Last updated: 17 September 2026
1. Scope
This notice describes the categories of information EduTest 360 may process when schools, administrators, staff, students, parents, applicants and other authorised users interact with the platform.
2. Information processed
Depending on the modules a school uses, records may include school identity and subscription information, account details, admissions data, student and guardian information, staff records, attendance, academic results, fees and payment references, messages, library and inventory records, transport assignments and security logs.
3. School ownership and tenant separation
Operational school records are scoped to a school tenant. EduTest 360 uses school identifiers and role checks throughout the application so authorised users access the records associated with their school and role.
4. Location information
Location is used only in features that require it. Admission applicants may optionally share browser location, and transport tracking may receive GPS coordinates from an authorised driver device or tracker. Browser/device permission is required where applicable.
5. Biometric integrations
EduTest 360’s biometric attendance integration is designed to receive attendance events and mapped device identifiers from compatible devices or middleware. The platform should not be used to store raw fingerprint templates unless a future implementation is specifically designed, assessed and authorised for that purpose.
6. Payments and bank details
Online school-fee payments may be processed through the platform’s configured payment provider. Schools may provide settlement bank details for withdrawals. Sensitive payment-card credentials should remain with the payment provider and must not be stored directly in ordinary EduTest 360 application records.
7. Security
Security controls include role-based access, tenant-aware queries, CSRF protection, password hashing, optional or required two-factor authentication for supported roles, login controls, protected device/API credentials and secure deployment requirements such as HTTPS.
8. Communications
Schools may use email, SMS and in-app notifications to communicate with authorised recipients. SMS availability depends on the school plan and configured provider. Contact information should be used only for legitimate school and platform communication.
9. Retention and deletion
Schools should retain records only for as long as they are legitimately required for academic, administrative, financial, safeguarding or legal purposes. Platform administrators should maintain appropriate backup, archival and deletion procedures for production use.
10. Children's information
Schools are responsible for ensuring that student information, including information about children, is collected and used for legitimate educational purposes with the notices, permissions and safeguards required by applicable law and school policy.
11. Third-party services
EduTest 360 may integrate with hosting, SMTP, SMS, payment, domain/DNS, mapping or device services. Information sent to those services is also subject to the provider’s own security and privacy practices.
12. Contact
For privacy or data-handling questions, email privacy@edutest.com.ng. For account-security concerns, email security@edutest.com.ng, or use the EduTest 360 contact page.