SchoolOS Privacy Policy
SchoolOS is used by schools. This explains what your school decides, what we do as the people who run the platform, and what the system is capable of holding.
Effective
17 September 2026
Your records held by
Your school
Advertising
None, ever
Your school decides what is recorded about a student, who may see it, and how long it is kept. Chinland InfoTech runs the platform that stores it, acting on the school's instructions. If you are a parent, a student or a member of staff and you want to see, correct or remove a record, ask your school first — they hold it, and they are the ones who can act on it.
Who is responsible for what
Your school is the controller. It chooses which modules to switch on, what to record, who has which role, and how long records are retained. Its own privacy notice governs those decisions.
Chinland InfoTech is the processor. We provide and operate the platform, keep it secure, and act on the school's instructions. We do not decide what a school collects, we do not use school data for our own purposes, and we never sell it or use it for advertising.
A school using SchoolOS should have a written agreement with us covering exactly this. Where that agreement and this page differ, the agreement governs.
What the platform can hold
Not every school uses every module. What follows is what SchoolOS is capable of storing when a school turns the relevant part on.
- People. Student records, guardians and their relationship to a student, emergency contacts, and staff records, including the identity and contact details a school needs.
- Attendance and daily life. Daily and per-session registers, reasons for absence, alerts sent to guardians, and timetables.
- Learning. Enrolments, coursework, grade components, exams, hall tickets, results, academic standing and library borrowing.
- Money. Fee assignments, invoices, instalments, payments and account transactions, in kyat.
- Sensitive categories. Where the school uses them: health logs, allergies, disciplinary records, and documents or photographs uploaded about a person. These deserve particular care and particular restraint about who is given access.
Face recognition, if a school enables it
SchoolOS includes an optional face recognition module for attendance and gate entry. It stores a mathematical representation of a face — an embedding — for a student or staff member, and a log of each match attempt. This is biometric data about identifiable people, most of them children.
It is off unless a school turns it on, and a school should not turn it on lightly. Biometric data about minors is treated more strictly than ordinary school records almost everywhere, and typically needs an explicit legal basis, informed consent from parents or guardians, a workable alternative for anyone who declines, and a decision about retention taken in advance. Obtaining and recording that consent is the school's responsibility, not ours.
Where the module is in use, embeddings can be deactivated and removed for an individual, and match logs age out. A school should ask us before switching it on, so that retention and consent are settled first.
Keeping schools apart
SchoolOS is multi-tenant: many schools run on shared infrastructure. Every record belongs to a school, and access is scoped to it and to the role a person has been given there. One school cannot see another's records, and a role only reaches what it needs — a teacher does not see the finance ledger because the system runs on one database.
Who else is involved
Sign-in is handled by Firebase Authentication, a Google service. Uploaded files and documents are stored in Google Cloud Storage. Email — invitations, alerts, receipts — is delivered through Resend. Payments are handled by the payment providers a school connects, and card details are handled by those providers rather than by us. We use cloud hosting and database providers to run the platform.
Each acts on our behalf to provide that infrastructure. We disclose information otherwise only where the law requires it, or where it is necessary to protect the security of the platform.
How long records are kept
Retention is the school's decision, because a school has obligations about how long student records must be kept that vary by country and by level of education. The platform keeps a record until the school deletes it or asks us to, and we delete a school's data on request when it stops using SchoolOS, subject to whatever the agreement between us says.
Your rights, and where to take them
If you are a parent, guardian, student or member of staff and you want to see, correct, or ask for the deletion of a record, contact your school. They hold the record, they know its context, and they are the ones who can change it. If we receive a request directly, we will pass it to the school rather than act on it ourselves.
If you are a school and need help with a request, or need to raise something about how the platform handles data, email admin@chinlandinfotech.com.
Security
Traffic travels over encrypted HTTPS. Access is controlled by role and scoped to a single school. Sign-in runs through Firebase rather than passwords we hold, and administrative actions are recorded in an audit trail. No system is perfectly secure; the strongest protection in a school system is usually restraint about who is given an administrator role.
Changes and contact
SchoolOS is still in development, and this page describes the platform as built rather than a live deployment. It will be revised as modules, providers and retention settings are finalised, and the effective date above updated.