Plain-English summary
If you only read one paragraph, read this one. We collect only the information a school actually needs to run: identity and contact details for students, parents, and staff; academic and attendance records; billing and payment information; and usage logs of the product. We use it to deliver the service, bill correctly, meet legal obligations (tax, accounting, child-safeguarding), and improve the product. We do not sell personal data. We do not use student data to train third-party AI models. Data is stored encrypted at rest and in transit. Schools own their data, can export it at any time, and can request deletion subject to the legal retention periods that apply to academic and financial records.
Who we are
The data controller for this website and for sales-related personal data is the entity listed in the footer below. For personal data uploaded by a school into the Kampus platform (student records, staff records, family data), the school is the data controller and Kampus acts as the data processor under their instructions. This is formalised in our Data Processing Agreement, which every school signs before going live.
What we collect
From schools and the people who run them
- Account and billing information: name, work email, role, phone.
- School profile: name, address, registration number, branding.
- Correspondence: anything you send us through the contact form, email, or support channels.
From end users through the platform
- Students: name, date of birth, photo, class, section, family contact, attendance, marks, fees, health notes the school chooses to record, certificates issued.
- Parents and guardians: name, relationship to student, contact details, payment records.
- Staff: name, contact details, employment history, salary structure, leave, attendance, performance notes, payroll records.
- Visitors and applicants: admission inquiry forms, survey responses.
Automatically
- Server logs: IP address, user agent, pages requested, timestamps.
- Product analytics: feature usage, crash reports, performance metrics.
- Cookies and similar technologies (see the Cookie Policy).
How we use it
- To deliver the platform and its features.
- To bill correctly and meet tax and accounting obligations.
- To respond to support requests and security incidents.
- To send essential service messages (outages, security notices, billing).
- To improve the product: aggregated, de-identified analytics only.
We rely on the following legal bases under GDPR: performance of a contract (delivering the service), legitimate interests (security, product improvement), legal obligation (tax, accounting, safeguarding), and consent (for any optional communications, which you can withdraw at any time).
AI and Kampus.ai
The Kampus.ai assistant answers questions from your school's own data. Prompts and responses are processed by our infrastructure and the third-party model providers we contract with. We do not permit those providers to use school data to train their underlying models, and the data processing terms we sign with them reflect that. No student or staff record leaves the Kampus data boundary unless the school explicitly exports it.
Who we share data with
We do not sell personal data. We share it only with:
- Sub-processors that host, transmit, or back up data on our behalf (hosting, email delivery, payment processing, error monitoring). A current list is available on request.
- Regulators, courts, and law enforcement when we are legally required to.
- A buyer only in the event of a merger or acquisition, with notice to schools beforehand.
How long we keep data
Schools keep live data while the account is active. When a school ends its subscription, we hold the data for a 30-day grace period so it can be exported, after which it is deleted from production systems within 90 days and from backups within a further 12 months. Financial records are retained for the period required by applicable tax law (typically 7 years).
Your rights
Depending on where you live, you have some or all of these rights: access, correction, deletion, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority. Requests can be sent to the address below. We respond within 30 days. For data held inside a school's Kampus account, the school handles these requests directly as the data controller.
International transfers
Data is stored in the region the school chooses at signup. Where data is transferred internationally (for example, to a global sub-processor), we use Standard Contractual Clauses or equivalent safeguards approved by the relevant regulators.
Security
Data is encrypted at rest and in transit. Access is gated by role-based authorisation at both page and API level. Production access is logged and reviewed. Independent security testing is carried out at least annually. The full technical and organisational measures list is in our DPA.
Children
Kampus processes children's data only on behalf of schools, for the educational purposes the school chooses. We do not direct the platform at children or collect their data outside that relationship. Schools are responsible for parental notice and consent under the laws that apply to them.
Changes to this policy
We update this page when our practices change. Material changes are announced to schools by email at least 30 days before they take effect. The effective date at the top of this page always shows the current version.
Contact
Email hello@kampus.appwith the word “Privacy” in the subject line.