Privacy

Privacy
Policy.

Last updated: May 2026dpo@edupro.ng

Your privacy matters to us. This policy describes how EduPro collects, uses, and protects information about schools, staff, and students.

1. Introduction

EduPro Technologies Ltd ("we", "us", "EduPro") respects your privacy. This Privacy Policy explains what personal data we collect, how we use it, and your rights. We comply with the Nigeria Data Protection Act (NDPA) 2023 and applicable international standards.

2. Data We Collect

We collect: (a) Account data — school name, subdomain, admin email, password hash; (b) User data — staff and student names, email addresses, roles, profile photos; (c) Academic data — attendance records, exam submissions and scores, timetable entries; (d) Payment data — billing references, amounts, subscription status (full card details are handled by Paystack/Flutterwave and never stored by EduPro); (e) Usage data — log files, IP addresses, browser type, and feature usage metrics for platform improvement.

3. How We Use Your Data

We use your data to: provide and improve the Service; process payments; send transactional emails and SMS; generate AI insights such as study plans and exam analytics; comply with legal obligations; investigate security incidents; and communicate product updates (you may unsubscribe at any time).

4. Data Isolation

Each school's data is stored in a shared database with strict row-level tenant isolation using a tenant_id column. Queries are scoped by tenant_id in every request, enforced at the application and query level. No school can ever read another school's data.

5. Third-Party Services

We use: Paystack and Flutterwave for payment processing; SendGrid for transactional email; Termii for SMS notifications; AWS S3 for document storage; and AI models (Claude API by Anthropic) for intelligent features. These providers are contractually bound to process data only as instructed by EduPro.

6. Data Retention

We retain account and academic data for the duration of your subscription plus 12 months after termination, after which it is permanently deleted unless required by law. Payment records are retained for 7 years for tax compliance. You may request early deletion via legal@edupro.ng.

7. Your Rights

You have the right to: access the personal data we hold about you; correct inaccurate data; request deletion of your data; object to processing; and receive a copy of your data in a portable format. Submit requests to legal@edupro.ng. We will respond within 30 days.

8. Security

We protect data with: AES-256 encryption at rest; TLS 1.3 in transit; bcrypt password hashing; JWT tokens with short expiry and refresh rotation; rate limiting; and regular penetration testing. We maintain an immutable audit log for sensitive operations.

9. Children's Privacy

EduPro is used to manage student records including children under 13. School administrators are responsible for obtaining appropriate parental consent before entering student data. EduPro does not market to or knowingly collect data directly from children without school-administrator intermediation.

10. Changes to This Policy

We will notify you of material changes by email and in-app notice at least 14 days in advance. Continued use after the effective date constitutes acceptance.

11. Contact

Data Protection Officer: dpo@edupro.ng | EduPro Technologies Ltd, Lagos, Nigeria.