Decyfogate Schools

Privacy policy

Last updated 26 September 2026

Decyfogate Schools is a school management platform operated by DecyfoTech. This page says what personal data the platform handles, on what legal basis, why, who can see it, how long it is kept, and what a person can ask us to do about it. It is written for the Nigeria Data Protection Act 2023. A school on the platform is the data controller of its own records and its own policy applies to what it does with them; this page covers what the platform itself does.

Who is responsible for what

A school decides what to record about its pupils, staff, and families, and why. That makes the school the data controller for its records, and DecyfoTech the data processor: we handle them on the school instruction, for the school, and for no purpose of our own. For the platform account itself, the sign-in details and the technical records of a request, DecyfoTech is the controller, because those exist to run and protect the service rather than to run the school.

What we hold

The platform handles the data a school needs to run:

  • Account details for the people who sign in: a name, an email address or phone number, and a password or a one-time code. A member of staff may also have a staff number.
  • For each child: their name, student number, class, date of birth, and the name and phone number of the guardian the school recorded.
  • What the school records: attendance marks, dismissal and pickup records, announcements, results, report cards, fee obligations, and payments.
  • For a payment: the amount, the reference the payment provider issued, and the last four digits and card type where the provider supplies them. Card numbers never reach our servers; the provider handles them and we store a reference.
  • What the server sees when a request arrives: an IP address, a timestamp, and the action taken. Privileged and financial actions are recorded in an audit log with the account that took them.

Why we handle it, and on what basis

Under the Nigeria Data Protection Act 2023 we need a lawful basis for each purpose, and these are ours. Account details are handled to perform the agreement with the school and with the person signing in. School records are handled on the school instruction as processor, which rests on the school own basis with the families it serves. Financial records are handled to meet a legal obligation to keep accounts. Security records, the audit log and the technical request log, are handled for our legitimate interest in keeping the platform working and answering for what happens on it, and we keep that to what the purpose needs. A one-time sign-in code is handled with the consent of the person it is sent to, and is spent the moment it is used.

Children

A child never signs in, is never contacted by the platform, and has no account. Their record is created by their school, which is responsible for having the guardian consent to it, and their guardian sees it. A guardian reaches it only by holding a code sent to the phone number the school already had for that child, which is what stops one family reading another family child. The platform does not profile a child or use a child record for anything beyond the school own teaching, welfare, and fee administration.

Decisions the platform makes about a pupil

The platform can work out whether a pupil has met the school conditions for sitting an examination, from the attendance the school marked and the fees it has recorded, and it shows the result to the school. The decision is the school to make: the platform prepares the position, the school reviews it, and a school can override the result for any pupil with a reason, which is recorded. A guardian who wants a decision looked at by a person can ask the school, and the school can ask us.

Who can see it

A school sees its own records and nothing belonging to another school; the platform enforces that boundary on every request rather than only in the interface. A teacher sees the classes they take. A parent sees their own children. A member of DecyfoTech staff can reach platform-level records, and that access is limited to the work in hand, and a privileged action carries the name of the person who took it.

Who we share it with

We share data with the service providers the platform runs on, and each receives only what its job needs: the payment gateway that moves money; the messaging providers that deliver an SMS, a WhatsApp message, an email, or a push notification; the storage provider that holds an uploaded file; and the hosting providers that run the application and the database. A provider that handles data on our behalf is bound by a written agreement to handle it only on our instructions and to protect it. The list of providers, and where each one processes data, is available on request, and we tell schools before adding a provider that changes where their data is handled. We do not sell personal data, we do not share it for advertising, and we do not use a child record to train anything.

Data leaving Nigeria

Some of the providers above process data outside Nigeria. Where that happens we rely on the provider contractual protections and on the transfer conditions in the Nigeria Data Protection Act 2023, and we choose providers that can meet them. A school that needs its records kept in a particular place should tell us, because it is a question about how the platform is hosted rather than about the software.

How long we keep it

School records are kept while the school is a customer, and a school can export or delete its own records when it leaves. After an account or a school is closed, its records are deleted within 90 days, except what a law requires us to keep: financial records are kept for six years, as Nigerian company law requires, and a receipt or an invoice is kept for that period even after everything else is gone. An audit row is never edited or deleted, because it is the record that a change happened, and it is kept for the life of the platform. A sign-in code expires within minutes, and a code that has been used or replaced stops working at once. A signed-in session lasts 30 days unless the account signs out or changes its password.

Your rights

Under the Nigeria Data Protection Act 2023 a person can ask for a copy of their data, ask for it to be corrected, ask for it to be deleted, ask for its handling to be restricted, object to a particular handling, ask for it in a portable form, and withdraw a consent they gave. We answer a request within 30 days and usually sooner. A parent or a teacher should contact their school first, because the school holds those records and is the controller of them; anything the school cannot resolve comes to us, and we will take it up rather than send it back.

If you are not satisfied

A person who is not satisfied with our answer can complain to the Nigeria Data Protection Commission, the regulator established by the Nigeria Data Protection Act 2023, through ndpc.gov.ng. We would rather settle a matter with you first, and nothing here takes that route away from you. Our route for a data question is the privacy address below, and it reaches the person responsible for data protection at DecyfoTech.

If something goes wrong

If personal data is lost or exposed, we tell the Nigeria Data Protection Commission within 72 hours of becoming aware of it, and we tell the schools affected without waiting: what happened, what data was involved, what we have done, and what the school should tell its families. A school that needs to tell its families is given what it needs to do that.

How it is protected

Traffic is encrypted in transit. Passwords and sign-in codes are stored as one-way hashes, never in a form that can be read back. Every request that changes something is validated on the server and checked against the school and the role it belongs to. Sensitive actions are written to an audit log in the same transaction as the action itself, so the record and the change cannot disagree. Access to production systems is limited to the people who need it.

Cookies and local storage

The platform uses browser storage for two things and no others: keeping you signed in, and remembering the theme and the language you chose. The sign-in storage is strictly necessary, because without it there is no signed-in session. There are no advertising cookies, no third-party trackers, and nothing shared with an advertising network, which is why no cookie banner is shown: there is nothing to consent to beyond what the platform needs to work. A school that embeds something of its own on a page it controls is responsible for that, and it is not part of the platform.

The messages we send

Every message the platform sends is transactional: a sign-in code, a fee reminder the school raised, an attendance notice, a receipt, an announcement the school wrote. We do not send marketing to parents or to pupils, and a message from the platform always names the school it came from.

Changes to this policy

When this policy changes in a way that matters, schools are told before it takes effect, with what changed and why, and the date at the top of this page moves with it.

Contact

A question about this policy, a request about your data, or a complaint goes to the privacy address below. A security issue goes to the security address.

Where to write

A question about your data, or a request to see, correct, or delete it: privacy@decyfotech.com

A security issue, which we would rather hear about from you than read about elsewhere: security@decyfotech.com

A notice under these terms, or anything about the agreement itself: legal@decyfotech.com