Legal

Privacy Policy

Effective: 21 July 2026 · Version 2026-07-21

This policy must receive qualified Kenyan privacy/legal review before broad commercial launch. It does not claim ODPC registration or a designated DPO without external evidence.

1. Scope

This policy explains how NEYO handles personal data through its websites, demo requests, pilot environments and School OS services. Actual processing depends on the modules and integrations a customer enables.

2. Roles and responsibility

A school or organisation generally determines why and how its learner, guardian and staff records are used and is responsible for its notices, permissions, accuracy, releases and user access. NEYO processes customer data to provide and secure the service. NEYO may separately control limited account, website, commercial, security and support data for its own legitimate operations. Exact legal roles depend on the context and applicable agreement.

3. Data handled

  • Account and identity details such as name, role, phone, email and login identifiers.
  • School records such as admissions, classes, attendance, fees, payments, assessments, competencies, timetables, communications and documents.
  • Sensitive records a school chooses to use, such as health, discipline, safeguarding or biometric/passkey references.
  • Technical, security and audit information such as device/session details, IP address, sign-in and action logs.
  • Demo, quote, support, interview and school-contact information.

4. Purposes

  • Provide, authenticate, secure and support NEYO.
  • Process school workflows and produce requested documents, messages and reports.
  • Prevent fraud, misuse and cross-school access.
  • Maintain audit, backup, recovery, billing and service-health records.
  • Improve product reliability using appropriately limited operational information.
  • Meet legal obligations and respond to valid requests.

5. Sharing and providers

NEYO may use contracted infrastructure, payment, messaging, email, storage, authentication, support and monitoring providers when configured. Data is shared only as needed for the relevant service and subject to applicable safeguards. NEYO does not claim a government integration unless it is expressly shown as connected and verified.

6. Security

NEYO uses controls including role permissions, tenant isolation, password hashing, encrypted credential/file paths, HTTPS, rate limiting, audit logs and security challenges where configured. No system is absolutely secure. Customers must manage users, devices and exports responsibly and report suspected incidents promptly.

7. Retention

Retention depends on school policy, contract, record type, backups and legal, financial, safeguarding and audit requirements. Temporary files may follow lifecycle deletion rules. A deletion request may not remove information that must lawfully or securely be retained.

8. Individual rights

Depending on Kenyan law and the context, individuals may have rights to information, access, correction, objection, restriction, portability or erasure. For school-controlled records, contact the school first. NEYO will assist customers and respond to requests for data NEYO controls, subject to identity verification and lawful exceptions.

9. Children

Schools must provide appropriate notices and authority for processing children’s data and must configure parent/learner access carefully. NEYO does not permit public exposure of private learner records through ordinary School OS pages.

10. International processing and changes

Some approved service providers may process data outside Kenya. Appropriate contractual and legal safeguards should be assessed before production activation. This policy may be updated with a new effective date and reasonable notice for material changes.

11. Contact

Privacy questions or requests may be sent to hello@neyo.co.ke. NEYO will publish a dedicated privacy or Data Protection Officer contact only after the relevant appointment and operational process are formally established.