Edu Maisha

Privacy Policy

Last updated September 2026

Edu Maisha ("Edu Maisha", "we", "us") provides school management software to schools in Kenya. This policy explains what personal data passes through the platform, why, and who's responsible for it.

1. Who controls this data, and who processes it

This distinction matters more than most of what follows, so it comes first.

Your school is the data controller. The school decides what student, staff, and guardian information to collect and why. Edu Maisha doesn't. If you're a parent, guardian, student, or staff member with a question about your own data, your first point of contact is the school that enrolled or employed you, not Edu Maisha directly.

Edu Maisha is the data processor. We store and process that data on the school's behalf, following their instructions, using the technical measures described below. We don't sell data, and we don't use one school's data for another school's benefit. Each school's database is physically separate from every other school's (see Section 5).

2. What data passes through the platform

CategoryExamples
Student recordsName, date of birth, gender, admission number, class, guardian relationships
Academic recordsAssessment scores, competency ratings, exam results, report cards, attendance
Health recordsMedical conditions, allergies, incidents logged by the school's matron/nurse
Financial recordsFee invoices, payment history, M-Pesa transaction references
Guardian/parent dataName, phone number, email, relationship to student
Staff/employee dataName, contact details, role, TSC number, KRA PIN, payroll and salary records. Staff may create their own account (self-registration, verified by email/SMS) before a school admin assigns them a role.
Account & usage dataLogin email, password (hashed, never stored in plain text), sign-in history (time, IP address, device/browser)

3. Children's data

Most of the student data on this platform belongs to minors. Kenya's Data Protection Act, 2019 requires a parent or guardian's consent before processing a child's personal data, and extra care in how it's handled. In practice on this platform: a school enrolls a student and records their guardian's contact details as part of normal admission. The school, as the data controller, is responsible for having a lawful basis under the Data Protection Act, 2019. In practice that is the parent or guardian relationship, formalised when the child is enrolled. Edu Maisha processes that data only on the school's instructions.

4. Why data is collected, and who else sees it

Data is used to run the school day to day: admissions, fee collection, academic records, communication with guardians, payroll, and reporting. Some of it is shared with third parties strictly to make specific features work:

We don't share data with advertisers, data brokers, or anyone outside these specific, feature-necessary integrations.

5. Where data is stored, and how it's protected

Each school's data lives in its own separate database, physically isolated from every other school's. A query that goes wrong for one school cannot expose another school's records. All traffic to the platform is encrypted (HTTPS). Passwords are hashed, never stored as plain text. Access within a school is role-based. What a given staff member can see and do is limited to their role (e.g. a teacher cannot see financial records; a librarian cannot see medical records), and every account can be deactivated immediately if someone leaves the school, without deleting their history. The platform keeps a record of sign-ins (time, IP address, device) and emails an account holder if their account signs in from a device it hasn't used before.

Hosting location: the platform runs on a DigitalOcean server in Germany (EU). That is a transfer of Kenyan personal data outside Kenya. We make that transfer on the basis of the EU's data protection standard (GDPR) as an appropriate safeguard. Schools are told this when they sign up. We will tell schools if the hosting location changes.

School data is backed up automatically every day and kept for a short rolling period.

6. How long data is kept

Data is retained for as long as a school's account is active. A student's academic and financial records, and a school's financial (ledger) records, are not deletable through the platform at all once created (by design, not by accident). A mistake is corrected by editing or by changing a student's status (e.g. Transferred, Graduated, Inactive), never by erasing the record. This protects academic and financial history from being altered or lost. There is no in-app button that permanently erases this data. If a parent, student, or staff member asks for deletion, that request goes to the school first. Where the school instructs us to delete data that staff cannot delete themselves, we handle it manually.

If a school leaves the platform, we keep its data for 12 months after the account ends, unless the school asks us to delete it sooner or Kenyan law requires us to keep it longer (for example financial records).

7. Your rights

Under Kenya's Data Protection Act, you have the right to know what data is held about you, request a copy of it, ask for it to be corrected, and in some cases ask for it to be deleted. Because your school is the data controller, these requests should generally go to your school first. Edu Maisha supports schools in fulfilling these requests as their data processor.

8. Cookies

The platform uses only the cookies necessary to keep you logged in and to protect against cross-site request forgery. There are no advertising or third-party tracking cookies.

9. Data breaches

If a breach affecting personal data occurs, we notify affected schools without undue delay. Where Kenyan law requires it, we also notify the Office of the Data Protection Commissioner.

10. Contact

Questions about this policy, or about Edu Maisha's role as a data processor, can be sent to admin@edumaisha.com or +254 723 836 815. If your question is about your own personal data specifically, please contact your school directly first.

11. Changes to this policy

We update this policy when our practices change. The date at the top of the page is the date of the current version.