Privacy policy
Version of 1 October 2026
Draft for review. This text hasn't been approved yet and may change before launch.
This policy explains what personal data iedu.com.pk handles, why, and what choices you have. It covers school websites, the portal, the parents' app and our own website. iedu.com.pk is run by [Company legal name].
1. Who is responsible
Your school is responsible for its records. A school decides what it records about its students, parents and staff, who can see it, and how long it keeps it. We store and process those records for the school, following its instructions, as set out in our data processing statement. If you have a question about your or your child's records, ask the school first.
We are responsible for the small amount of data we collect to run the service ourselves, such as security logs and support requests.
2. What we handle
- Accounts: name, email address and/or phone number, a securely hashed password, the school and role.
- Student records the school enters: name, date of birth, gender, admission and roll numbers, class and section, guardians and how they are related, attendance, fee invoices and payments.
- Guardians and staff: contact details, and for staff, their job details and the classes they teach.
- Website content: the pages, news, events, photos and messages a school publishes.
- Contact form messages: the name, contact details and message a visitor sends to a school.
- The app: a notification token for the phone and the app version. The camera is used only to scan a school's QR code; no picture leaves the phone.
- Support requests: what school staff ask us, and our answers.
- Technical data: IP addresses, browser type and request logs, kept for security and troubleshooting.
3. Children's data
Children's records are entered by their school, not by the children. Children don't have accounts in this version. A child's records are shown only to school staff whose role allows it and to the guardians the school has linked to that child. Schools are responsible for telling parents about this and getting their consent where required. We never use children's data for advertising or profiling.
4. Why we use it
- To run the service for the school: sign-in, records, the website, fee challans and notifications.
- To keep it secure: preventing misuse, limiting sign-in attempts, investigating problems.
- To answer support requests and tell school owners about changes.
We don't sell personal data, show advertising, or use analytics or advertising trackers in the portal or the app.
5. Notifications
Parents who use the app get alerts when their child is marked absent, when a fee challan is issued, and when the school publishes news or events. These alerts go through Google's Firebase service and contain the child's name and a short message. Signing out of the app stops them.
6. Who we share it with
We use these service providers to run iedu.com.pk. They may process data only to provide their service to us:
- Laravel Cloud (Laravel Holdings Inc.): Runs the API, database, queues and file storage. Singapore (AWS ap-southeast-1).
- Cloudflare, Inc.: DNS for our domains, and file storage (R2) through Laravel Cloud. Global network.
- DigitalOcean, LLC: Runs the web servers that show school websites and portals. Singapore.
- Google LLC (Firebase Cloud Messaging): Delivers app notifications to parents' phones. Global network.
- [Email provider]: Sends password reset, contact form and support emails. [Region].
- Functional Software, Inc. (Sentry): Error reports, with personal data collection turned off. [Region].
We share data with others only when the school instructs us to, or when the law requires it, for example a valid order from a court or authority in Pakistan.
7. Where it is stored
Our database and servers are in Singapore. Some providers above work across a global network. We choose providers that protect data with strong security and contractual commitments.
8. How long we keep it
- School records: while the school uses iedu.com.pk. Within 90 days after a school leaves, we delete its data. Backups expire within 30 days after that.
- Within a school, the school decides: for example, students who leave are kept as records until the school removes them.
- Sign-in sessions expire after 12 hours on the web and 30 days in the app. A phone's notification token is removed when it signs out.
- Security logs: up to 90 days. Support requests: up to two years after they are closed.
9. Security
- All connections use HTTPS. Passwords are stored only as secure hashes.
- Each school's data is kept separate, and the system refuses any request that doesn't say which school it is for.
- Staff see only what their role allows. Private files, such as fee challans, are never publicly reachable.
- When our support staff sign in as a school user to help, it is time-limited and recorded.
10. Your choices and rights
You can ask to see, correct or delete personal data about you or your child. Because the school controls its records, send the request to the school; we help the school respond. If you contact us directly, we pass your request to the school. You can also ask us about the data we handle for ourselves (section 1).
11. Cookies
The portal uses one cookie to keep you signed in. It is encrypted, can't be read by scripts, and is deleted when you sign out. School websites and our own website don't set tracking cookies.
12. Changes
We update this policy when the service changes. The date at the top shows the current version.
13. Contact
[Company legal name], [Registered address, city, Pakistan]. Email: [privacy@PLATFORM_DOMAIN].