Get your free school ERP demo today.Book now

European data protection

GDPR Policy

This Policy explains Maskeen Edutech's GDPR roles and the measures used to support Institutions handling student, parent, staff, academic, fee, and school-operation data.

Last updated: 3 September 2026

1. Scope and purpose

This GDPR Policy explains Maskeen Edutech's approach when the European Union General Data Protection Regulation, the retained UK GDPR, or materially similar European data-protection requirements apply to personal data processed through our website, school management platform, mobile experiences, support services, or Institution-authorised integrations.

It supplements the Privacy Policy and does not independently expand the territorial scope of the GDPR. Whether European data-protection law applies depends on the location and activities of Maskeen Edutech, the Institution, the individuals concerned, and the relevant processing operation.

In this Policy, “Institution” means the school, pre-school, college, coaching centre, trust, society, group, or other organisation that purchases or controls a Maskeen Edutech workspace. “Institution Data” means personal data submitted to, received through, or generated in that workspace by the Institution or its Authorised Users.

2. Controller and processor roles

For website inquiries, demo requests, our direct commercial relationship, account security, subscription billing, service usage, and support administration, Maskeen Edutech may act as an independent controller because we determine the purpose and essential means of that processing.

For Institution Data—including student, parent, guardian, teacher, staff, academic, attendance, fee, transport, library, communication, and school-operation records—an Institution normally acts as controller and Maskeen Edutech normally acts as its processor. We process that data on documented instructions expressed through the agreement, platform configuration, and authorised use of the Services.

The factual allocation of roles controls. If the parties jointly determine a processing purpose or Maskeen Edutech uses specific data for an independent lawful purpose, the parties will address the applicable controller responsibilities for that operation.

Note: Students, parents, staff, and other individuals should ordinarily send requests about Institution Data to the Institution that controls the relevant workspace.

3. Data-protection principles

Where the GDPR applies, personal data should be processed lawfully, fairly, and transparently; collected for specified purposes; limited to what is necessary; kept accurate; retained only as long as needed; and protected with security appropriate to the risk. The responsible controller must also be able to demonstrate compliance.

Maskeen Edutech designs and operates the Services to support proportionate access, data minimisation, security, and accountable administration. Because the platform is configurable, each Institution must select appropriate fields, modules, roles, retention periods, reports, communications, and integrations for its own lawful educational purposes.

  • Lawfulness, fairness, and transparency.
  • Purpose limitation and compatible use.
  • Data minimisation and privacy-aware defaults.
  • Accuracy and appropriate correction processes.
  • Storage limitation and documented retention.
  • Integrity, confidentiality, resilience, and accountability.

4. Data categories and processing purposes

The Privacy Policy describes the categories processed across account, Institution, student, guardian, staff, academic, fee, communication, file, device, and security functions. The exact data depends on the Institution's selected modules and configuration.

As a processor, Maskeen Edutech processes Institution Data to host and secure the workspace; authenticate users; operate authorised school workflows; store and transmit records; generate requested reports; deliver communications; support configured integrations; maintain backups and logs; provide support; and return or delete data according to the agreement.

As a controller, we may process limited relationship and usage data to respond to inquiries, administer accounts and subscriptions, secure the Services, prevent fraud, maintain legal records, improve reliability, communicate important changes, and send permitted marketing.

6. Children and special-category data

Children merit specific protection under European data-protection law. An Institution must assess the child's age, capacity, best interests, applicable Member State rules, educational context, and whether parental or guardian authorisation is required. Information provided to children should be clear and age appropriate.

The Institution must apply heightened access, notice, minimisation, retention, and disclosure controls to student records. Parent access must be verified and must not expose information about another student, household, staff member, or protected school process.

Health, disability, biometric, religious, ethnic, or other special-category data may be processed only when the Institution has both an Article 6 lawful basis and an applicable Article 9 condition or other valid legal authority. Criminal-offence information also requires specific legal authority and safeguards. Institutions should not enable or upload such data unless necessary and supported by the selected Services and agreement.

7. Institution responsibilities as controller

The Institution determines why and how its educational and administrative records are processed and retains primary responsibility for GDPR compliance for Institution Data. Maskeen Edutech's tools and assistance do not replace the Institution's legal assessment.

  • Maintain a lawful basis, transparent notices, and any required parent, guardian, staff, or student permissions.
  • Collect only necessary information and avoid unnecessary free-text or sensitive records.
  • Keep data accurate, define retention, and use correction, archive, export, and deletion controls appropriately.
  • Assign least-privilege roles and regularly review school, class, subject, report, and integration access.
  • Respond to data-subject requests and verify identity, parental authority, and the rights of other people before disclosure.
  • Maintain records of processing and complete legitimate-interest assessments or Data Protection Impact Assessments where required.
  • Appoint a data protection officer or representative where the GDPR requires one.
  • Provide only lawful, documented instructions and promptly notify Maskeen Edutech of relevant risks or incidents.

8. Maskeen Edutech commitments as processor

Where Maskeen Edutech acts as a processor, the applicable agreement or Data Processing Addendum should govern the subject, duration, nature, purpose, data types, data subjects, and the parties' obligations. Subject to that agreement and the GDPR, we will process personal data on documented instructions and tell the Institution if an instruction appears to infringe applicable data-protection law, unless law prevents us from doing so.

  • Require authorised personnel to protect confidentiality.
  • Apply technical and organisational measures appropriate to the assessed risk.
  • Use subprocessors under written protection and the authorisation mechanism in the applicable DPA.
  • Provide reasonable assistance with rights requests, security, breach assessment, DPIAs, and regulator consultation.
  • Return or delete personal data at the Institution's choice after Services end, subject to lawful retention and backup cycles.
  • Maintain information reasonably needed to demonstrate processor compliance and support agreed audits.

9. Data-subject rights

Depending on the facts and lawful basis, individuals may have rights to be informed, access their personal data, correct inaccurate data, request erasure, restrict processing, receive eligible data in a portable format, object to processing, and avoid a decision based solely on automated processing that produces legal or similarly significant effects. They may also withdraw consent and complain to a competent supervisory authority.

Rights are not absolute and exceptions may apply. The controller must verify identity and authority, protect the rights and freedoms of other people, and respond within the period required by applicable law. Maskeen Edutech will provide reasonable assistance when the Institution receives a valid request involving data processed through the Services.

For Institution Data, submit the request to the relevant Institution first. Requests about Maskeen Edutech's independent controller activities may be sent to support@maskeenedutech.com with enough information to identify the relationship and request. Do not email passwords, OTPs, payment credentials, or unnecessary identity documents.

10. Subprocessors and authorised recipients

Maskeen Edutech may use subprocessors for infrastructure, hosting, databases, storage, backups, content delivery, email, SMS, push notifications, monitoring, support, security, payments, and other functions needed to operate the Services. Institution-selected payment, communication, biometric, GPS, app-store, or other integrations may also receive data under the Institution's instructions.

When the GDPR applies to processor activities, subprocessors must be engaged under written terms that provide data-protection obligations appropriate to their service. The applicable DPA will describe the Institution's authorisation and notification mechanism and any right to object to a new subprocessor on reasonable data-protection grounds.

Maskeen Edutech remains responsible for its processor obligations where a subprocessor performs covered processing on our behalf, subject to the agreement and applicable law. An independent service chosen and controlled directly by the Institution may act under its own terms and privacy responsibilities.

11. International data transfers

If personal data protected by the GDPR is transferred outside the European Economic Area, United Kingdom, or another protected territory, the exporter must ensure that an approved transfer mechanism and supplementary safeguards apply where required.

Depending on the transfer, safeguards may include an adequacy decision, approved standard contractual clauses, a UK transfer addendum or agreement, binding corporate rules, certification or code mechanisms, or a legally permitted derogation. The parties may also need to assess the destination law and apply additional contractual, organisational, or technical measures.

Institutions requiring a specific region or transfer mechanism should document it in the order form or DPA before uploading affected data. Maskeen Edutech will provide reasonably available information about relevant processing locations and safeguards for covered Services.

12. Security and data protection by design

Maskeen Edutech uses safeguards designed for a multi-tenant school ERP and the risks presented by the relevant processing. Measures may include Institution and school scoping, role-based access, authentication controls, protected credentials, encrypted network transport, restricted files, logging, backups, monitoring, rate limits, and security or audit events.

We review safeguards in light of available technology, implementation cost, processing scope and context, and risk to individuals. No online service is completely secure, and Institutions must also secure their users, devices, networks, integrations, exports, and administrator processes.

Privacy-aware configuration remains a shared responsibility. Institutions should disable unnecessary fields and modules, separate schools and roles correctly, restrict exports, avoid excessive retention, and test permissions before production use.

13. Personal-data breaches

Maskeen Edutech maintains processes to identify, investigate, contain, document, and remediate suspected security incidents. Where we act as processor and become aware of a personal-data breach affecting Institution Data, we will notify the relevant Institution without undue delay as required by the applicable DPA and provide information reasonably available to support its assessment.

The Institution, as controller, is responsible for determining whether notification to a supervisory authority or affected individuals is required and for meeting applicable deadlines. We will reasonably assist with facts about the affected Services, likely consequences, and measures taken, while recognising that an investigation may develop over time.

Institutions must report suspected incidents promptly, preserve relevant evidence, and avoid sending compromised credentials or unrelated personal data in an incident report.

14. Retention, return, and deletion

The Institution must define lawful retention periods for Institution Data based on educational, child-protection, employment, accounting, limitation, and other requirements. Maskeen Edutech processes active data for the service term and follows documented archive, export, return, or deletion instructions supported by the Services and agreement.

After termination, Institution Data is returned or deleted according to the DPA, order form, selected plan, and applicable law. Deleted data may remain temporarily in protected backups and recovery systems until scheduled overwrite or expiry, with access restricted to continuity, security, and legal purposes.

Maskeen Edutech may retain limited controller records such as contracts, invoices, tax records, security logs, requests, and legal correspondence for its independently determined lawful periods. Properly anonymised information that no longer identifies an individual is outside the scope of personal data.

15. DPIAs, records, audits, and compliance assistance

An Institution should assess whether planned processing is likely to create a high risk to individuals, particularly where it involves children, special-category data, systematic monitoring, biometrics, large-scale datasets, or new technology. Where required, the Institution must complete a Data Protection Impact Assessment and consult its supervisory authority before processing.

Subject to confidentiality, security, reasonable notice, and the applicable DPA, Maskeen Edutech will provide available information needed to demonstrate its processor obligations and support reasonable compliance reviews. Audit methods should first use current documentation, questionnaires, certifications, or independent reports where sufficient and must avoid exposing another Institution's data or compromising service security.

Each party is responsible for the processing records, data-protection officer, EU or UK representative, regulatory registrations, and supervisory-authority cooperation required for its own role and activities.

16. Automated decisions and educational judgment

Maskeen Edutech provides calculations, reports, reminders, filters, dashboards, and configurable workflow tools. The platform is not intended to make final admission, grading, promotion, discipline, employment, safeguarding, or other decisions that produce legal or similarly significant effects without meaningful Institution review.

If an Institution configures a process that involves profiling or solely automated significant decisions, it is responsible for identifying a lawful basis, providing required information, implementing safeguards and human review, and enabling eligible individuals to contest the result. The Institution should contact Maskeen Edutech before deploying a high-risk automated use that may require additional technical or contractual support.

17. Contact, complaints, and changes

For Institution Data, contact the relevant Institution's privacy or school administration team first. It controls the educational record and is normally best placed to verify the student, parent, employee, or other requester. Maskeen Edutech will assist that Institution as required by the applicable DPA and law.

Questions about this GDPR Policy, Maskeen Edutech's controller activities, DPA requests, or the relevant data-protection contact may be sent to support@maskeenedutech.com. Individuals also have the right to complain to the competent supervisory authority, particularly in the country where they live, work, or believe an infringement occurred.

We may update this Policy as our Services, subprocessors, safeguards, or legal requirements change. The current version and date will remain available here, and material changes will receive additional notice where required.

Need GDPR or DPA information?

Contact us from an authorised Institution email with the organisation name, your role, the affected Services, and the type of privacy or contractual assistance required.

support@maskeenedutech.com