Skip to main content
Schoolyi
School librarian arranging books and planning cards in a bright library

Browse docs

Security & compliance

Student data privacy

What personal data a Schoolyi deployment holds about a child and their family, who can read each part, what the audit log records, how long things are kept, and what the product does not do for you.

Security & compliance guide for day and boarding schools.

Last updated August 29, 2026

A data protection officer needs four answers: what is held, who can read it, what is logged, and how long it stays. Everything below is taken from the schema and the retention jobs rather than from a policy statement, so it can be checked.

What is held

A student is a user record carrying name, email, registration and roll number, class, section, stream, gender, and an optional photograph. Parents are stored separately with name, relationship, email, phone number, occupation, and a postal address, and are joined to the child explicitly. Modules add to that as they are used: attendance, exam marks, fee instances and payments, leave, transport assignments, and library loans. Boarding adds the most sensitive material of all - clinic stays, medication records, pastoral notes, and safeguarding cases.

Who can read what

DataWho can read itBoundary
Student profileStaff with roster access; linked parentsA parent never sees a child they are not linked to
Grades and report cardsTeachers for assigned classes; parents once publishedDraft marks stay hidden until publication
Fee balances and receiptsFinance roles; linked parents at /fees/meParent APIs filter on the linked child
Admission applicationsAdmissions staff; the applicant through the public track flowPublic track requires the guardian email and the applicant date of birth
Full activity logPlatform Admin, Principal, Vice Principal, AdminOther staff see a narrower view; students, parents, and vendors are refused entirely
Boarding health and safeguarding recordsBoarding and pastoral rolesNot visible to general teaching staff

What is logged, and for how long

The activity log records the actor, their role, the action and module, a summary, the entity touched, the HTTP method and path, the source IP address and user agent, and a success or failure status. Each row also carries a SHA-256 hash chained to the previous row, so tampering after the fact is detectable. Retention differs by data type and every purge depends on the daily job being scheduled.

Record typeDefault retentionNotes
Activity log90 daysACTIVITY_LOG_HOT_DAYS; view telemetry is purged first; no archive behind it
Conversation messages365 daysPurged by the daily job
Transport location history30 daysTRANSPORT_GPS_RETENTION_DAYS
Transport boarding scans730 daysTRANSPORT_BOARDING_RETENTION_DAYS
Academic and financial recordsIndefiniteNo automatic deletion; removal is a manual decision

What the product does not do

  • No consent register. Consent captured on paper or elsewhere is not modelled, except within the boarding outing workflow.
  • No automated erasure workflow, and no single subject-access export.
  • No application-level encryption of stored fields. The database sits on the same server as the application.
  • No separation of student records per school when several schools share a deployment.
  • No certification against any data-protection standard. No audit has been performed.

Common questions

Quick answers in plain language.

Who can read a child’s grades and contact details?+

Teachers reach the classes they are assigned to for the active year, parents reach only the children linked to them at /parents, and finance roles reach fee data. Every screen and API route is gated by role, and the read itself is recorded in the activity log.

Can we produce everything held about one child for a subject access request?+

Not from one button. There is no single subject-access export. You assemble it from the module exports - roster, fees, attendance, grades, activity log - which is workable but should be rehearsed once before a real request arrives with a deadline attached.

How long is the audit trail kept?+

About ninety days, set by ACTIVITY_LOG_HOT_DAYS, and there is no archive behind it. The purge only runs when the daily cron is scheduled, so a deployment without cron keeps everything indefinitely. If your policy needs longer, export CSV or NDJSON from /activity-log before the window closes.

Does deleting a student remove their data?+

Deletion cascades into linked records and is destructive, which is why the roster favours deactivation. Decide deliberately which one an erasure request calls for, and record that decision, because deactivation leaves fee, attendance, and admissions history in place by design.

Related searches

School leaders and IT teams often search for: FERPA school ERP, and child data protection.