← Back to home

Privacy Policy

Last updated: September 9, 2026 · Version: 2026-09-v1

This Privacy Policy explains how Schuwap Technologies (“Schuwap”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use our services, including the Schuwap School Management System (“SMS Platform”) and the Schuwap Computer-Based Testing platform (“CBT Platform”), collectively referred to as the “Services”.

This policy is issued in compliance with the Nigeria Data Protection Act 2023 (NDPA), the General Application and Implementation Directive (GAID) 2025, and the Child’s Rights Act 2003.

1. Data Controller & Processor

Under the NDPA:

  • Schools that use our Services are the data controllers for student, staff, and parent data they manage through the platform. They determine the purposes and means of processing that data.
  • Schuwap Technologies acts as a data processor on behalf of schools, processing personal data solely to provide the Services as described in our agreement with each school.
  • For marketing data (e.g., lead forms on our website) and platform account data, Schuwap Technologies is the data controller.

2. Data Protection Officer

Our Data Protection Officer can be contacted at:

  • Email: privacy@schuwap.xyz
  • Address: [PLACEHOLDER — Insert registered business address]

You may contact our DPO with any questions about how your personal data is handled, to exercise your data subject rights, or to lodge a complaint.

We process personal data under the following lawful bases as defined by the NDPA:

  • Consent: Where you have given clear, informed consent for us to process your data for a specific purpose (e.g., marketing communications, proctoring during CBT exams).
  • Contractual necessity: Processing necessary to perform our contract with schools (the subscription agreement) and to provide the Services to end users.
  • Legitimate interest: Processing necessary for our legitimate interests (e.g., fraud prevention, service security, platform improvement), where those interests are not overridden by the data subject’s rights.
  • Legal obligation: Processing necessary to comply with Nigerian law (e.g., maintaining academic records as required by education regulations).

4. Categories of Personal Data We Collect

4.1 School Management System (SMS Platform)

  • Student data: Full name, admission number, date of birth, gender, class assignment, house, clubs, photograph (optional), parent/guardian name, email, and phone number.
  • Staff data: Full name, email address, role, secondary roles, custom permissions.
  • Parent data: Full name, email address, phone number, linked student relationships.
  • Academic records: Scores, computed results, grades, class positions, teacher comments, principal remarks, psychomotor ratings, attendance records, lesson notes.
  • Administrative data: School name, address, type, academic sessions, terms, class structures, timetables, announcements.

4.2 Computer-Based Testing (CBT Platform)

In addition to basic account information (name, email, role), the CBT Platform collects:

  • Exam data: Question responses, submission timestamps, scores, grades, time spent per question.
  • Proctoring data (when enabled by the school/teacher):
    • Facial photographs: An identity verification photo captured before the exam begins, and up to 10 random snapshot images taken at intervals during the exam.
    • Face detection data: Whether a face is detected in the camera feed (face presence/absence), number of faces detected.
    • Gaze and head pose data: Iris position ratios and head orientation angles computed from facial landmarks, used to detect if the student is looking away from the screen. This data is processed entirely on the student’s device and is not transmitted to any external server.
    • Violation snapshots: Additional photographs captured automatically when the system detects a potential integrity violation (e.g., no face detected, looking away, multiple faces).
  • Device information: IP address, browser user agent, screen resolution, timezone, hardware concurrency (CPU core count), and a hashed device fingerprint derived from these values. The fingerprint is a one-way hash — the original device characteristics cannot be reconstructed from it.
  • Violation logs: Records of tab switches, fullscreen exits, suspected developer tools usage, and other integrity events with timestamps.
  • Gamification data: Experience points, badges earned, practice history, leaderboard rankings, study session statistics.

4.3 Payment Data

Subscription payments are processed by Paystack, a PCI DSS-compliant payment processor. Schuwap does not receive, store, or process your card number, CVV, or full card details. We only receive and store:

  • Subscription plan and billing cycle
  • Payment status (active, cancelled, expired)
  • Paystack subscription reference code
  • Transaction amounts and dates

4.4 Marketing & Lead Data

When you fill out a contact or demo request form on our website, we collect: full name, email, phone number, school name, your role, school type, estimated student count, and any message you include.

5. Children’s Data

Our Services are used in educational settings with students who may be under 18 years of age. We take the following measures to protect children’s data:

  • Student accounts are created by authorized school administrators, not by children directly. The school acts as an institutional proxy providing consent on behalf of parents/guardians in its capacity as an educational institution.
  • Parents/guardians with portal accounts can view what data is held about their child and may request corrections or deletion by contacting the school or our DPO.
  • Proctoring data for minors: When the CBT Platform’s proctoring features are enabled for exams taken by students under 18, the school (as data controller) is responsible for ensuring appropriate parental/guardian consent is in place. Students are shown a clear consent screen explaining what data will be captured before each proctored exam and may decline (which may prevent them from taking the proctored exam, at the school’s discretion).
  • We apply the principle of data minimization — we collect only the data necessary to deliver the educational services. Proctoring photos are not used for any purpose other than exam integrity verification.

6. Purpose of Processing

  • Education delivery: Providing school management tools, academic record-keeping, attendance tracking, result computation and publishing, timetable management, lesson note management, and communication features.
  • Exam integrity: Proctoring features (facial recognition, gaze tracking, device monitoring) to maintain the integrity of computer-based tests, at the school’s discretion.
  • Account management: User authentication, session management, role- and permission-based access control.
  • Billing & subscriptions: Processing subscription payments via Paystack, managing plan limits, trial periods.
  • Communication: Sending account credentials, password reset emails, announcements, and service notifications via email.
  • Security: Rate limiting, audit logging, fraud prevention, session management.
  • Platform improvement: Aggregated, anonymized analytics to improve the Services.
  • Marketing: Responding to demo/trial requests (only with your consent).

7. Proctoring Data — Detailed Disclosure

This section provides additional detail about the CBT Platform’s proctoring features, which collect sensitive biometric-adjacent data:

  • What is captured: Facial photographs (JPEG images captured via the device’s camera), gaze direction estimates, head pose angles, and violation event logs.
  • When and why: Proctoring is activated only when the exam creator (teacher or administrator) enables it for a specific exam. A mandatory consent screen is shown to the student before the exam begins. The purpose is exclusively to maintain exam integrity.
  • On-device processing: Face detection, gaze estimation, and head pose computation use TensorFlow.js and MediaPipe running entirely on the student’s device. No facial data or biometric computations are sent to Google, Meta, or any external AI service. Only the resulting photographs and violation logs are stored.
  • Storage: Proctoring photographs are stored in Firebase Cloud Storage with path-based access control. Only teachers and administrators of the same school can view them.
  • Retention: Proctoring photographs are retained for up to 90 days after exam completion to allow for result disputes and academic integrity reviews. After 90 days, they are automatically deleted unless a dispute is pending. You may request earlier deletion by contacting your school or our DPO.
  • Access: Proctoring photos are accessible only to authorized staff (teachers and administrators) of the school that administered the exam. Schuwap platform administrators do not routinely access proctoring data.

8. Data Sharing & Third-Party Services

We share personal data with the following categories of third-party service providers, solely to operate the Services:

  • Supabase Inc. — Database hosting, user authentication, and file storage for the SMS Platform.
  • Google Firebase (Google LLC) — Database (Firestore), user authentication, cloud functions, and file storage (proctoring photos) for the CBT Platform.
  • Paystack Payments Ltd. — Subscription payment processing. Paystack is a PCI DSS-compliant processor; card data is handled entirely by Paystack and never touches our servers.
  • Resend Inc. — Transactional email delivery (account invitations, password resets, notifications).
  • Cloudflare Inc. — R2 object storage for generated PDF files (results, broadsheets).
  • Vercel Inc. — Application hosting and serverless compute. Optional privacy-friendly analytics.
  • Inngest Inc. — Background job processing (result computation, PDF generation, PIN generation).
  • Upstash Inc. — Redis-based rate limiting for security.

We do not sell personal data to third parties, use it for advertising, or share it with data brokers. Data is shared with the providers above only as necessary to deliver the Services, under appropriate data processing agreements.

9. International Data Transfers

Some of our third-party service providers operate servers outside Nigeria (primarily in the United States and Europe). When personal data is transferred internationally, we ensure appropriate safeguards are in place as required by the NDPA, including:

  • Contractual obligations on processors to maintain data protection standards equivalent to those required under Nigerian law.
  • Use of encrypted data transmission (TLS/SSL) for all data in transit.
  • Encryption of data at rest where supported by the provider.

10. Data Retention

  • Active subscription: Data is retained for the duration of the school’s active subscription.
  • Academic records: Retained in accordance with Nigerian education record-keeping requirements. Schools may request data export and deletion upon subscription termination.
  • Proctoring photographs: Retained for up to 90 days after exam completion, then automatically deleted. Earlier deletion available upon request.
  • Device fingerprints and IP addresses: Retained for the duration of the exam session and for security audit purposes (up to 12 months).
  • Consent records: Retained indefinitely as required by NDPA to demonstrate lawful consent.
  • Audit logs: Retained indefinitely for security and compliance purposes.
  • Marketing lead data: Retained for up to 24 months from submission, or until you request deletion.
  • Post-termination: When a school terminates its subscription, we retain data for 30 days to allow for reactivation or data export, after which it is permanently deleted. Academic records may be retained longer where required by law.

11. Your Rights

Under the NDPA, you have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data, subject to legal retention obligations and legitimate interests.
  • Right to data portability: Receive your data in a structured, commonly used, and machine-readable format.
  • Right to object: Object to processing based on legitimate interest or for direct marketing purposes.
  • Right to restrict processing: Request that we limit how we use your data while a complaint or request is being resolved.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, contact our Data Protection Officer at privacy@schuwap.xyz. We will respond within 30 days.

For student data managed by a school, please contact the school directly in the first instance, as they are the data controller. If the school is unable to assist, you may contact us.

12. Security Measures

We implement appropriate technical and organizational measures to protect personal data:

  • All data transmitted between your device and our servers is encrypted using TLS.
  • Database access is controlled through Row Level Security (Supabase) and Firestore Security Rules (Firebase), ensuring tenant isolation — one school cannot access another school’s data.
  • API endpoints are protected by rate limiting to prevent brute-force attacks.
  • Administrative actions are recorded in an immutable, append-only audit log.
  • Staff accounts use role-based access control with granular permissions.
  • Passwords are hashed and never stored in plain text. Temporary passwords are generated with cryptographic randomness and must be changed on first login.
  • Proctoring photos are stored with path-based access control (only the student and authorized school staff can access them).

13. Cookies & Tracking Technologies

We use only essential cookies required for the Services to function:

  • Authentication session cookies: Set by Supabase Auth and Firebase Auth to maintain your login session. These are strictly necessary and cannot be disabled while using the Services.
  • Vercel Analytics (optional): Privacy-friendly, anonymized web analytics that do not use cookies or track individual users across sites.

We do not use advertising cookies, social media trackers, or third-party analytics that create cross-site user profiles.

14. Right to Lodge a Complaint with the NDPC

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC):

We encourage you to contact our DPO first so we can attempt to resolve your concern directly.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes:

  • We will update the “Last updated” date and version number at the top of this page.
  • For significant changes affecting how we process your data, we will notify you via email or an in-app notification and may require you to re-accept the updated policy.
  • Previous versions of this policy will remain available upon request.

Schuwap Technologies · [PLACEHOLDER — Registered address] · RC [PLACEHOLDER — RC Number]

Questions? Contact our DPO at privacy@schuwap.xyz