Privacy Policy

Your privacy matters to us. Learn how EDVES collects, uses, and protects your information in compliance with global data protection standards.

GDPR Compliant FERPA Aligned COPPA Compliant CCPA Ready
Effective Date: December 2025 | Version 2.0

1. Data Controller Information

For the purposes of applicable data protection laws, the data controller responsible for your personal data is:

EDVES Inc.

Website: www.edves.com

Email: hello@edves.net

Data Protection Officer: hello@edves.net

EU/UK Representative: For data subjects in the European Union or United Kingdom, our representative can be contacted at hello@edves.net.

2. Introduction

EDVES is an Educational Management Information System (E.M.I.S.) and a software service that automates educational processes from enrolment and registration to result computation and publishing. It is a comprehensive Educational Portal system designed to service the information needs of students, their parents, and educators.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. It applies to all users of our services, including students, parents, guardians, educators, school administrators, and institutional staff across all regions where EDVES operates.

This policy is designed to comply with the following regulations:

  • General Data Protection Regulation (GDPR) — European Union and United Kingdom
  • Family Educational Rights and Privacy Act (FERPA) — United States
  • Children's Online Privacy Protection Act (COPPA) — United States
  • California Consumer Privacy Act (CCPA/CPRA) — California, United States
  • Nigeria Data Protection Regulation (NDPR) — Nigeria
  • Data Protection Act, 2012 (Act 843) — Ghana
  • Protection of Personal Information Act (POPIA) — South Africa
  • UK Data Protection Act 2018 — United Kingdom

3. Categories of Data We Collect

We collect the following categories of personal data:

3.1 Identity Information

  • Full name, date of birth, gender
  • Student ID numbers, national identification numbers (where applicable)
  • Photographs for identification purposes
  • Parent/guardian names and relationship to student

3.2 Contact Information

  • Email addresses (student, parent, educator)
  • Phone numbers (mobile, home, emergency contacts)
  • Physical addresses

3.3 Educational Records

  • Grades, transcripts, assessment results
  • Attendance records and participation data
  • Curriculum progress and learning analytics
  • Class enrolments and academic history
  • Disciplinary records (where applicable)
  • Special Educational Needs (SEN) information

3.4 Financial Information

  • Fee payment records and invoices
  • Financial aid and scholarship information
  • Payment method details (processed by third-party payment providers)

3.5 Technical Data

  • IP addresses and device identifiers
  • Browser type and version
  • Operating system
  • Login timestamps and session data
  • Pages visited and features used

3.6 Sensitive Data (Special Categories)

With explicit consent or as required for educational purposes, we may process:

  • Health information relevant to educational needs
  • Disability and accessibility requirements
  • Religious beliefs (for scheduling purposes)
  • Ethnicity data (for statistical reporting where legally required)

5. How We Use Your Data

We use the collected information for the following purposes:

5.1 Educational Service Delivery

  • Managing student enrolment, registration, and class assignments
  • Recording and computing academic results and grades
  • Generating transcripts, report cards, and certificates
  • Tracking attendance and participation
  • Facilitating communication between educators, students, and parents
  • Providing AI-powered personalised learning recommendations

5.2 Administrative Functions

  • Processing tuition and fee payments
  • Managing staff payroll and human resources
  • Generating compliance reports for education authorities
  • Scheduling and timetable management

5.3 Platform Improvement

  • Analysing usage patterns to improve functionality
  • Conducting research to enhance educational outcomes
  • Testing new features and services

5.4 Security and Compliance

  • Preventing fraud and unauthorised access
  • Enforcing our terms of service
  • Complying with legal obligations and court orders

6. How We Share Your Data

We do not sell your personal data. We may share your information with the following categories of recipients:

6.1 Educational Institutions

Schools and districts that have contracted with EDVES to provide educational management services. They act as joint data controllers or data controllers with EDVES acting as a data processor.

6.2 Service Providers

Third-party vendors who perform services on our behalf, including:

  • Cloud hosting providers (data storage and computing)
  • Payment processors (Paystack, Flutterwave, Stripe)
  • Email service providers (SendGrid, for transactional emails)
  • Analytics providers (anonymised usage data only)

All service providers are bound by data processing agreements requiring them to protect your data and use it only for specified purposes.

6.3 Government and Regulatory Bodies

We may disclose data to education authorities, examination bodies (WAEC, NECO, etc.), and regulatory agencies as required by law.

6.4 Legal Requirements

We may disclose data when required by law, court order, or to protect our rights, safety, or property.

California Residents (CCPA): We do not "sell" personal information as defined by the CCPA. You have the right to opt-out of any future sales, should our practices change.

7. International Data Transfers

EDVES operates globally, and your data may be transferred to and processed in countries outside your country of residence. When we transfer personal data internationally, we implement appropriate safeguards:

7.1 Transfer Mechanisms

  • Adequacy Decisions: Transfers to countries with EU adequacy decisions
  • Standard Contractual Clauses (SCCs): EU-approved contractual terms with data importers
  • Binding Corporate Rules: Where applicable for intra-group transfers
  • Supplementary Measures: Technical measures including encryption and access controls

7.2 Data Storage Locations

Our primary data centres are located in:

  • Ireland (Dublin)

You may request information about the specific safeguards applied to your data transfers by contacting our Data Protection Officer.

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:

Data Category Retention Period
Student academic records Permanently (or as required by educational authorities)
Attendance records 7 years after leaving institution
Financial/payment records 7 years (for tax and audit purposes)
User account data Duration of account + 2 years
Technical logs 90 days (rolling)
Marketing consent records Duration of consent + 3 years
Support communications 3 years from resolution

When retention periods expire, data is securely deleted or anonymised using industry-standard destruction methods.

9. Your Data Protection Rights

Depending on your location, you have the following rights regarding your personal data:

Right to Access

Request a copy of the personal data we hold about you, along with information about how we process it.

Right to Rectification

Request correction of inaccurate or incomplete personal data we hold about you.

Right to Erasure

Request deletion of your personal data in certain circumstances ("right to be forgotten").

Right to Restriction

Request that we limit the processing of your personal data in certain circumstances.

Right to Data Portability

Receive your personal data in a structured, machine-readable format and transfer it to another controller.

Right to Object

Object to processing based on legitimate interests, direct marketing, or research/statistical purposes.

Automated Decision Rights

Not be subject to decisions based solely on automated processing that significantly affect you.

Right to Withdraw Consent

Withdraw your consent at any time where we rely on consent to process your data.

How to Exercise Your Rights

To exercise any of these rights, please contact us at:

We will respond to your request within 30 days (or 45 days for CCPA requests). We may request proof of identity before processing your request.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority:

  • UK: Information Commissioner's Office (ICO) — ico.org.uk
  • EU: Your local Data Protection Authority
  • Nigeria: Nigeria Data Protection Commission (NDPC)
  • USA: Federal Trade Commission (FTC) or state attorney general

10. Children's Privacy (COPPA Compliance)

EDVES is an educational platform designed to serve students of all ages. We are committed to protecting the privacy of children and comply with the Children's Online Privacy Protection Act (COPPA) for users under 13 years of age in the United States.

10.1 Consent Requirements

  • For children under 13, we require verifiable parental consent before collecting personal information, unless the school has agreed to obtain consent on behalf of parents.
  • Schools using EDVES act as agents of the parent for purposes of consent, but only for educational purposes.
  • We limit collection from children to information reasonably necessary for educational activities.

10.2 Parental Rights

Parents and guardians have the right to:

  • Review personal information collected from their child
  • Request deletion of their child's personal information
  • Refuse further collection or use of their child's information
  • Agree to collection but not disclosure to third parties

10.3 Data Minimisation

We collect only the personal information necessary to provide educational services. We do not:

  • Require children to disclose more information than necessary
  • Use children's data for targeted advertising
  • Share children's data for commercial purposes unrelated to education

Parents may contact us at hello@edves.net to exercise their rights under COPPA.

11. FERPA Compliance (US Educational Institutions)

For schools in the United States, EDVES operates as a "school official" under the Family Educational Rights and Privacy Act (FERPA). We are contractually bound to:

11.1 Education Records

  • Use education records only for authorised educational purposes
  • Not disclose education records without proper consent or legal basis
  • Maintain the security and confidentiality of student records
  • Return or destroy education records when no longer needed

11.2 Directory Information

Schools may designate certain student information as "directory information" that can be disclosed without consent. Parents may opt-out of directory information disclosure by contacting their school.

11.3 Parent and Student Rights

  • Parents of students under 18 may inspect and review education records
  • Eligible students (18 or older) may exercise these rights themselves
  • Right to request amendment of inaccurate records
  • Right to consent before disclosure (with exceptions)

FERPA requests should be directed to your educational institution. The school, not EDVES, is the custodian of education records under FERPA.

12. Data Security

We implement comprehensive technical and organisational measures to protect your personal data:

12.1 Technical Safeguards

  • Encryption: TLS 1.3 for data in transit; AES-256 for data at rest
  • Access Controls: Role-based access, multi-factor authentication
  • Infrastructure: Secure cloud hosting with SOC 2 Type II certified providers from 2026
  • Monitoring: 24/7 security monitoring and intrusion detection
  • Backups: Regular encrypted backups with tested recovery procedures

12.2 Organisational Measures

  • Employee training on data protection and security awareness
  • Background checks for personnel with access to sensitive data
  • Vendor due diligence and data processing agreements
  • Regular security audits and penetration testing
  • Incident response plan and procedures

13. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience:

13.1 Types of Cookies

  • Essential Cookies: Required for platform functionality (authentication, security)
  • Preference Cookies: Remember your settings and preferences
  • Analytics Cookies: Help us understand usage patterns (anonymised)
  • Performance Cookies: Monitor platform performance and errors

13.2 Managing Cookies

You can control cookies through:

  • Our cookie consent banner when you first visit
  • Your browser settings (note: disabling cookies may affect functionality)
  • Cookie preference centre in your account settings

For detailed information, see our Cookie Policy.

14. Automated Decision-Making and AI

EDVES uses AI and automated processes to enhance educational outcomes:

14.1 How We Use AI

  • Learning Analytics: Identifying student (using non-personal data) strengths and areas for improvement
  • Recommendations: Suggesting resources and activities
  • Learning Content Training: Generating educative content
  • Automated Grading: Assisting with objective assessment scoring

14.2 Your Rights

We do not make decisions that produce legal or similarly significant effects based solely on automated processing. Where AI influences educational decisions:

  • Human review is always available before usage
  • You can request an explanation of how decisions were made
  • You can contest automated decisions through your school

15. Data Breach Notification

In the event of a personal data breach, we follow a strict notification protocol:

  • Detection: Continuous monitoring systems to identify potential breaches
  • Assessment: Immediate evaluation of scope, severity, and risk
  • Regulatory Notification: Report to supervisory authorities within 72 hours where required (GDPR)
  • User Notification: Notify affected individuals without undue delay if the breach poses a high risk to their rights
  • School Notification: Immediate notification to educational institutions under contract
  • Documentation: Complete records of all breaches, regardless of notification requirement

If you believe your data has been compromised, contact us immediately at security@edves.net.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How We Notify You

  • Material Changes: Email notification and prominent notice on our platform
  • Minor Changes: Updated date at the top of this page
  • Review Period: At least 30 days before significant changes take effect

Continued use of our services after changes become effective constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.

17. Contact Us

For questions about this Privacy Policy or to exercise your data protection rights:

Data Protection Officer

Email: hello@edves.net

Response Time: Within 5 business days

Privacy Team

Email: hello@edves.net

Subject Access Requests: hello@edves.net

Your Acceptance

By using EDVES services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our services. For educational institutions, your continued use of our platform signifies acceptance on behalf of your institution and its users as authorised representatives.

This Privacy Policy should be read in conjunction with our Terms of Service and Cookie Policy.