Skip to content

Theme

Legal

Privacy Policy

Effective 2026-05-12 · Last updated 2026-05-12

Privacy Policy

This Privacy Policy explains how Noria Technologies Ltd ("SchoolTrack", "we", "us", "our") collects, uses, shares, and protects personal data when you use the SchoolTrack platform (the "Service") or visit our websites.

We are committed to compliance with the Data Protection Act 2019 of Kenya (the "DPA") and guidance issued by the Office of the Data Protection Commissioner ("ODPC"). Where the Service is provided to a school or other institution, that institution is the data controller and we act as a data processor on its behalf.

This Policy uses the same definitions as our Terms of Service.


1. Our roles under the DPA

Context Our role Their role
A school using SchoolTrack to manage its learners and staff Data processor The school is the data controller
You browsing our public website, signing up, or contacting our sales team Data controller —
Our employees, candidates, and suppliers Data controller —

Where we act as a processor, our processing of personal data is governed by our agreement with the controller (the school). Data-subject requests in that context should normally be addressed to the school in the first instance; we will assist the school in responding within statutory timeframes.


2. Personal data we process

2.1 As a processor on behalf of schools

We process the categories of data the school's authorised users enter into the Service. These typically include:

  • Learner data — full name, date of birth, gender, nationality, photograph, admission number, KEMIS unique learner ID, guardian relationships, academic records (marks, rubrics, observation notes, portfolios), attendance, fee statements, medical profile (where the clinic module is in use), disciplinary records, transport allocations, boarding allocations, library loans;
  • Guardian and next-of-kin data — name, relationship, phone, email, address, ID/passport number, employment details, communication preferences;
  • Staff data — name, TSC number, contact details, role, employment terms, payroll details where the payroll module is in use, TPAD records where in use;
  • Visitor and security data — name, ID number, photograph, vehicle, time in/out, purpose of visit;
  • Communication records — SMS, WhatsApp, email, in-app messages sent through the Service, including delivery and read receipts.

2.2 As a controller for our own purposes

We collect:

  • Account data — name, work email, phone, job title, school affiliation;
  • Billing data — invoicing contact, M-Pesa transaction references, bank-transfer details, tax registration;
  • Usage data — pages visited, features used, device and browser type, IP address, approximate location (city), session durations;
  • Support and sales correspondence — emails, call notes, demo recordings (with consent), chat transcripts;
  • Marketing data — newsletter subscriptions, event attendance, content downloads, marketing-preference choices;
  • Job-applicant data — CV, application materials, interview notes (only where you apply for a role with us).

2.3 Special-category and sensitive data

The Service may, at the controlling school's discretion, be used to process health, biometric, or other special-category data about learners (e.g. clinic visit logs, allergies, photographs of work). Such data is processed only on documented instructions from the school and only where the school has a lawful basis (typically guardian consent or, in some cases, vital interests).

We never process financial-account credentials belonging to data subjects (e.g. M-Pesa PINs, bank passwords). We process only the transaction metadata returned by payment providers.


3. Lawful bases for processing (as controller)

Where we act as a controller, we rely on:

Purpose Lawful basis (s. 30 DPA)
Providing the Service to your school Contract
Sending product-update emails to existing customers Legitimate interests
Sending marketing to non-customers Consent (opt-in)
Responding to sales enquiries Legitimate interests / steps prior to contract
Tax, accounting, audit records Legal obligation
Defending legal claims Legitimate interests
Recruiting Steps prior to contract / consent

You can withdraw consent at any time by emailing [email protected]. Withdrawal does not affect processing carried out before the withdrawal.


4. How we use personal data

We use personal data to:

  1. Provide, operate, secure, monitor, and improve the Service;
  2. Authenticate users and prevent fraud or abuse;
  3. Communicate with you about your account, support requests, security alerts, and material product changes;
  4. Issue invoices, take payment, and chase overdue amounts;
  5. Comply with our legal obligations (tax, anti-money-laundering, lawful regulator requests);
  6. Conduct internal research and product analytics, using pseudonymised or aggregated data where possible;
  7. Train our own customer-support staff on de-identified case examples;
  8. With the school's instruction, send communications to guardians (fee reminders, attendance alerts, school notices) via SMS, WhatsApp, or email through the school's configured channels;
  9. Where AI features are enabled, draft suggestions for teachers and bursars, which they review before sending. AI inputs are not used to train any third-party general-purpose model.

We do not:

  • Sell personal data;
  • Use Customer Data to train our own machine-learning models without explicit written agreement from the controlling school;
  • Process personal data for purposes outside those listed here or in the Service agreement, except where the law requires it.

5. Sharing and disclosure

We share personal data only with:

5.1 Sub-processors

We engage carefully selected sub-processors to deliver the Service. The current list is maintained at schooltrack.co.ke/sub-processors and includes (illustrative, not exhaustive):

Category Vendor Purpose Region
Cloud hosting Enterprise cloud infrastructure provider Application hosting, storage Africa (primary), EU (encrypted backup)
Email delivery Postmark or Resend Transactional and marketing email EU / US
SMS Africa's Talking Bulk SMS delivery Kenya
Messaging Meta Platforms (WhatsApp Business API) WhatsApp delivery Global
Payments Safaricom (Daraja / M-Pesa) Payment processing Kenya
Error monitoring Sentry Crash reports, performance data EU / US
AI features Anthropic and/or Google (Gemini) AI-assisted drafting US / EU

We require each sub-processor to be bound by a written data-processing agreement with obligations no less protective than those in this Policy and the DPA. We will provide thirty (30) days' advance notice before adding or replacing a sub-processor that processes Learner Data, and customers may object on reasonable grounds.

5.2 Schools (when we act as controller)

Where you contact us about a particular school, we may share your enquiry with that school as part of providing them with sales support.

5.3 Professional advisors

Our lawyers, auditors, and bankers, under duties of confidentiality.

5.4 Regulators and law enforcement

We disclose personal data where required by Kenyan law, court order, or a lawful regulator request. Where lawful, we notify the controlling school before disclosing Learner Data.

5.5 Corporate transactions

If we are involved in a merger, acquisition, sale of assets, or insolvency proceeding, personal data may be transferred. We will require any successor to honour this Policy and will notify you of any material change.


6. International transfers

Some sub-processors are located outside Kenya. Where personal data is transferred outside Kenya we rely on the safeguards permitted under Section 49 of the DPA, including:

  • Adequacy decisions by the ODPC;
  • Appropriate safeguards such as standard contractual clauses;
  • Specific consent for the transfer, where appropriate;
  • Necessity for performance of the contract.

The current locations of our infrastructure and sub-processors are summarised in Section 5.1. Customers may request a copy of our cross-border transfer assessment by emailing [email protected].


7. Retention

We retain personal data only as long as necessary for the purposes set out in this Policy and to comply with our legal obligations.

Category Retention period
Active customer Service Data For the duration of the customer's subscription
Data after termination of subscription 30 days for export, then deleted unless the customer requests longer retention or law requires it
Backups containing Customer Data 30 days rolling
Sales and marketing data Until you withdraw consent or 36 months of inactivity
Billing and tax records 7 years from the end of the relevant tax year (Kenya Income Tax Act)
Support correspondence 36 months from closure
Job-applicant data (unsuccessful) 12 months from decision
Security and audit logs 24 months minimum, longer where investigations require it

Customers may instruct us, via a Data Processing Addendum, to apply shorter retention periods to specific data categories.


8. Your rights as a data subject

Subject to the DPA you have the right to:

  • Be informed about how we process your personal data (this Policy);
  • Access the personal data we hold about you;
  • Correct or update inaccurate personal data;
  • Delete your personal data where there is no overriding lawful reason for us to keep it;
  • Restrict or object to processing in certain circumstances;
  • Portability — receive your personal data in a structured, commonly used, machine-readable format;
  • Withdraw consent at any time, where processing is based on consent;
  • Lodge a complaint with the ODPC at [email protected] or odpc.go.ke.

To exercise any of these rights:

  • If we act as a processor (i.e. the data is in a school's account), please contact your school first. We will assist the school in responding within the statutory timeframe.
  • If we act as a controller, email [email protected]. We will respond within thirty (30) days, or notify you sooner if we need more time on complex requests.

We may need to verify your identity before responding. We do not charge for reasonable requests; manifestly unfounded or excessive requests may attract a reasonable fee or be refused, as permitted by the DPA.


9. Children's data

The Service is used predominantly to process data about learners, many of whom are children. We do not knowingly collect personal data directly from children for our own purposes (i.e. when acting as a controller).

When acting as a processor:

  • Schools are responsible for obtaining all required parental consents;
  • We provide tools (consent capture, versioning, withdrawal logging) for schools to administer that consent;
  • Where AI features process learner data, the controlling school decides whether to enable those features and informs guardians as required.

If you believe we have inadvertently received data about a child outside the processor context, please email [email protected] and we will delete it.


10. Security

We use commercially reasonable technical and organisational measures to protect personal data, including:

  • TLS 1.2+ encryption in transit;
  • Encryption at rest for primary stores and backups (AES-256);
  • Least-privilege role-based access controls within the platform;
  • Multi-tenant data isolation via row-level scoping and access policies;
  • Audit logging on sensitive operations;
  • Regular security updates and dependency scanning;
  • Segregated production and development environments;
  • Penetration testing on a recurring schedule (frequency increases with customer volume).

No system is perfectly secure. If you discover a vulnerability please report it responsibly to [email protected] and allow us a reasonable period to remediate before public disclosure.


11. Breach notification

If we become aware of a breach affecting personal data, we will:

  • Notify the controlling school without undue delay and in any case within seventy-two (72) hours of becoming aware, as required by Section 43 of the DPA;
  • Provide all information the school reasonably requires to comply with its own notification obligations to the ODPC and affected data subjects;
  • Cooperate fully with the school's investigation and remediation.

Where we act as a controller, we notify the ODPC and affected data subjects directly within the same timeframe.


12. Cookies and tracking

Our public website uses a minimal set of cookies:

  • Strictly necessary — session, CSRF token, theme preference. No consent required.
  • Analytics — anonymised page-view counts. We do not use third-party advertising trackers.
  • Sales chat — only loaded when you actively open it.

We do not load any third-party advertising or behavioural-tracking cookies.

The Service itself (the school-facing application) uses only strictly necessary cookies.

You can refuse non-essential cookies in your browser settings; the site will continue to work.


13. Marketing communications

We send product update emails to active customers as part of the service relationship. You may opt out of newsletters and product-marketing emails at any time using the unsubscribe link in any such email or by emailing [email protected]. We will continue to send essential service notices (billing, security alerts, material changes to this Policy) regardless of marketing preferences.


14. Automated decision-making

The Service does not make automated decisions producing legal or similarly significant effects on data subjects without meaningful human review. AI features (rubric drafting, comment generation, fee-default scoring) produce suggestions that an authorised user must review and approve before action is taken.


15. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified to customers by email and announced at schooltrack.co.ke/privacy-policy at least thirty (30) days before they take effect. Non-material changes (typo fixes, clarifications) take effect on posting.


16. Contact

Subject Email
Privacy, DPA enquiries, data-subject rights [email protected]
Security and vulnerability disclosure [email protected]
Legal matters [email protected]
General [email protected]

Data controller (where we act as one): Noria Technologies Ltd, Nairobi, Kenya. We will publish our ODPC registration number here once issued.

Supervisory authority: Office of the Data Protection Commissioner 1st Ngong Avenue, CBK Pension House P.O. Box 30920–00100, Nairobi [email protected] · odpc.go.ke