Trust & Transparency
Privacy Protocol
Our commitment to protecting institutional integrity, staff privacy, and student data in a global digital environment.
Version 2.4.0Last Updated: March 13, 2026
1. Data Sovereignty & Tenancy Isolation
EducaSphere operates on a strict multi-tenant architecture. Every byte of institutional data is isolated at the database layer using Row-Level Security (RLS). The Institution ('The Tenant') remains the sole Data Controller. EducaSphere acts exclusively as a Data Processor under your direction. We do not aggregate institutional data for our own commercial purposes.
2. Comprehensive Data Collection
We process four categories of data: (a) Institutional Data (Finance, Assets, HR); (b) Personnel Data (Staff records, payroll, qualifications); (c) Student Data (Academic results, attendance, behavior, and where enabled, health/IEP records); and (d) Technical Metadata (Audit logs, access patterns, device fingerprints).
3. Lawful Basis for Processing
We process data primarily for the performance of the educational contract between the Institution and its stakeholders. This includes statutory financial reporting, academic certification, and student safeguarding. For health or special education data (IEP), we rely on the explicit consent mechanisms managed within the platform.
4. Global Sub-processors
EducaSphere utilizes Tier-1 cloud infrastructure (AWS/GCP) and regional payment gateways (Flutterwave, Paystack, M-Pesa). All sub-processors are vetted for SOC 2 and ISO 27001 compliance. We maintain a live Sub-processor Registry available to Institutional DPOs upon request.
5. Retention & Destruction
Data is retained according to the Institution's configured retention schedule. Upon account termination, we initiate a 60-day 'Cooling Period' for data export. Following this, an automated cryptographic erasure process is triggered across primary and secondary backup volumes.
6. Data Subject Rights (DSAR)
The platform includes native tools for fulfilling GDPR/DPA rights, including the Right to Access, Right to Rectification, and the Right to Portability. These tools allow Institutional Admins to generate complete student data archives in under 5 minutes.
7. Children's Privacy & Safeguarding
As an institutional provider, EducaSphere treats all student data with the highest level of protection. We comply with international safeguarding standards (including COPPA-equivalent principles). Student data is used solely for educational and administrative purposes directed by the School. We do not build marketing profiles on minors or serve advertisements within the platform.
8. Website Cookies & Marketing Data
For visitors to our public marketing site, we use cookies and tracking technologies (e.g., Google Analytics, CRM pixels) to analyze traffic and improve user experience. You may opt-out of non-essential cookies via your browser settings. Contact data submitted via our 'Book a Demo' or 'Contact Sales' forms is used exclusively for institutional outreach and can be deleted upon request.
9. Security Safeguards
Encryption
AES-256 for data-at-rest and TLS 1.3 for transit.
Isolation
Row-Level Security (RLS) per institutional tenant.
Auditing
Immutable logs for every administrative action.
Compliance
Regular third-party SOC 2 and GDPR audits.
Contact Our Global DPO
For questions regarding our privacy protocol, international data transfers, or regional compliance, please contact our Data Protection Office.
Email: [email protected]
Trust Portal: trust.educasphere.com