School District Sierra Leone

Legal

Data Processing Agreement

Effective: 20 July 2026  ·  Version: 1.0  ·  Satisfies: Article 28 UK/EU GDPR

This agreement applies whenever a school, institution or ministry (the Controller) uses the School District Sierra Leone platform (the Processor) to process personal data. It forms part of, and is governed by, our Terms of Service. It is accepted automatically when a school uses the platform, and no signature is required — though we will sign a countersigned copy on request.

Contents

  1. Scope and roles
  2. Annex A — Nature of the processing
  3. Our obligations as processor
  4. Your obligations as controller
  5. Sub-processors
  6. International transfers
  7. Assisting with data subject rights
  8. Breach notification
  9. Audit and evidence
  10. Deletion and return of data
  11. Annex B — Security measures
  12. Liability

1. Scope and roles

For personal data about students, parents, guardians and staff held in a school's tenant:

Use of the platform's features constitutes the school's documented instructions. Any further instruction must be given in writing to dev@school.edu.sl; we may charge for work materially beyond the service.

We will tell the school if, in our opinion, an instruction infringes applicable data protection law, and may pause that processing until it is resolved.

We do not act as controller of school data, and we do not process it for our own purposes. Where we do act as controller — our marketing site, enquiries, billing and security logs — the Privacy Policy applies instead.

2. Annex A — Nature of the processing

Subject matterProvision of a school management and education platform
DurationThe term of the subscription, plus the deletion period in section 10
NatureCollection, recording, storage, organisation, retrieval, transmission, backup, display and erasure
PurposeStudent administration, academic records, attendance, assessment and reporting, fee collection, staff administration and payroll support, communication with parents, national statistical reporting
Data subjectsStudents (predominantly children under 18), parents and guardians, teaching and non-teaching staff, school administrators, ministry officials
Personal dataIdentity and contact details, photographs, academic records, attendance, assessment results, financial and fee records, employment and payroll data, account and technical data, user-generated content
Special category dataHealth and disability data (disability status and type, special learning needs, blood group, medical and maternity leave), religion, and welfare markers including orphan and low-income status. Processed under Article 9(2)(g) or 9(2)(c) as directed by the Controller.
Children's dataThe majority of data subjects are children. Both parties treat this as high-risk processing requiring heightened safeguards.

3. Our obligations as processor

We will:

4. Your obligations as controller

The school warrants that it will:

5. Sub-processors

The Controller gives general written authorisation for us to engage sub-processors, subject to the conditions below. We impose data protection obligations on each sub-processor that are no less protective than this agreement, and we remain fully liable to the Controller for their performance.

Sub-processorPurposeData involved
Peeap Pay Limited (our parent company)Payment processing, wallets, fee collectionIdentifier, amount, phone number for confirmation. No academic or welfare data. Affiliation confers no wider access.
Hosting providerApplication servers and database hostingAll platform data, encrypted at rest
Object storage providerFiles, photographs, documents, backupsUploaded files and images
Email delivery providerTransactional emailRecipient address, message content
SMS providerText alerts and one-time passcodesPhone number, message content
Push notification providerMobile and browser notificationsDevice token, notification content
AI providersAssistant, lesson planning, content generationOnly the text submitted in an AI request. Contractually excluded from model training.

Notice of change. We will give the Controller at least 30 days' notice before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Controller may terminate the affected service without penalty and receive a pro-rata refund of prepaid fees.

To receive sub-processor change notices, email dev@school.edu.sl and ask to be added to the list.

6. International transfers

Some sub-processors operate outside Sierra Leone, including in the EEA and the United States. Where personal data protected by the GDPR is transferred outside the EEA, that transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Three (processor to sub-processor), or under an adequacy decision where one applies. The Standard Contractual Clauses are incorporated into this agreement by reference, with:

We apply supplementary measures including encryption in transit and at rest, data minimisation before transfer, and a commitment to challenge any government access request that is unlawful or overbroad and to notify the Controller unless legally prohibited.

7. Assisting with data subject rights

The platform gives schools direct tools to view, correct, export and delete records — so most requests can be answered without involving us. Where our assistance is needed we will provide it without undue delay and, save for extraordinary requests, without additional charge.

If we receive a request directly from a data subject relating to a school's records, we will not respond substantively. We will acknowledge, redirect them to the school, and inform the school without undue delay.

8. Breach notification

9. Audit and evidence

On reasonable written request, and no more than once in any 12 months unless a breach or a regulator requires otherwise, we will:

The Controller bears its own audit costs; we bear ours, unless the audit reveals material non-compliance, in which case we bear both.

10. Deletion and return of data

11. Annex B — Security measures

AreaMeasure
EncryptionTLS in transit across all services; encryption at rest for stored files and backups
AuthenticationOne-way password hashing; two-factor authentication available on privileged accounts; session management with CSRF protection
Access controlRole-based permissions; least-privilege administrative access; access reviewed on personnel change
Tenant isolationEvery query scoped by school identifier at the data-access layer, so one school cannot reach another's records
Upload safetyUploaded files stored so they cannot be executed as server-side code; type restrictions enforced server-side
LoggingAudit logging of sensitive actions; security and error logs retained up to 12 months
ResilienceRegular automated backups held outside the web root; restoration tested periodically
DevelopmentSecurity review of code changes; dependency monitoring; responsible disclosure channel at dev@school.edu.sl
PersonnelConfidentiality obligations; access granted on need-to-know and revoked on departure
MinimisationSpecial category and welfare data excluded from AI requests, payment integrations and analytics

We may update these measures as technology develops, provided the level of protection is not reduced.

12. Liability

Each party's liability under this agreement is subject to the limitations in our Terms of Service, except that nothing limits liability that cannot lawfully be limited — including liability to a data subject under Article 82 GDPR or an administrative fine imposed by a supervisory authority.

Data protection contact

Email: dev@school.edu.sl (subject line: “DPA”)

Phone: +232 72 799 454

For a countersigned copy of this agreement, or to be added to sub-processor change notices, contact us at the address above.

© 2026 School District Sierra Leone Home  ·  Privacy  ·  Terms