KAT for Schools

School Privacy Notice

Last updated: July 2026

This notice explains how Kindle a Techie handles personal data for schools that license the KAT curriculum. It reflects our role as a data processor under the Nigeria Data Protection Act 2023, working on the instructions of the school, which is the data controller for its pupils and staff.

Our role: processor, not controller#

When a school licenses the KAT curriculum for its pupils, the school is the data controller for the personal data of its pupils and staff. It decides what data is collected and why. Kindle a Techie is a data processor: we process that data only to deliver the service, and only on the school’s documented instructions.

This is different from our consumer service, where a parent enrols a single child directly and we act as controller. That relationship is covered by our consumer Privacy Policy, which does not apply to school pupils. The full processor terms for schools are set out in our Data Processing Agreement, which forms part of every school licence.

Who this notice covers#

  • School staff, the administrators and teachers a school gives access to.
  • Rostered pupils, the children a school enrols on the platform through its roster.

What data we process for your school#

Staff accounts

  • Name, email address, and school role (administrator or teacher)
  • Password, stored only as a one-way bcrypt hash, we cannot read it

Pupil records

  • The identifier the school assigns, held as an opaque reference. We do not put a pupil’s name or email in URLs, query strings, or logs.
  • The minimum roster fields the school supplies to place a pupil (such as first name, class, and year), no more than the school chooses to send.
  • Learning activity: lesson progress, assessment submissions and scores, capstone project files, module completion, and certificates earned.

Technical data

  • Session cookies that keep signed-in users authenticated (see our Cookie Policy)
  • Basic server logs (IP address, request timestamps) retained for security
  • Bot-protection signals on sign-in, processed by Cloudflare Turnstile (see Sub-processors)

Pupil billing data is not collected: schools are invoiced per seat, so we process a school’s billing-contact details, never a pupil’s or a parent’s payment information.

Why we process it#

We process school data for one purpose: to deliver the curriculum service the school has licensed. Concretely, to:

  • Create and secure staff and pupil accounts
  • Deliver lessons, assessments, and projects, and record progress
  • Give the school’s own teachers and administrators visibility into their pupils
  • Keep the platform secure and prevent abuse

We do not sell school or pupil data, use it for advertising, or use it for our own purposes. We do not combine a school’s pupil data with our consumer service.

Children’s data#

Under the Nigeria Data Protection Act 2023 (NDPA), a child is a person under 18, and processing a child’s data requires the consent of a parent or guardian. Because the school is the controller, obtaining and recording that parental consent is the school’s responsibility. We process pupil data on the school’s instruction and rely on the school’s confirmation that it has the necessary consent.

We build for data minimisation for children by design:

  • Pupils are addressed by an opaque reference, never by name or email in URLs or logs.
  • A pupil’s name or work is never shown on any public page unless a parental-consent flag has been recorded for that pupil.
  • Pupil records are deactivated rather than hard-deleted, so a child’s progress and certificates are not silently destroyed. The school can instruct erasure (see Retention).

Sub-processors#

We use a small set of vetted infrastructure providers to run the service. Each processes data only to provide its function to us, under contract. Current sub-processors:

  • Neon, managed PostgreSQL database hosting (the primary data store)
  • Cloudflare R2, file storage for pupil project uploads (private buckets, access-controlled)
  • Cloudflare, edge network, bot protection (Turnstile), and per-school embed framing
  • Paystack, processing of school invoice payments (billing-contact data only)
  • Upstash, rate limiting
  • Sentry, error monitoring (may incidentally process technical data such as IP)
  • Our email provider, transactional email (invitations, password resets, notices)
  • Google, only where a staff user chooses to sign in with Google
  • Self-hosted Jitsi / Jibri, only where a school uses live video sessions

We maintain a current list and give the school advance notice before adding or replacing a sub-processor, so it can object, as required by our Data Processing Agreement.

International data transfers#

Some sub-processors above host data outside Nigeria. Where that happens, we transfer data only under the safeguards required by Part IX of the NDPA, relying on the provider’s contractual data-protection commitments and, where applicable, an adequacy determination by the Nigeria Data Protection Commission (NDPC). The school, as controller, remains responsible for the lawful basis of any transfer it instructs.

Retention and deletion#

  • We retain school data for as long as the school’s licence is active.
  • A pupil who leaves is deactivated by default, preserving their record, unless the school instructs deletion.
  • On termination of the licence, we return or delete the school’s data on request, within the period set out in the Data Processing Agreement, save where law requires us to retain specific records (for example, payment records for tax purposes).

How we protect the data#

  • All traffic is encrypted in transit over HTTPS.
  • Passwords are stored only as one-way bcrypt hashes. Session tokens are HTTP-only, Secure cookies.
  • Pupil project files are stored in private Cloudflare R2 buckets and served only through access-controlled URLs.
  • Every request for a school’s data is scoped to that school and checked against the requesting user’s membership and role, so one school can never read another’s data. This isolation is enforced in code and covered by an automated authorisation test.
  • Payment webhooks are verified with an HMAC signature before any action is taken.
  • Access is rate-limited and errors are monitored so we can detect and respond to abuse.

Pupil and staff rights#

The NDPA gives data subjects rights to access, correct, delete, restrict, port, or object to the processing of their data, and to withdraw consent. Because the school is the controller, those rights are exercised through the school. A parent, pupil, or staff member should contact their school; the school can act directly in the platform or ask us to assist, and we will support the school promptly, as set out in the Data Processing Agreement.

Data breaches#

If we become aware of a personal data breach affecting a school’s data, we notify the school without undue delay so that the school, as controller, can meet its NDPA obligation to notify the NDPC (and affected individuals where required) within 72 hours. We provide the information the school reasonably needs to make that notification.

Contact and data protection queries#

For any data protection question about the school service, contact hello@kindleatechie.com.

Controller and processor details for the record:

  • Processor: Kindle a Techie Technologies Limited (RC 9411414)
  • Registered office: On file with the Corporate Affairs Commission (Nigeria), available to licensed schools on request; notices may be sent to hello@kindleatechie.com.
  • Data Protection Officer: Onyishi James, james@kindleatechie.com
  • NDPC registration: [NDPC data controller/processor registration number, once registered]

↑ Back to top