Privacy Policy

Effective August 30, 2026

1. Who we are

Edumito is a school management platform built and operated by Goldus Technologies Limited (“Edumito”, “we”, “us”, or “our”), based in Lagos, Nigeria. This policy explains how we collect, use, share, and protect information when a school (a “Customer”) and its staff, students, and parents (“Users”) use Edumito.

2. Controller and processor roles

Schools sign up for Edumito, create student, staff, and guardian records, and manage that data through the platform. In doing so:

  • The school is the data controller for the student, staff, and guardian personal data it enters into Edumito — the school decides what data to collect and why, and is responsible for having a lawful basis to collect it (including any consent required from parents/guardians for a minor’s data).
  • Edumito is the data processor — we process that data only to provide the service, following the school’s instructions (given through their use of the platform), and do not sell, rent, or use student/guardian data for advertising.

For data we collect directly to run our own business — e.g. from a school administrator during signup and billing, or from a visitor to our marketing site — Edumito is the controller, and the rest of this policy applies in the ordinary sense.

3. What data we process

Depending on how a school configures and uses Edumito, this can include:

  • Student records: name, date of birth, gender, admission number, Learner Identification Number (LIN), classroom and academic history, attendance, exam and assignment results, report cards, profile photo, guardian/parent linkage.
  • Staff and guardian records: name, email, phone number, role, signature image (for report card sign-off), and account credentials.
  • Billing data: subscription and payment history, bank transfer references. Card and bank details themselves are handled directly by our payment processor, Paystack — we never receive or store full card numbers.
  • Usage data: login activity, audit logs of actions taken in the platform (who changed what, and when), device/browser information, and IP address, collected for security, abuse prevention, and support.

4. Children's data

A large part of what Edumito stores is student data, and many students are minors. Edumito does not knowingly collect this data directly from children — it is entered and managed by the school itself, acting as controller. Schools are responsible for ensuring they have the appropriate legal basis (including, where required, parental or guardian consent) before entering a student’s personal data into the platform. Parents and guardians who have questions about their child’s data in Edumito should contact their child’s school directly in the first instance, as the school controls that record.

5. How we use data

  • To operate the core features of the platform — enrollment, attendance, exams and results, fee billing, timetabling, messaging, and reporting.
  • To process subscription payments and installments, and to send related billing notices.
  • To send transactional email and notifications (e.g. OTP codes, password resets, payment confirmations, report card availability).
  • To generate optional AI-assisted insights (e.g. class performance summaries) — this feature is opt-in per school and can be disabled by the school administrator at any time.
  • To maintain security: detecting and preventing fraud, abuse, and unauthorized access, and keeping an audit trail of sensitive actions.
  • To comply with legal obligations and to enforce our Terms of Service.

6. Data isolation between schools

Edumito is multi-tenant software: every school’s records are logically separated and scoped to that school in our database, and every request is checked against the requesting user’s own school. Staff, students, and parents at one school cannot access another school’s data through the platform.

7. Sub-processors we use

We share data with the following third parties, only as needed to provide the service, and each under its own data protection terms:

  • Paystack — payment processing for subscription billing.
  • Amazon Web Services (S3) — storage of uploaded files (logos, signatures, gallery photos, documents).
  • Zoho ZeptoMail — delivery of transactional email (OTPs, receipts, notifications).
  • Cloudflare — network security and content delivery in front of our servers.
  • An AI language model provider, only for schools that opt in to AI-assisted insights, and limited to the aggregate performance data needed to generate that specific insight.

We do not sell personal data to any third party, and we do not permit our sub-processors to use data we share with them for their own marketing purposes.

8. International data transfer

Some sub-processors above (e.g. our cloud storage) may process or store data outside Nigeria. Where that happens, we require appropriate safeguards from that provider consistent with the Nigeria Data Protection Act, 2023 (NDPA).

9. Data retention

We retain school data for as long as the school’s subscription is active, plus a reasonable period afterward to allow the school to export records or reactivate. Withdrawn students and past academic records are kept (rather than deleted) by default, because schools need historical records — a school administrator can request deletion of specific records subject to any legal retention requirements that apply to educational records. On request from a school (as controller), we will delete or export the school’s data within a reasonable timeframe, consistent with our obligations under the NDPA.

10. Security measures

  • Authentication tokens are stored in httpOnly cookies, not accessible to JavaScript, reducing exposure to cross-site scripting attacks.
  • Sensitive configuration secrets (e.g. a school’s own payment gateway keys) are encrypted at rest.
  • Access to student and staff records is role-scoped — a user only sees the data their role and school entitle them to.
  • All traffic to Edumito is encrypted in transit (HTTPS).
  • We log sensitive administrative actions for accountability and investigation.

No system is perfectly secure, and we cannot guarantee absolute security — but we apply industry-standard practices and continue to improve them.

11. Cookies

We use a small number of strictly necessary cookies to keep you signed in (an httpOnly session cookie) and to remember your preferences. We do not use third-party advertising or cross-site tracking cookies.

12. Your rights under the NDPA

If you are a data subject in Nigeria, the Nigeria Data Protection Act, 2023 gives you rights including access to your data, correction of inaccurate data, deletion in certain circumstances, and objection to certain processing. If your data was entered by your school, please raise the request with your school first, since they control that record; if we hold data as controller (e.g. a school administrator’s own account details), contact us directly using the details below.

13. Changes to this policy

We may update this policy from time to time, for example as we add new features or sub-processors. We’ll update the effective date above, and for material changes we’ll make reasonable efforts to notify school administrators directly.

14. Contact us

Questions about this policy, or requests relating to personal data, can be sent to [email protected].

Ready to modernise your school?

Join hundreds of Nigerian schools already running on Edumito. Start your free 30-day trial — no credit card required.