Compliance

Meeting regulatory and data protection standards

SchoolPilot is designed to help schools meet their regulatory obligations while providing a modern, efficient platform. We align our practices with applicable data protection laws and education sector requirements to support compliant school operations.

1. Data Protection Framework

SchoolPilot processes personal data in compliance with applicable data protection regulations, including the Nigeria Data Protection Regulation (NDPR), the General Data Protection Regulation (GDPR) for users in the European Economic Area, and other relevant local data protection laws.

2. Children's Privacy Compliance

SchoolPilot processes children's data exclusively in an educational context, under the authority and supervision of schools. We implement the following safeguards:

3. Lawful Basis for Processing

We process personal data based on one or more of the following lawful bases: (a) Contractual Necessity — processing required to provide the Service under our agreement with the School; (b) Legitimate Interest — processing necessary for the safe and efficient operation of the platform, such as security monitoring and fraud prevention; (c) Consent — where required by applicable law, particularly for communications and optional features; (d) Legal Obligation — processing required to comply with applicable laws and regulations.

4. Data Subject Rights

We support the exercise of data subject rights as required by applicable law, including: the right to access personal data held about them; the right to rectification of inaccurate data; the right to erasure (right to be forgotten), subject to legal retention requirements; the right to restrict processing in certain circumstances; the right to data portability in a structured, machine-readable format; the right to object to processing based on legitimate interests.

1. Data Protection Framework

SchoolPilot processes personal data in compliance with applicable data protection regulations, including the Nigeria Data Protection Regulation (NDPR), the General Data Protection Regulation (GDPR) for users in the European Economic Area, and other relevant local data protection laws.

We operate under a data controller / data processor model: Schools are the data controllers who determine what data is collected and how it is used within the platform. SchoolPilot acts as a data processor, processing School Data solely on behalf of and under the instructions of the School.

We maintain Data Processing Agreements (DPAs) that define the scope, purpose, and duration of data processing, as well as the obligations of both parties regarding data protection.

2. Children's Privacy Compliance

SchoolPilot processes children's data exclusively in an educational context, under the authority and supervision of schools. We implement the following safeguards:

Parental Consent: Schools are responsible for obtaining necessary parental or guardian consent before entering student data into the platform. We provide tools and documentation to support schools in this process.

Minimal Data Collection: We only process student data that is necessary for educational purposes — academic records, attendance, report cards, and school communications. We do not collect student data for marketing or advertising.

Age-Appropriate Access: Student accounts use school-issued credentials (admission number + PIN) rather than email/password, eliminating the need for children to maintain personal email accounts. Student access is limited to age-appropriate features.

No Behavioral Tracking: We do not track students for behavioral profiling, targeted advertising, or any purpose unrelated to the educational services provided through the platform.

These practices align with the principles of the Children's Online Privacy Protection Act (COPPA), the GDPR's special provisions for children's data (Article 8), and the NDPR's requirements for processing children's personal data.

3. Lawful Basis for Processing

We process personal data based on one or more of the following lawful bases: (a) Contractual Necessity — processing required to provide the Service under our agreement with the School; (b) Legitimate Interest — processing necessary for the safe and efficient operation of the platform, such as security monitoring and fraud prevention; (c) Consent — where required by applicable law, particularly for communications and optional features; (d) Legal Obligation — processing required to comply with applicable laws and regulations.

Schools are responsible for ensuring they have an appropriate lawful basis for the data they enter into the platform, particularly regarding student and parent data.

4. Data Subject Rights

We support the exercise of data subject rights as required by applicable law, including: the right to access personal data held about them; the right to rectification of inaccurate data; the right to erasure (right to be forgotten), subject to legal retention requirements; the right to restrict processing in certain circumstances; the right to data portability in a structured, machine-readable format; the right to object to processing based on legitimate interests.

For school-managed accounts, data subject requests should be directed to the school, which controls the data. Schools can fulfill most requests directly through the platform's administrative tools. For platform-level requests, contact support@schoolpilot.xyz.

We respond to verified data subject requests within 30 days, or as otherwise required by applicable law.

5. Data Retention and Deletion

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, and support legitimate operational needs.

Active account data is retained for the duration of the school's subscription. Upon account termination, Schools have a 90-day window to export their data. After this period, all School Data is permanently and irreversibly deleted from our systems, including backups, within 30 additional days.

Aggregated, anonymized data that cannot be linked to any individual may be retained indefinitely for analytics and product improvement purposes.

Schools can request immediate deletion of specific records at any time through the platform's administrative interface or by contacting our support team.

6. International Data Transfers

SchoolPilot's infrastructure providers may process data in multiple jurisdictions. When personal data is transferred outside the user's country of residence, we ensure appropriate safeguards are in place.

For transfers from the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, and we assess the data protection laws of the recipient country.

Our infrastructure providers (Vercel, Supabase, Cloudflare) maintain their own compliance certifications and transfer mechanisms, which we review as part of our vendor assessment process.

7. Record Keeping and Audit Trail

The platform maintains structured records of key operations including: user account creation and role assignments; academic record publication and modifications; fee transactions and payment records; communication history (announcements, messages); result publication and access logs.

These records support schools' compliance obligations by providing a traceable audit trail of administrative actions. Schools can access their audit records through the platform's reporting tools.

8. Third-Party Vendor Compliance

We carefully evaluate third-party service providers before integration and require them to meet our data protection standards. Our key vendors include:

Supabase (database and authentication) — SOC 2 Type II certified, GDPR compliant. Vercel (application hosting) — SOC 2 Type II certified, GDPR compliant. Cloudflare R2 (file storage) — SOC 2 Type II certified, GDPR compliant. Payment processors — PCI DSS compliant for handling payment card data.

We maintain a register of all third-party processors and review their compliance status at least annually.

9. Education Sector Requirements

SchoolPilot is designed to support compliance with education sector regulations, including: structured academic record keeping with term-based organization; traceable result computation and publication workflows; role-based access that aligns with institutional hierarchies; parent and guardian communication channels that respect school communication policies.

Schools remain responsible for ensuring their use of the platform complies with local education authority requirements, accreditation standards, and institutional policies.

10. Google Play and Apple App Store Compliance

Our mobile applications comply with Google Play Store and Apple App Store policies, including: accurate representation of app functionality and features; transparent disclosure of data collection and usage practices through app store privacy labels; compliance with Families Policy requirements for apps that handle children's data; appropriate content ratings reflecting the educational nature of the app; clear user consent mechanisms before data collection.

Our app does not contain ads, does not share data with advertising networks, and does not engage in any practices that violate platform developer policies.

11. Continuous Compliance

We regularly review and update our compliance practices to reflect changes in applicable laws, regulations, and industry standards. Our compliance efforts include: periodic privacy impact assessments for new features and data processing activities; regular review of data processing agreements with third-party providers; employee training on data protection and security practices; documentation of compliance measures and incident response procedures.