Legal

Privacy Policy

How personal data, including children’s data, is handled.

Last updated 5 August 2026 Version 1.0 ~5 min read
Key points
  • Your school is the Controller; ScholaGH is the Processor.
  • We never sell student data, or use it for advertising or to train AI.
  • Data is encrypted, access is role-based, and sensitive actions are logged.
  • You can access, correct, or delete personal data through your school.
A plain-language summary for quick reading. The full terms are below.
Contents

This Privacy Policy explains how Personal Data is handled in the ScholaGH platform, in line with the Data Protection Act, 2012 (Act 843) of Ghana. A key point runs through this whole policy: for the school records in ScholaGH, the School is the data Controller and ScholaGH is the data Processor. That means the School decides why and how the data is used, and ScholaGH acts only on the School's instructions. This policy should be read together with our Data Processing Agreement and Cookie Policy.

1. Who we are

The ScholaGH platform is operated by SCHOLAGH TECHNOLOGIES, a Ghanaian technology business run as a sole proprietorship by Ahenkora Joshua Owusu. Through the ScholaGH platform we provide school-management software to schools ("Schools") in Ghana. Our contact details are in clause 12.

2. Controller and Processor: who is responsible

2.1 A Controller decides why and how Personal Data is used. A Processor acts on the Controller's instructions.

2.2 For the records a School keeps in ScholaGH, covering its students, parents, and staff, the School is the Controller and ScholaGH is the Processor. The School owns the relationship with parents and guardians and is responsible for the lawful basis and for the notices and consents required under Act 843.

2.3 Because ScholaGH is the Processor, we do not decide new purposes for the School's data and we do not use it for our own purposes. Where we handle limited data as a Controller (for example the School's own account and billing contacts), we do so as described in this policy.

3. The Personal Data we handle

On behalf of a School, the platform may hold:

  • Student Data (about minors): names, ages/date of birth, photographs, class, admission number, guardian details, attendance, assessment scores, and report cards.
  • Parent/guardian data: names, phone numbers, email addresses, and relationship to the student.
  • Staff data: names, roles, contact details, attendance, GPS clock-in location where staff use QR sign-in, and information used for payroll-adjacent records the School chooses to keep.
  • Fee and payment records: invoices, amounts, and payment status.
  • Communication logs: records of SMS or WhatsApp messages sent through the platform.
  • Account and security data: usernames, securely hashed passwords, and encrypted two-factor authentication secrets.

4. How and why the data is used

The data is used to provide the Service the School has asked for, including to:

  • run day-to-day operations: attendance, assessments, report cards, billing, and communication;
  • send parents the alerts the School configures, such as invoice, report, and absence notifications;
  • secure accounts and keep an audit trail of sensitive actions; and
  • provide support and keep the Service reliable.

We do not sell Personal Data, do not use Student Data for advertising, and do not use Student Data to train machine-learning or artificial-intelligence models.

5. Children's data

5.1 Much of the data in ScholaGH concerns children, and it is treated with particular care. Access to Student Data is limited to the child's School staff (scoped to their role) and to the child's approved parents or guardians through the parent portal.

5.2 As Controller, the School is responsible for giving parents the required information and for obtaining any parental consent needed under Act 843 and the duty of care to minors reflected in the Children's Act, 1998 (Act 560). ScholaGH processes Student Data only on the School's instructions.

6. Data minimisation and purpose limitation

6.1 The platform is designed to collect only the data a School needs to run its school. Schools are encouraged to enter only what is necessary.

6.2 Personal Data is used only for the purposes described in clause 4 and the School's own instructions, and not for unrelated purposes.

7. Sharing and Sub-processors

7.1 We share Personal Data only with the Sub-processors needed to run the Service, each bound to protect it:

  • Hubtel: sends the SMS the School enables, and supports payment features where used.
  • Railway (United States): hosts the application and database.
  • Cloudflare R2 (Cloudflare, Inc., United States): stores uploaded logos and photographs.

7.2 A current list of Sub-processors is kept in the Data Processing Agreement. We do not disclose Personal Data to any other third party except where the law requires it.

8. Security

We use appropriate technical and organisational measures, including:

  • encryption of traffic in transit (HTTPS);
  • two-factor authentication for administrator, finance, and teaching accounts;
  • encrypted storage of two-factor secrets and secure hashing of passwords;
  • role-based access control, so each user sees only what their role permits; and
  • an audit trail of sensitive actions such as payments, corrections, and publishing.

No system can be guaranteed perfectly secure, but we work to protect Personal Data and to improve these measures over time.

9. Retention and deletion

9.1 A School's records are kept for as long as the School uses ScholaGH and as needed to meet its academic and legal obligations.

9.2 On termination, the School may export its data during the Export Window described in our Terms and Data Processing Agreement, after which we delete or irreversibly anonymise it within a reasonable period, except for any copy the law requires us to keep or that remains in routine backups until those backups expire.

10. Your rights under Act 843

10.1 Under the Data Protection Act, 2012 (Act 843), individuals have rights over their Personal Data, including to be informed about its use, to access it, to correct inaccurate data, and to object to certain processing.

10.2 Because the School is the Controller, please send such requests to the relevant School first. As Processor, ScholaGH will assist the School in responding within the timeframes the law requires.

11. The Data Protection Commission

Ghana's Data Protection Commission (DPC) supervises compliance with Act 843. We work towards compliance with Act 843 and support Schools in meeting their own obligations as Controllers. We are arranging our registration with the DPC and will update this page once it is complete.

12. Changes and contact

12.1 We may update this Privacy Policy and will change the "Last updated" date above when we do.

12.2 Questions about privacy can be sent to:

  • Email: [email protected]
  • Phone: +233 53 704 1324
  • Post: SCHOLAGH TECHNOLOGIES, Greater Accra, Ghana

This document forms part of your agreement with SCHOLAGH TECHNOLOGIES and is provided for information. It is not legal advice.

Related documents
Terms of Service The agreement with your school Privacy Policy How personal data is handled Data Processing Agreement Controller and processor terms Acceptable Use Policy What you may and may not do Refund & Billing Policy Subscriptions and refunds Cookie Policy Cookies and local storage