1 Introduction
Scholax ("we", "us", or "our") operates a multi-tenant school management platform and its companion mobile application. This Privacy Policy explains how we collect, use, store, and protect information when you use our services.
By using the Scholax platform or mobile application, you agree to the collection and use of information as described in this policy.
2 Information We Collect
We collect the following categories of information:
- Personal Information: Name, email address, phone number, national ID, role (teacher, parent, student, administrator), and school affiliation.
- Authentication Data: Login credentials (encrypted), API tokens, and device identifiers for session management.
- Attendance & Location Data: GPS coordinates and geofence verification data are collected only during attendance check-in/check-out to verify the employee's physical presence at the designated workplace. Location data is not tracked outside of attendance operations.
- Device Information: Device model, OS version, and unique device identifier — used for device binding (one account per device) and to prevent unauthorized access.
- Academic Data: Student grades, enrollment status, attendance records, and course information managed by authorized school administrators.
- Financial Data: Tuition fees, payment records, and payroll information — processed and stored securely within the platform.
- Biometric Indicators: Face detection data (if enabled) is processed locally on the device for liveness verification and is never transmitted to or stored on our servers.
- Camera Access: The camera is used solely for face-detection based attendance verification. No photos or videos are stored or transmitted.
3 How We Use Your Information
- To provide, maintain, and improve the educational management platform.
- To authenticate users and enforce role-based access control.
- To process attendance records and calculate payroll deductions.
- To send notifications related to academic updates, attendance, leave approvals, and administrative communications.
- To generate reports for authorized school administrators.
- To ensure platform security and prevent fraudulent access.
4 Data Sharing & Disclosure
We do not sell, trade, or rent personal information to third parties. Data may be shared only in the following circumstances:
- Within the school ecosystem: Authorized administrators within the same school can access data relevant to their role.
- Legal obligations: When required by law or to respond to valid legal processes.
- Platform security: To investigate, prevent, or address fraud, security issues, or technical problems.
Each school (tenant) operates in complete data isolation. Administrators of one school cannot access data belonging to another school.
5 Data Security
- All data transmissions are encrypted using industry-standard TLS/SSL protocols.
- Passwords are hashed using secure one-way hashing algorithms.
- API authentication uses token-based authorization with automatic session expiration.
- Database access is restricted to authorized services only.
- Regular security audits and automated backups are performed.
- Optional device binding and GPS anti-spoofing mechanisms add additional security layers.
6 Data Retention
We retain personal data for as long as your account is active or as needed to provide services. Academic and attendance records are retained for the duration required by the educational institution's policies. You may request data deletion by contacting your school administrator or emailing us at info@scholax.org.
7 Your Rights
- Access: You may request a copy of the personal data we hold about you.
- Correction: You may request correction of inaccurate data.
- Deletion: You may request deletion of your personal data, subject to legal and institutional requirements.
- Opt-out: You may opt out of non-essential notifications through the application settings.
8 Children's Privacy
Our platform may contain data about students under the age of 13. This data is managed exclusively by authorized school administrators and parents/guardians. We do not knowingly collect personal information directly from children. All interactions with student data are performed through authorized adult accounts.
9 Changes to This Policy
We may update this Privacy Policy periodically. Changes will be communicated through the platform's notification system and will be effective upon posting. Continued use of the platform after changes constitutes acceptance.
10 Contact Us
If you have questions about this Privacy Policy, please contact us: