Privacy
How this platform handles school and student data.
Last updated 26 September 2026
Who controls the data
Your school is the controller of its records; Darasio processes them on the school’s instructions. That distinction matters in practice: we cannot give a parent, a relative or anyone else access to a child’s records without the school’s authorisation, and requests about a specific child should go to the school.
What we collect
- School details: name, country, contact information, branding, academic structure.
- Staff and guardian accounts: name, email, phone, role, and a password stored only as a hash.
- Student records: the fields your school chooses to keep, which may include date of birth, photograph, guardians, address and — where your school records them — medical or emergency notes.
- Academic records: attendance, marks, results, assignments and submissions.
- Financial records: fees charged, payments received and receipts issued.
- Where the AI tutor is enabled: the student’s questions and the tutor’s replies, the topics engaged with, and usage counts.
- Technical records: sign-in times, device description and IP address, kept for security and to let you manage your own sessions.
What we do not do
- We do not sell data, and we do not share it with advertisers.
- We do not use children’s data to build advertising profiles.
- We do not use your school’s data to train AI models.
- We do not let one school see another school’s data — this is enforced in the database, not only in the application.
Children’s data
We collect the minimum a school needs to operate, and sensitive categories are permissioned separately — a bursar who can bill a family cannot read that child’s medical notes. AI tutor conversations have a retention period the school sets, after which they are deleted. Teachers see which topics a class struggles with, not individual students’ messages.
Where a student appears to be at risk, the safety system routes the conversation to the school’s designated safeguarding staff. It does not attempt to assess or diagnose the child.
Your rights
- Export: your school can export its records at any time.
- Correction: records can be corrected in the application, and changes to marks and payments are logged.
- Deletion: your school can request deletion of a record or of the whole account, subject to any period it must keep records for by law.
- Access: a guardian may see the categories of their child’s data the school has permitted for them.
Requirements differ by country. Where your deployment’s jurisdiction imposes additional duties — Nigeria’s NDPA, Kenya’s Data Protection Act, South Africa’s POPIA and others — the platform’s retention, consent and export settings are configurable to meet them, and your school is responsible for configuring them correctly for where it operates.
Security
- Encrypted transport, and payment and AI provider secrets encrypted at rest.
- Passwords stored with a memory-hard hash, never in plain text.
- Optional two-factor authentication, required by default for administrative and finance roles.
- An audit trail of administrative actions, with grade and payment changes recorded in detail.
- Automated backups with a tested restore procedure.
Contact
Questions about this policy: support@darasio.com.
