Privacy Policy

Last updated: March 2026

Kalanikama ("we", "us", "our") operates a multi-tenant school management platform accessible at kalanikama.com (the "Service"). This Privacy Policy explains how we collect, use, store, and protect personal data when you use our Service.

By using Kalanikama, you acknowledge that you have read and understood this Privacy Policy.


1. Data Controller and Processor Roles

Kalanikama acts as a data processor on behalf of schools and educational institutions ("Schools") that subscribe to our Service. Each School is the data controller for the personal data of its staff, students, and parents. Schools are responsible for ensuring they have a lawful basis (such as legitimate interest or consent) to collect and process personal data through our platform.

For data related to School administrators and account management, Kalanikama acts as the data controller.


2. Data We Collect

2.1 Account and School Information

  • School name, address, phone number, email, and logo
  • Administrator name, email address, and login credentials
  • School subscription and billing information

2.2 User Information

  • First name, last name, and email address
  • Role within the school (administrator, principal, teacher, student, parent)
  • Username and encrypted password
  • Language preference

2.3 Educational Data

  • Student enrollment records and classroom assignments
  • Grade levels and academic progression
  • Lesson plans and subject information
  • Timetable and scheduling data
  • Attendance records (daily status: present, absent, late, excused)
  • Grading systems, grade records, and report cards

2.4 Financial Data

  • Tuition fee structures and payment schedules
  • Invoice records and payment history
  • Payment status and outstanding balances

Note: We do not store credit card numbers or bank account details. All payment processing is handled securely by Stripe (see Section 5).

2.5 Communication Data

  • School announcements and notification records
  • Email notification logs

2.6 Technical Data

  • IP address and browser type (server logs)
  • Session tokens and authentication data
  • Timestamps of account activity

3. How We Use Your Data

We process personal data for the following purposes:

  • Platform Operation: Providing the school management features you subscribed to, including user management, attendance tracking, grading, timetable scheduling, and financial management.
  • Authentication and Security: Verifying user identity, managing sessions, and protecting accounts from unauthorized access.
  • Communication: Sending school announcements, grade notifications, invoice alerts, and system notifications on behalf of Schools.
  • Billing and Subscriptions: Processing subscription payments, generating invoices, and managing School accounts.
  • Analytics and Reporting: Generating school-level reports such as attendance summaries, grade distributions, and financial overviews. These analytics are visible only to authorized users within each School.
  • Service Improvement: Analyzing aggregate, anonymized usage patterns to improve platform features and performance.
  • Legal Compliance: Maintaining audit logs and fulfilling legal obligations.

We do not sell personal data to third parties. We do not use personal data for advertising or marketing profiling.


4. Data Storage and Security

4.1 Infrastructure

Your data is stored in PostgreSQL databases hosted on Railway cloud infrastructure. Data is transmitted over encrypted HTTPS connections. Authentication tokens are signed using industry-standard JWT (JSON Web Tokens).

4.2 Multi-Tenant Isolation

Kalanikama enforces strict multi-tenant data isolation. Each School's data is logically separated at the database level through row-level security. Users from one School cannot access data belonging to another School.

4.3 Security Measures

  • Passwords are hashed using strong one-way algorithms and are never stored in plain text.
  • All API communications use TLS encryption.
  • Session tokens expire automatically and must be refreshed.
  • Audit logs track all significant data access and modifications.
  • Soft-delete architecture ensures data is never permanently lost by accident.

5. Third-Party Services

We use the following third-party services:

ServicePurposeData Shared
StripeSubscription billing and payment processingSchool name, billing email, subscription plan, payment method tokens (we never see or store full card numbers)
Email ProviderTransactional emails (password resets, notifications)Recipient email address, email subject and content
RailwayCloud hosting infrastructureAll platform data (stored in their infrastructure)

Each third-party provider has their own privacy policy and data processing agreements. We select providers that demonstrate adequate data protection standards.


6. Data Retention

  • Active Accounts: We retain all data for as long as a School's subscription is active and the account exists.
  • After Deletion Request: When a School requests account deletion, we retain data for 30 calendar days to allow for recovery in case of accidental deletion. After 30 days, all School data is permanently deleted.
  • Individual User Deletion: When a School administrator removes a user, the user record is soft-deleted (deactivated) and excluded from all queries. Schools may request permanent deletion of individual records.
  • Audit Logs: Audit log entries are retained for the lifetime of the School account for compliance purposes.
  • Backup Data: Database backups follow the retention schedule of our infrastructure provider.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure: Request deletion of your personal data, subject to legal retention requirements.
  • Right to Data Portability: Request an export of your data in a structured, machine-readable format. School administrators can export all school data through the platform.
  • Right to Restriction: Request that we limit processing of your data in certain circumstances.
  • Right to Object: Object to processing of your data for specific purposes.

For students, parents, and teachers: please contact your School administrator to exercise these rights, as your School is the data controller for your information.

For School administrators: contact us directly at privacy@kalanikama.com to exercise these rights regarding your account data.

We will respond to all legitimate requests within 30 days.


8. Children's Data

Kalanikama processes student data, which may include data of minors, solely on behalf of Schools. Schools are the data controllers and are responsible for:

  • Obtaining any required parental consent for processing children's data
  • Ensuring compliance with applicable child data protection laws (including GDPR provisions for minors)
  • Determining what student data is entered into the platform

We do not knowingly collect data directly from children. All student data is entered and managed by authorized School personnel (administrators, principals, and teachers).

Parent accounts in Kalanikama provide read-only access to their own children's data (attendance, timetable, grades, and financial information).


9. Cookies

Kalanikama uses only essential cookies required for the platform to function:

  • Session Cookie: Maintains your authenticated session while using the platform.
  • Language Preference: Stores your selected display language (English or French).

We do not use tracking cookies, advertising cookies, or third-party analytics cookies. No cookie consent is required for essential cookies under most jurisdictions, but we inform you of their use as a matter of transparency.


10. International Data Transfers

Kalanikama is operated by a company based in France. Our cloud infrastructure may process data in regions outside your country of residence. Where data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.


11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will notify School administrators by email and update the "Last updated" date at the top of this page. Continued use of the Service after changes constitutes acceptance of the revised policy.


12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Email: privacy@kalanikama.com

For data protection inquiries specific to your school, please contact your School administrator first, as they are the data controller for your information.