Privacy Policy

Your data, protected.

Last updated: March 2026 · Effective: 1 January 2025

EduMyles (“we”, “us”, “our”) is a school management platform operated by MylesCorp Technologies Ltd, incorporated in Kenya. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our platform. We comply with the Kenya Data Protection Act, 2019 and applicable East African data protection laws.

Data We Collect

Student Data

  • Full name, date of birth, admission number
  • Academic records, grades, CBC competency scores
  • Attendance records
  • Fee balance and payment history

Parent / Guardian Data

  • Name, phone number (M-Pesa registered)
  • Email address, relationship to student
  • Communication preferences
  • M-Pesa transaction IDs

Staff Data

  • Name, national ID number, role
  • Payroll information, bank details
  • Contact details, address
  • Leave records, performance data

Usage & Technical Data

  • Pages visited, features used
  • Login timestamps, device information
  • IP address, browser type
  • Session duration, click patterns

We do not store full card numbers, M-Pesa PINs, or passwords in plain text. Payment data is processed via Safaricom Daraja API and we only retain transaction reference IDs.

How We Use Your Data

  • Provide, maintain, and improve the EduMyles platform
  • Generate academic reports, fee statements, and attendance records for schools
  • Send automated SMS/email alerts to parents (fee reminders, report cards, attendance alerts)
  • Process M-Pesa fee payments via Safaricom Daraja API
  • Comply with Kenya's CBC, NEMIS, and KNEC reporting requirements
  • Analyse anonymised usage patterns to improve product features
  • Respond to support requests and resolve technical issues
  • Send product update emails (you can unsubscribe at any time)

Data Sharing

We do NOT sell, rent, or trade your personal data to any third party — ever.

Data is shared only with the following processors, bound by data processing agreements:

Safaricom (M-Pesa/Daraja)Process school fee payments
SMS providerSMS delivery to parents and staff
Amazon Web Services (AWS)Cloud infrastructure and data storage
Hosting providerPlatform hosting and delivery
NEMIS / KNEC (Kenya Govt.)Mandatory government reporting only
Authentication providerAuthentication and single sign-on

Your Rights

Under the Kenya Data Protection Act, 2019, you have the following rights:

Right to Access

Request a copy of all personal data we hold about you or your school.

Right to Correction

Update or correct inaccurate student, parent, or staff records.

Right to Deletion

Request deletion of your data (subject to legal retention requirements).

Right to Portability

Export your school's complete data in CSV or Excel format at any time.

Right to Object

Opt out of non-essential communications such as marketing emails.

Right to Withdraw Consent

Where processing is consent-based, you may withdraw consent at any time.

To exercise any of these rights, email privacy@edumyles.com. We respond within 30 business days.

Data Retention

Data TypeRetention Period
Active student records7 years after leaving school
Payment records7 years
Inactive school accounts2 years after subscription ends
Staff HR records7 years after employment ends
Usage logs90 days
Marketing emailsUntil unsubscribed

Security Measures

256-bit AES encryption for all data at rest
TLS 1.3 for all data in transit
Multi-factor authentication for admin accounts
Role-based access control (teachers see only their classes)
Regular penetration testing by third-party security firms
Documented security and access-control processes
All staff undergo data protection training annually
Automatic session timeout after inactivity

Kenya DPA Compliance

MylesCorp Technologies Ltd is registered as a data processorunder Kenya's Data Protection Act, 2019. Schools using EduMyles are the data controllersfor their students' and staff' personal data.

  • Data Protection Officer: dpo@edumyles.com
  • Data stored in Nairobi, Kenya and EU (Ireland, AWS) — never transferred outside adequate-safeguard regions
  • Annual Data Protection Impact Assessments (DPIAs) conducted
  • Schools provided with a Data Processing Agreement (DPA) on request

Contact Our Privacy Team

Privacy enquiries

privacy@edumyles.com

Data Protection Officer

dpo@edumyles.com

Postal address

WesternHeights, Nairobi, Kenya

Questions about your data?

Our privacy team typically responds within 2 business days.

Contact Us