Samdos Smart EMS

Pure educational management system for private and public schools in Nigeria and beyond.

Follow Us

// Legal

Privacy Policy

Last updated: October 7, 2026

This Privacy Policy explains how Samdos Technologies GC (“Samdos”, “we”, “us” or “the Company”) collects, uses, stores, shares and protects your personal information when you use the Samdos Smart Educational Management System, our website, and the School App, Staff App, Student App and Parent App (together, “the Service”). It also explains your privacy rights and how Nigerian data protection law, and where applicable international law, protects you. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

We are committed to protecting the personal data of everyone who touches the Samdos ecosystem — including school owners, administrators, teachers, staff, students, parents and guardians, association members, vendors, regulators and other stakeholders in the education sector — in full compliance with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR), and where applicable the General Data Protection Regulation (GDPR).

1. Interpretation and Definitions

Interpretation

Words whose initial letter is capitalised have meanings defined under the following conditions. These definitions apply whether they appear in the singular or in the plural.

Definitions

For the purposes of this Privacy Policy:

  • You means the individual accessing or using the Service, or the company or other legal entity on whose behalf such individual is acting. This includes school owners, administrators, teachers, staff, students, parents and guardians, association members, vendors, regulators and any other education-sector stakeholder. Under the NDPA and GDPR you may be referred to as the Data Subject.
  • Company (referred to as “we”, “us” or “our”) means Samdos Technologies GC, operated from Lagos, Nigeria. For the purposes of the NDPA and GDPR, the Company is the Data Controller of your personal data.
  • Service means the Samdos website, the School App, Staff App, Student App, Parent App and any related sub-applications, APIs or sub-domains operated by the Company.
  • Account means a unique account created for you to access the Service or parts of the Service.
  • Personal Data means any information relating to an identified or identifiable individual — such as a name, identification number, location data, online identifier, or factors specific to your physical, physiological, genetic, mental, economic, cultural or social identity.
  • Sensitive Personal Data means Personal Data revealing racial or ethnic origin, political opinions, religious beliefs, health data, biometric data or financial information. We process such data only with your explicit consent or where required by law.
  • Usage Data means data collected automatically, either generated by your use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
  • Service Provider means any natural or legal person who processes data on our behalf. Service Providers are considered Data Processors under the NDPA and GDPR and are required to enter into a Data Processing Agreement with us before accessing any Personal Data.
  • Cookies are small files placed on your computer, mobile device or other device by a website, containing details of your browsing history on that site among their many uses.
  • Device means any device that can access the Service, such as a computer, cellphone or digital tablet.
  • NDPA means the Nigeria Data Protection Act 2023; NDPR means the Nigeria Data Protection Regulation 2019; and NDPC means the Nigeria Data Protection Commission, the supervisory authority for data protection in Nigeria.

2. Information We Collect

Personal Data you provide

While using the Service, we may ask you to provide certain personally identifiable information that can be used to contact or identify you. This may include, but is not limited to:

  • Full name and title
  • Email address and phone number
  • Address, state, city and postal code
  • Date of birth (for identity verification purposes)
  • National Identification Number (NIN), passport or other government-issued ID where verification is required
  • Bank account or payment information needed to complete transactions within the Service
  • Professional credentials, institutional affiliation, role and designation
  • Usage Data

Stakeholder-specific information

To serve every role in the education ecosystem properly, we collect additional information based on your role on the platform:

  • Teachers: teaching qualifications, subject specialisations, employment records and professional registration numbers.
  • Administrators and school staff: administrative role, institution name and staff ID.
  • Schools and institutions: institution name, registration and accreditation status and contact person details.
  • Parents and guardians: relationship to the student and the student’s class or year group, so results, fees and communications can be linked correctly.
  • Students: admission number, class, subjects and academic records created through normal use of the Service.
  • Vendors and service providers: business name, CAC registration number, tax identification and descriptions of products or services offered.

We do not require sensitive Personal Data such as health records, biometric templates or financial statements for ordinary use of the Service. Where such information is ever needed (for example, a waiver that a school must record), we rely on your explicit consent and process it only for that stated purpose.

Information collected automatically

Usage Data is collected automatically when you use the Service. It may include your Device’s Internet Protocol address (IP address), browser type and version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data. When you access the Service through a mobile device, we may also collect the type of mobile device you use, your mobile device unique ID, the operating system, the type of mobile browser and other diagnostic data.

Information from third-party sign-in

The Service allows you to create an account and log in through third-party social login providers such as Google and Facebook. If you choose this route, we may receive personal data already associated with that account — typically your name, email address and public profile. You can review and disconnect these permissions at any time through your account settings.

Information from payments

We do not store or collect your payment card details. When you pay by card or bank transfer, that information is provided directly to our third-party payment processors, whose use of your information is governed by their own privacy policies. We receive only confirmation of the transaction and the minimum details needed to verify your identity and reconcile payment.

3. How We Use Your Information

The Company may use Personal Data for the following purposes:

  • To provide and maintain the Service, including monitoring how the Service is used.
  • To manage your Account — registration, login, profile setup and access to features available to registered users.
  • To deliver the education service itself — attendance, timetables, results, report cards, CBT assessments, fees, records, messaging and communication between schools, staff, students and parents.
  • To perform a contract — fulfilling subscription purchases and any other agreement you enter into with us through the Service.
  • To contact you by email, telephone, SMS or push notification about updates, security alerts and communications relating to the functionalities, products or contracted services you use.
  • To send news and offers about similar goods, services or events, unless you have opted out of receiving such information.
  • To verify identity in line with Know Your Customer (KYC) requirements and applicable Nigerian regulations.
  • To enforce Multi-Factor Authentication and other security measures that protect your account and Personal Data.
  • To comply with legal obligations under Nigerian law and applicable international law, including the NDPA 2023 and NDPR 2019.
  • To manage your requests and respond to your questions, support tickets and complaints.
  • To detect and prevent fraud, abuse and technical incidents, and to verify that the Service is being used in line with our Terms and Conditions.

4. Cookies and Tracking Technologies

We use Cookies and similar tracking technologies — beacons, tags and scripts — to track activity on our Service, store certain information and help us understand how the Service is used. You can instruct your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if you do not accept Cookies, you may not be able to use some parts of our Service. Cookies may be “Persistent” (they stay on your device when you go offline) or “Session” (they are deleted as soon as you close your browser).

We use both session and persistent Cookies for the following purposes:

  • Essential cookies (session): required to provide the Service and enable core features. They authenticate users and prevent fraudulent use of accounts. Without these, services you have requested cannot be provided.
  • Cookie consent cookies (persistent): remember whether you have accepted the use of cookies on the website.
  • Functionality cookies (persistent): remember choices you make, such as login details, language preference and saved school or class context, so you do not have to re-enter them every time.
  • Security and MFA cookies (session or short-lived): support multi-factor authentication checks and trusted device recognition to protect your account from unauthorised access.
  • Analytics and performance cookies (persistent, may be set by third parties): help us understand which pages are popular, where users drop off and how the Service performs, using pseudonymous identifiers rather than your name.

5. How We Share and Disclose Information

We do not sell your Personal Data. We may share your information only in the following circumstances:

  • With Service Providers: to monitor and analyse use of the Service, process payments, deliver communications and support security features. Every Service Provider must sign a Data Processing Agreement before accessing any Personal Data.
  • Within your school or institution: when you use the Service as part of an institution, authorised administrators can see the profile and academic information needed to run the school — for example class lists, results, attendance, fees and staff records. This is normal operation of an education management system and is governed by your institution’s own instructions.
  • Between linked accounts: a student’s record may be visible to a parent or guardian linked to that student, and a teacher’s verified credentials may be shared with the institution that engages them, subject to consent.
  • With Regulators and Authorities: we may share institution data or aggregated, anonymised data with regulators where their mandate or Nigerian law requires it, or where we receive a lawful request from a court, the NDPC, NITDA, the Ministry of Education or another public authority.
  • For business transfers: in connection with, or during negotiations of, any merger, sale of Company assets, financing or acquisition of all or a portion of our business to another company. We will notify you before your Personal Data becomes subject to a different privacy policy.
  • With Affiliates and business partners: in which case we require those parties to honour this Privacy Policy.
  • With your consent: for any other purpose disclosed to you at the point the information is collected.
  • Public areas: when you choose to share personal information in public areas of the Service, it may be viewed by other users and may be distributed outside the Service. Please apply the same care you would on any public platform.

We may disclose your Personal Data in the good-faith belief that such action is necessary to: comply with a legal obligation; protect and defend the rights or property of the Company; prevent or investigate possible wrongdoing in connection with the Service; protect the personal safety of users or the public; or protect against legal liability.

6. Retention of Your Personal Data

The Company will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. Specific retention periods apply:

  • Account data is retained for the life of your account and for 5 years after account closure, in line with Nigerian legal and regulatory requirements.
  • Student academic and institutional records are retained while the student is enrolled and for a reasonable period afterwards, so schools can meet academic, audit and verification obligations.
  • Transaction records are retained for a minimum of 6 years in compliance with Nigerian tax and financial regulations.
  • Usage Data and logs are generally retained for 30 days, unless required for security investigations or legal obligations.
  • MFA authentication logs are retained for 90 days for security audit purposes.
  • Marketing preferences are retained until you withdraw your consent or object to processing.

We conduct regular data retention reviews to ensure that data is not held longer than necessary. Usage Data is retained for internal analysis purposes, except where it is needed to strengthen security, improve the Service or where we are legally obligated to keep it for longer.

7. Transfer of Your Personal Data

Your information, including Personal Data, is primarily processed and stored in Nigeria. Where data is transferred to, or accessed from, outside Nigeria, we ensure adequate safeguards are in place — including transfers to countries recognised by the NDPC as providing an adequate level of protection, and the use of Standard Contractual Clauses or equivalent binding instruments approved under the NDPA 2023. Your consent to this Privacy Policy, followed by your submission of such information, represents your agreement to that transfer. We will not transfer your Personal Data to an organisation or country unless there are adequate controls in place, including the security of your data and other personal information.

8. Security of Your Personal Data

The security of your Personal Data is a top priority. We implement and maintain a comprehensive, risk-based security programme in line with the NDPA 2023, NDPR 2019 and international best practice. Our measures include:

  • Encryption in transit: all data sent between your device and our servers is protected with TLS 1.2 or higher (HTTPS).
  • Encryption at rest: sensitive stored data, including passwords (hashed) and payment confirmation details, is encrypted at rest.
  • Access controls: role-based access controls ensure staff and systems can access only the data required for their function (the principle of least privilege).
  • Audit logging: access to Personal Data and key system events are logged and regularly reviewed to detect unauthorised activity.
  • Monitoring and testing: continuous infrastructure monitoring, regular vulnerability assessments and penetration testing, with encrypted backups maintained for resilience.
  • Organisational measures: staff are bound by strict confidentiality obligations, receive regular data protection training, and third-party vendors are vetted and bound by Data Processing Agreements.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of the breach, as required by the NDPA 2023, and will notify affected users without undue delay with information on the nature of the breach, the data affected and the steps taken to mitigate harm. While we strive to use commercially acceptable means to protect your Personal Data, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

9. Multi-Factor Authentication (MFA)

To enhance account security and protect sensitive educational and personal data, Samdos supports Multi-Factor Authentication across the platform. MFA requires you to provide two or more verification factors to access your account, which significantly reduces the risk of unauthorised access even if your password is compromised.

Supported MFA methods may include:

  • One-Time Password (OTP) via SMS — a time-sensitive code sent to your registered phone number.
  • One-Time Password (OTP) via Email — a time-sensitive code sent to your registered email address.
  • Authenticator App — support for TOTP-based authenticator applications such as Google Authenticator, Microsoft Authenticator or Authy.

To deliver MFA we process your registered phone number and email address, timestamps of authentication attempts, device identifiers (to detect new device logins) and login location (IP address and approximate geography) for anomaly detection. This data is used only for security and fraud prevention and is retained only as long as necessary — authentication logs are retained for 90 days for audit purposes. MFA is mandatory for users accessing sensitive features such as institutional administration, financial transactions and regulatory data management; users who do not complete MFA setup will have restricted access to those areas. If you lose access to your MFA method, contact [email protected] and we will guide you through a verified account recovery process.

10. Your Data Protection Rights

Under the Nigeria Data Protection Act 2023 and the NDPR 2019, and where applicable the GDPR, you have the following rights, which the Company undertakes to respect:

  • To be informed. You have the right to know what Personal Data we collect, why we collect it and how it is used — this Privacy Policy fulfils that obligation.
  • Access. You may request access to the Personal Data we hold about you, and receive a copy of it.
  • Correction. You may request that incomplete or inaccurate information be corrected or updated.
  • Deletion. You may request that we delete or remove your Personal Data where there is no good reason for us to continue processing it, subject to legal retention duties (see Section 6).
  • Objection. You may object to processing based on legitimate interests, and you may object at any time to processing for direct marketing purposes.
  • Restriction. You may request that we restrict how we use your Personal Data while a concern is investigated.
  • Portability. You may request that we provide your Personal Data in a structured, commonly used, machine-readable format, or transfer it to a third party you choose.
  • Withdraw consent. Where processing is based on consent, you may withdraw it at any time. We may not be able to provide certain functionalities of the Service if you do so.
  • Lodge a complaint. You have the right to lodge a complaint with the Nigeria Data Protection Commission at https://ndpc.gov.ng if you believe your rights have been violated. Users in the EU/EEA may also contact their local supervisory authority.

To exercise any of these rights, contact us using the details in Section 14. We may ask you to verify your identity before responding, and we will normally respond within 30 days. This period may be extended by a further 30 days in complex cases, with prior notice to you.

11. Children’s Privacy

Our Service is designed for use by schools, staff, students and parents under the supervision of an institution. The Service is not addressed to children under 13 acting on their own, and we do not knowingly collect personal information directly from children under 13 without verification of parental or school consent. Where a student is under 13, the account is created and managed by the school or parent/guardian, and the information collected is limited to what the school legitimately requires to run its operations. If you are a parent or guardian and believe your child has provided us with Personal Data without that consent, please contact us and we will take steps to remove the information from our servers.

Our Service may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the privacy policy of every site you visit. We have no control over, and assume no responsibility for, the content, privacy policies or practices of any third-party sites or services.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and, for material changes, by email or a prominent notice on the Service at least 14 days before the changes take effect. We will also update the “Last updated” date at the top of this policy, and where required by law we will seek your fresh consent before applying changes that affect how we process your data. You are advised to review this Privacy Policy periodically for any changes. Changes take effect when they are posted on this page.

14. Contact Us

If you have any questions about this Privacy Policy, your personal data, or how to exercise your rights, you can contact us:

We are happy to clarify anything in this policy that is not clear — protecting your data is part of protecting your school.