Privacy Policy

Last Updated: May 23, 2026 Effective Date: May 23, 2026 SMASA – Comprehensive Academic System

1. Introduction

Welcome to SMASA (School Management and Administration System), a comprehensive school management platform developed by TechSate Software Company. We are committed to protecting the privacy and security of all users, including students, teachers, parents, and school administrators.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By accessing or using SMASA, you agree to the terms outlined in this policy.

Our commitment: We process personal data transparently and only for legitimate educational purposes.

2. Information We Collect

Personal Information
Account info, student records (name, DOB, gender, address, photo), teacher/staff profiles, parent/guardian contact details, school administrative data.
Academic & Administrative Data
Class allocations, subject enrollments, examination grades, attendance logs, discipline records, fee payments (if applicable).
Technical Data
IP address, browser type, device info, OS, timestamps, pages visited, cookies and similar tracking technologies.
Cookies
Essential, functional, analytics, and security cookies to improve performance and security.

All collected data is strictly limited to what is necessary for operating the academic platform and ensuring a seamless experience for schools.

3. How We Use Your Information

Purpose Data Used
Provide & maintain Service All personal and academic data
Manage user accounts Account information, credentials
Process school admin tasks School, student, teacher data
Generate academic reports Examination results, attendance, grades
Communicate with users Contact info (email, phone)
Improve & secure service Usage data, IP addresses, logs
Comply with legal obligations All data as required by law
Prevent fraud & abuse Technical and behavioral patterns

4. Legal Basis for Processing (GDPR Compliance)

  • Consent: When explicit consent is provided.
  • Contract Performance: To fulfill service agreements with schools.
  • Legal Obligation: Compliance with applicable laws.
  • Legitimate Interests: Security, fraud prevention, service improvement.
  • Vital Interests: To protect safety of students and staff.

5. Information Sharing and Disclosure

We share data only as necessary for school operations and legal compliance:

  • With Your School: Administrators, teachers, and authorized personnel.
  • With Service Providers: Cloud hosting (Google Cloud Platform), email services, analytics, security providers – all contractually bound to confidentiality.
  • Legal Reasons: To comply with law enforcement, court orders, or public authorities.
We do NOT sell your personal information to third parties.

6. Data Security

Encryption: HTTPS/TLS in transit & AES-256 at rest.

Role-Based Access Control (RBAC): Granular permissions for every user type.

Password Security: bcrypt hashed passwords.

Audit Trails: Comprehensive logging of all system activities.

Automated Backups: Regular backups with disaster recovery procedures.

Network Security: Firewalls & DDoS protection.

Data Minimization: We collect only what is necessary for our Service.

Infrastructure: Google Cloud Platform secure data centers.

Security First: We continuously monitor and update our security practices to protect your data.

7. Data Retention

Data Type Retention Period
Student academic records 7-10 years after graduation (per educational laws)
User account information Active account + 2 years
Attendance records As required by school policies
Examination results Permanent (transcripts)
System logs 90 days
Backups 30–90 days (rotating)

You may request deletion of data as per Section 9.

8. Cookies & Tracking Technologies

We use essential cookies (laravel_session, XSRF-TOKEN), functional cookies (remember preferences), analytics (Google Analytics) and security cookies. You can manage cookies via browser settings, but essential cookies are required for platform operation.

9. Your Privacy Rights

Access & Portability
Request access or receive a portable copy of your data.
Correction
Rectify inaccurate or incomplete information.
Deletion
Request erasure, subject to legal holds.
Restriction & Objection
Restrict processing or object to legitimate interest processing.
Withdraw Consent
Withdraw consent at any time when processing is based on consent.
To exercise these rights, contact us at privacy@techsatesoftwarecompany.com. Response within 30 days.

10. Children's Privacy (COPPA Compliance)

SMASA is designed for schools. Schools act as data controllers and are responsible for obtaining parental consent where required (COPPA). We do not use student information for targeted advertising. Parents may review or delete child's information upon request.

11. International Transfers & Third-Party Links

Data may be processed on Google Cloud Platform servers located in the US/EU. We utilize Standard Contractual Clauses (SCCs) for adequate protection. Our service may contain links to external sites — we are not responsible for their privacy practices.

12. Contact Us & Data Controller

Data Controller: TechSate Software Company
Address: Kampala, Uganda
Email: privacy@techsatesoftwarecompany.com
Phone: +256 702 082 209
DPO: TechSate Software Company – dpo@techsatesoftwarecompany.com

For schools acting as data controllers: please direct privacy inquiries from your community to your designated school privacy contact.

13. Changes to Policy & Jurisdiction-Specific Notices

We may update this Privacy Policy. Changes will be posted with updated "Last Updated" date. Please review periodically.

🇺🇸 United States (COPPA, FERPA)
We comply with COPPA (parental consent for under 13) and FERPA regarding student education records.
🇪🇺 European Union (GDPR)
Legal basis per Section 4. Data subject rights under GDPR; right to lodge complaint with local DPA.
🇺🇬 Uganda (Data Protection Act, 2019)
Processing aligns with the Uganda Data Protection and Privacy Act, 2019. Data subject rights as described.
Other Jurisdictions
We adhere to applicable data protection laws in all regions where we operate.