Data processing statement

Version of 1 October 2026

Draft for review. This text hasn't been approved yet and may change before launch.

This statement is part of the terms of service between [Company legal name] (“we”) and the school or college using iedu.com.pk (“the school”). It sets out how we handle personal data on the school's behalf.

1. Roles

The school is the controller of the personal data it puts into iedu.com.pk: it decides why and how that data is used. We are the processor: we process it only to provide the service to the school.

2. Instructions

We process school data only on the school's instructions. Using the service, and settings the school chooses in it, are those instructions. If an instruction would break the law, we tell the school and don't follow it. We may also process data where the law requires us to; if so, we tell the school first unless the law forbids it.

3. What data, and whose

  • Whose: students (usually children), parents and guardians, staff, and visitors who contact the school through its website.
  • What: names, contact details, dates of birth, gender, admission and class details, guardian links, attendance, fees and payments, website content and contact messages, and sign-in and device data.
  • How long: for as long as the school uses the service, then as in section 10.

The school should not enter special categories of data, such as health or religious information, unless it is needed and lawful.

4. The school's part

  • The school makes sure it may lawfully collect and use the data, including telling parents and guardians and getting their consent where needed.
  • The school decides who gets an account and which role, and removes access when people leave.
  • The school keeps its records accurate and answers requests from parents, guardians and staff about their data.

5. Confidentiality

Only our staff who need to, to run or support the service, can reach school data, and they are bound to keep it confidential. When support staff sign in as a school user to help with a problem, the session lasts at most an hour and is recorded in our audit log.

6. Security

  • Encrypted connections (HTTPS) everywhere, and encryption at rest by our hosting providers.
  • Each school's data is separated in the database; a request without a school is refused, not answered with everyone's data.
  • Role-based access in the portal, hashed passwords, limits on sign-in attempts, and session expiry.
  • Private files, such as fee challans, are kept in a private store and only served to people allowed to see them.
  • Daily backups with point-in-time recovery, and a tested restore procedure.
  • Error reporting with personal data collection turned off.

7. Sub-processors

The school agrees that we use these providers. Each is bound to protect the data at least as well as this statement requires.

  • Laravel Cloud (Laravel Holdings Inc.): Runs the API, database, queues and file storage. Singapore (AWS ap-southeast-1).
  • Cloudflare, Inc.: DNS for our domains, and file storage (R2) through Laravel Cloud. Global network.
  • DigitalOcean, LLC: Runs the web servers that show school websites and portals. Singapore.
  • Google LLC (Firebase Cloud Messaging): Delivers app notifications to parents' phones. Global network.
  • [Email provider]: Sends password reset, contact form and support emails. [Region].
  • Functional Software, Inc. (Sentry): Error reports, with personal data collection turned off. [Region].

We tell school owners at least 30 days before adding or replacing a sub-processor. If the school objects for a good reason and we can't resolve it, the school may end the service without penalty.

8. Data breaches

If we become aware of a breach affecting the school's data, we tell the school's owner without undue delay, and within 72 hours. We say what happened, what data and people are affected, and what we are doing about it, and we help the school meet its own duties to inform people.

9. Help with requests

If a parent, guardian or staff member asks us directly about their data, we pass the request to the school rather than answering it ourselves. We help the school answer requests, for example by exporting records.

10. When the service ends

The school can ask for a copy of its data, in common formats (CSV or JSON, plus its files), within 30 days after the service ends. We delete the school's data within 90 days after the end, and backups containing it expire within a further 30 days, unless the law requires us to keep something longer.

11. Information and audits

We answer the school's reasonable questions about how we protect its data, and give a written summary of our security measures on request.

12. Contact

Questions about this statement: [privacy@PLATFORM_DOMAIN], [Company legal name], [Registered address, city, Pakistan].