Skoulou
Legal

Privacy Policy

Cameroon Law 2010/012 on personal data · GDPR-aligned

Law 2010/012 compliance

Hosting in the Africa region. Data encrypted at rest (AES-256-GCM) and in transit (TLS 1.3). You own your data. On termination: full Excel export within 30 days, purge within 90 days unless legally required to retain.

⚠️ DRAFT DOCUMENT. MUST BE REVIEWED BY A LAWYER ADMITTED TO THE CAMEROON BAR BEFORE PUBLICATION. Version: 1.0-DRAFT Effective date (TBC): __ / __ / 2026 Updated: 2026-04-29 Primary legal basis: Law N° 2010/012 of 21 December 2010 on cybersecurity and cybercriminality in Cameroon. In case of any discrepancy between this English version and the French version (04-privacy-policy-fr.md), the French version prevails.


1. Commitment

SchoolApp SARL (the "Provider") attaches particular importance to the protection of personal data, especially that of minor students enrolled in client schools. This Policy describes the data-processing operations carried out within the SchoolApp service and the rights of data subjects.

2. Data controller and processor

  • Data controller: the school (the "Client"), which determines the purposes and means of processing the personal data of its students, parents, teachers, and staff.
  • Data processor: SchoolApp SARL, which hosts and processes the data on behalf of the Client, under documented instructions.

3. Data collected

3.1 Data provided by the Client

  • Student identity: first/last name, gender, date of birth, photo (optional), nationality.
  • Parent contacts: name, phone, email, family relationship.
  • School records: class, subsystem (Francophone/Anglophone), academic history, marks, attendance, behaviour.
  • Payments: amounts due, amounts paid, Mobile Money transaction references.
  • School staff: identity, role, login credentials.

3.2 Data collected automatically

  • Technical data: IP address, device type, OS version, authentication logs.
  • Usage data: pages viewed, actions performed, timestamps.
  • Functional cookies only on schoolapp.cm (session management, language preference).

3.3 Sensitive data

The Provider does not deliberately collect sensitive data (health, religion, political opinion). If the Client uploads such data through free-text fields, the Client assumes responsibility and related obligations.

4. Purposes of processing

Data is processed solely for:

PurposeLegal basis
Provision of SchoolApp services (school management, report cards, attendance)Performance of the contract with the Client
Communication with parents (notifications, report cards)Legitimate interest of the Client + parental consent
Payment tracking and invoicingLegal obligation (accounting, tax)
Service security (logs, anti-fraud)Legitimate interest
Service improvement (aggregated, anonymised statistics)Legitimate interest
Response to authority requestsLegal obligation

5. Minors' data

In accordance with Articles 41-44 of Law N° 2010/012, the data of minor students benefits from heightened protection:

  • Parental consent is required for any processing beyond the strict execution of the educational service.
  • No commercial communication is sent to minors.
  • No automated profiling for marketing purposes is carried out on minors' data.
  • Student photos are never used outside the school context (e.g., service marketing) without explicit, written parental consent.

6. Hosting and location

Data is hosted in an African region, currently with AWS af-south-1 (Cape Town, South Africa). The Provider prioritises regional sovereignty and is evaluating a future migration to Cameroonian infrastructure once it matures.

7. Security

The Provider implements:

  • Encryption at rest: identifying personal data (name, phone, email, photo) is envelope-encrypted with AES-256-GCM, with periodic key rotation.
  • Encryption in transit: TLS 1.3 on all client-server communications.
  • Access control: multi-factor authentication for internal administrators; server-side roles + permissions enforced via CASL.
  • Logging: all sensitive actions (access, edits, exports) are logged and retained for 12 months.
  • Backups: automatic daily backups, retained 30 days, encrypted.
  • Security testing: quarterly internal audits; annual external pen-tests (from operations year 2 onwards).
  • Incident response: documented procedure. Notification to the Client + ANTIC within 72 hours of a data breach affecting data subjects.

8. Retention durations

CategoryDuration
Student data (identity, schooling, marks)Duration of schooling + 5 years (academic archive), unless instructed otherwise by the Client
Payment data (invoices, MoMo references)10 years (OHADA accounting and tax obligation)
Technical and audit logs12 months
Prospect data (contact form)3 years without interaction → deleted
Data after termination90 days read-only access for the Client → permanent deletion (subject to legal obligations)

9. Recipients

Data is shared only with the following recipients, strictly as needed:

  • Authorised Client staff (school)
  • Authorised Provider staff (support, engineering, under confidentiality agreements)
  • Technical sub-processors (list published at schoolapp.cm/legal/subprocessors): AWS hosting, SMS/WhatsApp gateway, Mobile Money provider
  • Competent authorities upon legal requisition

No data is sold, rented, or transferred to third parties for commercial purposes.

10. International transfers

Data is stored in Africa (af-south-1). Any technical-support operation requiring access from outside the region is subject to:

  • an access log,
  • the third party's confidentiality undertaking,
  • notification to the Client in case of sustained access (>24 h).

Occasional transfers to other regions may occur (sub-processors: e.g., Twilio in the United States for international SMS gateway). The up-to-date list of sub-processors is published at schoolapp.cm/legal/subprocessors. Each transfer relies on contractual clauses equivalent to the local protection standard.

11. Data subject rights

In accordance with Law N° 2010/012, data subjects have the following rights:

  • Right of access: confirm processing and obtain a copy of the data.
  • Right to rectification: have inaccurate or incomplete data corrected.
  • Right to object: object to processing for legitimate reasons, except when bound by contractual or legal obligation.
  • Right to erasure: request deletion within the limits of legal obligations (notably academic and accounting archives).
  • Right to portability: receive a copy of the data in a structured format (CSV, JSON, PDF as appropriate).
  • Right to complain: refer to ANTIC or competent courts in case of unresolved disagreement.

How to exercise these rights

  • For data where the school is the controller: contact the school's leadership directly.
  • For technical access questions: privacy@schoolapp.cm.
  • Response time: 30 days, extendable once for complex requests, with reasoned notification.

12. Cookies

The schoolapp.cm site uses a limited set of cookies:

CookiePurposeDuration
Authentication sessionMaintain logged-in sessionSession
Language preferenceRemember FR/EN12 months
Anonymous audience measurementAggregated statistics (Plausible / Matomo, no full IP)13 months

The SchoolApp mobile application does not set cookies. Equivalent technical settings (authentication tokens) are stored locally on the device and are not shared with third parties.

13. DPO and contact

An internal Data Protection Officer (DPO) is designated:

  • Name: [TBA]
  • Email: dpo@schoolapp.cm
  • Postal address: [SchoolApp SARL registered office]

The supervisory authority in Cameroon is ANTIC (Agence Nationale des Technologies de l'Information et de la Communication):

  • Website: antic.cm
  • Email: (see site)
  • Address: Yaoundé

14. Changes

This Policy may be updated to reflect legal or technical changes. Any material change is notified:

  • to the Client by email or in-app notification,
  • to Users via a banner on the next application access,
  • at least 30 days before entry into force.

Version history is available on request to privacy@schoolapp.cm.

15. Contact

SchoolApp SARL Address: [TBC] RCCM: [TBC] NIU: [TBC] General email: hello@schoolapp.cm DPO: dpo@schoolapp.cm WhatsApp: +237 XXX XXX XXX


Notes for legal review (delete before publication)

  • Verify the vocabulary used: "data controller", "data processor", "data subject" — are these the terms of Law 2010/012 or borrowed from GDPR? Align with local terminology if it differs.
  • Confirm the ANTIC breach-notification deadline (72 hours is GDPR-inspired; verify Cameroonian practice).
  • Confirm the academic archive duration (5 years) against MINESEC circulars.
  • Review the "Cookies" section against local regulation (limited case law to date).
  • Confirm the sub-processor list to publish — make it exhaustive and current before launch.
  • Decide on a formal policy for responding to authority requests (requisitions, warrants) — separate internal annex.
  • Verify compatibility with any recent amendments of Law 2010/012 or ANTIC implementing decrees.