Skip to content

Privacy

How this platform handles school and student data.

Last updated 26 September 2026

Who controls the data

Your school is the controller of its records; Darasio processes them on the school’s instructions. That distinction matters in practice: we cannot give a parent, a relative or anyone else access to a child’s records without the school’s authorisation, and requests about a specific child should go to the school.

What we collect

  • School details: name, country, contact information, branding, academic structure.
  • Staff and guardian accounts: name, email, phone, role, and a password stored only as a hash.
  • Student records: the fields your school chooses to keep, which may include date of birth, photograph, guardians, address and — where your school records them — medical or emergency notes.
  • Academic records: attendance, marks, results, assignments and submissions.
  • Financial records: fees charged, payments received and receipts issued.
  • Where the AI tutor is enabled: the student’s questions and the tutor’s replies, the topics engaged with, and usage counts.
  • Technical records: sign-in times, device description and IP address, kept for security and to let you manage your own sessions.

What we do not do

  • We do not sell data, and we do not share it with advertisers.
  • We do not use children’s data to build advertising profiles.
  • We do not use your school’s data to train AI models.
  • We do not let one school see another school’s data — this is enforced in the database, not only in the application.

Children’s data

We collect the minimum a school needs to operate, and sensitive categories are permissioned separately — a bursar who can bill a family cannot read that child’s medical notes. AI tutor conversations have a retention period the school sets, after which they are deleted. Teachers see which topics a class struggles with, not individual students’ messages.

Where a student appears to be at risk, the safety system routes the conversation to the school’s designated safeguarding staff. It does not attempt to assess or diagnose the child.

Your rights

  • Export: your school can export its records at any time.
  • Correction: records can be corrected in the application, and changes to marks and payments are logged.
  • Deletion: your school can request deletion of a record or of the whole account, subject to any period it must keep records for by law.
  • Access: a guardian may see the categories of their child’s data the school has permitted for them.

Requirements differ by country. Where your deployment’s jurisdiction imposes additional duties — Nigeria’s NDPA, Kenya’s Data Protection Act, South Africa’s POPIA and others — the platform’s retention, consent and export settings are configurable to meet them, and your school is responsible for configuring them correctly for where it operates.

Security

  • Encrypted transport, and payment and AI provider secrets encrypted at rest.
  • Passwords stored with a memory-hard hash, never in plain text.
  • Optional two-factor authentication, required by default for administrative and finance roles.
  • An audit trail of administrative actions, with grade and payment changes recorded in detail.
  • Automated backups with a tested restore procedure.

Contact

Questions about this policy: support@darasio.com.