1. Our role and your school's role
This policy explains how Sckool360 handles personal information through its website and school management platform. It applies to school administrators, staff, students, parents and other authorised users.
Your school generally determines why its educational, employment and school administration records are processed and acts as their data controller. Sckool360 processes those records to provide the platform on the school's instructions. For platform account administration, subscription billing, security and direct support, Sckool360 determines the relevant purposes of processing. The exact allocation of responsibilities may also be set out in the school's service agreement.
Your school's own privacy notice should explain its use of your records. Contact the school about school decisions or inaccuracies in those records, and contact Sckool360 about platform privacy concerns.
2. Information the platform handles
The information processed depends on your role, the school's enabled modules and what you or the school supply. It may include:
- Identity and account details: names, contact details, usernames, school affiliation, role, profile photos, password hashes and authentication records.
- School and learning records: student and parent relationships, class placement, attendance, assessments, answers, marks, report cards, library activity and uploaded learning resources.
- Staff records: assignments, attendance, employment-related entries, professional development and payroll information.
- Financial records: subscription purchases, invoices, payment amounts, references, status and uploaded payment evidence. Payment checkout details are handled by the provider presented at checkout; do not upload full card details into school records.
- Sensitive records: health or sick-bay information, safeguarding concerns, confidential reports and related messages when the school uses those modules.
- Communication and technical information: announcements, support requests, notifications, account activity, audit events, request and error logs, and device or network information exposed when connecting to the Service.
- Attendance location inputs: points submitted to enabled geofence or breadcrumb features. Current simulated map points are not verified GPS positions.
We receive information directly from users, from authorised school staff and imports, and from enabled services such as payment verification or optional Google sign-in.
3. Why information is processed
Information is used to establish and authenticate accounts, apply school and role permissions, operate enabled modules, maintain records, deliver service messages, process subscription payments, answer support requests, investigate faults and misuse, and meet legal obligations.
For school-controlled records, the school must identify an appropriate lawful basis and instruct processing accordingly. For processing Sckool360 determines, relevant bases may include performing a service contract, complying with legal obligations, legitimate interests in providing and securing the platform, and consent where required. Sensitive information and children's information require any additional conditions applicable under law.
Acceptance of the Terms of Service or acknowledgement of this policy is not blanket consent to every use of personal information. Where a particular use requires consent, it must be requested separately and may be withdrawn subject to applicable law.
4. Children and sensitive information
Sckool360 is used by schools and may hold children's records. Children should use school-provisioned accounts under appropriate school and parent or guardian supervision. The school must provide suitable notices and obtain or verify any authorisation required before supplying children's information.
Health, safeguarding and confidential staff records must be entered only for an appropriate school purpose and accessed only by people authorised for that purpose. Confidential reports record the reporter's identity; they are not anonymous. Report access depends on the person's role and current reviewer appointment. Information may also need to be disclosed where safeguarding duties or law require it.
A parent or guardian may contact the school about a child's information, subject to identity, authority and any applicable safeguarding or legal restrictions.
6. Browser storage and service messages
The app uses browser storage for authentication and preferences. Depending on your sign-in choice, credentials may be stored for the browser session or retained locally so you remain signed in. Signing out clears the app's stored authentication state. Use shared devices carefully and sign out when finished.
Essential storage and authentication are used to make the Service work. Any optional tracking introduced in the future will require appropriate disclosure and consent where applicable. Clearing browser storage does not delete records held by the school or on the backend.
Service emails and notifications may concern invitations, password resets, billing, school activity and support. Some notices are necessary for account security or service operation. School announcements and their recipients are managed by the school.
7. Security and incident handling
The platform includes password hashing, authenticated access, role and school boundaries, and audit or revision records for supported activities. Protection also depends on deployment settings, correct permissions and users keeping credentials secure. No online system can guarantee complete security.
Report suspected access misuse or data exposure promptly to your school administrator and Sckool360 support. We will investigate and coordinate with the relevant school. Where an incident requires notification, the responsible parties must notify affected people and the relevant authority as required by applicable law.
8. Retention, closure and deletion
School records are retained according to the school's lawful instructions, operational needs and applicable retention duties. Subscription, security, support and financial records may need to remain for legal compliance, dispute handling and accountability. There is no single retention period for every type of record.
Suspending an account or archiving a school disables access but does not automatically erase its records, files, financial history or audit information. A deletion request must be assessed against the relevant controller's obligations and other people's rights. Backup copies and records under a legal hold may require separate handling before deletion is complete.
Contact the school for its retention schedule and export or deletion requests. Sckool360 support can assist the authorised school and respond to requests concerning processing for which Sckool360 is responsible.
9. Processing outside Nigeria
Depending on where hosting and service providers operate, information may be processed outside Nigeria. Such processing must follow applicable transfer requirements and use appropriate safeguards. Ask support for details of the providers and safeguards applicable to your school's deployment; this policy does not promise storage exclusively in Nigeria.
10. Your privacy rights
Subject to applicable law, you may request information about processing, access, correction, deletion, restriction, portability, or objection, and withdraw consent where processing depends on it. You may also request human review of a decision based solely on automated processing where protected by law. Rights can be limited by legal duties and others' rights.
Send school-record requests to your school; send platform requests to starheadtechenterprise@gmail.com. We may verify identity and authority, and will respond or coordinate with the school within applicable legal time limits. You may complain to the Nigeria Data Protection Commission or another competent authority.
11. Changes and contact
We will update this policy when practices or legal requirements change, display the current effective date, and communicate material changes through an appropriate service channel. Additional consent will be sought where required.
For privacy questions, email starheadtechenterprise@gmail.com or use in-app support. Include your school name, the type of request and a safe way to reach you. Do not send passwords, payment card details or unnecessary medical or safeguarding information by email.
