Privacy Policy
Version 2026-09-07
Scholara is provided by Cruze Intelligent Systems ("Scholara", "we", "us") as software that schools use to run their own records, including academic, attendance, health, financial, and staff data. This policy explains what personal data passes through the system, why, and what rights you have over it.
Who controls your data
Your school is the data controller for the records it enters about you or your child. It decides what to collect and why, and it's who you should contact first for anything about your own data (a correction, a question about why something was recorded, a request to delete it). Scholara acts as a data processor: we run the software your school uses and never sell, share, or use school data for our own purposes outside of operating and supporting the platform.
What we collect
Depending on your role, a school may record:
- Identity & contact: name, email, phone, address, and (where a school opts in) a National ID number for identity verification.
- Academic records: enrolment, class/stream, marks, attendance, lesson plans, report cards.
- Health records: for schools using the nurse module: clinic visits, medication administration, nursery daily logs, developmental milestones. This is the most sensitive category we handle and is treated accordingly (see Security below).
- Financial records: fee invoices, payments, and (for staff) payroll and salary information.
- Usage data: login activity and an audit trail of who accessed or changed a record, kept for accountability and security investigation.
Why we process it
Every category above exists to run a specific school function you or your child are enrolled in or employed by. We don't collect data "just in case," and a field that isn't needed for a module isn't collected by it. Processing is based on your (or, for a minor, your parent/guardian's) consent to the school's use of Scholara, and on the contract between your school and Scholara to provide the service.
Children's data
Where a learner is a minor, a parent or guardian's account is created by the school and that guardian consents on the child's behalf, in line with Uganda's Data Protection and Privacy Act 2019. A guardian can see only their own children's records, never another family's, and never another school's.
Who your data is shared with
Never with another school. Every school's data is isolated from every other school on the platform. Within a school, only the roles that need a given record to do their job can see it (e.g. a Teacher never sees payroll; a Bursar never sees health records). Access is role- and school-scoped in the software itself, not just by policy. We use third-party services only where necessary to run the platform, including Google Analytics for aggregate, anonymized usage statistics on our public pages (see Cookies below), and a payment gateway to process fee payments a guardian initiates. Those providers only ever receive the minimum needed to perform that function.
Security
Access to every record is scoped by role and by school at the database query level, so a user account simply cannot request another school's data through the app, regardless of role. Health and financial records carry an audit trail of who read or changed them. Passwords are hashed, never stored or logged in plain text.
Retention
Records are kept for as long as your school's account is active. If your school's account itself becomes inactive for an extended period, it is flagged under your school's own record-keeping obligations before any deletion.
When an individual learner graduates, transfers, or withdraws, their records follow a separate, shorter timeline: day-to-day records (attendance, clinic visits, medication administration, daily activity logs, milestones, and similar operational entries) are deleted one year after they leave. Academic and financial records (assessment history and invoices) are kept longer and deleted five years after they leave, along with the rest of their record. Before either date, the admin and the learner's parent or guardian are notified and encouraged to download and keep their own copy of the full record. Your school can ask support to adjust these periods if it has a different legal obligation.
Your rights
Under Uganda's Data Protection and Privacy Act 2019 (and equivalent protections elsewhere), you can ask to access, correct, or request deletion of your personal data. Start with your school administrator, since they control the record. If you're not sure who that is, or need to reach Scholara directly, use the contact details below.
Cookies & analytics
Our public pages use Google Analytics to understand aggregate traffic (not individual behaviour inside the school app itself). You can decline this on your first visit via the cookie banner. Declining doesn't affect your ability to use Scholara.
Changes to this policy
If we make a material change, every user is asked to review and re-accept it the next time they sign in, and the version number at the top of this page changes.
Contact
Questions about this policy: admin@scholara.site.
This document is a documented default drafted for Scholara's own use, not a substitute for legal advice. A qualified lawyer/DPO should review it against your school's specific situation before you rely on it (see docs/COMPLIANCE.md).