SchoolNest

Privacy Policy

Last updated: 31 March 2026

Introduction

SchoolNest ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our education management platform and related services. We process personal data in accordance with the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Regulation (NDPR), and under the supervision of the Nigeria Data Protection Commission (NDPC). By using our Service, you consent to the practices described in this policy where consent is the lawful basis for processing.

1. Information We Collect

We may collect the following categories of personal data:

  • Account information: name, email address, password (stored in hashed form), phone number (if provided), and role (e.g. school admin, teacher, parent, student).
  • School and educational data: school details, classes, terms, academic years, student records, grades, attendance, fees, and other data that schools and authorized users enter into the Service.
  • Usage data: how you use the Service (e.g. pages visited, actions taken) to improve our product, security, and user experience.
  • Device and technical data: IP address, browser or app type, and similar technical information when you access the Service.

We collect only data that is adequate, relevant, and limited to what is necessary for the purposes described (data minimization under the NDPA). We obtain your consent or rely on another lawful basis as permitted under the NDPA before processing your personal data.

2. How We Use Your Information

We use the information we collect for specified, explicit, and legitimate purposes, including: to provide, operate, and improve the Service; to authenticate users and manage accounts; to process and display school, class, and student data as directed by the school; to send service-related communications; to comply with legal obligations under Nigerian law; and to protect the security and integrity of the Service. We do not use your personal data for purposes incompatible with those disclosed to you. We do not sell your personal information.

2A. Controller and Processor Roles

SchoolNest acts in different capacities depending on context. For student academic records and school operational data entered by a school, the school is generally the data controller and SchoolNest acts as a data processor/service provider. For platform account management, security operations, fraud prevention, and legal compliance records, SchoolNest acts as a data controller. Where a request concerns school-controlled records, we route the request to the relevant school and assist as required by law.

3. Sharing of Information

We do not sell your personal data. We may share information: with service providers who assist us (e.g. hosting, analytics), under strict confidentiality and data processing agreements that meet NDPA requirements; within the SchoolNest product as needed for your role (e.g. teachers and parents see data permitted by the school); when required by Nigerian law or by order of a competent authority; or in connection with a merger, sale, or transfer of assets, with notice as required by law. We do not share your data with third parties for their marketing. Where we transfer data to processors or sub-processors, we ensure appropriate safeguards in line with the NDPA.

4. Data Security

We implement appropriate technical and organizational measures to protect your personal data and ensure its security, integrity, and confidentiality, as required under the NDPA. These measures include encryption in transit and at rest, access controls, secure development practices, and staff training. No method of transmission or storage is 100% secure; we encourage you to use strong passwords and keep your login details confidential. In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify the NDPC and affected data subjects as required by the NDPA.

5. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to provide the Service and as described in this policy. We may retain certain data to comply with legal obligations under Nigerian law, resolve disputes, and enforce our agreements. Schools may have their own retention requirements for educational records. When data is no longer necessary, we will delete or anonymize it in accordance with our retention schedule and the NDPA principle of storage limitation.

For account deletion requests, we process verified requests within 30 days except where legal retention obligations require us to keep specific records for longer.

6. Your Rights Under the NDPA

Under the Nigeria Data Protection Act 2023, you have the right to: be informed about our processing activities; access your personal data and receive a copy (Data Subject Access Request); request correction of inaccurate or incomplete data; request erasure of your data in certain circumstances; object to or restrict certain processing; withdraw consent where processing is based on consent; and lodge a complaint with the Nigeria Data Protection Commission (NDPC). You can update account details in the Service. To request deletion of your account and associated data, see Request account deletion. For privacy requests, you can also submit a ticket through Contact us and choose the relevant privacy request category. For mailbox requests, contact privacy@yourdomain.com. We will respond within the timeframe required by the NDPA. Schools are responsible for fulfilling requests regarding student and school data they control as data controllers.

7. Children's Privacy

The Service is used by schools to manage student information. Student data is processed on behalf of the school and in accordance with applicable Nigerian law, including the Child's Rights Act and the NDPA. We do not use student data for advertising or unrelated purposes. Where consent is required for processing a child's data, we and the school will ensure that appropriate consent (e.g. from a parent or guardian) is obtained as required by the NDPA. Parents and schools may have additional rights regarding student data under Nigerian law.

8. International Transfers

Your information may be processed in or transferred to countries other than Nigeria. Where we transfer personal data outside Nigeria, we will ensure that such transfers are subject to appropriate safeguards as required by the NDPA (e.g. adequacy decisions, standard contractual clauses, or your consent where applicable). We will not transfer your data to a jurisdiction that does not provide an adequate level of data protection without implementing the required safeguards.

Our key service providers may include cloud hosting/database providers, push notification providers, and transactional email providers. We apply contractual and organizational safeguards for these transfers and maintain an internal sub-processor register.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date. For material changes that affect how we process your data, we will provide additional notice where reasonably practicable (e.g. by email or in-app notification) and, where required by the NDPA, obtain your consent. We encourage you to review this policy periodically.

10. Contact Us and NDPC

For privacy-related questions, to exercise your data subject rights, or to report a concern, contact our privacy team at privacy@yourdomain.com. You may also submit a request through Contact us. Interim DPO/Privacy Lead: Founder, SchoolNest. You may also lodge a complaint with the Nigeria Data Protection Commission (NDPC) at the contact details published on the NDPC official website (ndpc.gov.ng).

Back to sign up