Privacy Policy

Last changed: 26 September 2026

1. Who We Are

Sajama Campus is a multi-tenant school management platform operated by Sajama Technologies, based in Accra, Ghana. We provide digital infrastructure for schools to manage students, teachers, classes, results, lessons, quizzes, assignments, attendance, and communications.

Our platform is designed for the Ghanaian education sector. Applicable data-protection obligations, including Ghana's Data Protection Act, 2012 (Act 843), must be assessed for the actual deployment. This notice is not a certification of legal compliance.

School authorisation at registration

Registration requires an authorised representative to accept the versioned school data-processing notice. We retain the accepted text, version, timestamp and representative details. This does not replace notices or permissions required from individuals, and does not authorise unrelated marketing or sale of data.

2. Data We Collect

School Data

School name, code, address, phone, email, logo, subscription status, and payment records.

Staff Data (Admins and Teachers)

Full name, email address, phone number, role, login history, security request information, and activity within the platform.

Student Data

Full name, student code, email, date of birth, gender, class assignment, parent linkage, academic results, quiz scores, assignment submissions, attendance records, and payment status.

Parent Data

Full name, email address, phone number, relationship to student, and linkage to student accounts.

Technical Data

Security logs may include request information such as IP address and user agent; access is restricted. Authentication session data is used to provide the service. Optional analytics are separate aggregate counters and do not store raw IP addresses, raw user agents, account IDs, fingerprints, or GPS coordinates.

3. How We Use Data

  • To provide the school management platform and its features to your school.
  • To enforce role-based access control so each user sees only what their role permits.
  • To process platform payments (school subscription, teacher addition, student access) via Paystack.
  • To send transactional emails (account creation, password reset, payment receipts, announcements).
  • To maintain audit logs for security, compliance, and dispute resolution.
  • To detect and prevent fraud, abuse, and unauthorized access.
  • With opt-in permission, to understand aggregate public-site and adult staff usage by day, allowlisted page, school (for staff pages), device category, browser family and approximate country. Student and parent portal activity is excluded from optional analytics.

4. Legal Basis for Processing

The applicable lawful basis must be established for each purpose. Depending on the relationship and applicable law, these may include:

  • Consent: Schools are responsible for providing appropriate notices and obtaining parental consent where required. The recorded school authorisation is not evidence that each individual has consented. Optional public-site and adult staff analytics require a separate opt-in, which can be withdrawn in Analytics preferences on the Cookie Policy page.
  • Contractual necessity: Processing is necessary to deliver the platform services your school has subscribed to.
  • Legal obligation: We retain audit logs and financial records as required by Ghanaian law.
  • Legitimate interest: Necessary security monitoring and fraud prevention. Optional usage analytics are opt-in, not enabled under this basis.

5. Data Sharing

We share data only with:

  • Supabase (database hosting): Core platform records are stored through Supabase. Storage encryption depends on the managed provider’s controls; provider certifications do not independently certify this application.
  • Paystack (payment processing): Payment references and amounts are shared with Paystack to process transactions. We never share card numbers. Paystack handles all card data directly.
  • Resend (email delivery): Email addresses and message content are shared with Resend to deliver transactional emails.

We do not sell, rent, or share personal data with advertisers, data brokers, or any third party not listed above.

6. Data Security

We implement the following security measures:

  • Production HTTPS connections and managed-provider storage encryption, subject to deployment configuration.
  • Password authentication is handled by the configured authentication provider; password-reset and invitation tokens are hashed.
  • Row Level Security (RLS) enforced at the database level for multi-tenant isolation.
  • Server-side authentication and authorisation on protected API requests.
  • Rate limiting on all authentication endpoints to prevent brute-force attacks.
  • Audit records for security and sensitive administrative workflows.
  • Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), and other security headers.
  • Invite-based account creation with cryptographically secure tokens (bcrypt-hashed, 24-hour expiry).

7. Data Retention

  • School records are retained for delivering the service and applicable legal, accounting and security needs. Subscription expiry restricts access; it does not automatically erase records.
  • A deployment-specific retention schedule must be agreed with the school. No unimplemented automatic 30-day deletion, 12-month archiving or fixed audit-retention promise is made.
  • Deletion requests require identity/authority checks and consideration of legal holds. Database deletion, authentication accounts, stored files, provider records and backup expiry are separate operational steps.
  • Expired tokens cannot be used. Physical cleanup of expired tokens and aggregate analytics depends on configured scheduled jobs.
  • Contact us for the applicable retention schedule, an export or a deletion request. Payment restrictions do not remove applicable privacy rights.

8. Your Rights

Depending on applicable law and the type of processing, you may request:

  • Access your personal data held on the platform.
  • Correct inaccurate or incomplete data.
  • Request deletion of your personal data (subject to legal retention requirements).
  • Object to processing of your data for specific purposes.
  • Data portability: Receive your data in a structured, machine-readable format.
  • Withdraw consent at any time (this may affect your ability to use the platform).

To exercise these rights, contact your school administrator or email us at privacy@sajamacampus.com.

9. Children's Data

Sajama Campus processes data of minors (students under 18) solely for educational purposes as directed by their school. Schools generally determine the purposes of their educational records; Sajama processes these records on their instructions. Responsibility for account, billing and security processing must also be addressed in the school agreement. Parents may request access to, correction of, or deletion of their child's data through the school.

10. International Data Transfers

Our infrastructure is hosted on Supabase (AWS regions). Data may be processed outside Ghana. Hosting locations, provider contracts and applicable transfer safeguards must be confirmed for the school deployment before live personal data is uploaded. Contact us for the current provider and transfer information.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email to school administrators and posted on this page with an updated date.

12. Contact

Sajama Technologies

Data Protection Officer

Email: privacy@sajamacampus.com

Support: support@sajamacampus.com

If you are not satisfied with our response, you may lodge a complaint with the Ghana Data Protection Commission.