Legal & Compliance
Data Protection & Privacy Policy
The internal data protection governance and safeguards that Skoolfly applies to personal data.
1. Policy Statement
Skoolfly is committed to the lawful, fair and transparent processing of personal data. This Policy describes the internal governance, principles and controls Skoolfly applies to protect personal data, and complements the customer-facing Privacy Policy.
2. Purpose and Scope
The purpose of this Policy is to ensure that personal data is processed lawfully, kept secure, and handled in a way that respects the rights of individuals, including students, parents, teachers, staff and other users. It applies to all Skoolfly personnel, systems and processing activities.
3. Relationship to the Privacy Policy
The user-facing Privacy Policy explains to individuals how their data is collected, used and protected and how they can exercise their rights.
This Data Protection & Privacy Policy sets out the internal standards, roles and procedures that make those commitments possible. Where schools act as data controllers, Skoolfly supports their obligations through appropriate agreements and documented controls.
4. Data Protection Principles
Skoolfly's processing of personal data is guided by the following principles.
Lawfulness, fairness and transparency.
Purpose limitation: data is collected for specified, explicit and legitimate purposes.
Data minimisation: only data needed for the purpose is collected and processed.
Accuracy: reasonable steps are taken to keep data accurate and up to date.
Storage limitation: data is kept only as long as necessary, in line with the Data Retention Policy.
Integrity and confidentiality: data is processed securely and protected against unauthorised access or loss.
Accountability: Skoolfly maintains documentation and controls to demonstrate compliance.
5. Roles and Responsibilities
6. Lawful Bases for Processing
Personal data is processed only where an appropriate lawful basis exists under applicable law, such as performance of a contract, compliance with a legal obligation, legitimate interests (properly balanced), or consent where required or appropriate.
Where Skoolfly processes data on behalf of a school as controller, the school determines and documents the lawful basis for that processing.
7. Data Subject Rights
Subject to applicable law, individuals may have rights to information, access, correction, erasure, restriction, portability, objection and withdrawal of consent.
Requests are processed in accordance with the Privacy Policy and applicable procedures. Where data is controlled by a school, requests may be referred to the relevant school or handled according to its documented instructions.
8. Data Protection by Design and Default
Privacy considerations are incorporated during design and development of features.
Default settings favour privacy, for example by limiting data collection and sharing by default.
Data minimisation, access controls and secure processing are applied from the start.
New features are assessed for data protection impact before release where required.
9. Data Protection Impact Assessments
Where a processing activity is likely to result in a high risk to individuals, Skoolfly carries out a Data Protection Impact Assessment (DPIA) to identify and mitigate risks before processing begins, in line with applicable law.
10. Records of Processing
Skoolfly maintains appropriate documentation of its processing activities, including categories of data, purposes, recipients, retention and security. This documentation is kept up to date and supports transparency and accountability.
11. Security of Personal Data
Personal data is protected by technical and organisational measures described in the Information Security Policy, including access controls, encryption in transit and at rest where appropriate, logging, backups and incident response procedures.
12. Personal Data Breaches
Suspected personal data breaches are handled under the Incident Response Policy. This includes containment, investigation, risk assessment, documentation, and notification to regulators and affected individuals where required by applicable law.
13. International Transfers
Where personal data is transferred outside Nigeria or made accessible across borders, Skoolfly assesses the circumstances and applies safeguards required by applicable Nigerian law and, where applicable, GDPR/UK GDPR requirements, including contractual safeguards.
14. Third-Party Processors
Personal data may be entrusted to third parties only where necessary and under appropriate contractual terms, including data processing and confidentiality obligations, in accordance with the Third-Party / Vendor Security Policy.
15. Training and Awareness
Personnel who handle personal data receive training on data protection obligations, this Policy and the Privacy Policy, and are kept aware of relevant changes.
16. Compliance and Enforcement
Non-compliance with this Policy may result in corrective action, including disciplinary or contractual measures. Compliance is monitored through reviews, audits and incident learnings.
17. Review and Contact
This Policy is reviewed at least annually or when significant changes to processing, law or technology occur.
Questions and privacy requests may be directed to info@skoolfly.com or the Data Protection Officer.
