Privacy Policy
Last updated 14 August 2026 · version 2026-08-14
1. Controller and processor
Your school is the data controller: it decides what student, guardian and staff information is recorded and why. Halidot Trading PLC is the data processor: we store and process that information on the school’s instructions in order to run the Service.
To correct or remove a record, contact your school. If you contact us directly, we will refer you to the school rather than change its records ourselves.
2. What we hold
- Student records — name (given, father, grandfather, and optionally mother), sex, date of birth, photograph where the school uploads one, grade and section, enrolment history, and the school-issued student ID number.
- Where the school records them, further student details — the national identity (Fayda) number, nationality, home address, and the school attended previously. All of these are optional and are entered by the school.
- Where the school records them, special-need categories and a related note for a student. This is health-related information about a child: it is entered by the school, it is readable only by the school's super admin, administrators, registrars and that student's own teachers, and it is never included in any spreadsheet the Service produces.
- Guardian records — name, relationship to the student, phone number and, optionally, a second contact number, email address, occupation and work address.
- Staff records — name, role, email address and phone number.
- Academic records — attendance, marks, grades and report cards.
- Financial records — fees charged, payments received, receipt numbers, and TeleBirr payment references. We do not store card or wallet credentials.
- Documents the school uploads, such as birth certificates, held in private storage.
- Technical records — sign-in events and an audit log of sensitive actions, including who acted, what changed, when, and the IP address and browser used.
3. Why we hold it
To provide the Service to your school: registering and enrolling students, recording attendance and results, issuing and reconciling fee payments, producing ID cards and report cards, and sending the messages described in section 5.
The audit log exists for accountability — so a school can establish who changed a grade or a financial entry, and when. It is also our own protection against misuse.
We do not sell personal data, and we do not use it for advertising or profiling.
4. Who can see what
Access is enforced by the database itself, not only by the screens you see. Each school’s data is isolated from every other school’s.
- School administrators see their own school's records.
- Teachers see the students in the sections and subjects assigned to them.
- Registrars see student and guardian records for their school.
- Accountants see financial records for their school. They cannot see a student's special-need information — the database itself refuses it, not just the screen.
- Parents and guardians see only their own children.
- Students see only themselves.
- Our platform operators can see account and school-level administrative information, and can reach underlying records only where necessary to operate or support the Service. Such access is logged.
5. Messages
We send SMS through an Ethiopian SMS provider and email through an email delivery provider, for sign-in codes, payment requests and receipts, and school announcements. The providers receive the phone number or email address and the message content, for delivery only.
6. Where data is processed
Records are stored in a managed PostgreSQL database, and the application runs on a server operated for this Service. Some processors — for payments, SMS, email delivery, error monitoring and abuse prevention — may process data outside Ethiopia.
7. How long we keep it
- Student and academic records are kept for as long as the school's account is active, because a school needs a permanent academic history.
- Financial records are kept as an append-only ledger and are not deleted while the account is active; entries are corrected by reversing entries, never erased.
- Records marked as deleted in the Service are hidden from normal use but retained, so that an accidental deletion can be recovered and the audit trail stays intact.
- When a school's agreement ends, the school may request an export. We then delete its data within a reasonable period, except where we are required to retain something by law.
8. How we protect it
- Every school's data is separated at the database level, so one school's account cannot read another's.
- Sensitive records carry a second check on the specific rows a person may see — a teacher's own sections, a parent's own children.
- Uploaded documents are held in private storage and reached only through short-lived links.
- Traffic is encrypted in transit, sign-in is rate-limited and protected by a CAPTCHA, and sensitive actions are audit-logged.
No system is perfectly secure. If a breach affects your school’s data, we will inform the school without undue delay so it can meet its own obligations.
9. Children
The Service holds records about children by design. Those records are entered and controlled by the school. Where a student is a minor, we expect the school to have the appropriate authority from the parent or guardian.
10. Your choices
To see, correct or object to how your information is used, contact your school first, as the controller. Service messages such as sign-in codes cannot be switched off while an account is active, since they are required to use the Service.
11. Changes and contact
We may update this policy; the version and date at the top will change and you will be asked to accept the update at your next sign-in. See also the Terms of Service.
Halidot Trading PLC — Addis Ababa, Bole, Woreda 04, House No. 001/1-04, Ethiopia.
info@halidot.com · +251900762076