Privacy Policy

1.Information we collect

Visitors to the public website. If you submit the admission-inquiry / tour-booking form, we collect the guardian's name, phone number, the student's name, the requested grade, a preferred date, and any notes you add, so admissions staff can contact you. If you use the AI assistant chat widget, your message is processed to generate a reply (see section 3) — we do not require you to create an account to browse the website or read published information.

Enrolled students and their guardians. Once a family applies or enrolls, our management system holds the student's identity information (name, gender, date of birth, place of birth, nationality, national ID where applicable, photo), guardian names and contact details, address and emergency contacts, a restricted-access medical/health profile, uploaded documents (birth certificate, identification, previous-school certificates, signed undertakings), admission and enrollment history, academic records (grade, section, attendance, homework), and financial records (fees, installments, payments, receipts, discounts, and refunds).

Mobile app accounts (guardians and teachers). Accounts are issued by the school — a guardian or teacher receives an activation code from school staff and sets their own password; children do not register their own accounts. The app records the device's model, operating system, and app version, a push-notification token, your chosen language, and session activity, so the service can be delivered and so a lost or replaced device's access can be revoked on request. A guardian can see only their own children's fees, installments, payments, receipts, attendance, homework, and documents; a teacher can see their own classes, schedule, roster, attendance, and homework.

Staff. Employee accounts, login history (date and time, success or failure, IP address, user agent), assigned roles and permissions, and — for hiring — recruitment information entered by HR staff during the application process.

2.Cookies

The website uses only strictly functional cookies: a django_language cookie (kept for one year) to remember your language choice, the standard session cookie, and a CSRF-protection cookie. We do not use advertising cookies, and there is no third-party analytics or tracking script anywhere on this website.

3.The AI assistant on this website

The chat widget on our homepage runs on our own server — your message is never sent to a third-party AI company. It is not stored in a database; only an anonymous, per-IP-address usage counter is kept for up to one hour, purely to prevent abuse of the free service. The assistant answers from a fixed set of published facts about the school and is not authoritative for fees, admission decisions, or any official matter — please confirm those directly with our staff.

4.How we use this information

5.Children's privacy

Our systems are used by children only through a guardian's own, school-issued account, or through access that authorized school staff provide directly. A child does not independently register an account on the mobile app or management system. Access to a specific child's academic, financial, and health information is restricted to that child's own guardians and to the staff whose role requires it.

6.Sharing your information

We do not sell personal information, and we do not share it for advertising. We share it only:

7.How long we keep it

Financial records (fees, payments, receipts) are retained for at least ten years, consistent with our record-keeping policy. Academic records are kept permanently unless school policy changes. Audit logs are append-only and are never edited. Admission-inquiry submissions and closed job applications are kept only as long as reasonably needed and can be deleted on request, unless the law requires us to keep them longer.

8.How we protect it

All pages are served over an encrypted (HTTPS) connection. Session cookies are marked secure and are not readable by page scripts. Access to every screen and record is governed by role- and permission-based access control, and sensitive actions are recorded in an audit trail that ordinary users cannot edit. A mobile device's sign-in credential is stored as a one-way hash, never in a readable form.

9.Your rights

You may ask us to give you a copy of your (or your child's) personal information, correct it, or delete it — subject to the legal retention duties described in section 7. You may ask us to revoke a mobile session (for example, after losing a device), and you may choose not to use optional features such as the AI assistant. To exercise any of these rights, contact us using the details in section 11.

10.Changes to this policy

If we make a material change to this policy, we will update the date above and, where appropriate, notify guardians through the mobile app or by another reasonable means.