Legal Document

Privacy Policy

How DarasaDigital collects, processes, stores, and protects your personal data in compliance with the Kenya Data Protection Act, 2019.

Effective Date: 28 July 2026Version 1.0

1Data Controller

Darasa Digital ("Company," "we," "us," or "our") is an educational technology school operating system registered in Kenya.

For the purposes of the Kenya Data Protection Act, 2019 (the "DPA"), Darasa Digital operates as a Data Processor for all student academic records, CBC assessment rubrics, parent contact details, attendance logs, and school fee records entered into the Platform by subscribing schools (where each subscribing school acts as the Data Controller). Darasa Digital operates as a Data Controller for registered school administrator account details, subscription billing records, website analytics, and customer support communications.

ODPC Compliance

Darasa Digital is registered with the Office of the Data Protection Commissioner (ODPC) of Kenya in compliance with Section 18 of the Data Protection Act, 2019 and the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021.

2Scope & Applicability

This Privacy Policy applies to all users of the DarasaDigital platform, including but not limited to:

  • School Administrators and Principals who register and manage school accounts
  • Teachers and Staff who access the platform for academic, administrative, or payroll purposes
  • Bursars and Finance Officers who manage fee structures, payments, and financial records
  • Parents and Guardians who access student academic records, fee balances, and communication portals
  • Students who access timetables, results, and academic resources
  • Visitors to the public DarasaDigital website (darasadigital.com)

This Policy covers data collected through the web application, tenant subdomains (e.g., yourschool.darasadigital.com), API integrations, and any associated mobile interfaces.

3Legal Basis for Processing

We process personal data in accordance with the Kenya Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021. Our legal bases for processing include:

Consent (Section 30)

You provide explicit consent when registering for our services and accepting this Privacy Policy and our Terms of Service.

Contractual Necessity (Section 30(1)(b))

Processing is necessary for the performance of the subscription agreement between the school and DarasaDigital.

Legal Obligation (Section 30(1)(c))

We process data as required by Kenyan law, including compliance with the Kenya Institute of Curriculum Development (KICD) assessment frameworks, National Education Management Information System (NEMIS) reporting, and Kenya National Examinations Council (KNEC) requirements.

Legitimate Interest (Section 30(1)(f))

Processing for platform security, fraud prevention, service improvement, and analytics where such interests are not overridden by the data subject's rights.

4Data We Collect

We collect and process the following categories of personal data:

A. School Registration Data

  • School name, physical address, county, sub-county
  • School type, level coverage, curriculum mode
  • NEMIS code, KNEC centre number
  • Administrator name, email address, phone number
  • School logo and branding preferences

B. Student Personal Data

  • Full name, date of birth, gender, nationality
  • Admission number, UPI (Unique Personal Identifier) number
  • Birth certificate number, NEMIS number
  • Medical information and special needs records (where applicable)
  • Photographs (where uploaded for identification or report cards)
  • Parent/guardian contact details and emergency contacts
  • Home address and county of residence

C. Academic Records

  • CBC formative and summative assessment scores and rubric ratings
  • Examination results and report cards
  • Attendance records (daily and per-period)
  • Subject enrolments and stream/class assignments
  • Teacher assessments, behaviour notes, and remarks
  • Senior School pathway and track selections

D. Financial Data

  • Fee structures, balances, and payment histories
  • M-Pesa transaction records (transaction IDs, amounts, phone numbers, timestamps)
  • Bank import reconciliation data
  • Capitation and government funding records (for public schools)
  • Staff salary configurations and payroll records

E. Staff and Employment Data

  • Full name, email, phone number, national ID number
  • TSC (Teachers Service Commission) number
  • Gender, date of birth, employment type
  • Qualifications, department, and subject assignments
  • Attendance records, leave requests, and TPAD appraisal data
  • Salary, deductions, and payslip information

F. Technical and Usage Data

  • IP addresses and browser/device information
  • Login timestamps and session data
  • Audit logs of actions performed within the platform
  • Error logs and performance metrics

5Purposes of Processing

We process personal data for the following specific purposes:

PurposeData Categories Used
Provision of school management servicesA, B, C, D, E
CBC assessment recording and report card generationB, C
Automated M-Pesa fee reconciliationB, D
NEMIS and KNEC compliance reportingA, B, C
Timetable generation and schedulingA, C, E
Staff payroll processingE
SMS and email communication to parentsB, E, F
Platform security, audit logging, and fraud preventionF
Service improvement and analyticsF
Subscription billing and account managementA, D
Legal and regulatory complianceAll categories as required

6Data Sharing & Third Parties

We do not sell, rent, or trade personal data. We may share personal data with the following categories of recipients only as necessary:

Safaricom PLC (M-Pesa)

Payment Processor

For processing fee payments via the M-Pesa Daraja API. Transaction data (phone numbers, amounts, timestamps) is shared as necessary to process and reconcile payments.

Email & SMS Service Providers

Communication

We use third-party communication providers to deliver transactional emails (verification codes, report cards) and SMS messages (fee receipts, attendance alerts). Only the minimum data necessary for delivery is shared.

Cloud Infrastructure Providers

Hosting

Our platform is hosted on secure cloud infrastructure. Data is stored in encrypted databases with access limited to authorised personnel and automated systems.

Government Authorities

Legal Obligation

When required by law, we may share data with government bodies including the Ministry of Education (via NEMIS), KNEC, the ODPC, and law enforcement agencies in response to lawful requests.

All third-party service providers are contractually obligated to process personal data in compliance with the DPA 2019 and to implement appropriate security measures.

7Data Retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this Policy, or as required by law. Specific retention periods are:

Data CategoryRetention Period
Active school account dataDuration of subscription + 90 days
Student academic recordsDuration of subscription + 2 years (for transcript generation)
Financial transaction records7 years (Kenya tax and audit requirements)
Staff employment and payroll recordsDuration of employment + 5 years
Audit logs3 years
Communication logs (SMS/email)1 year
Technical/usage logs12 months (rolling)
Backup dataPer school configuration (default: 5 backups)

Upon termination of a school's subscription, the school administrator may request a full data export. After the retention period, data is permanently and irreversibly deleted from all systems, including backups.

8Data Security

We implement technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction, including:

Encryption in Transit

All data transmitted between your browser and our servers is encrypted using TLS 1.2+ (HTTPS).

Encryption at Rest

Database storage uses AES-256 encryption. Sensitive fields (passwords, API keys) are hashed using bcrypt.

Access Controls

Role-based access control (RBAC) ensures users can only access data relevant to their role. JWT-based authentication with short-lived tokens.

Audit Logging

All significant actions (data access, modifications, exports) are recorded in immutable audit logs with user ID, timestamp, and IP address.

Automated Backups

Regular encrypted backups are performed per school configuration. Backup data is stored separately from primary systems.

Tenant Isolation

Each school operates within an isolated tenant namespace. Cross-tenant data access is architecturally prevented.

9Your Rights Under the DPA 2019

Under the Kenya Data Protection Act, 2019, data subjects have the following rights. You may exercise these rights by contacting us at the details provided below:

Right of Access (Section 26(a))

You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data.

Right to Rectification (Section 26(c))

You have the right to request correction of inaccurate or incomplete personal data.

Right to Deletion (Section 26(d))

You have the right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to legal retention requirements.

Right to Restrict Processing (Section 26(b))

You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability (Section 26(e))

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., CSV, JSON).

Right to Object (Section 26(f))

You have the right to object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.

Right to Withdraw Consent (Section 32)

Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of prior processing.

Right to Lodge a Complaint

You have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) if you believe your data protection rights have been violated.

How to exercise your rights: School administrators can submit Data Subject Requests directly through the DarasaDigital admin portal under Admin → Compliance → Data Subject Requests. Individuals may also contact us at privacy@darasadigital.com. We will respond within 30 days as required by law.

10Children's Data

DarasaDigital processes the personal data of children (students under the age of 18) as a necessary component of providing school management services. We implement the following special protections in compliance with Section 33 of the DPA 2019:

  • Student personal data is entered and managed exclusively by authorised school staff (administrators, teachers, bursars) — students do not self-register.
  • Schools are responsible for obtaining any necessary parental or guardian consent for the processing of student data as required by applicable law and school policies.
  • Student data is only accessible to authorised users within the specific school tenant — cross-school access is prevented by architecture.
  • We do not use student data for marketing, advertising, profiling, or any purpose unrelated to the provision of educational services.
  • Student photographs (where collected) are used solely for identification on report cards and ID cards, and are not shared externally.
  • The platform does not directly collect data from children — all interactions are mediated through school administrators, teachers, and parents.

11International Data Transfers

Our primary data processing and storage infrastructure is hosted on cloud servers. In the event that personal data is transferred outside Kenya, we ensure that:

  • The destination country provides an adequate level of data protection as determined by the ODPC, or
  • Appropriate safeguards are in place, including standard contractual clauses, binding corporate rules, or explicit consent of the data subject (per Section 48-50 of the DPA 2019)
  • All cloud infrastructure providers are contractually bound to comply with equivalent data protection standards

12Cookies & Analytics

The DarasaDigital platform uses the following types of cookies and similar technologies:

TypePurposeDuration
Essential/AuthenticationSession management, JWT tokens, CSRF protectionSession / 7 days
FunctionalUser preferences (theme, role selection)Persistent
AnalyticsAnonymised usage statistics to improve the platform12 months

We do not use third-party advertising cookies. Essential cookies are required for the platform to function and cannot be disabled. You can manage cookie preferences in your browser settings.

13Data Breach Procedures

In the event of a personal data breach, DarasaDigital will:

  1. Notify the ODPC within 72 hours of becoming aware of the breach, as required by Section 43 of the DPA 2019, providing details of the nature, scope, and likely consequences of the breach.
  2. Notify affected schools without undue delay, providing clear information about the breach, the data affected, potential consequences, and remedial actions taken.
  3. Investigate and remediate the breach, implementing measures to prevent recurrence.
  4. Document the breach in the internal breach register, including all facts, effects, and remedial actions, for ODPC audit purposes.

Schools are also encouraged to report any suspected data breaches through the platform's Admin → Compliance → Data Breach Report feature or by contacting security@darasadigital.com.

14Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. When we make material changes:

  • We will notify all registered school administrators via email at least 30 days before the changes take effect.
  • A prominent notice will be displayed within the platform dashboard.
  • The "Effective Date" and "Version" at the top of this page will be updated.
  • Continued use of the platform after the effective date constitutes acceptance of the updated Policy.

15Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:

Data Controller

Bravio Technologies Limited — DarasaDigital

Address

Machakos Town, Machakos County, Kenya

© 2026 Bravio Technologies Limited. All rights reserved.