Plain-English summary
If you only read one paragraph, read this one. We collect only the information a school actually needs to run: identity and contact details for students, parents, and staff; academic and attendance records; billing and payment information; and usage logs of the product. We use it to deliver the service, bill correctly, meet legal obligations (tax, accounting, child-safeguarding), and improve the product. We do not sell personal data. We do not use student data to train third-party AI models. Data is stored encrypted at rest and in transit. Schools own their data, can export it at any time, and can request deletion subject to the legal retention periods that apply to academic and financial records.
Who we are
Kampus is presently operated by its founder as an individual, ahead of formal incorporation — this section will name the registered company as soon as that is complete. For this website and for sales-related personal data, that individual is the data controller, reachable at hello@kampuscloud.app.
For personal data uploaded by a school into the Kampus platform (student records, staff records, family data), the school is the data controller and Kampus acts as the data processor under their instructions. This is formalised in our Data Processing Agreement, which every school signs before going live.
What we collect
From schools and the people who run them
- Account and billing information: name, work email, role, phone.
- School profile: name, address, registration number, branding.
- Correspondence: anything you send us through the contact form, email, or support channels.
From end users through the platform
- Students: name, date of birth, photo, class, section, family contact, attendance, marks, fees, health notes the school chooses to record, certificates issued.
- Parents and guardians: name, relationship to student, contact details, payment records.
- Staff: name, contact details, employment history, salary structure, leave, attendance, performance notes, payroll records.
- Visitors and applicants: admission inquiry forms, survey responses.
Automatically
- Server logs: IP address, user agent, pages requested, timestamps.
- Product analytics: feature usage, crash reports, performance metrics.
- Cookies and similar technologies (see the Cookie Policy).
How we use it
- To deliver the platform and its features.
- To bill correctly and meet tax and accounting obligations.
- To respond to support requests and security incidents.
- To send essential service messages (outages, security notices, billing).
- To improve the product: aggregated, de-identified analytics only.
We rely on the following legal bases under GDPR: performance of a contract (delivering the service), legitimate interests (security, product improvement), legal obligation (tax, accounting, safeguarding), and consent (for any optional communications, which you can withdraw at any time).
AI and Kampus.ai
The Kampus.ai assistant answers questions from your school's own data. Prompts and responses are processed by our infrastructure and the third-party model providers we contract with. We do not permit those providers to use school data to train their underlying models, and the data processing terms we sign with them reflect that. No student or staff record leaves the Kampus data boundary unless the school explicitly exports it.
Who we share data with
We do not sell personal data. We share it only with:
- Sub-processors that host, transmit, or back up data on our behalf (hosting, email delivery, payment processing, error monitoring). A current list is available on request.
- Regulators, courts, and law enforcement when we are legally required to.
- A buyer only in the event of a merger or acquisition, with notice to schools beforehand.
How long we keep data
Schools keep live data while the account is active. When a school ends its subscription, we hold the data for a 30-day grace period so it can be exported, after which it is deleted from production systems within 90 days and from backups within a further 12 months. Financial records are retained for the period required by applicable tax law (typically 7 years).
Deleting an account and its data
Accounts in Kampus are created by the school in its admin console — nobody can sign themselves up, and nobody can delete a school's record of a student on their own account. To have an account closed, and the data behind it deleted, email hello@kampuscloud.appwith the word “Privacy” in the subject line and include: your full name as the school records it, your institution and campus, your role and your roll or registration number, the phone number or email address on the account, and whether you want the account closed only or the records behind it deleted too.
We acknowledge the request, verify it against the account, and pass it to your institution, which holds the records as the data controller. We respond within 30 days. Closing the account revokes every session, signs out every device, and destroys each device's notification token. Academic and financial records are retained for the periods set out above, because the school is legally required to keep them.
The full policy — what is removed, what is kept and why, and how long each stage takes — is on the Data & Account Deletionpage. In the Kampus mobile app the same route is under Settings › Delete my account and data.
Your rights
Depending on where you live, you have some or all of these rights: access, correction, deletion, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority. Requests can be sent to the address below. We respond within 30 days. For data held inside a school's Kampus account, the school handles these requests directly as the data controller.
International transfers
Data is stored in the region the school chooses at signup. Where data is transferred internationally (for example, to a global sub-processor), we use Standard Contractual Clauses or equivalent safeguards approved by the relevant regulators.
Security
Data is encrypted at rest and in transit. Access is gated by role-based authorisation at both page and API level. Production access is logged and reviewed. Independent security testing is carried out at least annually. The full technical and organisational measures list is in our DPA.
Children
Kampus processes children's data only on behalf of schools, for the educational purposes the school chooses. We do not direct the platform at children or collect their data outside that relationship. Schools are responsible for parental notice and consent under the laws that apply to them.
Changes to this policy
We update this page when our practices change. Material changes are announced to schools by email at least 30 days before they take effect. The effective date at the top of this page always shows the current version.
Contact
Email hello@kampuscloud.appwith the word “Privacy” in the subject line.