Data Retention Policy

Effective Date: 21 May 2026

This Data Retention Policy sets out how long School Konnect retains different categories of personal data, and how data is securely deleted when the retention period ends. This policy supports our obligations under the Ghana Data Protection Act 2012 (Act 843) and our Privacy Policy.

1. Principles

  • We collect only the data necessary to provide the school management service.
  • We retain data only for as long as it is needed for the purpose it was collected.
  • When a retention period ends, data is permanently and securely deleted.
  • Schools may request early deletion of their data at any time (see Section 5).

2. Retention Periods by Data Category

Data categoryRetention periodReason
Student academic records (scores, grades, report cards)Duration of school subscription + 90 days after terminationCore service data; needed for report generation
Attendance recordsDuration of school subscription + 90 days after terminationCore service data; needed for reports and compliance
Student health data (allergies, medical conditions)Duration of student enrolment + 90 days after terminationStudent safety; deleted when no longer enrolled
User account data (name, email, phone)Duration of school subscription + 90 days after terminationRequired to operate the service
Messages (teacher-parent)Duration of school subscription + 90 days after terminationPart of the school's communication record
Security logs (login attempts, IP addresses)90 days from the date of the eventSecurity monitoring; not needed beyond 90 days
Uploaded files (profile photos, attachments)Duration of school subscription + 90 days after terminationStored on Cloudinary; deleted on account closure
Payment recordsDuration required by Paystack and applicable financial regulationsTransaction history, receipts, and dispute resolution
Backup data30 days rolling backup retentionDisaster recovery; older backups are overwritten
Anonymised analyticsIndefinitelyNo personal data — used only for product improvement

3. What Happens When a School Closes Its Account

  1. The school administrator requests account termination by contacting hello@dedee.digital.
  2. A 90-day data export window begins. During this period the school can download all student records, attendance logs, report cards, and messages as CSV or PDF.
  3. After 90 days, all personal data associated with the school is permanently deleted from our production database.
  4. Cloudinary files (photos, attachments) are deleted via the Cloudinary API.
  5. Backup snapshots containing the school's data are purged within 30 days of the last backup rotation.
  6. We send a written confirmation of deletion to the school administrator.

4. Individual Data Deletion Requests

Any user — Admin, Teacher, Parent, or Student — can deactivate their own account directly in the app at any time, with no need to go through their school administrator: open the app, go to Settings, scroll to the Danger Zone section, and tap Delete Account. This immediately disables the account (the user is signed out and can no longer log in); a school administrator can reinstate it if this was done in error. See our Account Deletion instructions for full details and what happens to the underlying data afterwards.

If a parent, student, or staff member instead wants their personal data permanently deleted sooner than the standard retention period above (the "right to erasure" under Act 843), they — or their school administrator, on their behalf — should submit the request to hello@dedee.digital. We will process the request within 30 days. Note that some data may be retained where we have a legal obligation to do so, or where it is necessary to maintain the integrity of academic records.

5. Data Export

Schools can export their data at any time from within the platform:

  • Attendance records: Attendance screen > Download CSV icon.
  • Student and user lists: Users screen > Download CSV icon.
  • Report cards: Reports screen > PDF export per student.
  • For a full data export, contact hello@dedee.digital.

6. Security of Deleted Data

When data is deleted, it is removed from the active database and from Cloudinary. It will remain in database backups for up to 30 days (the backup rotation window) before being permanently overwritten. We do not use special data wiping tools beyond standard database deletion and Cloudinary API deletion, which is sufficient for the cloud-hosted infrastructure we use.

7. Review of This Policy

This policy is reviewed annually or whenever there is a material change to how we store or process data. Schools will be notified of any changes.

8. Contact

For data retention queries, contact:

Email: hello@dedee.digital

Website: schoolkonnectinfo.dedee.digital

This policy should be read alongside the School Konnect Privacy Policy and Terms of Service.