Privacy Policy
How Fractal handles personal information when you use Edunex on the web or in the mobile app.
FRACTAL SOLUCIONES TECNOLOGICAS C.A.
RIF: J508147294
Privacy contact: fractal.admin@fractal-software.com
Last updated / effective date:
1. Who is responsible
FRACTAL SOLUCIONES TECNOLOGICAS C.A., RIF J508147294, operates Edunex. Edunex is the product, not a separate company. This policy covers its web and mobile services for institutions, staff, representatives and students.
For records managed by an institution, such as enrollment, grades, attendance and school charges, the institution determines their educational or administrative use and the people authorized to access them. Fractal processes those records to provide Edunex. Fractal also handles its own account administration, platform billing, support and security operations.
Features and the information requested differ by role, institution, enabled integration and whether you use the web or mobile app. A record may be supplied by your institution or an authorized representative rather than entered by you personally.
2. Information we handle
- Account and contact information: names, email addresses, user identifiers, roles, authentication and session records. Supported institutional forms may also contain telephone numbers, postal addresses, identity documents, date of birth, nationality and other enrollment or staff details.
- Academic and communication records: student and representative relationships, enrollment, activities, grades, attendance, descriptions, observations, school messages and their read status. Authorized staff may enter health-related absence explanations. Some web enrollment forms also allow health and religious information; these are not a general invitation to submit unnecessary sensitive details.
- Financial information: school charges, debts, credits, payment amounts, currencies, references, payer bank codes and Pago Móvil telephone numbers, registered bank destinations, reconciliation records and invoices. The current mobile payment flow does not request card numbers, card security codes or online-banking passwords.
- Images and documents: Google sign-in through Clerk can import your Google profile photo. Supported web workflows allow institutions to upload documents or images, such as bank statements and institutional records. The current native mobile app has no active document or receipt-upload flow and does not collect audio or video files.
- Technical information: IP addresses, approximate city/country inferred from IP by authentication services, device/browser and session identifiers, push notification tokens, installation identifiers, access timestamps and audit records of actions. Approximate IP location is different from GPS location.
- Support requests: the email address, optional school name, platform, issue category, language and message you submit, together with the case reference, dates and handling status. We use these records to investigate your request and respond. Please do not include passwords, verification codes, banking credentials or unnecessary student information.
3. Why we use it
Edunex currently does not display advertising, sell personal information or build advertising profiles from student information.
- Create and manage accounts, authenticate users, apply roles and keep each institution's information separate.
- Provide academic, attendance, communication, payment-recording, reconciliation, billing and reporting functions requested by institutions and authorized users.
- Deliver service notifications, maintain payment and academic traceability, prevent duplicate or unauthorized operations, investigate support issues and protect accounts.
- Meet applicable institutional, contractual, accounting and legal obligations, and respond to valid requests from competent authorities.
4. Mobile permissions and choices
You can use available academic functions without registering a Pago Móvil account or reporting a payment. Free-text observations and messages are supplied when an authorized user chooses to enter them. School-maintained records, required account information and the records of operations you execute cannot all be individually switched off.
You can decline or revoke notification permission in your device settings. This disables push notifications, not the account/session identifiers needed for authentication. You can use email and password instead of linking Google, where that sign-in method is available for your account.
The current native app does not request access to GPS location, your contact list, personal calendar, browsing history, microphone or camera. Its technical error messages are logged locally; it has no integrated remote mobile crash or performance reporting service. The servers still keep operational and security records needed to run Edunex.
Cookies and device storage support authentication, session continuity, language and theme. These are not used by Edunex for advertising tracking. Revoking a permission or uninstalling the app does not delete records already held by Edunex or an institution.
5. Who can receive information
Using a service provider does involve transferring information. Some provider transfers and user-requested disclosures are exempt from the Google Play label 'shared'; that label does not mean information never leaves your device or that no provider processes it.
- Your institution and its authorized users receive the records needed for their roles. For example, staff manage the students assigned to them and representatives access the students linked to their accounts; records are not made publicly available by these workflows.
- Cloud and technical providers support the service: AWS for hosting, storage and supported document processing; Clerk for authentication and associated profile/session information; and Expo and Google Firebase for enabled push notification delivery. A provider receives information relevant to the service it performs, such as a notification token and notification content.
- For production support alerts, AWS and Slack process the case reference, platform, issue category and a link to our restricted administration area. These alerts do not include your email address, school name or message; authorized Edunex administrators access those details in Edunex.
- When security verification is enabled for the web institution-registration form, the configured provider (AWS WAF CAPTCHA or Cloudflare Turnstile) processes technical connection/browser data and verification challenges and tokens to prevent automated abuse. This verification is not used for native-app advertising, banking or payment processing.
- When a supported financial or document-processing integration is activated and used, participating banks, payment/reconciliation services, extraction services or fiscal providers receive the information needed for that operation. Uploading an institutional document for processing may transmit its contents to the configured processing provider.
- Information may also be disclosed when required by law, to respond to valid authority requests, protect rights or investigate abuse. Banks, institutions and sign-in providers may have their own policies for services under their control.
6. Students and younger children
Direct use of the native app by students is intended for students aged 13 and over with access authorized by their institution and, where applicable, their representative. This is an intended-use rule, not a claim that every login includes automated age verification.
Schools and authorized representatives may manage records of younger students without those students operating their own app accounts. Institutions must establish the authority and notices or consents required for the information they provide. Please report inappropriate access or unnecessary sensitive information to the institution and Fractal.
7. Retention of information
Records are not kept for one universal period. Their purpose, institutional responsibility, applicable obligations and any unresolved dispute or security incident determine what must be retained.
The 24-hour request-processing commitment does not set one universal retention period for all records. Fractal must determine the deletion scope, explain any legally retained information and its applicable period or review criterion, and confirm the outcome. Submission does not instantly erase every associated record or automatically expire every backup.
- Account, contact and linked sign-in information is retained to operate the account and associated services. A web account-deletion request starts a review rather than immediate erasure. The native app's account-removal action immediately disables Edunex access and removes identifying information and credentials from the login profile; remaining associated records require the separate review described below.
- Academic, enrollment, attendance and financial records may need to remain under the institution's responsibility after platform access ends, for educational records, accounting, payment reconciliation or applicable legal duties. Closing an account does not cancel debts or erase another person's records.
- Audit and security records may need to be retained to investigate misuse, resolve disputes and establish what happened. Their scope and need for retention must be assessed separately from an active login account.
- Backup copies require separate handling and may persist after an active record is removed. Backup retention and any restrictions on removal are part of the request review; access remains restricted.
8. Account deletion and other requests
Use the account-deletion page linked below or write to fractal.admin@fractal-software.com to request deletion of your account and associated personal data. The web request is under My account → Danger Zone → Request account deletion. You do not need to reinstall the mobile app to use the web process.
Fractal will process deletion requests within 24 hours of receipt: delete eligible personal data, itemize any data retained to meet legal obligations with its basis and applicable retention period or review criterion, and send an outcome notice. This does not promise that all institutional records or backup copies are erased within 24 hours.
Fractal will respond to content reports within 24 hours of receipt. Reporting does not automatically remove content or change academic records.
The web request is saved for review. It does not immediately deactivate your account, end sessions or erase your information. A pending or in-review status is not confirmation that deletion has been completed. Signing out, uninstalling the app or disabling access is also not the same as deleting all associated data.
If you authenticate successfully but no longer have an active institution membership, the web account-recovery screen offers a separate, limited account-removal action. It requires explicit confirmation, immediately removes the login profile and access, and opens or updates the associated-data review. This limited session cannot access school records or administration and is distinct from the regular web deletion-request form.
In the native app, the account-removal action immediately ends Edunex account access and removes identifying information and credentials from the login profile. It also opens or updates a restricted review request for remaining associated data, including external-provider data, institutional records and backups. Identifying details needed to handle that request may remain in the restricted case. This does not mean that all associated records or external-provider accounts have already been erased.
Request processing includes scoped local cleanup and attempts to delete a linked authentication-provider account when the provider identity is verified. Failures or unverified links require follow-up, not a claim of erasure. Completion requires documented outcomes for authentication-provider data, institutional records, uploads and other data, and backups. Retained data must have a recorded basis and review date; a completed review with retention is not total erasure. Delivery of the outcome notice is recorded separately from completion.
We may verify your identity and coordinate with the institution for records under its responsibility. You can contact Fractal directly even if you cannot sign in. Do not email passwords, one-time codes or authentication tokens. The review must distinguish eligible account/provider data from records that need to be retained for the reasons described above.
For access or correction of institutional records, contact your institution. For privacy questions, request follow-up or help with your account, contact fractal.admin@fractal-software.com.
9. Security and processing locations
Production web and mobile connections to supported Edunex services use HTTPS. We apply role-based authorization, institution separation, restricted infrastructure access and audit controls. This is not end-to-end encryption: authorized staff and providers can process the information needed to provide the service. No internet service can guarantee absolute security.
Cloud and specialist providers may process information outside Venezuela, including in the United States. Users and institutions must also protect their credentials, devices and exported documents.
10. Updates and contact
We will update the date and text on this public page when our practices change. Material changes may also be communicated through the service. The Spanish and English pages describe the same practices.
Contact FRACTAL SOLUCIONES TECNOLOGICAS C.A. about Edunex privacy at fractal.admin@fractal-software.com.
Fractal