Effective Date: 1-09-2025

Data Protection Policy

This Data Protection Policy explains how SchoolPilot collects, uses, stores, and protects personal and institutional data in accordance with Uganda's Data Protection and Privacy Act, 2019 and international privacy standards.

📞 0747 170 325 | 0772 548 084
Website: schoolpilot.org

1Purpose of This Policy

This Data Protection Policy explains how SchoolPilot collects, uses, stores, and protects personal and institutional data of our clients (schools), their staff, students, and parents in accordance with Uganda's Data Protection and Privacy Act, 2019 and international privacy standards.

We are committed to ensuring that all data entrusted to us is handled lawfully, securely, and transparently.

2Scope

This policy applies to:

  • All users of the SchoolPilot system (administrators, teachers, bursars, etc.)
  • All data collected through the SchoolPilot platform
  • All devices and systems used to store or process SchoolPilot data

3Types of Data Collected

We collect and process the following categories of data:

a. Personal Data

  • Student names, gender, date of birth, photos, class details
  • Staff names, titles, contact information, teaching responsibilities
  • Parent/guardian names and phone numbers (for SMS communication)

b. Academic & Institutional Data

  • Exam results, report cards (O & A Level)
  • Attendance, disciplinary records
  • Library loans, medical visits, science lab usage
  • Fee payment records

c. Technical Data

  • Login activity, IP addresses, device/browser info (for security)

4Data Collection Principles

We adhere to the following principles when processing data:

Lawfulness, fairness, and transparency
Data minimization (only collect what is necessary)
Accuracy and timely updates
Storage limitation (retain only as long as needed)
Integrity and confidentiality

5Lawful Basis for Processing

SchoolPilot collects and processes data:

  • With the consent of the school or school administrator
  • As part of a service contract with the school
  • To comply with legal obligations (e.g., reporting or audits)

We rely on schools to obtain necessary consent from parents and staff where required.

6Data Storage and Retention

  • All data is stored securely on encrypted servers with restricted access
  • Daily system backups are performed to avoid data loss
  • Data will be retained for up to 12 months after service cancellation, unless deletion is requested earlier by the school
  • Access to old data is restricted to administrative users

7Data Security Measures

We implement the following security safeguards:

🔐
Strong user authentication
(usernames + passwords)
👥
Role-based access controls
(admin, teacher, bursar, etc.)
🔒
End-to-end encryption
(SSL/TLS) for data in transit
💾
Encrypted database storage
AES-256 encryption at rest
📊
Audit logs
to monitor access and changes
🔄
Regular system updates
to patch vulnerabilities

8Access and Sharing of Data

School data is not shared with third parties except:

  • With explicit permission from the school
  • With system service providers (e.g., SMS gateways) under strict confidentiality agreements
  • When required by law or regulation (e.g., court orders)

We maintain a list of all sub-processors (third-party service providers) who may handle data on our behalf, and this list is available to school administrators upon request. Each user's access to data is limited by their assigned role.

9User Responsibilities

Schools and users are responsible for:

  • Keeping their login credentials confidential
  • Ensuring only authorized staff use the system
  • Immediately reporting suspected data breaches to SchoolPilot

10Data Subject Rights

In line with the Uganda Data Protection and Privacy Act, all data subjects (students, staff, parents) have the right to:

👁️
Know what data is held about them
✏️
Request corrections or deletions of inaccurate data
🚫
Object to unlawful processing of their data

Schools are responsible for responding to these requests and may contact SchoolPilot for support. We will provide schools with the necessary tools and assistance to access, correct, or export data as required to fulfill these requests in a timely manner.

11Data Breach Notification

In the event of a data breach:

  • SchoolPilot will notify affected schools within 72 hours of discovery
  • We will provide details on the nature of the breach and recommended steps
  • We will work quickly to restore system integrity and security

12Updates to This Policy

This policy may be updated periodically to reflect changes in law or system features. All changes will be published on our platform, and significant updates will be communicated directly to school administrators.

13Contact Information

If you have any questions or data-related concerns, please contact us:

SchoolPilot Uganda

📱 0759 022 731 | 0772 548 084
🌐 Website: schoolpilot.org
At SchoolPilot, we don't just manage data — we protect it with care and responsibility.