Privacy Policy – Student Monitor Application
1. Introduction
Welcome to the Student Monitor Application (the “App”).
This Privacy Policy explains how personal data is handled when using the App. The School or Educational Institution acts as the Data Controller, determining the purpose and legal basis for all personal data processing. The Technology Provider acts as the Data Processor, managing infrastructure and services strictly under the School’s instructions.
This Policy is designed to comply with global and regional data privacy laws, including but not limited to:
European Union General Data Protection Regulation (EU GDPR)
UK GDPR
United States COPPA & FERPA
Canada’s PIPEDA
Australia’s Privacy Act
South Africa’s Protection of Personal Information Act (POPIA)
Zimbabwe’s Cyber and Data Protection Act
Nigeria’s Nigeria Data Protection Regulation (NDPR)
African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention)
By using the App, you agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the App.
2. Roles and Responsibilities
Data Controller (School): Responsible for deciding which data is collected and how it is processed.
Data Processor (Technology Provider): Acts only on instructions from the School and does not determine the purpose of data processing.
3. Types of Data Processed
Data processed under the School’s authority may include:
Personal Data
Full name, date of birth
Contact details (email, phone number)
Student ID numbers
Parent/guardian information
Profile photographs
Academic and School-Related Data
Attendance records
Assessment results and grades
Assignments, timetables, coursework
Disciplinary or behavioral records
Technical and Usage Data
IP address and device metadata
Login timestamps and user activity
Session data used for support and diagnostics
Note: The Technology Provider never uses data for its own purposes or without explicit authorization from the School.
4. Purpose of Processing
Data is processed solely for legitimate educational purposes as defined by the School, such as:
Student information and academic performance tracking
Communication between students, staff, and guardians
Compliance with educational and child protection regulations
Enhancing administrative and operational efficiency
5. Data Ownership and Control
Ownership: All personal data belongs to the School or the individual data subjects.
Control: The School maintains full control over data collection, updates, sharing, and deletion.
Access: The Technology Provider accesses data only when explicitly permitted or legally required.
6. Data Sharing and International Transfers
Data may be shared with:
Authorized School staff and administrators
Parents or guardians for academic updates
Third-party service providers under strict data protection agreements
Regulatory authorities, if required by law
Where data is stored or processed outside the originating country, it is protected through safeguards such as:
Standard Contractual Clauses (SCCs)
Cross-border data agreements
African data protection frameworks (e.g., Malabo Convention)
7. Data Security
To protect user data, the App implements:
Encryption at rest and in transit
Role-based access controls
Secure authentication systems
Regular vulnerability assessments and system monitoring
In the event of a data breach, the School will be notified promptly, and steps will be taken to investigate and mitigate the impact in accordance with applicable national laws.
8. Data Retention and Deletion
The School determines data retention periods based on educational, operational, and legal requirements.
Upon the School’s request or contract termination, all data will be securely deleted or returned, unless retention is required by applicable law.
9. User Rights
Depending on the relevant jurisdiction (e.g., GDPR, POPIA, NDPR), individuals may have rights including:
Right to access their data
Right to rectification (correction)
Right to erasure (deletion)
Right to object to or restrict processing
Right to data portability
Right to lodge a complaint with a national Data Protection Authority
All such requests should be directed to the School. The Technology Provider will support the School in fulfilling these rights.
10. Children’s Data
The App may process data of students under the age of 18:
The School is responsible for ensuring compliance with child data protection laws (e.g., parental consent)
The Technology Provider never uses children’s data for advertising, profiling, or other unauthorized purposes
11. Cookies and Tracking Technologies
Cookies or tracking tools may be used only to:
Enable secure sessions
Improve app performance and user experience
No marketing or behavioral tracking is conducted. Any required consent is managed by the School.
12. Responsibilities of the Technology Provider
The Technology Provider:
Acts only under the School’s lawful instructions
Implements strong technical and organizational measures
Does not use or disclose personal data for independent purposes
Is not responsible for the School’s compliance with legal or regulatory requirements
13. Changes to This Policy
This Privacy Policy may be updated as needed. The School will be notified of any material changes and is responsible for informing end users. Continued use of the App after changes indicates acceptance of the updated terms.
14. Contact Information
For privacy inquiries or data rights requests, please contact your School’s designated Data Protection Officer or relevant authority.
For technical support, contact your School or administrator.
By using the App, you acknowledge that you understand and agree to the roles and responsibilities outlined in this Privacy Policy, and that your data will be processed in accordance with applicable local and international data protection laws.