification needed, and communicate the outcome or next steps. Timing depends on the scope, account authority, and applicable requirements. We do not publish a fixed completion period that cannot be met for every record type; applicable legal deadlines still apply.

4. What deletion can include

Depending on the request and authority, action may include correcting a record, removing a file or photo, deleting or anonymising personal information, removing integration credentials, or closing an account. We will explain the scope rather than assume that a request to disconnect one integration means deleting the whole institute.

Before complete account closure, authorised administrators should request any necessary export and agree on the records to retain or remove. Removing a user’s login does not automatically delete records that user entered for an institute.

5. WhatsApp and Meta-related requests

If the request concerns a WhatsApp integration, include the institute and connected business phone number, if known. Specify whether you want the integration disconnected, stored connection information removed, or particular message or recipient information reviewed for deletion.

Disconnecting WhatsApp stops future use of that connection through InstiPilot, but does not automatically erase historical messages, delivery records, or recipients. Those records must be included in the deletion request where relevant.

InstiPilot can address information held in its own systems. It cannot delete messages from recipients’ devices or erase records independently maintained by Meta, WhatsApp, or another provider. You may need to use those providers’ own request processes as well.

6. Attendance and device records

For attendance data, identify the institute and relevant person or record. Deleting information from InstiPilot does not necessarily remove a user profile, credential, or attendance log stored on a separate reader or biometric device. The institute may need to manage those records on its hardware too.

We can help identify the relevant scope, but will not treat deleting a platform record as proof that every connected device has erased its own copy.

7. Retention, archives, and backups

Some information may need to be retained to meet applicable legal obligations or to address security, accounting, disputes, and audit requirements. We will explain relevant restrictions and consider correction, restricted access, or anonymisation where appropriate.

Archiving an enrollment or marking a record deleted in the application may preserve history and is not necessarily permanent erasure. Backups and restricted logs may retain copies until their applicable retention or rotation period ends. A verified request will be assessed with these copies and any relevant restoration process in mind.

8. Questions and related policies

If you disagree with the outcome or need clarification, reply to our response or email admin@instipilot.com with your previous request details. See our Privacy Policy for how information is handled and our Terms of Service for account-use and closure terms.

InstiPilot home
Privacy PolicyTerms of ServiceData Retention Policy

Questions? admin@instipilot.com