Legal

Privacy Policy & Data Protection

Last updated: July 2026

1. Overview

EduKit ("we," "us," "our") provides two connected products to schools in Nigeria: EduKit, an AI-powered learning and CBT exam platform, and the School Management System (SMS), which handles day-to-day school administration — students, staff, attendance, fees, exams, and communication with parents.

This policy explains what information we collect, why we collect it, who we share it with, and how you can exercise control over it. It applies to anyone who uses EduKit or the SMS: school administrators, teachers, other staff, students, and parents.

2. Information we collect

What we collect depends on your role:

From schools (admins/staff who set up the platform)

  • School name, address, and contact details
  • Admin, teacher, and other staff names, roles, phone numbers, and email addresses
  • Subscription and payment records (see Section 5 for how payments are actually processed)

From and about students

  • Name, date of birth, gender, class, admission number, and parent/guardian contact details
  • Academic records: exam scores, attendance, report cards, and class assignments
  • Fee and payment status
  • Where a school uses these modules: library borrowing records, hostel assignments, and health/clinic records (allergies, chronic conditions, blood group) entered by school staff

From parents

  • Name and contact details, and their relationship to the student(s) they're linked to
  • Payment history for their child's/children's fees

Student and parent accounts are created by the school, not by self-registration — a school's administrator enters this information when a student is admitted, and generates login credentials for the student, their parent, and relevant staff.

3. How we use information

  • To run the core features of EduKit and the SMS: recording scores, tracking attendance and fees, generating report cards, and giving each person (student, parent, teacher, admin) access to only what's relevant to them
  • To verify who's logging in and keep one school's data separate from another's
  • To process and confirm subscription payments
  • To send account-related notifications (e.g. a new result being published, a fee reminder) through the platform
  • To fix problems, investigate misuse, and improve the platform based on how it's actually used

We do not sell student, parent, or staff data to advertisers or other third parties, and we do not use student data to build advertising profiles.

4. Children's data & the school's responsibility

Because EduKit and the SMS are used by K-12 schools, a significant amount of the data on the platform belongs to children. We take this seriously, and the way responsibility is split matters:

  • The school is the data controller for its students' information — the school decides what student data to enter, who at the school can access it, and is responsible for having appropriate consent from parents/guardians under its own enrollment process.
  • EduKit acts as a data processor — we store and process that data on the school's behalf, following the access permissions the school sets (e.g. a teacher only sees their assigned classes and subjects; a parent only sees their own child).

If you're a parent with questions about what data has been entered about your child, or want it corrected or removed, your first point of contact is your child's school — they control the record. We'll support the school in fulfilling that request.

5. Who we share data with

We share data only where it's necessary to run the platform:

  • Payment processors — Paystack and Flutterwave handle subscription and fee payments. We never see or store your full card details; that's handled directly by these processors, which are licensed payment providers in Nigeria.
  • Cloud infrastructure — school and student data is stored on MongoDB Atlas (database hosting) and served via Render and Vercel (application hosting), all of which are contractually required to protect data they process on our behalf.
  • Within a school — data is only visible to the roles the school has assigned it to: a subject teacher sees their own classes' scores, a parent sees only their own children, a school admin sees their whole school. Different schools never see each other's data.

We do not share student, parent, or staff data with any other third party for marketing purposes.

6. How we protect data

  • Passwords are stored using industry-standard hashing (bcrypt) — even we can't read a user's actual password
  • All traffic between your browser and our servers is encrypted (HTTPS)
  • Access to a school's data requires a valid login tied to that specific school — a login for one school cannot access another's records
  • Login credentials generated for students, staff, and parents are randomized per account rather than using shared or predictable defaults

No system is perfectly secure, and we can't guarantee absolute security — but we treat security issues as urgent, and we keep improving these protections as the platform grows.

7. Data retention & deletion

We retain a school's data for as long as the school maintains an active subscription, plus a reasonable period afterward in case the school wishes to renew. Session records from prior academic years (results, fee history, attendance) are archived rather than deleted when a school moves to a new session, so historical records remain available.

If a school closes its account permanently and requests deletion, we remove the school's data from active systems. Some information may be retained where we're legally required to (for example, financial transaction records).

8. Your rights

Depending on your role, you can typically:

  • Request to see what information is held about you or your child (via your school's administrator)
  • Request corrections to inaccurate information
  • Request your password be reset if you believe your account has been compromised
  • Ask your school to remove your data when you're no longer associated with it (e.g. after graduation or leaving employment), subject to the school's own record-keeping obligations

Because the school controls student and staff records, most of these requests should go to your school first. If you're not getting a response, you can contact us directly (Section 11) and we'll help facilitate it.

9. Cookies & local storage

We use a small number of essential cookies and browser storage to keep you logged in and remember basic preferences (like your selected language). We don't use third-party advertising or tracking cookies.

10. Changes to this policy

We may update this policy as the platform evolves. If we make a material change to how we handle data, we'll update the "Last updated" date at the top of this page. Continued use of EduKit or the SMS after a change means you accept the updated policy.

11. Contact us

Questions about this policy, or a data request that your school hasn't been able to resolve, can be sent to: