Terms & Privacy Policy

Last Updated: December 24, 2024

Introduction

Welcome to Schooly ERP ("we," "our," or "us"). This Privacy Policy and Terms of Service explains how we collect, use, disclose, and safeguard your information when you use our mobile application and services. We are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and the Kenya Data Protection Act, 2019.

TERMS OF SERVICE

1. Acceptance of Terms

By accessing or using Schooly ERP, you agree to be bound by these Terms of Service. If you do not agree to these terms, please do not use our services.

2. User Accounts

2.1. You must provide accurate, current, and complete information during registration.

2.2. You are responsible for maintaining the confidentiality of your account credentials.

2.3. You must notify us immediately of any unauthorized access to your account.

2.4. Schools are responsible for managing user access and permissions within their organization.

3. Acceptable Use

You agree not to:

Use the service for any illegal purpose

Violate any laws in your jurisdiction

Infringe on intellectual property rights

Transmit harmful code or malware

Attempt to gain unauthorized access to our systems

Harass, abuse, or harm other users

Share false or misleading information

4. Intellectual Property

4.1. All content, features, and functionality of Schooly ERP are owned by us and protected by international copyright, trademark, and other intellectual property laws.

4.2. You retain ownership of any content you upload to the platform.

4.3. By uploading content, you grant us a license to use, store, and display that content as necessary to provide our services.

5. Service Availability

5.1. We strive to maintain 99.9% uptime but do not guarantee uninterrupted service.

5.2. We reserve the right to modify or discontinue services with reasonable notice.

5.3. Scheduled maintenance will be communicated in advance when possible.

6. Termination

6.1. We may terminate or suspend your account immediately for violations of these terms.

6.2. You may terminate your account at any time by contacting us.

6.3. Upon termination, your right to use the service will immediately cease.

PRIVACY POLICY

1. Data Controller

Schooly ERP is the data controller responsible for your personal data. For data protection inquiries, contact us at: privacy@schoolyerp.com

2. Information We Collect

2.1. Personal Information:

Name, email address, phone number

School affiliation and role

Student information (for parents and teachers)

Academic records and performance data

Attendance and behavior records

Financial information (fee payments)

2.2. Technical Information:

Device information and identifiers

IP address and location data

Usage data and analytics

Log files and crash reports

2.3. Biometric Data (Optional):

Fingerprint or facial recognition data for authentication

Stored locally on your device only

Never transmitted to our servers

3. Legal Basis for Processing (GDPR)

We process your data based on:

Consent: You have given explicit consent

Contract: Processing is necessary for service delivery

Legal Obligation: Compliance with education regulations

Legitimate Interests: Improving our services and security

4. How We Use Your Information

We use your information to:

Provide and maintain our services

Process transactions and send notifications

Communicate important updates

Improve user experience and functionality

Ensure security and prevent fraud

Comply with legal obligations

Generate analytics and reports

5. Data Sharing and Disclosure

We may share your information with:

Your school administrators and authorized staff

Parents (for student information)

Service providers (cloud hosting, analytics)

Law enforcement when legally required

Third parties with your explicit consent

We do NOT sell your personal data to third parties.

6. Data Security

We implement industry-standard security measures:

End-to-end encryption for data transmission

Encrypted data storage

Regular security audits and updates

Access controls and authentication

Employee training on data protection

Incident response procedures

7. Data Retention

7.1. We retain personal data only as long as necessary for the purposes stated.

7.2. Student records are retained according to educational regulations (typically 7 years).

7.3. Financial records are retained for 7 years as per Kenya tax laws.

7.4. You may request deletion of your data subject to legal requirements.

8. Your Rights (GDPR & Kenya DPA)

You have the right to:

Access your personal data

Rectify inaccurate data

Request data deletion ("right to be forgotten")

Object to data processing

Data portability

Withdraw consent at any time

Lodge a complaint with supervisory authorities

To exercise these rights, contact us at:

Email: privacy@schoolyerp.com

Email: support@schoolyerp.com

Phone: +254 722 317006 / +254 713 197824

9. Children's Privacy

9.1. We collect student data only with parental/guardian consent.

9.2. Parents have the right to review and request deletion of their child's data.

9.3. We implement additional safeguards for children's data.

9.4. Student data is only accessible to authorized school staff and parents.

10. International Data Transfers

10.1. Data may be transferred to and processed in countries outside Kenya.

10.2. We ensure adequate safeguards are in place for such transfers.

10.3. We comply with GDPR requirements for international transfers.

11. Cookies and Tracking

11.1. We use cookies and similar technologies to enhance user experience.

11.2. You can control cookie preferences in your device settings.

11.3. Analytics cookies help us improve our services.

12. Push Notifications

12.1. We send push notifications for important updates and alerts.

12.2. You can disable notifications in your device settings.

12.3. Notification preferences can be managed in the app settings.

13. Data Breach Notification

13.1. We will notify affected users within 72 hours of discovering a data breach.

13.2. We will report breaches to relevant authorities as required by law.

13.3. Notifications will include the nature of the breach and remedial actions.

14. Third-Party Services

We use the following third-party services:

Cloud hosting providers (AWS, Google Cloud)

Analytics services (Firebase Analytics)

Payment processors (M-Pesa, Stripe)

Email service providers

Push notification services (Expo)

These services have their own privacy policies and data protection measures.

15. Updates to This Policy

15.1. We may update this policy from time to time.

15.2. We will notify you of significant changes via email or in-app notification.

15.3. Continued use after changes constitutes acceptance.

16. Contact Information

For questions about these terms or privacy concerns:

Email: privacy@schoolyerp.com

Email: support@schoolyerp.com

Phone: +254 722 317006 / +254 713 197824

Address: Off North Airport Road, Kandia Building Suit 1, Off Mombasa road, Nairobi, Kenya

17. Supervisory Authority

Kenya: Office of the Data Protection Commissioner

Website: www.odpc.go.ke

Email: info@odpc.go.ke

18. Governing Law

These terms are governed by the laws of Kenya. Any disputes shall be resolved in Kenyan courts.

19. Severability

If any provision of these terms is found to be unenforceable, the remaining provisions will remain in full force and effect.

20. Entire Agreement

These terms constitute the entire agreement between you and Schooly ERP regarding the use of our services.