Privacy & Data Protection Policy
How PakEducate collects, stores, protects, and handles your school's data.
1. Who We Are
PakEducate is a school management platform operated by Wang Lab of Innovation (WALI) PVT Limited. We provide digital tools for Pakistani primary and secondary schools to manage students, teachers, attendance, results, fees, and school operations.
Contact: info@pakeducate.com
2. What Data We Collect
Student Data
- Full name (English and Urdu)
- Father's name and phone number
- Date of birth, gender
- Admission number
- Student photograph
- Attendance records
- Exam results and grades
- Fee payment history
Teacher/Staff Data
- Full name, email, phone number
- CNIC (National Identity Card) number
- Qualification, date of joining, address
- Emergency contact information
- Salary and payroll records
- Leave requests and balances
- Photograph
School Data
- School name, address, registration number
- School logo
- Class structures and timetables
- Financial records (fees, expenses, payroll)
Technical Data
- IP address (for security and rate limiting)
- Login timestamps and attempts
- Browser type (user-agent)
3. How We Store Your Data
| Data Type | Storage | Protection |
|---|---|---|
| Student & school records | Secure cloud database | Encrypted in transit (TLS), access-controlled |
| Photos & logos | Secure cloud storage | Authentication required, school-scoped access |
| Passwords | Secure cloud database | Industry-standard hashing — never stored in plain text |
| Auth tokens | HttpOnly secure cookies | Cannot be accessed by JavaScript, HTTPS only |
| Financial records | Secure cloud database | Role-based access (admin/owner only) |
All data is transmitted over HTTPS (TLS 1.3). Our infrastructure runs on a globally distributed cloud network with built-in DDoS protection, SSL encryption, and edge security.
4. Data Isolation (Multi-Tenancy)
Each school's data is completely isolated. Every database query is filtered by school ID, ensuring:
- School A cannot see School B's students, teachers, or financial data
- Teachers can only see data for their assigned classes
- Financial data (fees, salaries, expenses) is restricted to admin, head teacher, and owner roles
- Super administrators can access school data only for platform management purposes
5. Who Can Access Your Data
| Role | Can Access |
|---|---|
| Teacher | Attendance and results for assigned classes, own leave requests |
| Admin | All school data except system settings |
| Head Teacher | Full school management including staff management |
| Owner | Dashboard, fees, payroll, expenses across owned schools |
| PakEducate Team | Platform administration, technical support (never shared externally) |
6. Third-Party Services
We use the following external services. We do not sell your data to any third party.
| Service | Purpose | Data Shared |
|---|---|---|
| Google Firebase | Google Sign-In authentication | Email address only |
| Google Gemini AI | AI chat assistant (optional) | School name, class stats, user's question — no student names or financial details |
| Cloudflare | Hosting, database, file storage | All data (as infrastructure provider) |
The AI assistant feature is optional. Schools that do not use it send no data to AI providers. When used, we send only anonymized school context — never individual student names, CNIC numbers, or salary information.
7. Data Security Measures
- Encryption in transit: All data encrypted via HTTPS
- Password security: Industry-standard hashing with unique salt per password — never stored in plain text
- Secure authentication: Tokens stored in secure, HttpOnly cookies inaccessible to browser scripts
- Brute force protection: Accounts are automatically locked after repeated failed login attempts
- Rate limiting: API requests are limited to prevent abuse
- File security: All uploaded files require authentication and are scoped to the uploading school
- Input validation: All inputs are validated server-side to prevent malicious data
- Automated backups: Daily database backups with 30-day retention
- Emergency controls: System-wide shutdown capability for critical security incidents
8. Children's Data
PakEducate processes data about children (students) on behalf of schools. We take this responsibility seriously:
- Student data is entered and managed by authorized school staff only
- Student photographs are stored securely and accessible only to authenticated school staff
- We do not use children's data for advertising, marketing, or profiling
- We do not share children's data with any third party for commercial purposes
- Schools are responsible for obtaining any required consent from parents/guardians for data collection
- Student data can be permanently deleted upon request (see Section 10)
9. Data Retention
- Active accounts: Data is retained as long as the school's subscription is active
- Deactivated students/staff: Soft-deleted records are retained for the academic year and can be permanently deleted on request
- Login attempts: Stored for security monitoring purposes
- Backups: Retained for 30 days, then automatically deleted
- Cancelled accounts: School data will be permanently deleted within 90 days of account cancellation, unless the school requests immediate deletion
10. Your Rights
Schools and individuals have the following rights regarding their data:
- Right to Access: Export all your school's data in JSON format via the Data Protection settings
- Right to Deletion: Request permanent deletion of individual student/teacher records or your entire school's data
- Right to Correction: Update or correct any data through the platform's edit features
- Right to Portability: Export your data in standard formats (JSON, CSV, Excel)
To exercise any of these rights, contact us at info@pakeducate.com or use the Data Protection features in your school dashboard.
11. Data Breach Notification
In the event of a data breach that affects your school's data:
- We will notify affected schools within 72 hours of becoming aware of the breach
- Notification will be sent via email to the school's registered head teacher and owner accounts
- We will provide details of what data was affected and what steps we are taking
- We maintain automated security monitoring and alerting systems
12. Applicable Law
PakEducate operates under:
- Pakistan: Prevention of Electronic Crimes Act (PECA) 2016 and applicable data protection regulations
- Pakistan: As Wang Lab of Innovation (WALI) PVT Limited is incorporated in Pakistan
13. Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify registered schools via email.
14. Contact Us
For any questions about this policy or your data:
- Email: info@pakeducate.com
- Website: pakeducate.com