Privacy notice
Last updated: 2026-06-06.
Who we are
Eduvella is a school-management service. Each school that uses Eduvella is the data controller for its students, guardians, staff, and applicants. Eduvella Ltd is the data processor on the school's behalf for the records that pass through the service.
Eduvella Ltd is a company registered in Nigeria. Our data-protection contact, and the point of contact for our registered office details, is privacy@eduvella.com.
Lawful basis
We process personal data on behalf of the school under the following lawful bases (Nigeria Data Protection Act 2023 s.25; GDPR Art. 6 where applicable):
- Contract — providing the school-management service the school has subscribed to (managing students, classes, attendance, grades, admissions).
- Legal obligation — retaining academic and financial records for the periods required by law, and issuing tax-compliant invoices.
- Legitimate interests — securing the service, investigating misuse via the audit log, and limited error and performance telemetry, balanced against the rights of data subjects.
- Consent — where the school relies on guardian consent (for example, publishing a student's photo on the school's public site). The school manages that consent as controller.
Sub-processors
We use a small number of vetted third parties to operate the service. Each handles only the data needed for its purpose and is bound by a data-processing agreement.
| Sub-processor | Purpose | Location |
|---|---|---|
| Neon | Primary database (Postgres) hosting | European Union / United States |
| Vercel | Application hosting and delivery | United States (global edge) |
| Cloudflare R2 | File and media storage (logos, documents, images) | Global (configurable region) |
| Resend | Transactional and bulletin email delivery | United States |
| Paystack | Payment processing (fees and subscriptions) | Nigeria |
| orravo.com relay | Payment-webhook relay between Paystack and Eduvella | United States |
| Sentry | Error and performance telemetry (diagnostics) | United States |
SMS notifications, where a school enables them, are delivered through a Nigerian SMS gateway. We will give advance notice of any material change to this list.
Cross-border transfers
Some sub-processors above host or process data outside Nigeria (for example in the European Union or the United States). Where data leaves Nigeria we rely on the transfer mechanisms permitted by the NDPA 2023 and, where relevant, GDPR (adequacy decisions or standard contractual clauses), and we require each sub-processor to maintain appropriate safeguards.
What we collect
- Identifiers — name, registration number, date of birth, sex.
- Contact — guardian phone and email.
- Academic — grades, attendance, exam results, transcripts.
- Financial — fee assignments and payment records.
- Account — sign-in email, hashed password (or Supabase session id).
- Operational — request IP, user agent, and time stamps, recorded in an audit log used to investigate access.
Minor data
Most student records concern minors. The school is the controller of consent under the relevant local law (NDPR / GDPR / FERPA / equivalent). We do not market to or profile minors. We retain student records only as long as the school instructs us to, and we delete on request.
Your rights
Guardians may request a copy of their child's record (subject access), its correction, or its erasure, and may object to certain processing. Because the school is the data controller, these requests are made to the school office, which decides and instructs us. Eduvella assists the school in fulfilling valid requests. If you are unsure who to contact, write to privacy@eduvella.com and we will direct your request to the right school.
Retention
Active student records: kept while the student is enrolled plus the period required by local regulation (typically 7 years after departure). Audit log entries: 5 years.
Security
Transport encryption (TLS), at-rest encryption on hosted databases, principle-of-least-privilege access control, and per-tenant row isolation enforced both at the application and database layer. Security events trigger an audit entry.
Data breaches
If a personal-data breach occurs that affects records we process, we will notify the affected school (the controller) without undue delay so it can meet its own obligations, and we will support the controller in notifying the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of the breach where the NDPA requires it, and affected data subjects where the breach is likely to result in high risk.
Contact
For data-subject requests or security concerns, contact the school directly or write to privacy@eduvella.com.