← Back home

Privacy Policy

Last updated: 23 September 2026. This policy explains what data MtandaoLabsEdu processes when a school uses the platform, and the choices available to schools, parents, and staff.

Who we are

MtandaoLabsEdu is a multi-tenant school management platform operated by MtandaoLabs, Nairobi, Kenya — contact mtandaolabs@gmail.com, +254 728 249135. Each school is the controller of its own data; MtandaoLabsEdu processes that data on the school's instructions, in line with the Kenya Data Protection Act.

Data we process

We collect only what is needed to run a school — if a field is optional it is labelled “optional”. We do not collect device advertising IDs, precise geolocation, or biometric data, and we do not buy data from brokers.

How we use data

Data is used to operate the platform for the school: managing students and academics, issuing and reconciling fee invoices, sending communications the school initiates, and producing reports. We do not sell personal data or use it for advertising.

Sharing

Data is shared only with processors needed to run the service on the school's behalf — for example hosting and database providers, email delivery, WhatsApp messaging, and mobile money payment providers. Each school configures its own payment, email, and messaging integrations.

Third-party SDKs and processors

The application uses a deliberately small dependency footprint — no advertising, analytics, or cross-site tracking SDKs. Current processors, active only when a school enables them:

Retention and security

Data is retained for as long as the school's account is active. Sensitive integration credentials are encrypted at rest. Access within the platform is role-based, and administrative actions are recorded in audit logs.

Google Workspace integration

Where a school connects its own Google account (Settings → Integrations → Google), we access only what the school authorizes through Google OAuth:

Google OAuth tokens are encrypted at rest, never shown to users, and revocable at any time by disconnecting in Settings or from the school's Google account security page. Disconnecting stops all synchronization; files already created remain owned by the school in its own Drive. PostgreSQL remains the authoritative record — Drive and Sheets are a synchronization layer only.

Your rights

Requests to access, correct, or delete personal data should be made to the relevant school, which controls that data. We support schools in fulfilling those requests. Where applicable, this processing is carried out in line with the Kenya Data Protection Act.

Children's data and age consent

Student records (including dates of birth) are provided by the school or by a parent/guardian — children do not register themselves. Admissions and enrollment require a named parent/guardian and their explicit data-processing consent. Parents can review or revoke consent at any time via the school, and request deletion as described below.

Cookies

We use strictly necessary session cookies plus local preference storage (theme and cookie choice) — no advertising or tracking cookies. See our Cookie Policy. You can accept or reject optional storage in the cookie banner at any time.

Marketing emails and unsubscribe

Transactional emails (verification codes, receipts, invoices) are necessary to operate your account and cannot be unsubscribed while the account is active. Any non-essential announcements include an unsubscribe link, and you can also opt out any time by emailing mtandaolabs@gmail.com.

Data deletion requests

Ask your school administrator (Settings → Privacy & consent) or use our deletion request page to ask us directly. We verify ownership, forward the request to the controlling school, and confirm within 30 days.

Contact

Questions about this policy: mtandaolabs@gmail.com, +254 728 249135, Nairobi, Kenya. See also our Terms, Refund Policy, and Cookie Policy.

This summary describes current practice and is not legal advice.