Privacy Policy
Effective and Last Updated: July 15, 2026
1. Scope and Operator
This Privacy Policy describes how SMIK-Af (School Management & Information Kit – Africa) ("SMIK-Af", "we", "us") processes personal information through its applications, websites, dashboards, APIs, support channels, and related services (the "Platform"). SMIK-Af is designed solely for educational institutions and users located in Africa.
Contact: office.smikaf@gmail.com. A school-specific privacy contact may also be available from the participating school.
Privacy and education laws differ among African countries. Mandatory law in the country of the relevant school or user applies in addition to this Policy. Where a conflict exists, mandatory local law controls.
2. Our Roles and School Responsibilities
For school-managed records, the participating school generally determines why and how information is used and SMIK-Af processes that information on the school's documented instructions. For platform registration, security, subscriptions, support, fraud prevention, and service improvement, SMIK-Af may determine the purposes and means of processing. The exact legal classification is governed by local law and the agreement with each school.
Schools must have a lawful basis to upload and use information, provide required notices, obtain required parent or guardian authorisation, configure permissions, keep records accurate, and respond to school-record requests. SMIK-Af does not sell personal information or use student information for behavioural advertising.
3. People Covered
This Policy covers students, children, parents, guardians, applicants, teachers, staff, alumni, school owners and administrators, visitors, drivers, finance personnel, librarians, security personnel, platform administrators, and other authorised users.
4. Information We Process
Depending on enabled modules and user role, we may process:
- Identity and contact data: name, date of birth, gender where lawfully required, nationality, address, email, phone number, profile image, school or employee identifiers, and identity-verification information.
- Account and authentication data: credentials, authentication provider, role, school affiliation, parent-child links, account status, consent records, and login history.
- School and admissions data: school registration, accreditation, location, applications, admissions, class, programme, department, house, and promotion or graduation history.
- Academic data: attendance, assignments, lesson notes, timetables, marks, examinations, report cards, teacher comments, awards, leadership roles, and learning records.
- Conduct and safeguarding data: behaviour, disciplinary records, complaints, incidents, gate passes, visitor logs, staff conduct, safeguarding reports, and related evidence.
- Financial data: fees, invoices, scholarships, payments, receipts, refunds, ledgers, subscriptions, transaction references, and billing contacts. Payment-card credentials are handled by the payment processor and are not intended to be stored by SMIK-Af.
- Communications and content: notices, appointments, support tickets, school inbox messages, forum posts, comments, reactions, chats, complaints, letters, files, photographs, and other uploads.
- Operations data: hostel allocation and incidents, library catalogue and borrowing records, transport routes, vehicles, trips, driver records, and live or recent location when transport tracking is enabled.
- Technical data: device and app information, IP address, timestamps, notification tokens, crash diagnostics, security events, audit logs, App Check signals, and usage information.
- Exports: PDFs, CSV files, reports, receipts, and other documents users generate or download.
5. How Information Is Collected
Information comes from users, parents or guardians, participating schools, authorised school personnel, authentication providers, payment processors, devices and permissions, platform activity, support communications, and lawful integrations. Schools may import historical records.
6. Purposes and Legal Bases
We process information to provide and administer accounts; deliver academic and school operations; link authorised family members; process payments; enable communications; protect children and users; provide transport, hostel, library, security, and administrative functions; authenticate users; prevent fraud and abuse; maintain auditability; provide support; comply with law; enforce agreements; and improve reliability.
The legal basis depends on local law and may include performance of a contract, steps requested before a contract, legal obligation, public or educational functions, legitimate interests, protection of vital interests, and consent. Sensitive and child data is processed only where an additional lawful condition or authorisation exists. Schools must identify their applicable basis.
7. Children and Students
The best interests, dignity, safety, privacy, and evolving capacity of the child guide our processing. A school, parent, or guardian must authorise a child's account or data where required. Children should receive an age-appropriate notice and should not provide information beyond what their school requests.
School officials and parents may supervise child accounts as permitted by law, but access must remain proportionate and authorised. Suspected exploitation, abuse, grooming, credible threats, or serious safety risks may be preserved and reported to the school, safeguarding authorities, emergency services, or law enforcement where legally required or necessary to protect a person.
8. Sharing and Disclosure
Information may be disclosed to the participating school and its authorised users; an authorised parent or guardian; service providers listed in our Subprocessor List; payment providers; professional advisers; regulators, courts, emergency services, safeguarding bodies, or law enforcement where legally required; and a successor in a lawful corporate transaction with appropriate safeguards.
Role-based access does not guarantee that every recipient is legally entitled to every record; schools must configure and regularly review permissions. We do not sell or rent personal information.
9. International and Cross-Border Processing
Cloud providers may process information outside the user's country, including in countries where provider infrastructure is located. SMIK-Af and schools must use safeguards required by applicable national law, such as contractual protections, regulator approval, adequacy mechanisms, localisation, or consent where legally valid. A school must not enable cross-border processing prohibited by its local law.
10. Retention
Information is retained only as long as needed for the stated purpose, school instructions, safety, dispute resolution, accounting, audit, and legal obligations. Default periods are described in the Data Retention Schedule. Schools may impose different lawful periods. Legal holds, safeguarding duties, academic-record requirements, or financial laws may prevent immediate deletion.
11. Security
We use proportionate technical and organisational safeguards described in the Security Measures Schedule, including access controls, authentication, logging, cloud security controls, and incident management. No system is completely secure. Users must protect credentials and promptly report suspected compromise.
12. Rights and Choices
Subject to applicable law, a person may request access, correction, deletion, restriction, objection, portability, consent withdrawal, or review of certain decisions. School-record requests should ordinarily be directed to the school. Platform-level requests may be sent to office.smikaf@gmail.com.
We may verify identity and authority before acting. Parents and guardians must show authority to act for a child. A request may be limited where law requires retention, disclosure would harm another person's rights, or the school must preserve an official educational or safeguarding record. Users may complain to the competent data-protection or education authority in their country.
13. Account Deletion
Users may initiate deletion through available account settings or contact us using the process in the Account & Data Deletion Policy. Deleting an authentication account does not automatically erase school-controlled records that a school must retain. Shared content will be removed, anonymised, or retained only where lawful and necessary.
14. Device Permissions and Communications
Camera, photo, file, location, and notification permissions are requested only when needed for a feature. Device settings can withdraw permissions, although the related feature may stop working. Essential service and safety messages are not marketing. Optional promotional communications require any consent mandated by local law.
15. Automated Decisions
SMIK-Af does not intend to make solely automated decisions that determine admission, grading, discipline, employment, health treatment, or other similarly significant outcomes. Schools and authorised humans remain responsible for those decisions. Analytics and administrative summaries must be reviewed by qualified personnel.
16. Changes
We may update this Policy to reflect legal, technical, or operational changes. Material changes will be communicated through the Platform, website, school, or other appropriate channel. Where law requires renewed consent, it will be requested before the relevant processing continues.
17. Contact
Privacy questions and requests may be sent to office.smikaf@gmail.com. Include your name, school, role, country, request, and a safe method for us to verify your identity. Do not email health records, passwords, payment-card details, or highly sensitive student information.