Trust at Edsynk

Privacy Policy

Last updated: 22 June 2026

Edsynk is a school-management platform. Most of the personal data we handle belongs to schoolchildren, so we treat it with particular care. This policy explains what we collect, why, who can see it, and the rights you hold under Nigerian law. It is written plainly on purpose — if anything here is unclear, write to us and we will explain it.

01Who we are

Edsynk is operated by Edsynk Technologies Ltd, a company registered in Nigeria with its base in Bauchi. We provide software that schools use to manage students, results, attendance, communication and payments.

An important distinction runs through this entire policy:

The school is the data controller. Your school decides what student records to keep, how they are used, and for how long. The records belong to the school.

Edsynk is the data processor.We store and process those records strictly on the school’s instructions, to deliver the service. We do not decide, on our own, what happens to a child’s data.

That relationship is written down formally in the Data Processing Agreement each school accepts at onboarding.

For Edsynk’s own business contacts — for example a proprietor who signs up, or a visitor to this website — Edsynk acts as the data controller. This policy covers both roles and says which is which where it matters.

03Children's data

Most students on Edsynk are minors. Their data is collected and held on behalf of the school, which has a direct relationship with the child and their family. Edsynk never markets to children and never builds advertising profiles of them.

Parental and guardian rights — to see a child’s records, to correct them, or to ask questions — are exercised through the school, which knows the family and can verify identity properly. The parent portal in Edsynk exists to give families that visibility directly, but the school remains the gatekeeper of who is connected to which child.

We apply heightened safeguards to minors’ records: stricter access controls, no use of their data to train external AI models, and export and deletion handled only on the school’s verified instruction.

04What we collect

We collect only what a school needs to run. Depending on how your school configures Edsynk, this may include:

  • Student records — name, class, admission number, date of birth, gender, photo, and the biodata your school chooses to keep.
  • Results and assessment data — continuous-assessment and exam scores, grades, positions, traits, and teacher and principal remarks.
  • Attendance — daily or session attendance marked by staff.
  • Guardian and contact details — names, phone numbers and email addresses of parents or guardians, so the school can reach them.
  • Staff data — names, roles, login credentials and the actions staff take in the system.
  • Payment metadata — what was paid, when, by whom and the reference. We do not store full card numbers; card payments are handled by our payment providers (see Sub-processors).
  • Usage and technical logs — log-in times, device and browser type, IP address and audit records of changes, kept for security and troubleshooting.

We do not collect special-category data (such as health or religious belief) except where a school deliberately records it as part of its own legitimate operation — for example, subjects taught at an Islamiyyah school — and only as the controller directs.

05How we use it

We use personal data for one purpose: to deliver the service the school pays for. Concretely, that means computing and sealing results, building broadsheets and report cards, marking attendance, notifying parents, processing payments and keeping audit logs.

Three commitments matter enough to state plainly:

We never sell personal data. Not student data, not guardian contacts, not staff data — to anyone, for any purpose.

AI features run on the school’s configuration only. Edsynk’s AI assistants (such as drafting remarks or generating practice questions) process a school’s data to produce output for that school. They are an aid; staff approve everything.

We never train external AI models on student data. Children’s records are not used to train third-party or foundation models. Where a school brings its own AI key (BYOK), that key is encrypted at rest and used solely to serve that school.

06Storage & security

Protecting children’s records is the most important thing we do. Our safeguards include:

  • Encryption in transit and at rest — data moves over TLS and is encrypted on our servers and in backups.
  • Role-based access controls— staff see only what their role allows; a subject teacher cannot browse another class’s records.
  • Audit logs — sensitive changes (such as editing a published result) are versioned and attributed, so nothing is changed silently.
  • Least-privilege internal access — Edsynk staff access customer data only when needed for support and only with appropriate authorisation, and such access is logged.

We host on reputable cloud infrastructure and select hosting regions to keep latency low and meet our obligations under Nigerian law. No system is perfectly secure, but we work continuously to reduce risk and respond quickly when issues arise.

07Sub-processors

To run the service we rely on a small number of trusted providers who process data on our behalf, under contract and only for the purposes below:

  • Paystack — processing card and bank payments. Payment details go to them directly; Edsynk does not store full card data.
  • SMS & messaging providers (Termii) — delivering notifications, result alerts and one-time codes to guardians and staff.
  • Cloud hosting & database (Vercel, Neon) — hosting the application, databases and encrypted backups.
  • File storage (Cloudflare R2) — storing school logos, photos and uploaded documents.
  • Error monitoring (Sentry) — capturing technical faults so we can fix them; configured to minimise personal data in reports.

We use only sub-processors that offer appropriate protections, and we remain responsible to the school for their handling of data. We will give schools reasonable notice of any material change to this list.

08Data ownership & export

The school’s data belongs to the school. Edsynk claims no ownership over student records, results or any other content a school puts into the platform. We are custodians, not owners.

A school can export its data at any time — students, results, attendance and report cards — in standard, portable formats.

We will never hold children’s data hostage. If an account is suspended — for example for non-payment — it becomes read-only rather than deleted, and export remains available throughout. A billing dispute will never cut a school off from its own records.

09Retention & deletion

We keep personal data for as long as the school (as controller) instructs, plus any minimum period Nigerian law requires. Academic records often need to be kept for years so that transcripts and historical results stay verifiable.

When a school offboards, or asks us to delete specific records, we delete or return the data on the school’s verified instruction, subject to any legal retention obligation. Backups containing deleted data are overwritten on our normal backup cycle.

10Your rights under the NDPA

Under the NDPA 2023 and NDPR, data subjects have the right to:

  • Access — ask what personal data is held about you or your child.
  • Rectification — have inaccurate data corrected.
  • Erasure — ask for data to be deleted, where no legal duty requires us to keep it.
  • Portability — receive your data in a portable format.
  • Objection — object to certain processing, and withdraw consent you have given.

How to exercise them: for a student’s records, contact the school in the first instance — as controller, it verifies identity and acts on requests. For data Edsynk controls directly, or if the school directs a request to us, write to privacy@edsynk.ng. We respond within the timeframe set by the NDPA.

11Data breach handling

If a personal data breach occurs, we act quickly to contain it and assess the risk. Where the law requires, we notify the affected school without undue delay so it can meet its own obligations as controller, and we notify the Nigeria Data Protection Commission (NDPC) within the timeframe set by the NDPA. Where a breach is likely to result in high risk to individuals, affected people are informed through the appropriate route.

12International transfers

We aim to keep data on infrastructure appropriate for Nigerian schools. Where any processing or backup involves a transfer outside Nigeria — for example a sub-processor’s regional infrastructure — we ensure an adequate level of protection through appropriate safeguards permitted under the NDPA, such as contractual data-protection terms with the recipient.

13Contact us

Questions about this policy, or about how your or your child’s data is handled, are welcome.

  • Privacy team privacy@edsynk.ng
  • For students — contact your school, which holds your records as data controller.
  • Company — Edsynk Technologies Ltd, Bauchi, Nigeria.

If you believe your rights under the NDPA have not been respected, you may also lodge a complaint with the Nigeria Data Protection Commission (NDPC).

↑ Back to top