SchoolOS Privacy Policy

SchoolOS is used by schools. This explains what your school decides, what we do as the people who run the platform, and what the system is capable of holding.

Effective

17 September 2026

Your records held by

Your school

Advertising

None, ever

Your school decides what is recorded about a student, who may see it, and how long it is kept. Chinland InfoTech runs the platform that stores it, acting on the school's instructions. If you are a parent, a student or a member of staff and you want to see, correct or remove a record, ask your school first — they hold it, and they are the ones who can act on it.

Who is responsible for what

Your school is the controller. It chooses which modules to switch on, what to record, who has which role, and how long records are retained. Its own privacy notice governs those decisions.

Chinland InfoTech is the processor. We provide and operate the platform, keep it secure, and act on the school's instructions. We do not decide what a school collects, we do not use school data for our own purposes, and we never sell it or use it for advertising.

A school using SchoolOS should have a written agreement with us covering exactly this. Where that agreement and this page differ, the agreement governs.

What the platform can hold

Not every school uses every module. What follows is what SchoolOS is capable of storing when a school turns the relevant part on.

  • People. Student records, guardians and their relationship to a student, emergency contacts, and staff records, including the identity and contact details a school needs.
  • Attendance and daily life. Daily and per-session registers, reasons for absence, alerts sent to guardians, and timetables.
  • Learning. Enrolments, coursework, grade components, exams, hall tickets, results, academic standing and library borrowing.
  • Money. Fee assignments, invoices, instalments, payments and account transactions, in kyat.
  • Sensitive categories. Where the school uses them: health logs, allergies, disciplinary records, and documents or photographs uploaded about a person. These deserve particular care and particular restraint about who is given access.

Face recognition, if a school enables it

SchoolOS includes an optional face recognition module for attendance and gate entry. It stores a mathematical representation of a face — an embedding — for a student or staff member, and a log of each match attempt. This is biometric data about identifiable people, most of them children.

It is off unless a school turns it on, and a school should not turn it on lightly. Biometric data about minors is treated more strictly than ordinary school records almost everywhere, and typically needs an explicit legal basis, informed consent from parents or guardians, a workable alternative for anyone who declines, and a decision about retention taken in advance. Obtaining and recording that consent is the school's responsibility, not ours.

Where the module is in use, embeddings can be deactivated and removed for an individual, and match logs age out. A school should ask us before switching it on, so that retention and consent are settled first.

Keeping schools apart

SchoolOS is multi-tenant: many schools run on shared infrastructure. Every record belongs to a school, and access is scoped to it and to the role a person has been given there. One school cannot see another's records, and a role only reaches what it needs — a teacher does not see the finance ledger because the system runs on one database.

Who else is involved

Sign-in is handled by Firebase Authentication, a Google service. Uploaded files and documents are stored in Google Cloud Storage. Email — invitations, alerts, receipts — is delivered through Resend. Payments are handled by the payment providers a school connects, and card details are handled by those providers rather than by us. We use cloud hosting and database providers to run the platform.

Each acts on our behalf to provide that infrastructure. We disclose information otherwise only where the law requires it, or where it is necessary to protect the security of the platform.

How long records are kept

Retention is the school's decision, because a school has obligations about how long student records must be kept that vary by country and by level of education. The platform keeps a record until the school deletes it or asks us to, and we delete a school's data on request when it stops using SchoolOS, subject to whatever the agreement between us says.

Your rights, and where to take them

If you are a parent, guardian, student or member of staff and you want to see, correct, or ask for the deletion of a record, contact your school. They hold the record, they know its context, and they are the ones who can change it. If we receive a request directly, we will pass it to the school rather than act on it ourselves.

If you are a school and need help with a request, or need to raise something about how the platform handles data, email admin@chinlandinfotech.com.

Security

Traffic travels over encrypted HTTPS. Access is controlled by role and scoped to a single school. Sign-in runs through Firebase rather than passwords we hold, and administrative actions are recorded in an audit trail. No system is perfectly secure; the strongest protection in a school system is usually restraint about who is given an administrator role.

Changes and contact

SchoolOS is still in development, and this page describes the platform as built rather than a live deployment. It will be revised as modules, providers and retention settings are finalised, and the effective date above updated.

Chinland InfoTech

admin@chinlandinfotech.com

Privacy enquiries for SchoolOS