1. Introduction
Welcome to the Horizon App (referred to as "the App"), the official mobile application designed and operated by Horizon Campus, located at Knowledge City Malabe, No. 252, Horizon Drive, Malabe, Sri Lanka. This App is designed for students and lecturers of Horizon Campus to access educational resources, check timetables, view announcements, and record attendance.
We respect your privacy and are committed to protecting the personal data you share with us. This Privacy Policy explains what information we collect, how we use and protect it, and your rights regarding your personal data when using the Horizon App on Android devices.
By downloading, installing, or registering to use the App, you agree to the collection and use of information in accordance with this Privacy Policy.
2. Personal Data We Collect
To provide you with access to university services and confirm your identity, we collect the following types of personal information:
- Identity Information: Student ID (Username) or Lecturer ID, full name, role (Student or Lecturer), and course enrollment details.
- Contact Information: Official university email address and telephone/SMS contacts (for verification and important alerts).
- Device Identifiers: Your Android Device ID (specifically the
Settings.Secure.ANDROID_ID) is automatically collected upon registration or login. - User-Generated Content: Optional profile images uploaded by the user, and communications sent through the app's announcement and chat features.
- App Activity & Analytics Data: Anonymous usage metrics, app interactions, device information, crash reports, and performance metrics collected via Google Firebase services.
Google Firebase Services
The Horizon App uses Google Firebase Services to collect usage information and deliver push notifications:
- Firebase Analytics: The Horizon App uses Google Firebase Analytics to collect anonymous usage information, such as app interactions, device information, and performance metrics. This information helps us understand how the application is used and improve the user experience. Firebase Analytics is provided by Google. For more information, please refer to Google's Privacy Policy and Firebase Privacy Information.
- Firebase Cloud Messaging (FCM): Used to safely deliver notification tokens and send push alerts regarding timetable updates and announcements to your device.
3. How We Use Your Data
Horizon Campus processes your data for academic and administrative purposes, specifically to:
- Manage and Verify Attendance: Process check-in and check-out logs utilizing QR codes to ensure accurate academic attendance records.
- Bind Accounts to Secure Devices: Link your Student/Lecturer profile to your unique Device ID. This prevents unauthorized external logins and proxy attendance submissions.
- Facilitate Secure Authentication: Integrate with Microsoft Azure Active Directory (Microsoft SSO) to allow safe, centralized login using your official college credentials.
- Deliver Notifications & Announcements: Send notifications regarding lecture timetables, class changes, and campus announcements using foreground data sync and push notification services.
- Analyze App Usage & Performance: Utilize anonymous analytics metrics to troubleshoot bugs, fix network issues, monitor performance, and enhance the overall user experience.
4. Device Permissions We Request
To run its core features, the Android application requests access to the following hardware features and permissions. We only request permissions that are strictly necessary for the App to function:
- Camera (
android.permission.CAMERA): Used exclusively to scan classroom QR codes for recording attendance. No photos or videos are captured, stored, or transmitted to our servers from this camera feed. - Biometric Credentials (
android.permission.USE_BIOMETRIC): Used to enable secure, local biometric lock screen features (fingerprint or face unlock) for fast access. - Storage/Photos Access (
android.permission.READ_EXTERNAL_STORAGE/READ_MEDIA_IMAGES): Used if you choose to select and upload a profile picture from your device gallery. - Notifications (
android.permission.POST_NOTIFICATIONS): Required to show real-time alerts for incoming class updates, library messages, and server notices. - Foreground Services (
android.permission.FOREGROUND_SERVICE/FOREGROUND_SERVICE_DATA_SYNC): Used by the background worker to sync announcements and timetable changes with the Horizon Campus database in real-time. - Internet Access (
android.permission.INTERNET): Used to communicate with the Horizon Campus backend API endpoints athttps://hc.lk/KCM/.
5. Biometrics Security
local-only biometric execution
The Horizon App supports fingerprint and face recognition login through the Android system's native BiometricPrompt API. The App does not access, collect, or store your biometric templates (fingerprint or face scans) on our servers or within the local database. Authentication is managed entirely on-device by the Android Operating System, which merely returns a success or failure token to the App.
6. Data Sharing & Third-Party Integrations
We value your trust and do not sell, rent, or lease your personal information to third-party commercial entities. Your data is shared only under the following conditions:
- University Administration: Attendance, student IDs, and class records are stored on Horizon Campus servers and accessed by the university's academic staff and registry to monitor student progress and academic compliance.
- Microsoft Authentication Services: The App uses official Microsoft OAuth authentication to log you in. Your login credentials are processed directly by Microsoft's secure authentication servers and are not collected by the App or Horizon Campus.
- Google Firebase Services: The application uses Google Firebase services including Firebase Analytics and Firebase Cloud Messaging to provide analytics, performance monitoring, and notification delivery.
- Legal Requirements: We may disclose your information if required to do so by law or in response to valid requests by public authorities in Sri Lanka.
7. Data Retention & Deletion Rights
We retain your personal data and attendance records only as long as you are actively enrolled or employed at Horizon Campus, or as required to comply with academic auditing regulations.
Device Unlinking & Account Deletion: Because your user account is bound to your specific Android Device ID, if you purchase a new mobile device or wish to reset your login configuration, you must request a device unlink. You can contact the Horizon Campus IT Department or registry office to request that your device association be cleared from the server database, or to request deletion of your profile data. Once approved, the device linkage will be immediately wiped from the database.
8. Security of Your Data
All communications between the Horizon App and our servers are encrypted using Secure Sockets Layer/Transport Layer Security (SSL/TLS) HTTPS technology. Databases are hosted in secure environments, protected by firewalls, and are accessible only to authorized university IT administrators.
However, please remember that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While we strive to use industry-standard security measures, we cannot guarantee its absolute security.
9. Children's Privacy
Our App is developed strictly for students, faculty, and administrative staff of Horizon Campus. The App is not intended for use by anyone under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If we discover that a child under 13 has provided us with personal information, we immediately delete this from our servers.
10. Contact Us
If you have any questions about this Privacy Policy, your data rights, or if you need to request a device unlink or account deletion, please contact us:
- Address: Horizon Campus, Knowledge City Malabe, No. 252, Horizon Drive, Malabe, Sri Lanka.
- Email: info@horizoncampus.edu.lk / support@hc.lk
- Web: https://horizoncampus.edu.lk