Scope and our data-protection roles
This Privacy Policy explains how SchoolOS handles personal data through its school management platform, portals, progressive web application, support channels, and related services. It is written primarily for Nigerian schools and reflects the Nigeria Data Protection Act 2023 (“NDP Act”).
When the School is controller
For student, parent, staff, academic, health, attendance, finance, safeguarding, transport, and other records entered for school operations, the School generally decides why and how the data is used and acts as data controller. SchoolOS processes that data on the School’s documented instructions and generally acts as data processor.
When SchoolOS is controller
SchoolOS acts as controller for limited data used to administer subscriptions, secure the platform, provide support, communicate with School representatives, prevent abuse, and meet our own legal obligations. Users should contact their School first for requests about school records and SchoolOS for requests about platform-operated data.
Personal data we process
The data processed depends on the modules enabled and the user’s role. It may include:
- Identity and account data: names, email addresses, telephone numbers, profile images, identifiers, role, School affiliation, login and account status.
- Student and family records: admission details, class, parent or guardian links, emergency contacts, attendance, promotions, transfers, and pickup authorisations.
- Academic data: subjects, timetables, assignments, submissions, quizzes, results, report cards, lesson progress, comments, and teacher feedback.
- Staff data: employment and recruitment information, qualifications, class assignments, leave records, permissions, and performance-related records entered by the School.
- Health and safeguarding data: sick-bay visits, medication schedules, incident reports, allergies or health notes, and other information entered by authorised School personnel. This may be sensitive personal data.
- Finance and operations data: fee schedules, invoices, payment status, receipts, expenses, library loans, transport records, announcements, and events.
- Communications: messages, support requests, notices, lesson comments, and files supplied through enabled communication features.
- Technical and security data: IP address, device and browser information, session records, timestamps, audit events, error logs, and security signals.
Children’s data
SchoolOS is used in an educational context and therefore processes data about children. Children do not independently create unrestricted SchoolOS accounts; access is provisioned or authorised by a School. The School must identify an appropriate lawful basis and obtain parental or legal-guardian consent where consent is required by the NDP Act.
Schools must apply appropriate age and consent verification, provide child-appropriate explanations, limit access to personnel with a genuine need, and avoid collecting more information than necessary. SchoolOS does not sell children’s data, use it for behavioural advertising, or knowingly create advertising profiles from educational activity.
A parent or guardian seeking access, correction, or deletion of a learner’s school record should normally contact the School, which can verify authority and consider education, safeguarding, record-retention, and third-party privacy obligations.
Why we process data and lawful bases
Depending on the context, personal data is processed to:
- provide, configure, maintain, and support SchoolOS;
- manage teaching, learning, attendance, assessment, fees, health, safety, and operations;
- authenticate users, enforce permissions, investigate abuse, and protect the Service;
- send transactional, security, support, and School-authorised communications;
- process subscriptions and reconcile authorised payments;
- diagnose errors, measure reliability, and improve functionality; and
- comply with legal obligations and establish, exercise, or defend legal claims.
Lawful bases may include performance of a contract, compliance with legal obligations, legitimate interests that do not override individual rights, consent, protection of vital interests, and performance of educational or public-interest responsibilities where applicable. Sensitive data is processed only where an additional lawful condition applies.
Where data comes from
Data may be supplied directly by a user, entered or uploaded by authorised School staff, generated through use of SchoolOS, received from a parent or guardian, imported from an existing School system, or returned by an enabled payment or service provider. Schools are responsible for ensuring imported records were collected lawfully and remain accurate.
Payment information
Where online payment is enabled, card or bank credentials are collected by the payment gateway presented at checkout, such as Paystack or a participating financial institution. SchoolOS may receive transaction references, payer details, amount, status, and reconciliation information, but payment providers handle payment credentials under their own privacy and security terms. School fee records entered manually remain School Data.
Retention and deletion
School records are retained for the period selected or instructed by the School, subject to subscription terms, educational record requirements, safeguarding needs, financial and tax obligations, limitation periods, and applicable law. Schools should maintain a documented retention schedule and delete data that is no longer required.
Platform security logs, subscription records, and support communications are retained only as long as reasonably necessary for security, service operation, legal compliance, and dispute resolution. Deleted data may remain in protected backups until the applicable backup cycle expires, unless preservation is legally required.
Security and personal data breaches
SchoolOS applies risk-based technical and organisational measures designed to protect confidentiality, integrity, and availability. Measures may include role-based access, credential protection, tenant separation, secure transmission, audit logging, backups, dependency maintenance, and incident-response procedures. Measures are reviewed as the Service and relevant risks evolve.
If SchoolOS becomes aware of a personal data breach affecting School Data, we will notify the affected School without undue delay and provide reasonably available information to support its legal duties. Where SchoolOS is controller, we will notify the Nigeria Data Protection Commission within the applicable period when the NDP Act requires it and notify affected individuals where the likely risk is high. No security method can eliminate every risk.
International data transfers
Some infrastructure or service providers may process data outside Nigeria. Before a restricted transfer, SchoolOS or the relevant School will use a mechanism permitted by the NDP Act, such as an adequacy basis, an approved cross-border transfer instrument, another recognised legal safeguard, or a specific statutory exception. Transfer risks and the sensitivity of children’s and School data are considered when selecting providers and safeguards.
Your privacy rights
Subject to applicable law and relevant exemptions, individuals may have rights to receive information about processing, access personal data, correct inaccurate data, request deletion or restriction, object to certain processing, withdraw consent without affecting earlier lawful processing, and receive portable data where applicable.
Requests concerning School records should be sent to the School first. SchoolOS will assist the School in responding where required. Requests concerning data controlled directly by SchoolOS may be sent to godsentpaulyerobiri@gmail.com. We may request information reasonably necessary to verify identity and authority before disclosing or changing data.
Individuals may also complain to the Nigeria Data Protection Commission or seek another remedy available under law.
Analytics and automated decisions
SchoolOS may calculate totals, summaries, attendance rates, balances, rankings, trends, and other operational indicators from data supplied by the School. These tools are intended to support authorised human decision-making. SchoolOS does not independently make decisions producing legal or similarly significant effects about a learner or employee. Schools must review outputs for accuracy, context, fairness, and compliance before acting on them.
Policy changes and contact
This Policy may be updated to reflect changes in law, guidance, providers, security practices, or SchoolOS features. Material changes will be communicated through the Service, email, or another reasonable channel, and the date above will be revised.
For privacy questions, rights requests concerning SchoolOS-controlled data, or security reports, contact godsentpaulyerobiri@gmail.com. For requests about a specific learner, parent, or staff record, contact the relevant School so it can verify identity, authority, and any safeguarding or legal restrictions.