⚠️ DRAFT DOCUMENT. MUST BE REVIEWED BY A LAWYER ADMITTED TO THE CAMEROON BAR BEFORE PUBLICATION. Version: 1.0-DRAFT Effective date (TBC): __ / __ / 2026 Updated: 2026-04-29 Primary legal basis: Law N° 2010/012 of 21 December 2010 on cybersecurity and cybercriminality in Cameroon. In case of any discrepancy between this English version and the French version (
04-privacy-policy-fr.md), the French version prevails.
1. Commitment
SchoolApp SARL (the "Provider") attaches particular importance to the protection of personal data, especially that of minor students enrolled in client schools. This Policy describes the data-processing operations carried out within the SchoolApp service and the rights of data subjects.
2. Data controller and processor
- Data controller: the school (the "Client"), which determines the purposes and means of processing the personal data of its students, parents, teachers, and staff.
- Data processor: SchoolApp SARL, which hosts and processes the data on behalf of the Client, under documented instructions.
3. Data collected
3.1 Data provided by the Client
- Student identity: first/last name, gender, date of birth, photo (optional), nationality.
- Parent contacts: name, phone, email, family relationship.
- School records: class, subsystem (Francophone/Anglophone), academic history, marks, attendance, behaviour.
- Payments: amounts due, amounts paid, Mobile Money transaction references.
- School staff: identity, role, login credentials.
3.2 Data collected automatically
- Technical data: IP address, device type, OS version, authentication logs.
- Usage data: pages viewed, actions performed, timestamps.
- Functional cookies only on
schoolapp.cm(session management, language preference).
3.3 Sensitive data
The Provider does not deliberately collect sensitive data (health, religion, political opinion). If the Client uploads such data through free-text fields, the Client assumes responsibility and related obligations.
4. Purposes of processing
Data is processed solely for:
| Purpose | Legal basis |
|---|---|
| Provision of SchoolApp services (school management, report cards, attendance) | Performance of the contract with the Client |
| Communication with parents (notifications, report cards) | Legitimate interest of the Client + parental consent |
| Payment tracking and invoicing | Legal obligation (accounting, tax) |
| Service security (logs, anti-fraud) | Legitimate interest |
| Service improvement (aggregated, anonymised statistics) | Legitimate interest |
| Response to authority requests | Legal obligation |
5. Minors' data
In accordance with Articles 41-44 of Law N° 2010/012, the data of minor students benefits from heightened protection:
- Parental consent is required for any processing beyond the strict execution of the educational service.
- No commercial communication is sent to minors.
- No automated profiling for marketing purposes is carried out on minors' data.
- Student photos are never used outside the school context (e.g., service marketing) without explicit, written parental consent.
6. Hosting and location
Data is hosted in an African region, currently with AWS af-south-1 (Cape Town, South Africa). The Provider prioritises regional sovereignty and is evaluating a future migration to Cameroonian infrastructure once it matures.
7. Security
The Provider implements:
- Encryption at rest: identifying personal data (name, phone, email, photo) is envelope-encrypted with AES-256-GCM, with periodic key rotation.
- Encryption in transit: TLS 1.3 on all client-server communications.
- Access control: multi-factor authentication for internal administrators; server-side roles + permissions enforced via CASL.
- Logging: all sensitive actions (access, edits, exports) are logged and retained for 12 months.
- Backups: automatic daily backups, retained 30 days, encrypted.
- Security testing: quarterly internal audits; annual external pen-tests (from operations year 2 onwards).
- Incident response: documented procedure. Notification to the Client + ANTIC within 72 hours of a data breach affecting data subjects.
8. Retention durations
| Category | Duration |
|---|---|
| Student data (identity, schooling, marks) | Duration of schooling + 5 years (academic archive), unless instructed otherwise by the Client |
| Payment data (invoices, MoMo references) | 10 years (OHADA accounting and tax obligation) |
| Technical and audit logs | 12 months |
| Prospect data (contact form) | 3 years without interaction → deleted |
| Data after termination | 90 days read-only access for the Client → permanent deletion (subject to legal obligations) |
9. Recipients
Data is shared only with the following recipients, strictly as needed:
- Authorised Client staff (school)
- Authorised Provider staff (support, engineering, under confidentiality agreements)
- Technical sub-processors (list published at
schoolapp.cm/legal/subprocessors): AWS hosting, SMS/WhatsApp gateway, Mobile Money provider - Competent authorities upon legal requisition
No data is sold, rented, or transferred to third parties for commercial purposes.
10. International transfers
Data is stored in Africa (af-south-1). Any technical-support operation requiring access from outside the region is subject to:
- an access log,
- the third party's confidentiality undertaking,
- notification to the Client in case of sustained access (>24 h).
Occasional transfers to other regions may occur (sub-processors: e.g., Twilio in the United States for international SMS gateway). The up-to-date list of sub-processors is published at schoolapp.cm/legal/subprocessors. Each transfer relies on contractual clauses equivalent to the local protection standard.
11. Data subject rights
In accordance with Law N° 2010/012, data subjects have the following rights:
- Right of access: confirm processing and obtain a copy of the data.
- Right to rectification: have inaccurate or incomplete data corrected.
- Right to object: object to processing for legitimate reasons, except when bound by contractual or legal obligation.
- Right to erasure: request deletion within the limits of legal obligations (notably academic and accounting archives).
- Right to portability: receive a copy of the data in a structured format (CSV, JSON, PDF as appropriate).
- Right to complain: refer to ANTIC or competent courts in case of unresolved disagreement.
How to exercise these rights
- For data where the school is the controller: contact the school's leadership directly.
- For technical access questions:
privacy@schoolapp.cm. - Response time: 30 days, extendable once for complex requests, with reasoned notification.
12. Cookies
The schoolapp.cm site uses a limited set of cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| Authentication session | Maintain logged-in session | Session |
| Language preference | Remember FR/EN | 12 months |
| Anonymous audience measurement | Aggregated statistics (Plausible / Matomo, no full IP) | 13 months |
The SchoolApp mobile application does not set cookies. Equivalent technical settings (authentication tokens) are stored locally on the device and are not shared with third parties.
13. DPO and contact
An internal Data Protection Officer (DPO) is designated:
- Name: [TBA]
- Email:
dpo@schoolapp.cm - Postal address: [SchoolApp SARL registered office]
The supervisory authority in Cameroon is ANTIC (Agence Nationale des Technologies de l'Information et de la Communication):
- Website:
antic.cm - Email: (see site)
- Address: Yaoundé
14. Changes
This Policy may be updated to reflect legal or technical changes. Any material change is notified:
- to the Client by email or in-app notification,
- to Users via a banner on the next application access,
- at least 30 days before entry into force.
Version history is available on request to privacy@schoolapp.cm.
15. Contact
SchoolApp SARL
Address: [TBC]
RCCM: [TBC]
NIU: [TBC]
General email: hello@schoolapp.cm
DPO: dpo@schoolapp.cm
WhatsApp: +237 XXX XXX XXX
Notes for legal review (delete before publication)
- Verify the vocabulary used: "data controller", "data processor", "data subject" — are these the terms of Law 2010/012 or borrowed from GDPR? Align with local terminology if it differs.
- Confirm the ANTIC breach-notification deadline (72 hours is GDPR-inspired; verify Cameroonian practice).
- Confirm the academic archive duration (5 years) against MINESEC circulars.
- Review the "Cookies" section against local regulation (limited case law to date).
- Confirm the sub-processor list to publish — make it exhaustive and current before launch.
- Decide on a formal policy for responding to authority requests (requisitions, warrants) — separate internal annex.
- Verify compatibility with any recent amendments of Law 2010/012 or ANTIC implementing decrees.