Privacy & Data Protection • Version 1.0

SSIMS Privacy Policy

How SSIMS collects, uses, protects, and manages educational and personal information.

Effective Date: 24 August 2026
Last Updated: 24 August 2026
Version: 1.0

1. Overview & Educational Scope

The Secondary School Information Management System (“SSIMS”) is committed to protecting the privacy, confidentiality, and integrity of personal information entrusted to us by secondary schools, educators, students, guardians, and education stakeholders across Malawi.

This Privacy Policy explains what personal data we collect, why we collect it, how it is processed and safeguarded, and your rights regarding your information when interacting with our platform.

2. Information We Collect

To provide institutional management capabilities, SSIMS collects and processes several categories of data:

  • Institutional & Administrator Information: School name, EMIS registration code, physical address, institutional email, phone number, and authorized administrator details.
  • Student & Academic Records: Student identification numbers, full names, date of birth, gender, class/stream enrollments, attendance records, exam results, grade boundaries, and academic term reports.
  • Staff & Teacher Records: Teacher employee IDs, academic qualifications, department assignments, subject allocations, and contact information.
  • Guardian & Contact Data: Guardian names, relationship to students, phone numbers, email addresses, and residential localities.
  • Financial & Fee Transactions: Fee assessment schedules, receipt records, invoice numbers, financial aid allocations, and payment reference numbers.
  • Technical & Audit Logs: Login timestamps, IP addresses, browser user agent strings, and legal document acceptance records for security and compliance audits.

3. Purpose and Legal Basis for Processing

We process personal information under lawful bases including contractual necessity, institutional educational mandate, legal compliance, and legitimate operational interests. Specifically, data is used to:

  • Facilitate school operations, student enrollment, grading calculations, and report card generation.
  • Manage fee clearance, bursar receipts, and subscription billing lifecycle.
  • Authenticate users, enforce granular role-based access control, and protect system integrity.
  • Support authorized Ministry of Education and EMIS data synchronization where configured.
  • Communicate administrative notices, academic announcements, and password resets.

4. Protection of Student & Minor Data

Given that secondary school students may be minors, SSIMS treats student data with rigorous safeguards. Student information is strictly maintained under the institutional authority of the enrolling school.

SSIMS does not sell student personal data, does not build marketing profiles of students, and does not serve commercial advertising. Access to student performance records is restricted strictly to authorized teachers, school administrators, and the student’s verified guardians.

5. Third-Party Service Providers & Subprocessors

We engage select third-party service providers to assist in platform operation, under strict confidentiality and data protection agreements:

  • Database & Authentication Infrastructure: Supabase / PostgreSQL for secure data persistence, row-level security, and authentication.
  • Payment Processors: PayChangu and licensed local mobile money gateways to handle secure subscription and fee payments. Financial payment details are processed directly by authorized payment gateways.
  • Transactional Email: Cloud email providers (e.g. Resend) for account invitations, password resets, and verification OTPs.

6. Data Security & Storage Measures

SSIMS implements industry-standard security controls designed to safeguard institutional records against unauthorized access, loss, or alteration. These measures include:

  • Encryption in transit using modern TLS protocols.
  • Database Row Level Security (RLS) policies enforcing multi-tenant isolation between schools.
  • Cryptographic hashing of passwords and sensitive tokens.
  • Role-based authorization gates across administrative and academic modules.
  • Comprehensive audit trails for administrative verifications and legal acceptances.

7. Data Retention & School Offboarding

Institutional data is retained for the duration of the school’s active account and subscription, or as required by applicable educational record retention regulations.

Upon formal institutional termination or deletion request, school data is handled in accordance with our institutional deletion and backup retention policies.

8. User Rights & Data Subject Inquiries

Users and educational institutions may access, review, and update their personal profile information directly through their SSIMS dashboard. For student record amendments, inquiries should be directed to the respective school administrator.

9. Changes to this Privacy Policy

We may update this Privacy Policy to reflect enhancements to our service or applicable regulatory requirements. When revisions occur, the updated policy will be published with a revised version number and effective date.

Where required by law or platform policy, authenticated users will be prompted to acknowledge updated terms upon login.

10. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact:

SSIMS Privacy & Data Protection Office

Secondary School Information Management System

Email: blessingschilemba21@gmail.com

Phone: +265 984 671 670 | +265 987 438 536

Lilongwe, Republic of Malawi