Privacy
EduControl Privacy & Data Protection Notice
Version 2026-09-02, in effect from 2 September 2026
Most of what EduControl holds is information about children. This notice says exactly what is held, why it is held, who else touches it, how it is protected, and what a parent or a member of staff can ask for. It is written under Ghana's Data Protection Act, 2012 (Act 843), and it forms part of the agreement your school accepts.
1Who we are, and our role
EduControl is built and operated by Pixelspective, of Accra, Ghana.
Your school is the data controller for the records it keeps in EduControl. It decides what to collect, why, and how long to keep it. We are the school's data processor: we hold and handle those records on the school's behalf, and we act on the school's instructions.
This matters for a practical reason. If you are a parent or a member of staff and you want to see, correct or remove something, the school is who decides — and section 8 explains how to ask. We help the school do it; we cannot do it over the school's head.
2What is held, and about whom
The Platform holds the following, grouped by who it is about. Not every school fills in every field; this is the full extent of what it is possible to store.
- Staff — name, school email address, phone number, role and permissions, job title, department, staff identifier, and the times the account signed in.
- Pupils — name, date of birth, gender, photograph, admission number, class and section, enrolment history, attendance records, marks and published terminal reports, and fee and payment history. Where the school enters them: allergies, blood group, medical notes, preferred hospital, and details of a previous school.
- Guardians — name, relationship to the pupil, phone number, email address, postal and digital address, and which guardian is responsible for paying fees.
- Financial — invoices, payments, how each payment was allocated, credit notes, refunds and corrections.
- Operational — an audit log of consequential actions, recording what was done, to what, and by which account.
3Why it is held
To run the school. Specifically: to admit pupils and issue admission numbers, to take and keep the class register, to record marks and produce terminal reports, to invoice fees and record payments, to operate the feeding programme, and to run the pupil and teacher portals.
Under Act 843, the school relies on its legitimate interest in administering the school, and on the record-keeping obligations placed on it by law. Where the school relies on consent instead — a photograph is the usual example — obtaining and recording that consent is the school's responsibility, and the school can tell you which basis it is relying on.
We do not use these records for our own purposes. We do not sell them, we do not share them for advertising, and we do not use them to train machine-learning systems.
4Photographs of pupils
This has its own section because it is the most sensitive thing the Platform holds.
A pupil's photograph is captured or chosen in the browser during admission, reduced in size before it leaves the device, and stored in Cloudflare R2 object storage. It is filed under a key that is not guessable, and that key is held on the pupil's record.
The image is not publicly readable. It is not indexed by search engines, and it cannot be reached by anyone who has not signed in to the school that admitted the pupil. It is served only to accounts that school has authorised.
It is used for one purpose: identifying the pupil on the school's own screens and documents. It is not used for anything else, by us or by anybody we work with.
5Who else touches the data
Running the Platform means relying on a small number of specialist providers. These are all of them, and what each one does.
- Supabase — hosts the Postgres database that holds school records, and provides staff sign-in.
- Cloudflare R2 — stores pupil and staff photographs, as section 4 describes.
- Sentry — receives error reports when something in the Platform fails. An error report may incidentally include a request path or an account identifier; it is not a copy of school records.
- Our application host — runs the Platform itself and serves it to browsers.
6Where it is stored
The database and the object storage are operated by the providers named in section 5, on infrastructure outside Ghana.
Transfers to those providers are covered by each provider's own terms and data-protection commitments. We choose providers that publish those commitments, and we will tell your school which regions its data sits in on request.
7How long it is kept
Your school decides, because your school carries the legal obligation. Academic records and financial records typically have to be kept for years after a pupil leaves, and neither we nor the school can simply delete them on request.
While a school's account is suspended — for example, for an unpaid invoice — its records are retained, not deleted.
When a school stops using EduControl, it may ask us for a full export of its records. After the window set out in the Terms of Service, we may delete what remains, and we will tell the school before we do.
8Access, correction and erasure
Under Act 843 you have the right to know what is held about you or about your child, to have it corrected if it is wrong, to object to how it is being used, and in some circumstances to have it erased.
Ask your school first. The school holds the relationship, decides what it keeps, and can answer directly. If the school needs our help to answer, we will give it.
Some requests can be refused, and it is fairer to say so here than at the time. A record the school is required by law to keep cannot be erased on request — a receipt for fees that were paid cannot be made to say they were not. Where we or the school decline a request, you will be told why.
9How it is protected
These are the protections actually in place. We have deliberately not listed anything aspirational.
- Separation between schools. Every record carries the identity of the school it belongs to, and the database enforces row-level security against it. A query from one school cannot return another school's rows, even if the code asking for them has a bug.
- Separate doors. Staff, pupils and guardians sign in by different routes, and a pupil or guardian session cannot become a staff session.
- Permissions checked centrally. What an account may do is decided in one place from its role, not screen by screen. A request for something the account may not do is refused by default rather than allowed by default.
- Encrypted connections. Traffic between the application and the database is protected by TLS against a pinned certificate authority.
- An audit log. Consequential actions — changes to money, to pupil records, to accounts and to school settings — are recorded with the account that took them.
10If something goes wrong
If we become aware of a security breach affecting your school's data, we will tell the school without undue delay. We will say what we know, what we do not yet know, and what we are doing about it.
The school then decides what it must tell guardians, staff and Ghana's Data Protection Commission, and we will support it in doing so.
11What is stored in your browser
The Platform stores very little on your device: the sign-in token issued when you sign in, your email address if you ticked the box asking us to remember it, and — in development mode only — the identifier of the account being used.
There are no advertising cookies and no third-party tracking. Clearing your browser's storage signs you out and loses nothing else.
12Questions and complaints
Ask your school first. It holds the records and it is the data controller.
If your question is about the Platform itself, or you are not satisfied with the school's answer, contact Pixelspective at the address published on our website.
If you remain dissatisfied, you may complain to the Data Protection Commission of Ghana, which regulates how personal data is handled in Ghana.