Privacy Policy
This policy covers two things: this marketing website, and the EduCore school-management application used by enrolled schools. They're described separately below, because EduCore's role is different in each.
Effective August 30, 2026 · Published by EduCore Technologies Ltd (registration no. PVT-93SSQEELA), 7th Floor, Sanlam Towers, Waiyaki Way, Westlands, Nairobi, Kenya.
Where things stand
This policy has been reviewed and approved by EduCore's founder for publication. It has not yet been reviewed by external legal counsel, and Part B includes one disclosed, unresolved item (data localization, Section 9) rather than claiming full compliance before that's addressed. This page will be updated as that review happens and as the Service changes.
Part A
This website
This section covers only what happens when you use educoreafrica.com itself — not the application schools use once enrolled, which is covered in Part B below.
What we collect
If you submit the contact/demo request form on this site, we collect the information you provide: your name, school name, role, email address, and phone number and message if you choose to include them. If you arrived via a marketing link containing campaign parameters (for example, from an ad or a shared link), we also record which campaign referred you at the time you submit the form, so we understand which channels are helpful. We do not collect this information anywhere else on the marketing site — pages you simply browse do not submit any personal information to us.
How we store and use it
Demo request submissions are stored in a dedicated database table, separate from any school's student, academic, or financial records, and are only ever written to, never read back, by this website. Access is restricted to the EduCore team, and used solely to respond to your enquiry and arrange a demo. We do not sell this information, and we do not use it for advertising.
Error monitoring, analytics, and cookies
This site uses Sentry to detect and diagnose technical errors. Default collection of personal data (such as IP addresses) is deliberately switched off in this configuration; Sentry receives only what is needed to identify and fix bugs, via an EU-region endpoint (see Section 9 in Part B for what that means for cross-border transfer). This site does not currently set analytics or advertising cookies — an analytics script (Plausible, cookie-less by design) is integrated but inactive until we choose to turn it on, and this page will be updated first if that changes.
Part B
The EduCore application
This is the substantive policy for schools, parents/guardians, students, and staff using the EduCore school-management application (the “Service”).
1. Who this is for, and who does what
EduCore is used by Schools (the paying customer — a school, or group of schools) and by Users the School authorises: school owners, principals, administrators, teachers, finance and support staff, parents/guardians, and students.
For personal data relating to students, parents/guardians, and staff (“School Personal Data”), the School is the data controller under Kenya's Data Protection Act, 2019 (the “DPA”) — the School decides what data to collect and why. EduCore is the data processor — we process School Personal Data only to provide the Service, on the School's instructions, as set out in our Terms of Service and any Data Processing Addendum.
For personal data EduCore collects directly about the School itself as our customer (e.g., the school's own contact details, billing information, and the accounts of the individuals who administer the Account), EduCore is the data controller.
If you are a parent, guardian, student, or staff member and have a question about your own data, your school is your first point of contact — they control what's collected and why, and can action most requests directly. If your school is unable to help, you may also contact us using the details in Section 13.
2. What we collect
Depending on which modules the School enables, the Service may process:
| Student identity & enrolment | Name, date of birth, admission number, class/stream, guardian relationships |
| Academic records | Grades, exam results, report-card comments (including AI-drafted, staff-reviewed comments), CBC competency assessments |
| Attendance | Daily attendance records, biometric check-in timestamps (where the School enables biometric attendance) |
| Health & discipline | Medical records relevant to school care (e.g., allergies, medication administered by school nurses), disciplinary records — only where the School's chosen modules collect these |
| Financial | Fee invoices, payment records (via M-Pesa), payment history, discounts/scholarships/waivers |
| Communications | Messages sent via the Service's WhatsApp/SMS integration (e.g., fee reminders, newsletters) |
| Staff | Employment records, payroll data, statutory numbers (e.g., NSSF/SHIF), leave records |
| Guardian/parent | Name, phone number, email, relationship to student |
| Technical | Login activity, device/browser information, IP address (for security and troubleshooting) |
We do not decide which of these categories a School collects — that is the School's decision, reflecting its own operations and legal obligations. We built the Service so a School only sees the modules (and therefore the data categories) it has actually enabled.
3. Sensitive personal data
Under the DPA, biometric data and data concerning health are “sensitive personal data,” subject to stricter requirements than general personal data. Where a School enables biometric attendance or health/medical record-keeping, the School is responsible for obtaining explicit consent (from a parent/guardian for a student, or from staff for their own data) before that data is collected, consistent with DPA requirements for sensitive personal data. We support this technically (these modules are opt-in per School, and access to this data is more tightly restricted within the Service than general records), but the underlying consent is the School's responsibility to obtain and record.
4. Children's data
Most students using the Service are children under Kenyan law (under 18). Consistent with DPA section 33, personal data relating to a child may only be processed with the consent of the child's parent or guardian, and where the processing is in the best interests of the child. This consent is obtained and recorded by the School as part of enrolment, not directly by EduCore — we are a processor acting on the School's instructions, not the party collecting consent from families. Schools should ensure their own enrolment/consent processes meet this standard.
5. Why we process this data
We (as processor, on the School's instructions as controller) process School Personal Data for purposes including: delivering the modules the School has enabled (admissions, academics, attendance, finance, communication, staffing, etc.); enabling the School to communicate with parents/guardians; processing fee payments via M-Pesa and reconciling them against invoices; generating reports for the School's own use; maintaining the security and integrity of the Service; and complying with legal obligations that apply to us as a processor. The lawful basis for each of these (performance of a contract, legitimate interest, consent, or legal obligation, per DPA section 30) is ultimately the School's determination, since the School is the controller — our Data Processing Addendum sets out the basis on which we act.
6. AI-assisted processing
The Service uses AI to draft report-card narrative comments (grounded in a student's recorded academic performance) and draft parent-facing WhatsApp/SMS messages. These drafts are always reviewed and approved by School staff before being finalised or sent — no AI-generated content reaches a parent, student, or permanent record without human review. We do not use automated processing to make decisions with legal or similarly significant effects on any individual (e.g., admissions, grading, or disciplinary outcomes) without meaningful human involvement.
7. Who we share data with (sub-processors)
We use the following categories of third-party service to operate the Service. None of them are permitted to use School Personal Data for their own purposes.
| Supabase | Database hosting, authentication, file storage | All School Personal Data stored by the Service |
| Vercel | Application hosting/CDN | Technical/request data; no direct database access |
| Safaricom (M-Pesa) | Fee payment processing | Payment amount, phone number, transaction reference — not full financial account details |
| Twilio (WhatsApp Business API) / SMS gateway | Sending parent communications the School initiates | Recipient phone number, message content |
| Sentry | Error monitoring | Technical error data only — default PII collection is disabled in every environment. Ingest endpoint is EU-region (*.ingest.de.sentry.io) — see Section 9. |
| Plausible | Website analytics (marketing site only, not the application) | Aggregated, cookie-less traffic data — not currently active |
We will update this list, and notify the School, if we change sub-processors in a way that affects how School Personal Data is handled.
8. Data retention
We retain School Personal Data for as long as the School's Account is active, and for the periods described in our Terms of Service following termination (30 days for export, then deletion from active systems within a further 60 days, subject to legal retention requirements and normal backup-rotation timing). Some records (e.g., payroll data relevant to tax obligations) may be subject to longer statutory retention periods, which are the School's responsibility to specify to us if they exceed our default schedule.
9. International data transfers — current status
Our database infrastructure (Supabase) is hosted in the eu-central-1 region (Frankfurt, Germany), and our error-monitoring provider (Sentry) also uses an EU-region ingest endpoint. This means data is transferred outside Kenya as part of normal Service operation — for Supabase, this includes the full range of School Personal Data; for Sentry, this is limited to technical error data with default PII collection explicitly disabled, which reduces but does not eliminate the transfer question, since error payloads can still incidentally include identifiers depending on where an error occurs.
This is flagged here deliberately, not glossed over. The DPA's cross-border transfer regime (sections 48–50) requires either an adequacy determination, appropriate safeguards, or another lawful transfer ground, before personal data leaves Kenya. Section 50 additionally imposes a heightened, specific requirement for certain categories of data controller/processor — including providers of basic (primary/secondary) education under the Basic Education Act — to keep at least one serving copy of personal data in a data centre located in Kenya. As a school-management platform serving Kenyan basic-education institutions, EduCore likely falls within that category, and we do not currently have a Kenya-based serving copy of the database. This is a genuine, unresolved item, not a documentation formality, and we are working through the engineering and legal steps required to address it.
10. Data security
We maintain technical and organisational measures appropriate to the sensitivity of School Personal Data, including per-school data isolation at the database level (row-level security policies scope every school's data to that school), encryption of data in transit and at rest, role-based access control within the Service, security-definer database functions with pinned search paths and least-privilege grants to prevent privilege-escalation between tenants, restricted and encrypted access to M-Pesa credentials, and regular dependency and vulnerability review.
11. Data breach notification
If we become aware of a security incident affecting School Personal Data, we will notify the affected School without undue delay, so the School can meet its own breach-notification obligations — including, where applicable, notifying the Office of the Data Protection Commissioner within the DPA's required timeframe and affected data subjects where required.
12. Data subject rights
Individuals whose data is processed through the Service (students, via their parent/guardian; parents/guardians themselves; staff) have rights under the DPA, including to be informed of how their data is used, to access it, to request correction of inaccurate data, to object to certain processing, and to request erasure or data portability, subject to the conditions in the DPA.
Because the School is the data controller, these requests should generally go to the School first — they hold the records and are best placed to action most requests directly within the Service. Where a request requires our assistance, we support the School in fulfilling it. If you're unable to resolve a request with your school, you may contact us at dpo@educore.co.ke.
13. Contact and Data Protection Officer
Email: dpo@educore.co.ke
Data Protection Officer: James Maina, Founder
ODPC registration: EduCore Technologies Ltd is registered with the Office of the Data Protection Commissioner as required under the Data Protection Act, 2019.
14. Changes to this policy
We will update this policy as the Service or our data practices change, and will notify Schools of material changes with reasonable notice, consistent with our Terms of Service.
Last updated: August 30, 2026.