Effective Date: 6 September 2026 · Version: 2.0
Status of this Policy. This Policy is issued under the Nigeria Data Protection Act 2023 ("NDPA") and the General Application and Implementation Directive 2025 ("GAID"), which took effect on 19 September 2025. The Nigeria Data Protection Regulation 2019 and its 2020 Implementation Framework ceased to apply on that date; the NDPA and GAID together are now the complete governing framework. This Policy supersedes Version 1.0 dated 21 June 2026.
1. Who we are and what this Policy covers
-
EduSure EdTech Limited ("EduSure", "we", "us") is the data controller for the personal data described in this Policy. Where we process data on the documented instructions of a partner school, we act as that school's data processor and say so.
-
This Policy covers the EduSure EdTech App, the Tech for Scholars learning platform, the EduSure Fee Management Platform, the EduSure School Intelligence Platform, and all personal data collected in the field by EduSure agents on paper or mobile forms, including the Parent / Guardian Assessment Questionnaire and the School Partnership Assessment Questionnaire.
-
It applies to every person whose data we hold: parents and guardians, scholars, partner school staff, field agents, guardians and foundations funding scholars, and any person issued an EduSure identity (EFID, ESS, ESP, EAG, EGD, EFD).
-
References in this Policy to a holding company apply to any company that becomes the holding company of EduSure EdTech Limited from time to time. No EduSure group entity other than EduSure EdTech Limited is a controller of this data unless separately named.
2. Our regulatory status and accountability
2.1 Registration with the NDPC
A data controller that processes the personal data of more than 200 data subjects within six months is a Data Controller of Major Importance ("DCMI") and must register with the Nigeria Data Protection Commission ("NDPC"). EduSure expects to cross that threshold in its first term of field operations and registers accordingly.
| Obligation | Our position | | --- | --- | | NDPC registration as a DCMI | Registration number: to be inserted on registration | | Notification of material change | Filed with the NDPC within 60 days of any significant change to our registration particulars | | Compliance Audit Return (CAR) | Filed annually by 31 March. As an entity incorporated after 12 June 2023, our first CAR is filed within 15 months of incorporation | | Filing through a DPCO | Where we are classified Ultra-High Level or Extra-High Level, our CAR is filed through a licensed Data Protection Compliance Organisation | | Data Protection Impact Assessment | Carried out before deploying software that processes sensitive personal data, and submitted to the NDPC within four months as GAID requires | | Record of Processing Activities | Maintained and available to the NDPC on request |
2.2 Data Protection Officer
We have designated a Data Protection Officer ("DPO") who reports directly to the Managing Director, cannot be penalised for performing the role, and is the contact point for data subjects and for the NDPC.
| Role | Detail | | --- | --- | | Data Protection Officer | Gerald Ozimhede Ivhador, Legal Practitioner. Email: dpo@edusure.ng (interim: edusuretech@gmail.com). Phone: 08154017624 | | Independence of the DPO | The DPO holds no role that determines the purposes or means of processing. He does not approve disbursements, hold regional operational authority, or configure the platform. Our systems enforce this: the platform refuses to let the DPO account approve a payment or run a disbursement cycle. | | Credentialing | The DPO maintains NDPC certification and verified status, and meets the annual continuous professional development requirement set by the Commission. Credentials are evidenced in each Compliance Audit Return. | | Accountable officer | Founder / Managing Director |
3. The personal data we collect
3.1 Parents, guardians and fee payers
- Name, gender, age band, relationship to the child, and level of education
- Phone number, community, ward, LGA and state of residence
- Occupation, household income band, income regularity, and whether income is seasonal
- School fee payment history, arrears, and coping behaviour when fees cannot be met
- Answers given in the Parent / Guardian Assessment Questionnaire, including opinions on saving and on the scheme
- Consent records: which consents were given, when, in which version of the form, and the signature or mark
- Contribution history, wallet balance, service fees and VAT paid, and ledger entries
- Where a shortfall arises, the circumstances recorded in a case file
3.2 Scholars (children)
- Name, class or level, school, and EduSure Scholar ID (ESS)
- Term fee target, funding status, and enrolment status
- Learning activity, progress and assessment results on Tech for Scholars
- Where relevant to fee continuity, the fact of a transfer, withdrawal or bereavement
What we do not collect from children. We do not profile scholars for marketing, we do not build behavioural advertising profiles, and we do not ask a scholar for personal data directly in the field. Field agents are instructed never to record a pupil's name or identifying detail in a free-text answer on the school questionnaire.
3.3 Partner schools and their staff
- School name, address, GPS coordinates, ward and LGA, and Ministry of Education approval details
- Name, role, phone and email of the proprietor, principal, bursar or other respondent
- Fee schedules, enrolment and collection figures, and salary arrears where disclosed
- Bank account name, bank and account number used to receive fee disbursements
- Photographs of the school signboard, frontage, classroom block and approval certificate, taken by the agent for verification
3.4 Field agents, guardians and foundations
- Agent name, EAG identity, phone, assigned area, commission and payout records
- Guardian (EGD) and foundation (EFD) contact details, funding commitments, and source-of-funds verification records
- For institutional sponsors, the details of the named contact person
3.5 Technical data
- IP address, device identifiers, operating system and app version
- Crash logs, diagnostics and performance analytics
- GPS coordinates captured at the start of a field interview or school visit
- Access logs and audit trails within the platform
4. Why we process it, on what lawful basis, and for how long
| Purpose | Lawful basis (NDPA s.25) | Retention | | --- | --- | --- | | Field research to design the fee savings service | Consent | 24 months from the date of interview, then deleted or irreversibly anonymised | | Contacting a respondent for follow-up or early adoption | Consent (separate, optional) | Until consent is withdrawn | | Creating and maintaining EduSure identities and accounts | Performance of a contract | Life of the relationship, then 6 years | | Collecting contributions, calculating the service fee and VAT, and disbursing to schools | Performance of a contract; legal obligation | 6 years from the end of the financial year, under CAMA 2020 and tax law | | Ledger, reconciliation and statements | Legal obligation | 6 years, immutable | | Investigating a shortfall and seeking a government partner, guardian or foundation | Consent (separate, per case) | 6 years from closure of the case | | Delivering curriculum and tracking academic progress | Performance of a contract; consent of the guardian | Duration of enrolment, plus any period the school or examination body requires | | Verifying schools and preventing fraud or identity misuse | Legitimate interest; legal obligation | 6 years | | Source-of-funds checks on guardians and foundations | Legal obligation | As required by anti-money-laundering law | | Aggregate reporting to government, partners and investors | Legitimate interest | Aggregate only; no identifiable data | | Security, audit logs and incident investigation | Legal obligation; legitimate interest | 24 months |
5. Consent: how we ask, and how you withdraw
-
Where we rely on consent, it is requested before any question is asked, not afterwards. Our field forms carry the consent statement on the first page and the agent must read it aloud before beginning.
-
Consent is separated by purpose. Our parent questionnaire carries two distinct boxes: a required consent to use the answers for research and product design, and an optional consent to be contacted again. A person may decline the second and still take part. Where the optional consent is not given, no phone number is recorded.
-
A third, separate permission governs the shortfall backstop. If a family falls short of a term target and we would need to share their circumstances with a government partner, a guardian or the Foundation in order to seek support, we do not do so unless that permission has been recorded. Our systems block the assignment of a sponsor to a case where it has not.
-
We record which version of a form a consent was given under, and the date. Withdrawing consent is free, requires no reason, and carries no consequence for any service already provided. Write to the DPO at the address in Section 15.
6. Children's data
-
Under section 31 of the NDPA, a child is a person under 18 and their personal data may be processed only with the consent of a parent or guardian, save in the limited circumstances the Act allows.
-
Every scholar record is linked to a parent, guardian or sponsor identity, and that person gives consent at enrolment. We verify the relationship at enrolment through the field assessment and, for partner schools, against the school's own class list.
-
A parent or guardian may see, correct or ask us to delete their child's data, subject only to records a school or examination body requires us to keep. Where a deletion request affects an academic record held for a school, we tell you which body requires it and for how long.
-
Any concern about a scholar's data or safety is handled as a priority by the DPO.
7. Who we share it with
We do not sell personal data, and we do not use it for advertising.
| Recipient | What is shared | Basis | | --- | --- | --- | | The scholar's partner school | Scholar identity, class, and the amount paid on their behalf | Contract | | A government partner, guardian or foundation asked to cover a term | Only what is necessary to assess the case | The parent's specific permission, recorded on the case | | Payment processor | Payment reference and amount | Contract | | Hosting and platform provider | Platform data under a processing agreement | Contract | | SMS, voice and messaging providers | Phone number and message content | Contract; contact consent | | Regulators, courts and law enforcement | As lawfully required | Legal obligation | | Investors and funders | Aggregate and anonymised figures only | Legitimate interest | | A school's parent community | Nothing. We do not approach a school's parents using data the school gave us, without the school's separate written permission | — |
8. Where your data is held, and transfers outside Nigeria
-
Our platform is hosted on a managed cloud service whose infrastructure is located outside Nigeria. Personal data described in this Policy is therefore transferred outside Nigeria in the ordinary course of operating the service. We say this plainly rather than describing our processing as domestic.
-
Such transfers are made under the mechanisms permitted by the NDPA and GAID: an adequacy determination where one exists, otherwise standard contractual clauses or another approved instrument, together with a written processing agreement imposing obligations no less protective than this Policy.
-
Paper field forms remain in Nigeria at all times and are uploaded to the platform within 24 hours of the interview.
9. How we protect it
- Encryption of data in transit, and at rest wherever the platform supports it
- Row-level security and role-based access, so a field agent sees only their own records, a school sees only its own pupils, and a regional director sees only records within the states of their region
- Access to a data subject's free-text answers and case circumstances is limited to those who need them to act, and is not granted by seniority alone
- Financial records held in an append-only ledger: entries are never edited or deleted, and corrections are posted as reversing entries, so the record of what happened to money cannot be quietly rewritten
- Separation of duties in code: whoever prepares a payment may not authorise it, and whoever authorises it may not record it as sent
- Separation of financial data from academic content systems
- Access logs reviewed, and credentials scoped to the minimum access required and rotated periodically
- Field agents carry photo identity with an agent code; every form prints a number the respondent can call to verify the agent is genuine
- Agents are instructed that EduSure never asks a respondent for money, a bank PIN or a BVN, and the form says so
- Completed paper forms are kept sealed, uploaded within 24 hours, and securely destroyed once verified
No system is completely secure. We do not claim absolute security; we claim measures proportionate to the sensitivity of what we hold, and honesty when something goes wrong.
10. Automated processing
-
Our systems flag a scholar as at risk or in shortfall by comparing what has been saved against the term target, and open a case automatically at the start of a term. That flag does not decide anything on its own: whether support is sought, and from whom, is decided by a person who first establishes why the family fell short.
-
No decision producing a legal or similarly significant effect is taken solely by automated means. You may ask for human review of any automated flag affecting you, and for an explanation of it.
11. Your rights
| Right | What it means | | --- | --- | | Access | A copy of the personal data we hold about you, and the purposes we hold it for | | Rectification | Correction of anything inaccurate or incomplete | | Erasure | Deletion where we no longer need the data, where you withdraw consent, or where processing was unlawful | | Restriction | A pause on processing while a dispute about accuracy or lawfulness is resolved | | Portability | Your data in a structured, commonly used, machine-readable form | | Objection | To object to processing based on legitimate interest, and to direct marketing at any time | | Withdraw consent | At any time, without reason and without consequence | | Human review | Of any automated flag or assessment affecting you | | Complain | To us, and to the NDPC, at any time |
- Write to the DPO using the details in Section 15. We respond within 30 days. If we need longer because the request is complex, we tell you why within that period. We never charge for a first request.
Your right to complain to the regulator. You may complain to us first, and you may also complain directly to the Nigeria Data Protection Commission at any time, whether or not you have raised it with us. GAID provides a standard grievance mechanism for this purpose. NDPC: No. 3 Zambezi Crescent, Off Aguiyi Ironsi Street, Maitama, Abuja — info@ndpc.gov.ng — www.ndpc.gov.ng
12. When things go wrong: breaches
-
Section 40 of the NDPA requires us to act within 72 hours of becoming aware of a personal data breach. We notify the NDPC within 72 hours, and we notify affected people promptly where the breach is likely to result in a risk to their rights and freedoms, in language they can act on.
-
We keep a breach register recording every incident, including those below the notification threshold, its effect and our response. Our detailed procedure is in the EduSure Data Backup and Disaster Recovery Policy, which forms part of this framework.
13. Data Protection Impact Assessments
- We carry out a Data Protection Impact Assessment before any processing likely to result in high risk, and before deploying software that processes sensitive personal data. Given that we process children's data and household financial data at scale, we treat the core platform as high risk by default. Where GAID requires it, the assessment is submitted to the NDPC within four months.
14. Changes to this Policy
- We review this Policy at least annually and immediately on any material change to our processing, our platform or the law. Material changes are notified through the app and, where we hold contact consent, directly. The version and effective date at the head of this Policy record the current revision.
15. Contact
Data Protection Officer, EduSure EdTech Limited
Email: edusuretech@gmail.com · Phone: 08154017624
Nigeria Data Protection Commission — info@ndpc.gov.ng — www.ndpc.gov.ng
Issued under the Nigeria Data Protection Act 2023 and the General Application and Implementation Directive 2025. Version 2.0, effective 6 September 2026. Supersedes Version 1.0 of 21 June 2026.
