Skip to main content
SchoolZee SchoolZee

Data & Security

High-level commitments — and the claims we do not make because they cannot be verified

Institution data includes student names, guardian phone numbers, attendance, fees and results. This is information placed with us in trust. So this page is written carefully — only commitments we genuinely keep.

We do not claim any security certification or specific technical guarantee here, because not every institution can verify such claims. Where institutional procurement requires it, there is room for detailed questions and answers — contact us directly.

1. How we think about this

Data security for an education institution is not, to us, a workflow issue — it is a question of trust. If an institution does not feel its data is safe, even the best software will not be used.

So we follow two principles: (a) we collect no more information than is genuinely needed, and (b) we grant no one more access than is genuinely needed.

2. Access control and role-based permissions

Every user in the system works with a role — admin, teacher, accounts or guardian. What a person can see and do is determined by that role. A teacher does not need everyone's data; a guardian needs only their own child's information.

Roles and permissions are set by the institution itself, and closing a person's access when they leave is the institution's responsibility. We keep this easy to do, so access is not granted once and then forgotten.

3. Who can see data

The principle is simple: the first right to see an institution's data belongs to the institution's authorised persons. Access on our side is limited and based on work need.

  • The support team sees only the data of the institution that has requested help to resolve an issue.
  • The technical team has access only when needed to diagnose and fix a problem, and only as much as is needed.
  • No staff member browses an institution's fees, results or guardian information on their own initiative — there must be a work reason.
  • The system keeps a record of who changed what, so activity can be reviewed.

4. Ownership of institution data

Student lists, attendance, fees and results belong to the institution, not to SchoolZee. We process that information to operate the service, and nothing more.

So an institution can view, correct or export its data. If it ends its relationship with us, returning or deleting the data follows the institution's decision and the agreement's terms.

5. General precautions in storing and protecting data

Data is generally stored in data-centre based systems, and we run the service with reasonable technical and administrative precautions. These include limited access, login protection and regular maintenance.

We make no claim here about a specific engineering standard, certification or third-party audit — because not every institution can verify these independently, and stating claims that cannot be verified is not our practice. If you have detailed technical questions, ask us directly and we will answer honestly with what we know.

6. The institution's role in login and password safety

A large part of security depends on user habits. However good the system is, a password shared with others weakens its protection.

  • A separate account for each user — do not share one login among several people.
  • Change the default or easy password once the account is created.
  • When staff change, close the account or change the role — this is the most effective protection.
  • Log out after work on a shared computer, especially on admin accounts.

7. Extra care with guardian and student data

Because students are minors, our caution with their information is higher. Student and guardian data is never used in any promotion, advertising or website case study — never without consent.

If an institution wishes to keep students' photographs, video or extra personal information in the system, that should follow the institution's own policy and guardian consent. We remind institutions of the necessary precautions here.

8. Technical providers and sub-processors

To run the service we rely on some technical providers — such as hosting, data storage, error monitoring or message delivery services. They see only the limited information needed to deliver their service and do not use it beyond that.

Where institutional verification or audit requires it, we can discuss what kinds of providers are used. We do not give institution names, student data or results to any provider for advertising purposes.

9. Deleting and exporting data

An institution can export its data at any time and keep it — this is the institution's data, and it has the right to hold it. This is useful at the end of an academic year or for the institution's own records.

Deletion requests are accepted only from the institution's authorised representative, so that data is not removed by mistake. In some cases limited records may have to be retained for accounting or legal needs — the institution is then informed clearly.

10. Reporting a security incident

If you believe an account has been accessed without authorisation, a password has leaked, or your institution's data is appearing where it should not — tell us immediately. Delay can widen the harm.

  • Contact: email info@schoolzee.net, WhatsApp +880 18777 8240.
  • Share what you know: institution name, when it happened, which account, and what looked unusual.
  • We first act to contain the problem, then try to inform the institution about what happened.
  • Never share your password with anyone over the app or email on suspicion — we never ask for your password.

11. Staff access policy

If someone on our team wants to see an institution's data, it must come from a work need — never out of curiosity or personal interest. This rule applies to support, technical and management staff alike.

If anyone on the team misuses institution data, that is treated by us as serious misconduct. If you become aware of anything like this, tell us directly — we investigate and act.

12. Verification and contact

If questions arise about security and data handling during institutional purchasing, tendering or internal approval, ask us directly. We will say honestly how things are done, and which claims we do not make.

Contact: email info@schoolzee.net, WhatsApp +880 18777 8240. For detailed data and security discussions, it is usually most effective to speak with the person authorised by the institution.

This page sets out high-level commitments; the detailed policy on collecting and using information is in the privacy policy, and conditions of service use are in the terms and conditions.

Common questions about data and security

Do you hold any security certification?

We claim no certification or specific technical standard on this page, because not every institution can verify such claims. If verification is needed, contact us — we will honestly share what exists.

Can your staff see our data?

Only where work requires it, and to a limited extent. The support team sees only the data of institutions that have asked for help, and the system keeps a record of who changed what.

What is the risk if several people use one admin password?

Then it becomes impossible to tell who changed what, and access cannot be closed when someone leaves. So a separate account and the correct role for each person is the safer route.

What happens to our data if we leave?

Before the relationship ends, the institution can export its data. Return or deletion then follows the institution's decision and the agreement's terms; where accounting or legal needs exist, limited records may be retained for a period, and the institution is informed.

What should we do if something looks suspicious?

Tell us first — info@schoolzee.net or WhatsApp +880 18777 8240. Sharing the institution name, time and affected account lets us act quickly. We never ask for your password.

Questions about data and security?

A detailed discussion can be arranged for institutional purchasing or approval — tell us what you need to know.