You are handing us records about children
A student system holds medical notes, safeguarding concerns, family circumstances and identity documents belonging to minors. That is a different category of responsibility from most business software, and it shapes how the platform is built.
How the data is protected
Encrypted in transit and at rest
Traffic between browsers and the platform is encrypted, and stored data is encrypted on disk. Neither is optional or configurable per school.
Role-based access, applied per module
Permissions follow the job. Sensitive areas — medical notes, inclusion records, safeguarding entries — are restricted to the staff who need them rather than open to anyone with a login.
Access is logged
Who looked at a record, who changed it and when. When a school needs to answer that question, the answer needs to exist already.
UAE data residency
Student records stay in UAE-based infrastructure. Where data lives is a question schools here are asked directly, and the answer should be simple.
Separated by school
One school cannot see another school’s records. Isolation is enforced by the platform rather than by a filter someone might forget to apply.
Export on request, always
Your records are yours. Open-format export is available at any time, including at the point you decide to stop using the platform.
Handling minors’ data
UAE data protection law treats personal data of minors as requiring particular care, and schools carry that obligation directly. The platform is built to support it rather than to leave it entirely to policy: sensitive categories are separated, access is restricted by role, and retention can be configured so records are not kept indefinitely by default.
What we do not do is decide your policy for you. Retention periods, who may access safeguarding records and what is shared with parents are school decisions. The platform’s job is to make those decisions enforceable rather than aspirational.
Common questions
Where is our data stored?
In the UAE. Student records are held in UAE-based infrastructure rather than replicated to other regions, which is a requirement for most schools here and a preference for the rest.
Who can see a student record?
Only staff whose role requires it. Permissions are role-based and applied per module, so a form tutor, a nurse and an admissions officer each see the parts of a record relevant to their job and not the rest.
Can we get our data out?
Yes, in open formats, whenever you ask — including if you decide to leave. Export is a standard function, not a request that has to be negotiated.
Is there a record of who accessed what?
Yes. Access to student records is logged, so a school can answer the question of who viewed or changed a record and when.
Security questions before a demo?
Send them over. We would rather answer them in writing up front than have them surface during procurement.
Ask us