Legal
Privacy Policy
The short version. We build school software. Most of the personal data on this platform — student records, marks, attendance, staff files — belongs to the school, not to us. The school decides what is collected and why; we store and process it on the school's instructions and we do not sell it, rent it, or use it to train third-party AI models. This policy explains that split, what we collect in our own right, and the rights you have over your data.
Contents
- Who is responsible for your data
- What personal data we handle
- Children's data
- Sensitive (special category) data
- Why we use it, and our legal basis
- The National Student Identifier (NSI)
- Who we share data with
- Artificial intelligence features
- International data transfers
- How long we keep data
- Your rights and how to use them
- Cookies and similar technologies
- How we protect data
- If something goes wrong
- Changes to this policy
- Contact and complaints
1. Who is responsible for your data
The answer depends on which part of the platform you are using. This distinction matters, because it determines who you ask when you want your data corrected or deleted.
When a school uses our software
Each school (and, for national reporting, the Ministry of Basic and Senior Secondary Education) is the data controller for its students, parents and staff. The school decides what to record, who may see it, and how long to keep it.
School District Sierra Leone acts as the data processor. We hold and process that data only to provide the service, and only on the school's documented instructions. The terms governing this are in our Data Processing Agreement.
If you are a parent, student or member of staff and you want to see, correct or delete a record, contact your school first. They control it. If your school does not respond, or you cannot reach them, contact us at dev@school.edu.sl and we will help you reach the right person — but we cannot change a school's records on our own initiative.
When you deal with us directly
We are the data controller for: this marketing website; school registration and demo requests; enquiries you send us; our own staff and contractor records; and platform-level security, billing and abuse-prevention logs.
Registered entity. School District Sierra Leone is a subsidiary of Peeap Pay Limited, a company registered in Sierra Leone with its registered office at 57 Babadorie Drive, Lumley, Freetown, Sierra Leone. Peeap Pay Limited stands behind the commitments in this policy, including the payment-processing arrangements described in section 7.
2. What personal data we handle
The list below reflects what the platform is actually built to store. Not every school uses every field — a school that does not run school transport collects no journey data, for example.
| Category | Examples |
|---|---|
| Student identity | Name, date of birth, sex, photograph, admission number, roll number, National Student Identifier (NSI), national or local ID number, nationality, religion, home and permanent address |
| Student academic | Class and section, subjects, attendance, marks and grades, exam results, report cards, lesson and homework records, certificates, disciplinary and lifecycle events (admission, transfer, dropout, return) |
| Student welfare | Height and weight, blood group, disability status and type, special learning needs, orphan status, low-income status, scholarship status and provider, welfare notes |
| Parent and guardian | Names, relationship to the child, mobile numbers, email addresses, occupations, photographs, addresses |
| Staff | Name, date of birth, photograph, contact and emergency contact details, marital status, qualifications, employment history, contract type, NASSIT number, MBSSE employee ID, salary and bank details, leave records (including medical and maternity leave), uploaded documents such as CVs, appointment letters and driving licences |
| Financial | Fee invoices and payments, wallet balances and transactions, payment references, one-time passcodes sent to a registered phone number. Full card numbers are handled by our payment provider and never stored on our systems. |
| Location | Where a school uses our transport module, the place and time a student boards or leaves a school vehicle. School site coordinates. |
| Account and technical | Username, hashed password, role and permissions, login timestamps, IP address, device and browser information, error and audit logs, push-notification tokens |
| Content you create | Messages, notes, documents, uploaded files, assignments, projects and anything else entered into the platform |
| Website and enquiries | School name, contact name, email address and phone number submitted through registration or demo request forms; the content of emails you send us |
3. Children's data
This platform exists to keep records about schoolchildren, most of whom are under 18 and many of whom are under 13. We treat that as the most sensitive thing we do.
- Children do not sign up on their own. A student record is created by a school, as part of that school's lawful admission process, or by a parent or guardian through an online admission form.
- We do not profile children for advertising. We do not serve behavioural advertising, we do not build marketing profiles, and we do not sell or licence student data to anyone, for any purpose, ever.
- Access is restricted by role. A teacher sees the classes they teach. A parent sees their own children. Staff at one school cannot see another school's students. This is enforced in the software, not by policy alone.
- Photographs. Student photographs are used for identification — ID cards, registers, verifying the right child. Schools should not publish them externally without the consent of a parent or guardian.
- Location. Where a school operates the transport module, a child's boarding and alighting points are recorded so the school and the parent know the child travelled safely. It is not continuous tracking, it is visible to the school and the child's own parents, and a school that does not use the module records nothing.
If you are a parent or guardian and you are uncomfortable with anything recorded about your child, raise it with the school. If you believe a child's data is being misused on this platform, tell us at dev@school.edu.sl and we will investigate, including where the school itself is the problem.
4. Sensitive (special category) data
Some of what schools record is special category data under Article 9 of the UK/EU GDPR and equivalent protections elsewhere — data revealing health, disability, religion, or comparable characteristics. On this platform that includes disability status and type, special learning needs, blood group, height and weight, religion, medical and maternity leave for staff, and welfare markers such as orphan or low-income status.
We hold this data because schools need it to educate and safeguard children — to arrange accessible classrooms, allocate scholarships and bursaries, respond to a medical emergency, and report on inclusion to the Ministry. Where the GDPR applies, the school relies on Article 9(2)(g) (substantial public interest, in the field of education and social protection) or Article 9(2)(c) (vital interests, in an emergency), and we process it solely as their processor.
Practically, this means: it is visible only to staff whose role requires it; it is never used for marketing; it is never shared with a payment provider, advertiser or AI vendor; and it is not exported outside the school except in the aggregate, anonymous form used for national statistics.
5. Why we use it, and our legal basis
Where the GDPR applies, we and the schools we serve rely on the following bases. Consent is deliberately not the main one — a school cannot run on consent that a parent could withdraw mid-term, and pretending otherwise would be misleading.
| Purpose | Legal basis |
|---|---|
| Enrolling students, keeping academic records, marking attendance, issuing results and certificates | Public task / legitimate interests of the school in delivering education; contract where the school is private |
| Safeguarding children and responding to emergencies | Vital interests; legal obligation |
| National education statistics and EMIS reporting | Public task (Ministry mandate); reported in aggregate wherever possible |
| Collecting school fees and operating wallets | Contract; legal obligation (financial record-keeping) |
| Paying staff and meeting employment obligations | Contract; legal obligation |
| Keeping accounts secure, investigating abuse, keeping audit logs | Legitimate interests in a secure service; legal obligation |
| Responding to your enquiry or demo request | Legitimate interests; steps prior to a contract |
| Non-essential cookies and third-party embeds | Consent (see section 12) |
Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they do not override them. You can ask us for that assessment.
6. The National Student Identifier (NSI)
Every student on the platform receives a National Student Identifier — a short code in the form A123456. It is worth being explicit about how this behaves, because it is unusual:
- It is a lifetime identifier. It follows a student between schools, from primary through to tertiary verification, and is never reissued to a different person.
- It is never recycled and never regenerated. If a student record is deleted, that NSI is retired permanently rather than reused.
- Identifiers issued under the earlier format are retained indefinitely so that an ID card printed years ago still resolves.
- It is used by connected systems — fee payments, wallet creation, parent–child linking, transcript verification at tertiary level, and national student search.
Because it is a permanent national identifier, a request to erase an NSI generally cannot be granted while the student has an active academic record: it is what makes a transcript verifiable years later. We explain this rather than bury it.
7. Who we share data with
We do not sell personal data. We do not share it for advertising. We do not licence it to data brokers. We share it only in the circumstances below.
| Recipient | What and why |
|---|---|
| The student's school | Everything that school records. It is their data. |
| Parents and guardians | Their own child's records — attendance, results, fees, messages. |
| MBSSE and EMIS | Enrolment and performance data for national planning and reporting, under the Ministry's statutory mandate. |
| Peeap Pay Limited (our parent company) | Payment processing and wallets. As our parent company it is an affiliate, but for payments it acts as a separate processor and receives only the minimum needed to process a payment — identifier, amount, and the phone number for confirmation. It does not receive academic or welfare data, and being an affiliate gives it no wider access. |
| Hosting and storage providers | Servers, backups and file storage. Bound by contract, no independent right to use the data. |
| Communication providers | Email, SMS and push notification delivery — recipient address and message content only. |
| AI providers | Only where an AI feature is used, and only the text needed to answer that request. See section 8. |
| Tertiary institutions | Verification of a transcript or NSI on request, to confirm a qualification is genuine. |
| Authorities | Where we are legally required to, or where disclosure is necessary to protect a child from serious harm. We will tell the affected school unless legally barred from doing so. |
| A buyer | If the business is sold or merged, under equivalent protections and with notice to schools. |
A current list of our sub-processors, and the notice we give before adding a new one, is in the Data Processing Agreement.
8. Artificial intelligence features
Parts of the platform use AI — a teaching assistant, lesson-plan drafting, curriculum suggestions, marking support. Because AI usually means sending text to a third party, we want to be direct about it.
- When you use an AI feature, the content of your request is sent to an AI provider so it can generate a response. Some providers operate outside Sierra Leone.
- We contract so that your data is not used to train the provider's models. If we ever cannot secure that for a given provider, we will not route your data to it.
- We send the minimum necessary and avoid including welfare or medical data in AI requests.
- No decision that materially affects a student is made by AI alone. AI drafts and suggests; a teacher or administrator decides. Grades, discipline, admission and progression are human decisions. You have the right under Article 22 GDPR not to be subject to a solely automated decision with legal or similarly significant effect, and we honour that by not making such decisions automatically in the first place.
- AI output can be wrong. Treat it as a draft, not as a record.
9. International data transfers
Our primary systems serve Sierra Leone, but some providers — hosting, storage, email, push notifications and AI — process data outside the country, including in the European Union and the United States.
Where personal data protected by the GDPR leaves the European Economic Area, we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one exists, together with additional safeguards such as encryption in transit and at rest. You can request details of the safeguards applying to a specific transfer.
10. How long we keep data
Schools set retention for their own records; the periods below are our defaults and the limits we apply.
| Data | Retention |
|---|---|
| Academic records — enrolment, results, certificates | Retained long-term. A transcript must remain verifiable decades after a student leaves. |
| National Student Identifier | Permanent; never reused (see section 6) |
| Attendance and day-to-day operational records | Typically 7 years after the student leaves, unless the school specifies otherwise |
| Financial and payment records | As required by Sierra Leone tax and accounting law — at least 6 years |
| Staff employment records | Duration of employment plus 6 years; longer where pension or NASSIT rules require |
| Welfare and disability records | Only while relevant to supporting the student, then removed by the school |
| Security, audit and error logs | Up to 12 months |
| Backups | Up to 90 days, after which deleted data ages out |
| Website enquiries and demo requests | 24 months from last contact |
| Data of a school that leaves the platform | Exported to the school, then deleted within 90 days of the school confirming |
When you delete something, it disappears from the live service immediately and ages out of backups within 90 days. We do not keep a shadow copy.
11. Your rights and how to use them
Subject to local law, and in full where the GDPR applies, you have the right to:
- Be informed — this policy.
- Access a copy of the personal data held about you.
- Rectify data that is wrong or incomplete.
- Erase data, where there is no overriding legal or academic reason to keep it.
- Restrict processing while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interests, and to direct marketing at any time and absolutely.
- Withdraw consent where consent was the basis, without affecting what happened before.
- Not be subject to solely automated decisions with legal or similarly significant effects.
- Complain to a supervisory authority (section 16).
How to exercise them. If the data sits in a school's records, ask the school — they are the controller and they can act immediately. For data we control, or if a school is unresponsive, email dev@school.edu.sl with enough detail to identify the record.
We respond within 30 days. Complex requests may take up to 60, and we will tell you within the first 30 if that applies. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to verify your identity — we will not hand a child's record to someone who cannot show they are entitled to it.
Requests about a child are normally made by a parent or guardian. Older children may exercise their own rights where they are capable of understanding them.
12. Cookies and similar technologies
We use as little of this as we can get away with.
| Type | What it does | Consent needed? |
|---|---|---|
| Essential | Session cookies that keep you logged in, and the CSRF token that stops other sites submitting forms as you. The platform does not work without them. | No — strictly necessary |
| Preferences | Local storage remembering your light/dark theme, accent colour and layout. Stays on your device. | No — set only by your own choice |
| Offline storage | The platform works offline. Records you are working on are cached on your device and synced when you reconnect. Cleared when you sign out. | No — necessary for a service you asked for |
| Third-party embeds | Where a school enables a chat widget or an embedded map, that third party may set its own cookies. | Yes — loaded only after you agree |
We do not use advertising cookies, tracking pixels or cross-site behavioural analytics. There is no Google Analytics, no advertising pixel and no third-party marketing tag on this site.
You can clear cookies and local storage through your browser at any time. Clearing them signs you out and discards unsynced offline work.
13. How we protect data
- Encryption in transit (HTTPS/TLS) across all services, and encryption at rest for backups and stored files.
- Passwords stored using a one-way hash — we cannot read your password, and neither can an attacker who takes the database.
- Strict tenant isolation: every query is scoped to a school, so one school cannot reach another's records.
- Role-based access control, so staff see only what their role requires.
- Two-factor authentication available on administrator accounts.
- Uploaded files are stored so they cannot be executed as code.
- Audit logging of sensitive actions, and regular security review of the codebase.
- Staff and contractors with access are bound by confidentiality obligations and are granted the least access needed.
No system is perfectly secure, and we will not claim otherwise. What we commit to is defending it properly and telling you honestly when something goes wrong.
14. If something goes wrong
If a breach occurs that is likely to result in a risk to people's rights and freedoms, we will notify the affected schools without undue delay and within 72 hours of becoming aware, with what we know, what we are doing, and what they should do. Where a school is the controller, the school notifies its regulator and the affected individuals; we give them everything they need to do that. Where we are the controller, we notify the regulator and affected individuals directly.
To report a vulnerability or a suspected breach, email dev@school.edu.sl. We do not pursue good-faith security researchers who report responsibly and do not access or exfiltrate other people's data.
15. Changes to this policy
We update this policy when what we do changes. The effective date and version are at the top. For material changes — a new category of data, a new type of recipient, a new purpose — we notify schools at least 30 days in advance by email and in the platform. Continuing to use the service after a change takes effect means the updated policy applies. Previous versions are available on request.
16. Contact and complaints
Privacy contact
Email: dev@school.edu.sl
Phone: +232 72 799 454
Post: School District Sierra Leone (a subsidiary of Peeap Pay Limited), 57 Babadorie Drive, Lumley, Freetown, Sierra Leone
Please put “Privacy” in the subject line so it is routed correctly.
Sierra Leone. Sierra Leone's Data Protection and Right to Access Information Bill was approved by Cabinet in April 2026 and is before Parliament. It has not yet been enacted, so no data protection authority is operating here yet. We have chosen to apply GDPR-standard practice in the meantime, and we will register with the Data Protection Commissioner once that office exists. Related duties under the Cyber Security and Crime Act 2021 and the Child Rights Act 2007 continue to apply, and we comply with them.
European Union / EEA. If you are in the EEA you may complain to your national supervisory authority. A list is at edpb.europa.eu. We would rather you came to us first — but that is your right, not our permission to give.
We would genuinely rather hear a complaint than have you go around us. If we have got something wrong, tell us and we will fix it.