PRIVACY POLICY
Mahhfaz School Management Platform
Operated by Mahhfaz Group
Effective date: 1 July 2026
Last updated: 22 July 2026
1. Introduction and Scope
1.1. This Privacy Policy explains how personal data is collected, used, disclosed, retained, and protected in connection with the Mahhfaz School Management Platform ("the Platform"), operated by Mahhfaz Group ("Mahhfaz", "we", "us", "our"), a company incorporated in the Federal Republic of Nigeria with registration number 9612441 and registered office at No. 17, Kasuwan Yelwa Street, Palace Way, Jalingo, Taraba State, Nigeria.
1.2. This Policy applies to personal data of students and applicants (many of whom are minors), parents and guardians, and school staff, as well as to the account holders and billing contacts of subscribing schools.
1.3. This Policy is issued in compliance with the Nigeria Data Protection Act 2023 ("NDPA") and the General Application and Implementation Directive 2025 ("GAID") issued by the Nigeria Data Protection Commission ("NDPC"). Since the GAID took effect on 19 September 2025, the NDPA and GAID together form the governing data-protection framework in Nigeria, and the former Nigeria Data Protection Regulation 2019 no longer applies. Where a data subject is protected by the EU or UK General Data Protection Regulation ("GDPR"), the additional rights in Clause 12 also apply.
1.4. This Policy is incorporated into, and should be read with, the Mahhfaz Terms of Service and the Data Processing Agreement between Mahhfaz and a school.
2. Definitions
2.1. "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject").
2.2. "Sensitive Personal Data" means Personal Data revealing categories treated as sensitive under the NDPA, including health information. In this Platform it includes a student's blood group and health/clinic records, and staff next-of-kin details.
2.3. "Data Controller" means the party that determines the purposes and means of processing Personal Data.
2.4. "Data Processor" means the party that processes Personal Data on behalf of, and on the instructions of, a Data Controller.
2.5. "School" means an educational institution that subscribes to the Platform.
2.6. "Sub-processor" means a third party engaged to process Personal Data in connection with the Service.
2.7. "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, transfer, and deletion.
3. Our Roles — Controller and Processor
3.1. School Data (students, applicants, parents/guardians, staff). For Personal Data that a School submits to or generates within the Platform about its students, applicants, parents/guardians, and staff:
(a) the School is the Data Controller, determining why and how the data is processed; and
(b) Mahhfaz is the Data Processor, processing that data only on the School's documented instructions and as described in this Policy and the Data Processing Agreement.
3.2. Mahhfaz's own data. For Personal Data that Mahhfaz processes for its own purposes — including a School's account and billing contacts, settlement records, marketing-website visitors, and security/audit logs maintained for Mahhfaz's own compliance and protection — Mahhfaz is the Data Controller.
3.3. Major-importance status. Mahhfaz is a data controller/processor of major importance under the NDPA and GAID (processing the personal data of more than 200 data subjects within a six-month period). Accordingly, Mahhfaz is registered with the NDPC, has appointed a Data Protection Officer, and files the compliance audit returns required of such an entity.
3.4. Where Mahhfaz is a Processor, the School (as Controller) is responsible for establishing a lawful basis and for responding to Data Subjects; Mahhfaz assists as described in this Policy and in the Data Processing Agreement.
4. Personal Data We Collect
4.1. Student and applicant data: full name; date of birth; blood group; passport photograph; admission/registration number; class; uploaded documents (for example birth certificate); attendance records; examination scores and results; health/clinic records; hostel allocation.
4.2. Parent/guardian data: names; phone numbers; email addresses.
4.3. Staff data: names; email addresses; phone numbers; staff ID; department; next-of-kin details; passport photograph; bank account number (for payroll); payslips; leave and attendance records.
4.4. Technical and log data: activity and audit logs, including IP addresses; message-delivery logs (for example SMS and email delivery status).
4.5. Account and billing data (Mahhfaz as Controller): School account details, authorised administrator identities, settlement subaccount details, and transaction/Commission records.
4.6. Payment data: Mahhfaz does not collect or store full card numbers, card verification values (CVV), or card PINs. All card data is collected and processed by Paystack. Mahhfaz receives only transaction references and settlement information. See Clause 8.
5. Sensitive Personal Data
5.1. The Platform processes Sensitive Personal Data, in particular the blood group and health/clinic records of students, and next-of-kin details of staff.
5.2. Sensitive Personal Data is processed only where a valid lawful basis and any additional condition required by the NDPA are satisfied — for example, explicit consent (including parental/guardian consent for a minor), the protection of the vital interests of the Data Subject (such as the use of a student's blood group in a medical emergency), or the provision of medical care. Access is restricted to authorised roles (for example, clinic/health staff).
5.3. Passport photographs. Passport photographs are collected and used for identification within the Platform (for example on student and staff profiles). They are not used to uniquely identify a person by automated biometric means and are therefore not processed as biometric data; they are nonetheless protected as Personal Data.
6. Children's Data and Parental Consent
6.1. Under the NDPA, a child is any person below the age of 18. The Platform processes the Personal Data of children, and Mahhfaz recognises the heightened protection this requires.
6.2. Where the NDPA requires consent as the lawful basis for processing a child's Personal Data, the School (as Controller) is responsible for obtaining and recording the consent of the child's parent or legal guardian holding parental responsibility, and for verifying that consent. Verification may be achieved by presentation of a government-approved identification document or another appropriate method, taking available technology into account.
6.3. Mahhfaz provides functionality to help Schools capture and record such consent but does not itself determine when consent is required or verify parental responsibility on the School's behalf.
7. Purposes and Lawful Bases
7.1. Personal Data is processed for the following purposes:
(a) providing school-management functionality (admissions/applicants, student records, academics, attendance, examinations and results, health records, hostel, library, transport, staff administration, and payroll);
(b) processing school-fee and application-fee payments and effecting split settlement;
(c) sending administrative and transactional communications by SMS and email;
(d) securing the Platform, maintaining audit logs, and preventing fraud and abuse;
(e) providing support and improving the Service; and
(f) complying with legal and regulatory obligations.
7.2. Lawful bases (NDPA section 25 and related provisions). Depending on the processing, the lawful basis may be: performance of a contract; consent (including parental/guardian consent for minors); compliance with a legal obligation; protection of vital interests (for example, use of a student's blood group in a medical emergency); or legitimate interests, where not overridden by the Data Subject's rights.
7.3. Where Mahhfaz is a Processor, the School determines and documents the lawful basis for School Data. Where Mahhfaz is a Controller (Clause 3.2), Mahhfaz relies on performance of its contract with the School, its legitimate interests in securing and administering the Platform, and, for direct marketing, consent where required by the GAID.
8. Payment Data and Paystack
8.1. Online payments are processed by Paystack Payments Limited. When a payer makes a payment, card and payment-instrument data is collected and processed directly by Paystack under Paystack's own privacy policy and its PCI-DSS-compliant environment.
8.2. Mahhfaz does not receive or store full card numbers, CVV, or PINs. Mahhfaz receives transaction references, amounts, status, and settlement details necessary to reconcile payments and effect split settlement to the School's subaccount and Mahhfaz's Commission.
8.3. Payers should review Paystack's privacy policy for information on how Paystack processes their payment data.
9. Sub-processors and Third-Party Recipients
9.1. Mahhfaz engages the following Sub-processors to provide the Service. Each is engaged under a data-processing agreement requiring appropriate security and data-protection safeguards:
Sub-processor
Function
Data involved
Hosting region
Paystack (Paystack Payments Limited)
Payment processing and split settlement
Transaction/settlement data (card data handled by Paystack only)
Nigeria
Termii
SMS delivery
Recipient phone numbers, message content, delivery logs
Nigeria
Resend
Email delivery
Recipient email addresses, message content, delivery logs
United States
Laravel Cloud
Application hosting and PostgreSQL database
All School Data
European Union (eu-west-1, Ireland)
Amazon Web Services (AWS S3)
File and media storage
Uploaded documents, passport photographs, files
European Union (eu-west-1, Ireland)
Cloudflare, Inc.
Marketing website and content delivery
Website visitor technical data
Global edge network
9.2. Mahhfaz will give Schools reasonable prior notice of the addition or replacement of a Sub-processor.
9.3. Mahhfaz may also disclose Personal Data where required by law, regulation, court order, or a competent authority, or to establish, exercise, or defend legal claims.
9.4. Mahhfaz does not sell Personal Data.
10. Cross-Border Transfers
10.1. Some Sub-processors process data on infrastructure outside Nigeria: hosting and file storage (Laravel Cloud and AWS S3) in the European Union (Ireland); email delivery (Resend) in the United States; and content delivery (Cloudflare) via a global edge network. Payment and SMS processing (Paystack and Termii) occur in Nigeria.
10.2. Where Personal Data is transferred outside Nigeria, Mahhfaz relies on a transfer mechanism permitted by the NDPA (sections 41–43) and GAID Schedule 5 — namely transfer to a jurisdiction subject to an NDPC adequacy determination, or, where none applies, appropriate contractual safeguards (including a data-processing agreement with the recipient), or another permitted basis such as the necessity of the transfer for performance of the contract.
11. Data Retention and Deletion
11.1. Personal Data is retained only for as long as necessary for the purposes described in this Policy, to satisfy the School's instructions (where Mahhfaz is Processor), and to comply with legal, accounting, and statutory retention obligations.
11.2. Retention schedule:
Data category
Retention
Basis
Active student/academic records
Duration of enrolment plus 5 years after the student leaves
School instruction; academic record-keeping
Examination results and transcripts
Retained for the life of the School's account; made available for download during offboarding, then deleted on termination
Academic record-keeping; controlled offboarding
Health/clinic records (Sensitive)
Duration of enrolment plus 5 years after the student leaves
School instruction; care records
Applicant data (unsuccessful applicants)
90 days after the admission cycle
Data minimisation
Parent/guardian contact data
5 years after the related student leaves
Contract; communication
Staff HR records
5 years after employment ends
Employment record-keeping
Payroll and financial records (bank details, payslips, transactions)
6 years
Statutory (CAMA 2020; CITA section 63; FIRS)
Activity/audit logs and IP addresses
Retained on a permanent basis
Security and accountability
Message-delivery logs (SMS/email)
Retained on a permanent basis
Operational and audit
Mahhfaz account/billing data
Duration of the relationship plus 6 years
Contract; tax/accounting
11.3. Deletion process. On expiry of the applicable retention period, or on a valid deletion instruction from the School (as Controller), or on termination in accordance with the Terms of Service, Mahhfaz will delete or irreversibly anonymise the relevant Personal Data, including from primary storage and, within 90 days, from backups, save where longer retention is required by law or is necessary to establish, exercise, or defend legal claims. Deletion is logged for accountability.
12. Data Subject Rights
12.1. Subject to applicable law and to any conditions and exemptions in the NDPA (and the GDPR where it applies), Data Subjects have the right to:
(a) be informed about how their data is processed;
(b) access their Personal Data;
(c) rectification of inaccurate or incomplete data;
(d) erasure / the "right to be forgotten", where a legal basis to retain the data no longer exists;
(e) restriction of processing in certain circumstances;
(f) object to processing, including to direct marketing;
(g) data portability — to receive their data in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller; and
(h) not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and to withdraw consent at any time where processing is based on consent.
12.2. How to exercise rights. Because a School is usually the Controller of student, parent, and staff data, Data Subjects should generally direct requests to their School. Where Mahhfaz receives a request relating to School Data, Mahhfaz will refer it to the School and assist the School in responding. For data where Mahhfaz is the Controller, requests may be made to Mahhfaz using the contact details in Clause 16.
12.3. Mahhfaz (or the School, as applicable) will respond without undue delay and, in any event, within one month of receipt, extendable where permitted by law for complex or numerous requests.
12.4. There is normally no fee for exercising these rights, though a reasonable fee or refusal may apply to manifestly unfounded or excessive requests, to the extent permitted by law.
13. Data Security
13.1. Mahhfaz implements appropriate technical and organisational measures to protect Personal Data, including: logical tenant separation; role-based access control aligned to the roles described in the Terms of Service, on a need-to-know basis; encryption of Personal Data in transit and at rest using industry-standard encryption; optional two-factor sign-in (a one-time code sent by email) available to all user accounts; audit logging; regular automated backups with periodic restoration testing; patch management and vulnerability monitoring; and periodic staff data-protection training.
13.2. Access to Sensitive Personal Data (for example health records) and to payroll data (for example bank account numbers) is restricted to roles with a legitimate need.
13.3. No system is completely secure. Mahhfaz cannot guarantee absolute security but maintains measures proportionate to the risk, including for the processing of minors' data.
13.4. Schools are responsible for managing their own Users' access, keeping credentials secure, and assigning roles appropriately.
14. Personal-Data Breach Notification
14.1. Mahhfaz maintains procedures to detect, investigate, and respond to personal-data breaches.
14.2. Where Mahhfaz is a Processor: on becoming aware of a personal-data breach affecting School Data, Mahhfaz will notify the affected School (as Controller) without undue delay, providing the information the School reasonably needs to meet its own obligations.
14.3. Where Mahhfaz is a Controller: Mahhfaz will notify the NDPC of a breach that is likely to result in a risk to the rights and freedoms of individuals within 72 hours of becoming aware of it (with information provided in phases where necessary), and will communicate the breach to affected Data Subjects without undue delay where it is likely to result in a high risk to their rights and freedoms.
14.4. Breaches and the response taken are documented for accountability.
15. Cookies and Marketing Sites
15.1. Mahhfaz's marketing websites (delivered via Cloudflare) may use cookies or similar technologies for functionality and analytics, and will present a cookie notice and obtain consent for non-essential cookies in accordance with GAID requirements.
15.2. The Platform application itself uses cookies or tokens necessary for authentication and security.
16. Contact and Complaints
16.1. Data Protection Officer.
Name: Anas Muhammad Yahaya
Email: dpo@mahhfaz.com.ng
Address: No. 17, Kasuwan Yelwa Street, Palace Way, Jalingo, Taraba State, Nigeria
16.2. Controller identity. Mahhfaz Group, RC 9612441, No. 17, Kasuwan Yelwa Street, Palace Way, Jalingo, Taraba State, Nigeria. General enquiries: info@mahhfaz.com.ng.
16.3. Right to complain. A Data Subject who believes their data has been mishandled may complain to Mahhfaz and has the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at https://ndpc.gov.ng.
17. Changes to This Policy
17.1. Mahhfaz may update this Policy from time to time. Material changes will be notified by email or in-Platform notice. The "Last updated" date at the top reflects the latest version.