EducaSphere
Trust & Transparency

Privacy Protocol

Our commitment to protecting institutional integrity, staff privacy, and student data in a global digital environment.

Version 2.4.0Last Updated: March 13, 2026

1. Data Sovereignty & Tenancy Isolation

EducaSphere operates on a strict multi-tenant architecture. Every byte of institutional data is isolated at the database layer using Row-Level Security (RLS). The Institution ('The Tenant') remains the sole Data Controller. EducaSphere acts exclusively as a Data Processor under your direction. We do not aggregate institutional data for our own commercial purposes.

2. Comprehensive Data Collection

We process four categories of data: (a) Institutional Data (Finance, Assets, HR); (b) Personnel Data (Staff records, payroll, qualifications); (c) Student Data (Academic results, attendance, behavior, and where enabled, health/IEP records); and (d) Technical Metadata (Audit logs, access patterns, device fingerprints).

3. Lawful Basis for Processing

We process data primarily for the performance of the educational contract between the Institution and its stakeholders. This includes statutory financial reporting, academic certification, and student safeguarding. For health or special education data (IEP), we rely on the explicit consent mechanisms managed within the platform.

4. Global Sub-processors

EducaSphere utilizes Tier-1 cloud infrastructure (AWS/GCP) and regional payment gateways (Flutterwave, Paystack, M-Pesa). All sub-processors are vetted for SOC 2 and ISO 27001 compliance. We maintain a live Sub-processor Registry available to Institutional DPOs upon request.

5. Retention & Destruction

Data is retained according to the Institution's configured retention schedule. Upon account termination, we initiate a 60-day 'Cooling Period' for data export. Following this, an automated cryptographic erasure process is triggered across primary and secondary backup volumes.

6. Data Subject Rights (DSAR)

The platform includes native tools for fulfilling GDPR/DPA rights, including the Right to Access, Right to Rectification, and the Right to Portability. These tools allow Institutional Admins to generate complete student data archives in under 5 minutes.

7. Children's Privacy & Safeguarding

As an institutional provider, EducaSphere treats all student data with the highest level of protection. We comply with international safeguarding standards (including COPPA-equivalent principles). Student data is used solely for educational and administrative purposes directed by the School. We do not build marketing profiles on minors or serve advertisements within the platform.

8. Website Cookies & Marketing Data

For visitors to our public marketing site, we use cookies and tracking technologies (e.g., Google Analytics, CRM pixels) to analyze traffic and improve user experience. You may opt-out of non-essential cookies via your browser settings. Contact data submitted via our 'Book a Demo' or 'Contact Sales' forms is used exclusively for institutional outreach and can be deleted upon request.

9. Security Safeguards

Encryption

AES-256 for data-at-rest and TLS 1.3 for transit.

Isolation

Row-Level Security (RLS) per institutional tenant.

Auditing

Immutable logs for every administrative action.

Compliance

Regular third-party SOC 2 and GDPR audits.

Contact Our Global DPO

For questions regarding our privacy protocol, international data transfers, or regional compliance, please contact our Data Protection Office.

Trust Portal: trust.educasphere.com