Security & Compliance

Information Security Policy

How Skoolfly protects the confidentiality, integrity and availability of its systems and data.

1. Policy Statement

Skoolfly is committed to protecting the confidentiality, integrity and availability of the information and systems it manages on behalf of schools, students, parents, teachers and other users. This Information Security Policy establishes the framework of principles, responsibilities and controls that guide how Skoolfly safeguards its platform, data and people.

2. Purpose

The purpose of this policy is to protect Skoolfly's information assets from accidental or deliberate unauthorised access, disclosure, alteration, destruction or disruption, and to establish a consistent, risk-based approach to information security across the organisation.

This policy is the authority under which more specific security policies operate, including the Password Policy, Access Control Policy, Backup Policy, Incident Response Policy and Vulnerability Management Policy.

3. Scope

All information systems, networks, applications, servers and data owned or operated by Skoolfly.

All personal data, academic records and other sensitive information hosted on the Skoolfly platform.

All employees, contractors, interns, consultants and other personnel who access Skoolfly systems.

Third parties and vendors that process data or provide technology services to Skoolfly.

All physical locations and equipment that support Skoolfly operations.

Schools and users are expected to cooperate with the controls described in this policy where they interact with the platform.

4. Information Security Objectives

Protect personal and educational data against unauthorised access and misuse.

Maintain the confidentiality, integrity and availability of the platform and its data.

Prevent, detect and respond to security incidents in a timely manner.

Meet applicable legal, regulatory and contractual security requirements.

Build a culture of security awareness among employees and stakeholders.

Continuously improve security controls through review, testing and lessons learned.

5. Roles and Responsibilities

Information security is a shared responsibility. The following roles are responsible for implementing and enforcing this policy.

Security Owner / Data Protection OfficerOwns this policy, sets security direction, and oversees compliance.
Engineering & ProductDesign, build and operate the platform securely, including secure coding and deployment.
DevOps / InfrastructureMaintain secure infrastructure, access controls, backups, monitoring and patching.
People / HRManage employee onboarding, offboarding, training and confidentiality obligations.
All personnelFollow this policy and related procedures, report incidents, and protect information they handle.
Schools & UsersUse the platform responsibly, protect their own credentials, and cooperate with security controls.

6. Security Principles

Confidentiality: information is accessible only to those authorised to access it.

Integrity: information remains accurate, complete and unmodified without authorisation.

Availability: information and systems are available when needed.

Least privilege: users receive the minimum access required to perform their role.

Defence in depth: multiple layers of control protect each asset.

Risk-based approach: controls are proportionate to the sensitivity of data and likelihood of harm.

Accountability: ownership and responsibility for security are clearly assigned.

7. Information Classification

Information should be classified according to sensitivity so that appropriate controls are applied.

PublicInformation intended for public distribution with no access restrictions.
InternalNon-public information used for business operations, to be shared only on a need-to-know basis.
ConfidentialInformation that could cause harm if disclosed, including personal data of students, parents and staff.
RestrictedHighly sensitive information, such as credentials, security configuration and payment details, subject to strict access control.

8. Physical and Environmental Security

Office areas are access-controlled and visitor access is managed and supervised.

Equipment that stores confidential information is protected and handled carefully.

Servers and infrastructure rely on secure, reputable data-centre providers with appropriate physical and environmental controls.

Personnel are expected to lock or secure devices when unattended, especially when carrying confidential information.

9. Third-Party and Vendor Security

Third parties that process Skoolfly data or provide technology services must meet proportionate security requirements. Vendors are assessed, bound by appropriate contractual terms and monitored on a risk basis, as described in the Third-Party / Vendor Security Policy.

10. Incident Handling

All suspected security incidents, anomalies or breaches must be reported without delay. Incidents are handled in accordance with the Incident Response Policy, which defines detection, containment, investigation, notification and recovery steps.

11. Training and Awareness

Security awareness training is provided to employees and relevant contractors.

Training covers password safety, phishing, data handling, incident reporting and this policy.

Awareness is refreshed periodically and after significant security events.

12. Compliance and Enforcement

Compliance with this policy is mandatory. Failure to comply may result in corrective action, including disciplinary measures, suspension of access, or removal of contractual arrangements, in accordance with applicable law and employment or contract terms.

Compliance is reviewed periodically through internal checks, audits and security assessments.

13. Review

This policy is reviewed at least annually, or more frequently when significant changes to the platform, law or threat landscape require it. Review findings are documented and communicated as appropriate.

14. Contact

Questions about this policy and its implementation may be directed to info@skoolfly.com or the Data Protection Officer.