How DarasaDigital collects, processes, stores, and protects your personal data in compliance with the Kenya Data Protection Act, 2019.
Darasa Digital ("Company," "we," "us," or "our") is an educational technology school operating system registered in Kenya.
For the purposes of the Kenya Data Protection Act, 2019 (the "DPA"), Darasa Digital operates as a Data Processor for all student academic records, CBC assessment rubrics, parent contact details, attendance logs, and school fee records entered into the Platform by subscribing schools (where each subscribing school acts as the Data Controller). Darasa Digital operates as a Data Controller for registered school administrator account details, subscription billing records, website analytics, and customer support communications.
ODPC Compliance
Darasa Digital is registered with the Office of the Data Protection Commissioner (ODPC) of Kenya in compliance with Section 18 of the Data Protection Act, 2019 and the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021.
This Privacy Policy applies to all users of the DarasaDigital platform, including but not limited to:
This Policy covers data collected through the web application, tenant subdomains (e.g., yourschool.darasadigital.com), API integrations, and any associated mobile interfaces.
We process personal data in accordance with the Kenya Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021. Our legal bases for processing include:
Consent (Section 30)
You provide explicit consent when registering for our services and accepting this Privacy Policy and our Terms of Service.
Contractual Necessity (Section 30(1)(b))
Processing is necessary for the performance of the subscription agreement between the school and DarasaDigital.
Legal Obligation (Section 30(1)(c))
We process data as required by Kenyan law, including compliance with the Kenya Institute of Curriculum Development (KICD) assessment frameworks, National Education Management Information System (NEMIS) reporting, and Kenya National Examinations Council (KNEC) requirements.
Legitimate Interest (Section 30(1)(f))
Processing for platform security, fraud prevention, service improvement, and analytics where such interests are not overridden by the data subject's rights.
We collect and process the following categories of personal data:
We process personal data for the following specific purposes:
| Purpose | Data Categories Used |
|---|---|
| Provision of school management services | A, B, C, D, E |
| CBC assessment recording and report card generation | B, C |
| Automated M-Pesa fee reconciliation | B, D |
| NEMIS and KNEC compliance reporting | A, B, C |
| Timetable generation and scheduling | A, C, E |
| Staff payroll processing | E |
| SMS and email communication to parents | B, E, F |
| Platform security, audit logging, and fraud prevention | F |
| Service improvement and analytics | F |
| Subscription billing and account management | A, D |
| Legal and regulatory compliance | All categories as required |
We do not sell, rent, or trade personal data. We may share personal data with the following categories of recipients only as necessary:
Safaricom PLC (M-Pesa)
Payment ProcessorFor processing fee payments via the M-Pesa Daraja API. Transaction data (phone numbers, amounts, timestamps) is shared as necessary to process and reconcile payments.
Email & SMS Service Providers
CommunicationWe use third-party communication providers to deliver transactional emails (verification codes, report cards) and SMS messages (fee receipts, attendance alerts). Only the minimum data necessary for delivery is shared.
Cloud Infrastructure Providers
HostingOur platform is hosted on secure cloud infrastructure. Data is stored in encrypted databases with access limited to authorised personnel and automated systems.
Government Authorities
Legal ObligationWhen required by law, we may share data with government bodies including the Ministry of Education (via NEMIS), KNEC, the ODPC, and law enforcement agencies in response to lawful requests.
All third-party service providers are contractually obligated to process personal data in compliance with the DPA 2019 and to implement appropriate security measures.
We retain personal data only for as long as necessary to fulfil the purposes outlined in this Policy, or as required by law. Specific retention periods are:
| Data Category | Retention Period |
|---|---|
| Active school account data | Duration of subscription + 90 days |
| Student academic records | Duration of subscription + 2 years (for transcript generation) |
| Financial transaction records | 7 years (Kenya tax and audit requirements) |
| Staff employment and payroll records | Duration of employment + 5 years |
| Audit logs | 3 years |
| Communication logs (SMS/email) | 1 year |
| Technical/usage logs | 12 months (rolling) |
| Backup data | Per school configuration (default: 5 backups) |
Upon termination of a school's subscription, the school administrator may request a full data export. After the retention period, data is permanently and irreversibly deleted from all systems, including backups.
We implement technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction, including:
Encryption in Transit
All data transmitted between your browser and our servers is encrypted using TLS 1.2+ (HTTPS).
Encryption at Rest
Database storage uses AES-256 encryption. Sensitive fields (passwords, API keys) are hashed using bcrypt.
Access Controls
Role-based access control (RBAC) ensures users can only access data relevant to their role. JWT-based authentication with short-lived tokens.
Audit Logging
All significant actions (data access, modifications, exports) are recorded in immutable audit logs with user ID, timestamp, and IP address.
Automated Backups
Regular encrypted backups are performed per school configuration. Backup data is stored separately from primary systems.
Tenant Isolation
Each school operates within an isolated tenant namespace. Cross-tenant data access is architecturally prevented.
Under the Kenya Data Protection Act, 2019, data subjects have the following rights. You may exercise these rights by contacting us at the details provided below:
Right of Access (Section 26(a))
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data.
Right to Rectification (Section 26(c))
You have the right to request correction of inaccurate or incomplete personal data.
Right to Deletion (Section 26(d))
You have the right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to legal retention requirements.
Right to Restrict Processing (Section 26(b))
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability (Section 26(e))
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., CSV, JSON).
Right to Object (Section 26(f))
You have the right to object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.
Right to Withdraw Consent (Section 32)
Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of prior processing.
Right to Lodge a Complaint
You have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) if you believe your data protection rights have been violated.
How to exercise your rights: School administrators can submit Data Subject Requests directly through the DarasaDigital admin portal under Admin → Compliance → Data Subject Requests. Individuals may also contact us at privacy@darasadigital.com. We will respond within 30 days as required by law.
DarasaDigital processes the personal data of children (students under the age of 18) as a necessary component of providing school management services. We implement the following special protections in compliance with Section 33 of the DPA 2019:
Our primary data processing and storage infrastructure is hosted on cloud servers. In the event that personal data is transferred outside Kenya, we ensure that:
The DarasaDigital platform uses the following types of cookies and similar technologies:
| Type | Purpose | Duration |
|---|---|---|
| Essential/Authentication | Session management, JWT tokens, CSRF protection | Session / 7 days |
| Functional | User preferences (theme, role selection) | Persistent |
| Analytics | Anonymised usage statistics to improve the platform | 12 months |
We do not use third-party advertising cookies. Essential cookies are required for the platform to function and cannot be disabled. You can manage cookie preferences in your browser settings.
In the event of a personal data breach, DarasaDigital will:
Schools are also encouraged to report any suspected data breaches through the platform's Admin → Compliance → Data Breach Report feature or by contacting security@darasadigital.com.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. When we make material changes:
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:
Data Controller
Bravio Technologies Limited — DarasaDigital
Email (Privacy)
privacy@darasadigital.comGeneral Email
contact@darasadigital.comPhone Numbers
Address
Machakos Town, Machakos County, Kenya