Privacy policy
Last updated September 2026
This is a plain-language summary of how Edubrains handles data. A school signing up should have a lawyer review it against their own obligations before adopting it as a data-processing agreement.
01. Who holds the data
A school that uses Edubrains remains the owner of its own records — students, guardians, staff, fees and results. Edubrains stores and processes that data on the school's behalf and does not sell it, share it with other schools, or use it to build products for anyone else.
02. What we collect
From a school: the details entered by its own staff — student and guardian records, staff records, attendance, fee and payment records, exam marks, and documents uploaded by the school. From visitors to this website: the name, mobile number and message submitted through the contact or demo forms, plus the IP address the submission came from.
03. How schools are separated
Each school's records are isolated at the database level. The separation is enforced on every query rather than by filtering what the interface displays, and a user signed in at one school cannot reach another school's records even by editing the address bar. We test this boundary deliberately as part of our release process.
04. Children's data
A school records information about children, including names, dates of birth, photographs and B-Form numbers. That data is visible only to staff of that school who hold the relevant permission, and to the child's own guardians. It is never used for advertising or shared with third parties.
05. Sensitive documents
Uploaded documents — CNIC and B-Form copies, certificates, staff records — are stored on private storage that is not reachable by a public URL. Every download is served through an authorisation check against the requesting user's school and permissions.
06. SMS and notifications
Where a school sends SMS to parents, the message is delivered through a gateway provider on the school's instruction. The provider receives the recipient number and message content in order to deliver it. Delivery records are kept so a school can prove a message was sent.
07. Who can see what
Within a school, access is controlled by role. An accountant sees fees and finance; a teacher sees their own classes; a parent sees only their own children. School owners choose who holds which role.
08. Where data is stored
Data is stored on servers operated for Edubrains. Backups are taken regularly and are subject to the same access controls as live data.
09. How long we keep it
While a school's account is active, and for a period afterwards so an account can be recovered if cancellation was a mistake. A school may request a full export of its data or its permanent deletion at any time.
10. Your rights
A school may request a copy of its data in a portable format, correct anything inaccurate, or ask us to delete it. Individuals — a parent or a staff member — should direct such requests to their school, which controls the record.
11. Changes to this policy
If this policy changes materially, schools with active accounts will be notified before the change takes effect.
12. Contact
Questions about privacy or data handling can be sent to [email protected] or raised with us on 0300 1234567.
Questions about this?
Write to [email protected] and we will answer plainly.