Privacy Intelligence

Platform Compliance: v2.4 (Uganda & East Africa)

Last Updated: October 24, 2024

Transparency is the foundation of trust. This policy details how EduVision protects the institutional integrity of our partner schools.

1. Identity and Scope

EduVision SMS is a high-security school management ecosystem operated by EduVision Institutional Systems. We provide tools for academic tracking, financial management, and institutional communication. Company: EduVision Africa Jurisdiction: Republic of Uganda Contact: privacy@eduvision.africa

2. Controller vs. Processor Roles

Under applicable data protection laws: A. THE INSTITUTION (The School) acts as the Data Controller. You own the data and determine the purpose for which student and staff information is processed. B. EDUVISION acts as the Data Processor. We process data strictly according to the institution's instructions and for the purpose of operating the platform.

3. Categories of Information Collected

We process information necessary for institutional excellence: A. BIOMETRIC & PERSONAL: Full names, DOB, gender, and profile photos. B. SENSITIVE HEALTH DATA: Student allergies and medical emergency contacts (to ensure classroom safety). C. FINANCIAL RECORDS: Fee payment history, bank/MoMo transaction references, and salary disbursements. D. ACADEMIC PERFORMANCE: Grades, attendance, and behavioral logs.

4. Third-Party Sub-Processors

To provide a seamless experience, we share data with limited essential partners: - Cloud Infrastructure: Google Cloud/Firebase (Global Security Standards). - Communication: UGSMS & WhatsApp Business API (For results and fee alerts). - Payouts: Integrated Banking Partners & Mobile Money Aggregators. All partners are bound by strict confidentiality agreements.

5. Data Security & AES-256 Encryption

We implement 'Defense in Depth' strategies: - All data in transit is encrypted via TLS 1.3. - Persistent data is stored using AES-256 bit encryption. - Granular Role-Based Access Control (RBAC) ensures a teacher cannot see a bursar's financial ledger.

6. The Immutable Audit Trail

Every sensitive action (marks entry, fee logging, password resets) is recorded in an immutable audit log. This ensures total accountability and protects the institution against internal fraud or data tampering.

7. Data Retention & Off-boarding

Institutions retain ownership of their data. Upon termination of service, we provide a 30-day window for full data export. Following this, data is permanently purged from our active servers in compliance with Ugandan statutory requirements.

8. Rights of Parents and Students

Individuals may request access to or correction of their data through their school administration. EduVision will assist schools in fulfilling these requests within 48 business hours.

9. Children’s Privacy Guard

We do not collect data directly from students. All student profiles are provisioned by verified school administrators or parents. We strictly adhere to regional laws regarding the protection of minors.

10. Contacting our DPO

For formal data inquiries or security concerns, contact our Data Protection Officer at: dpo@eduvision.africa

Secure by Design.

If you have questions about how we handle data or want to request a data audit for your school, please contact our Compliance Office.

Compliance Registrylegal@eduvision.africa