KAT for Schools

Data Processing Agreement

Last updated: July 2026

This agreement sets out how Kindle a Techie processes pupil and staff personal data on behalf of a school, as a processor acting on the school’s instructions under the Nigeria Data Protection Act 2023. It forms part of every school licence and pairs with the School Terms of Service and School Privacy Notice.

Roles and definitions#

This Data Processing Agreement (“DPA”) forms part of the School Terms of Service between the School and Kindle a Techie (“KAT”). It governs KAT’s processing of personal data on the School’s behalf and applies the terms of the Nigeria Data Protection Act 2023 (“NDPA”) and subsidiary regulation.

  • The School is the data controller: it determines the purposes and means of processing the data of its pupils and staff.
  • KAT is the data processor: it processes that data only for the School and only on the School’s documented instructions.
  • Data subjects are the School’s pupils and staff.
  • Terms such as personal data, processing, and personal data breach carry the meaning given in the NDPA.

Processing only on the School’s instructions#

KAT processes personal data only to provide the licensed service and only on the School’s documented instructions, including the instructions embodied in the platform’s features and the School Terms of Service. KAT will not process the data for its own purposes, will not sell it, and will not use it for advertising. If KAT believes an instruction breaches the NDPA, it will inform the School.

Details of the processing (Schedule A)#

  • Subject matter: delivery of the KAT curriculum service to the School.
  • Duration: for as long as the School holds an active licence, plus the return/deletion period below.
  • Nature and purpose: hosting, delivery of lessons and assessments, recording of learning progress, account management, and security.
  • Types of personal data: staff name, email, role, and hashed password; pupil roster identifiers and minimal roster fields; pupil learning activity (submissions, scores, projects, certificates); and technical data (session cookies, server logs, bot-protection signals).
  • Categories of data subjects: the School’s pupils (children under 18) and its staff.
  • Special categories: none are required or requested by the service.

Confidentiality#

KAT ensures that any person authorised to process the School’s data is bound by an obligation of confidentiality and processes the data only as needed to provide the service.

Security measures (Schedule B)#

KAT maintains technical and organisational measures appropriate to the risk, including:

  • Encryption of data in transit over HTTPS.
  • Passwords stored only as one-way bcrypt hashes; session tokens as HTTP-only, Secure cookies.
  • Pupil files stored in private object storage, served only through access-controlled URLs, with only storage keys held in the database.
  • Tenant isolation: every query for a school’s data is scoped to that school and checked against the requesting user’s membership and role, enforced in code and covered by an automated authorisation test, so one school cannot access another’s data.
  • Minimisation for children: pupils addressed by opaque reference; no pupil name or email in URLs, query strings, or logs; per-school framing restrictions for any embedded surface; no roster of minors on surfaces KAT does not control.
  • Verification of payment webhooks by HMAC signature; protection against server-side request forgery on any school-supplied URL.
  • Rate limiting and error monitoring to detect and respond to abuse.

Sub-processors (Schedule C)#

The School authorises KAT to engage sub-processors to provide the service. Each is bound by data-protection terms no less protective than this DPA. Current sub-processors:

  • Neon, managed PostgreSQL database hosting
  • Cloudflare R2, file storage for pupil project uploads
  • Cloudflare, edge network, bot protection (Turnstile), per-school embed framing
  • Paystack, school invoice payment processing
  • Upstash, rate limiting
  • Sentry, error monitoring
  • Email provider for transactional messages; Google for staff Google sign-in; self-hosted Jitsi / Jibri where a school uses live sessions

KAT gives the School at least [notice period, for example 30 days] notice before adding or replacing a sub-processor. The School may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the School may terminate the affected service.

Assisting with data subject rights#

Taking account of the nature of the processing, KAT assists the School by appropriate technical and organisational measures, so far as possible, to respond to requests from data subjects exercising their NDPA rights (access, rectification, erasure, restriction, portability, and objection). Where a data subject contacts KAT directly, KAT refers them to the School and does not respond substantively unless the School instructs it to.

Personal data breaches#

KAT notifies the School without undue delay after becoming aware of a personal data breach affecting the School’s data, and provides the information the School reasonably needs to meet its own NDPA obligation to notify the Nigeria Data Protection Commission (and affected data subjects where required) within 72 hours. KAT assists the School in investigating, mitigating, and remedying the breach.

Children’s data#

The School warrants that it has obtained and recorded the consent of a parent or guardian for each pupil, as required by the NDPA for children under 18, and that it will not instruct processing beyond the scope of that consent. KAT applies the child-specific minimisation measures in Schedule B and will not display a pupil’s identity or work publicly absent a recorded parental-consent flag.

International transfers#

Where a sub-processor hosts data outside Nigeria, KAT transfers data only under the safeguards required by Part IX of the NDPA, relying on the sub-processor’s contractual commitments and any applicable adequacy determination by the Nigeria Data Protection Commission. KAT makes the relevant details available to the School on request.

Audits and demonstrating compliance#

KAT makes available to the School the information reasonably necessary to demonstrate compliance with this DPA, and allows for and contributes to audits, including inspections, by the School or an auditor it mandates, on reasonable prior notice, no more than [frequency, for example once per year] except where required by the Commission or following a breach.

Return and deletion on termination#

On termination of the licence, at the School’s choice, KAT returns the School’s data in a commonly used format and/or deletes it within [return/deletion period, for example 60 days], except where law requires KAT to retain specific records (such as payment records for tax purposes), which KAT continues to protect under this DPA until it may lawfully delete them. Deactivated pupil records are retained during the licence and are returned or deleted on the same basis at termination.

Liability, precedence, and changes#

  • This DPA is subject to the limitations of liability in the School Terms of Service, save where the NDPA provides otherwise.
  • On any conflict between this DPA and the School Terms of Service regarding data protection, this DPA prevails. The NDPA prevails over both.
  • KAT may update this DPA to reflect changes in law or the service, on notice to the School; changes that materially reduce protection require the School’s agreement.

Contact#

Data protection queries and instructions under this DPA: hello@kindleatechie.com.

  • Processor: Kindle a Techie Technologies Limited (RC 9411414)
  • Registered office: On file with the Corporate Affairs Commission (Nigeria), available to licensed schools on request; notices may be sent to hello@kindleatechie.com.
  • Data Protection Officer: Onyishi James, james@kindleatechie.com
  • NDPC registration: [registration number, once registered]

↑ Back to top