Legal & Compliance

Data Protection & Privacy Policy

The internal data protection governance and safeguards that Skoolfly applies to personal data.

1. Policy Statement

Skoolfly is committed to the lawful, fair and transparent processing of personal data. This Policy describes the internal governance, principles and controls Skoolfly applies to protect personal data, and complements the customer-facing Privacy Policy.

2. Purpose and Scope

The purpose of this Policy is to ensure that personal data is processed lawfully, kept secure, and handled in a way that respects the rights of individuals, including students, parents, teachers, staff and other users. It applies to all Skoolfly personnel, systems and processing activities.

3. Relationship to the Privacy Policy

The user-facing Privacy Policy explains to individuals how their data is collected, used and protected and how they can exercise their rights.

This Data Protection & Privacy Policy sets out the internal standards, roles and procedures that make those commitments possible. Where schools act as data controllers, Skoolfly supports their obligations through appropriate agreements and documented controls.

4. Data Protection Principles

Skoolfly's processing of personal data is guided by the following principles.

Lawfulness, fairness and transparency.

Purpose limitation: data is collected for specified, explicit and legitimate purposes.

Data minimisation: only data needed for the purpose is collected and processed.

Accuracy: reasonable steps are taken to keep data accurate and up to date.

Storage limitation: data is kept only as long as necessary, in line with the Data Retention Policy.

Integrity and confidentiality: data is processed securely and protected against unauthorised access or loss.

Accountability: Skoolfly maintains documentation and controls to demonstrate compliance.

5. Roles and Responsibilities

Data Protection OfficerOversees data protection, handles privacy requests and advises on compliance.
ManagementEnsure adequate resources and controls for data protection.
PersonnelHandle personal data in accordance with this Policy and applicable law.
Engineering & ProductEmbed data protection by design and default into systems.
SchoolsAct as controllers for data they submit and comply with their own obligations.

6. Lawful Bases for Processing

Personal data is processed only where an appropriate lawful basis exists under applicable law, such as performance of a contract, compliance with a legal obligation, legitimate interests (properly balanced), or consent where required or appropriate.

Where Skoolfly processes data on behalf of a school as controller, the school determines and documents the lawful basis for that processing.

7. Data Subject Rights

Subject to applicable law, individuals may have rights to information, access, correction, erasure, restriction, portability, objection and withdrawal of consent.

Requests are processed in accordance with the Privacy Policy and applicable procedures. Where data is controlled by a school, requests may be referred to the relevant school or handled according to its documented instructions.

8. Data Protection by Design and Default

Privacy considerations are incorporated during design and development of features.

Default settings favour privacy, for example by limiting data collection and sharing by default.

Data minimisation, access controls and secure processing are applied from the start.

New features are assessed for data protection impact before release where required.

9. Data Protection Impact Assessments

Where a processing activity is likely to result in a high risk to individuals, Skoolfly carries out a Data Protection Impact Assessment (DPIA) to identify and mitigate risks before processing begins, in line with applicable law.

10. Records of Processing

Skoolfly maintains appropriate documentation of its processing activities, including categories of data, purposes, recipients, retention and security. This documentation is kept up to date and supports transparency and accountability.

11. Security of Personal Data

Personal data is protected by technical and organisational measures described in the Information Security Policy, including access controls, encryption in transit and at rest where appropriate, logging, backups and incident response procedures.

12. Personal Data Breaches

Suspected personal data breaches are handled under the Incident Response Policy. This includes containment, investigation, risk assessment, documentation, and notification to regulators and affected individuals where required by applicable law.

13. International Transfers

Where personal data is transferred outside Nigeria or made accessible across borders, Skoolfly assesses the circumstances and applies safeguards required by applicable Nigerian law and, where applicable, GDPR/UK GDPR requirements, including contractual safeguards.

14. Third-Party Processors

Personal data may be entrusted to third parties only where necessary and under appropriate contractual terms, including data processing and confidentiality obligations, in accordance with the Third-Party / Vendor Security Policy.

15. Training and Awareness

Personnel who handle personal data receive training on data protection obligations, this Policy and the Privacy Policy, and are kept aware of relevant changes.

16. Compliance and Enforcement

Non-compliance with this Policy may result in corrective action, including disciplinary or contractual measures. Compliance is monitored through reviews, audits and incident learnings.

17. Review and Contact

This Policy is reviewed at least annually or when significant changes to processing, law or technology occur.

Questions and privacy requests may be directed to info@skoolfly.com or the Data Protection Officer.