1.Who we are
SchoolSQL is a school management service operated by SchoolSQL Group in Nigeria. This policy explains how we handle personal information when a school uses SchoolSQL.
For the records a school enters — students, staff, results, attendance, fees — the school is the data controller and SchoolSQL is the processor. The school decides what is collected and who may see it; we hold and protect it on the school’s instructions.
2.What we collect
Information a school gives us
- Student records: name, registration number, date of birth, class and arm, guardian contact details, and a photograph where the school uploads one.
- Academic records: scores, grades, attendance, remarks, report cards and exam attempts.
- Financial records: invoices, payments, discounts and outstanding balances.
- Staff records: name, contact details, role and the permissions the school assigns.
Information we collect automatically
- Sign-in events, so a school can see when an account was last used.
- An activity log of significant actions, so a school can see who changed what.
- Basic technical information needed to serve the application securely, such as IP address and browser type.
We do not use tracking for advertising, and we do not sell personal information to anyone.
3.Why we hold it
- To provide the service the school subscribed to — records, report cards, attendance, billing and the student portal.
- To keep accounts secure, and to give schools an audit trail of who did what.
- To support schools when something goes wrong, and to fix faults in the service.
- To meet our legal and accounting obligations.
Our lawful basis is the contract with the school, our legitimate interest in running a secure service, and — where required — the consent the school obtains from families under the Nigeria Data Protection Act.
4.Children’s information
Most of the records in SchoolSQL are about children. Student accounts are created by the school, and a student portal only ever shows that student’s own records.
We do not profile children, we do not use their data to train advertising systems, and we do not disclose it to anyone outside the school except as described in this policy.
5.Who can see it
Within a school, visibility follows the permissions the school sets. A subject teacher sees their subjects; a class teacher sees their class; administrators see the school. Families see their own child.
Outside the school, we share information only with the service providers we need to run SchoolSQL, and only what they need:
- Hosting and database providers, to store and serve the application.
- Paystack, to process online fee payments. Card details are entered on Paystack’s systems and never reach ours.
- Email and messaging providers, to deliver notifications a school asks us to send.
We may also disclose information where the law requires it, or to protect the safety of a child or another person.
6.How we protect it
- Traffic between your browser and SchoolSQL is encrypted in transit.
- Passwords are stored hashed. Staff cannot read a family’s password, and temporary passwords stop working the moment they are used.
- Access inside the application is governed by the school’s own permission settings, enforced on the server rather than only hidden in the interface.
- Databases are backed up, and access to production systems is restricted to the small number of people who need it.
7.How long we keep it
A school’s records are kept for as long as the school uses SchoolSQL. Academic history is deliberately retained across sessions — a school needs a student’s full record, not only the current term.
When an authorised school administrator asks us to delete the school’s data, we delete it. Copies may persist in backups for a limited period before they are overwritten.
8.Your rights
Under the Nigeria Data Protection Act you may ask to see the personal information held about you, to have it corrected, or in some cases to have it deleted.
Because the school controls its own records, the quickest route is to ask the school directly — they can correct a record immediately. If you contact us instead, we will pass the request to the school and support them in answering it.
9.Changes to this policy
We update this policy when the way we handle information changes. The "Last updated" date at the top of this page always reflects the current version, and we tell school administrators directly about material changes.
Questions?
If you have questions about these Terms, our Privacy Policy, or how SchoolSQL handles your information, we'd be happy to help.
schoolsqlgroup@gmail.com