Last updated: 23 September 2026. This policy explains what data MtandaoLabsEdu processes when a school uses the platform, and the choices available to schools, parents, and staff.
MtandaoLabsEdu is a multi-tenant school management platform operated by MtandaoLabs, Nairobi, Kenya — contact mtandaolabs@gmail.com, +254 728 249135. Each school is the controller of its own data; MtandaoLabsEdu processes that data on the school's instructions, in line with the Kenya Data Protection Act.
We collect only what is needed to run a school — if a field is optional it is labelled “optional”. We do not collect device advertising IDs, precise geolocation, or biometric data, and we do not buy data from brokers.
Data is used to operate the platform for the school: managing students and academics, issuing and reconciling fee invoices, sending communications the school initiates, and producing reports. We do not sell personal data or use it for advertising.
Data is shared only with processors needed to run the service on the school's behalf — for example hosting and database providers, email delivery, WhatsApp messaging, and mobile money payment providers. Each school configures its own payment, email, and messaging integrations.
The application uses a deliberately small dependency footprint — no advertising, analytics, or cross-site tracking SDKs. Current processors, active only when a school enables them:
Data is retained for as long as the school's account is active. Sensitive integration credentials are encrypted at rest. Access within the platform is role-based, and administrative actions are recorded in audit logs.
Where a school connects its own Google account (Settings → Integrations → Google), we access only what the school authorizes through Google OAuth:
Google OAuth tokens are encrypted at rest, never shown to users, and revocable at any time by disconnecting in Settings or from the school's Google account security page. Disconnecting stops all synchronization; files already created remain owned by the school in its own Drive. PostgreSQL remains the authoritative record — Drive and Sheets are a synchronization layer only.
Requests to access, correct, or delete personal data should be made to the relevant school, which controls that data. We support schools in fulfilling those requests. Where applicable, this processing is carried out in line with the Kenya Data Protection Act.
Student records (including dates of birth) are provided by the school or by a parent/guardian — children do not register themselves. Admissions and enrollment require a named parent/guardian and their explicit data-processing consent. Parents can review or revoke consent at any time via the school, and request deletion as described below.
We use strictly necessary session cookies plus local preference storage (theme and cookie choice) — no advertising or tracking cookies. See our Cookie Policy. You can accept or reject optional storage in the cookie banner at any time.
Transactional emails (verification codes, receipts, invoices) are necessary to operate your account and cannot be unsubscribed while the account is active. Any non-essential announcements include an unsubscribe link, and you can also opt out any time by emailing mtandaolabs@gmail.com.
Ask your school administrator (Settings → Privacy & consent) or use our deletion request page to ask us directly. We verify ownership, forward the request to the controlling school, and confirm within 30 days.
Questions about this policy: mtandaolabs@gmail.com, +254 728 249135, Nairobi, Kenya. See also our Terms, Refund Policy, and Cookie Policy.
This summary describes current practice and is not legal advice.