Legal
Data Processing Agreement
This agreement applies whenever a school, institution or ministry (the Controller) uses the School District Sierra Leone platform (the Processor) to process personal data. It forms part of, and is governed by, our Terms of Service. It is accepted automatically when a school uses the platform, and no signature is required — though we will sign a countersigned copy on request.
Contents
1. Scope and roles
For personal data about students, parents, guardians and staff held in a school's tenant:
- The school is the controller. It determines what data is collected, for what purposes, who may access it, and how long it is kept.
- We are the processor. We process that data only on the school's documented instructions.
- Where the Ministry operates national modules (such as EMIS reporting), the Ministry is a controller for that processing.
Use of the platform's features constitutes the school's documented instructions. Any further instruction must be given in writing to dev@school.edu.sl; we may charge for work materially beyond the service.
We will tell the school if, in our opinion, an instruction infringes applicable data protection law, and may pause that processing until it is resolved.
We do not act as controller of school data, and we do not process it for our own purposes. Where we do act as controller — our marketing site, enquiries, billing and security logs — the Privacy Policy applies instead.
2. Annex A — Nature of the processing
| Subject matter | Provision of a school management and education platform |
|---|---|
| Duration | The term of the subscription, plus the deletion period in section 10 |
| Nature | Collection, recording, storage, organisation, retrieval, transmission, backup, display and erasure |
| Purpose | Student administration, academic records, attendance, assessment and reporting, fee collection, staff administration and payroll support, communication with parents, national statistical reporting |
| Data subjects | Students (predominantly children under 18), parents and guardians, teaching and non-teaching staff, school administrators, ministry officials |
| Personal data | Identity and contact details, photographs, academic records, attendance, assessment results, financial and fee records, employment and payroll data, account and technical data, user-generated content |
| Special category data | Health and disability data (disability status and type, special learning needs, blood group, medical and maternity leave), religion, and welfare markers including orphan and low-income status. Processed under Article 9(2)(g) or 9(2)(c) as directed by the Controller. |
| Children's data | The majority of data subjects are children. Both parties treat this as high-risk processing requiring heightened safeguards. |
3. Our obligations as processor
We will:
- Process personal data only on the Controller's documented instructions, including for transfers, unless required otherwise by law — in which case we will inform the Controller first, unless the law forbids it;
- Ensure personnel authorised to process the data are bound by confidentiality obligations that survive their engagement;
- Implement the technical and organisational measures in Annex B, in accordance with Article 32;
- Respect the conditions in section 5 for engaging sub-processors;
- Assist the Controller, by appropriate technical and organisational measures, in responding to data subject requests (section 7);
- Assist the Controller with its obligations under Articles 32 to 36 — security, breach notification, data protection impact assessments and prior consultation — taking into account the information available to us;
- Delete or return personal data at the Controller's choice on termination (section 10);
- Make available all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits (section 9);
- Never sell personal data, use it for advertising, or use identifiable data to train AI models.
4. Your obligations as controller
The school warrants that it will:
- Have a lawful basis for the personal data it enters, and where required an Article 9 condition for special category data;
- Provide its own privacy notice to students, parents and staff;
- Enter only data that is accurate, adequate, relevant and limited to what is necessary — in particular, not record welfare or medical details about a child beyond what safeguarding genuinely requires;
- Manage user accounts and permissions, and revoke access promptly when a person leaves;
- Set and apply its own retention periods;
- Respond to data subject requests concerning its records;
- Not instruct us to process data in a way that breaches applicable law.
5. Sub-processors
The Controller gives general written authorisation for us to engage sub-processors, subject to the conditions below. We impose data protection obligations on each sub-processor that are no less protective than this agreement, and we remain fully liable to the Controller for their performance.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Peeap Pay Limited (our parent company) | Payment processing, wallets, fee collection | Identifier, amount, phone number for confirmation. No academic or welfare data. Affiliation confers no wider access. |
| Hosting provider | Application servers and database hosting | All platform data, encrypted at rest |
| Object storage provider | Files, photographs, documents, backups | Uploaded files and images |
| Email delivery provider | Transactional email | Recipient address, message content |
| SMS provider | Text alerts and one-time passcodes | Phone number, message content |
| Push notification provider | Mobile and browser notifications | Device token, notification content |
| AI providers | Assistant, lesson planning, content generation | Only the text submitted in an AI request. Contractually excluded from model training. |
Notice of change. We will give the Controller at least 30 days' notice before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Controller may terminate the affected service without penalty and receive a pro-rata refund of prepaid fees.
To receive sub-processor change notices, email dev@school.edu.sl and ask to be added to the list.
6. International transfers
Some sub-processors operate outside Sierra Leone, including in the EEA and the United States. Where personal data protected by the GDPR is transferred outside the EEA, that transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Three (processor to sub-processor), or under an adequacy decision where one applies. The Standard Contractual Clauses are incorporated into this agreement by reference, with:
- Docking clause: applicable;
- Annex I populated from Annex A above;
- Annex II populated from Annex B below;
- Governing law and forum: as stated in our Terms of Service, save where the Clauses require an EU Member State.
We apply supplementary measures including encryption in transit and at rest, data minimisation before transfer, and a commitment to challenge any government access request that is unlawful or overbroad and to notify the Controller unless legally prohibited.
7. Assisting with data subject rights
The platform gives schools direct tools to view, correct, export and delete records — so most requests can be answered without involving us. Where our assistance is needed we will provide it without undue delay and, save for extraordinary requests, without additional charge.
If we receive a request directly from a data subject relating to a school's records, we will not respond substantively. We will acknowledge, redirect them to the school, and inform the school without undue delay.
8. Breach notification
- We will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting its data.
- The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point — to the extent known at the time, with updates as we learn more.
- We will assist the Controller with its own notifications to a supervisory authority and to affected data subjects.
- We will not make a public statement identifying the Controller without its prior agreement, unless legally required.
9. Audit and evidence
On reasonable written request, and no more than once in any 12 months unless a breach or a regulator requires otherwise, we will:
- Provide documentation on our security measures, and respond to a reasonable security questionnaire;
- Permit an audit by the Controller or an independent auditor it appoints, on 30 days' notice, during business hours, under confidentiality, and without access to other customers' data or anything that would compromise platform security;
- Contribute to inspections conducted by a competent supervisory authority.
The Controller bears its own audit costs; we bear ours, unless the audit reveals material non-compliance, in which case we bear both.
10. Deletion and return of data
- Throughout the term, the Controller may export its data at any time using the platform's export tools.
- On termination, the Controller may export for a further 30 days.
- After that period we delete the data from live systems within 90 days, and it ages out of backups within a further 90 days. We will certify deletion in writing on request.
- We retain data only where law requires — financial records for statutory accounting periods, and the National Student Identifier, which is a permanent national identifier and is never reused (see the Privacy Policy). Retained data remains subject to this agreement.
11. Annex B — Security measures
| Area | Measure |
|---|---|
| Encryption | TLS in transit across all services; encryption at rest for stored files and backups |
| Authentication | One-way password hashing; two-factor authentication available on privileged accounts; session management with CSRF protection |
| Access control | Role-based permissions; least-privilege administrative access; access reviewed on personnel change |
| Tenant isolation | Every query scoped by school identifier at the data-access layer, so one school cannot reach another's records |
| Upload safety | Uploaded files stored so they cannot be executed as server-side code; type restrictions enforced server-side |
| Logging | Audit logging of sensitive actions; security and error logs retained up to 12 months |
| Resilience | Regular automated backups held outside the web root; restoration tested periodically |
| Development | Security review of code changes; dependency monitoring; responsible disclosure channel at dev@school.edu.sl |
| Personnel | Confidentiality obligations; access granted on need-to-know and revoked on departure |
| Minimisation | Special category and welfare data excluded from AI requests, payment integrations and analytics |
We may update these measures as technology develops, provided the level of protection is not reduced.
12. Liability
Each party's liability under this agreement is subject to the limitations in our Terms of Service, except that nothing limits liability that cannot lawfully be limited — including liability to a data subject under Article 82 GDPR or an administrative fine imposed by a supervisory authority.
Data protection contact
Email: dev@school.edu.sl (subject line: “DPA”)
Phone: +232 72 799 454
For a countersigned copy of this agreement, or to be added to sub-processor change notices, contact us at the address above.