Privacy Policy
Last updated: August 2026
1. Who this policy covers
Taleem365 ("the Platform", "we") provides school management software to schools ("Schools", "Customers") on a multi-tenant basis. Each School controls its own data, including students, guardians, staff, attendance, results, and fee records, and acts as the data controller for that information. We act as the data processor that stores and processes it on the School's behalf and instructions.
If you are a parent, student, or staff member of a School using the Platform, your School is responsible for your personal data and how it is used. For a question about your own records, contact your School directly before contacting us.
2. Information we process
On behalf of a School, the Platform stores:
- Student records: name, date of birth, gender, B-Form/CNIC, address, admission and academic history.
- Guardian records: name, phone number, email, CNIC, and relationship to a student.
- Staff records: name, contact details, CNIC, employment details, and role.
- Attendance, exam results, homework, and fee/payment records.
- Account information: email address and hashed password for anyone with a login.
- Basic technical data such as IP address and browser type, used for security and to keep the service running.
3. How this information is used
- To provide the core service: attendance, admissions, fees, exams, and reporting a School configures.
- To send notifications a School triggers, such as a WhatsApp absence alert or fee reminder, through our messaging provider.
- To maintain the security, integrity, and availability of the Platform.
- To improve the Platform based on aggregated, de-identified usage patterns. We never read individual student or family records for this purpose.
We do not sell personal data, and we do not use a School's data to serve advertising.
4. Data isolation and security
Each School's data is logically isolated from every other School on the Platform; no record is ever visible across tenants. Access is scoped by role: a teacher, for example, only sees data for the sections assigned to them. Data in transit is encrypted, and access to production systems is restricted to authorized personnel for legitimate support and maintenance purposes.
5. Third parties
We rely on a small number of service providers to run the Platform, for example a hosting provider and a WhatsApp messaging provider. These providers only receive the minimum data needed to perform their function (such as a phone number and message text for a WhatsApp message) and are contractually restricted from using it for any other purpose.
6. Data retention
Data is retained for as long as a School maintains an active account, and for a reasonable period after account closure to allow for export or reactivation, after which it is deleted or anonymized, except where retention is required by law.
7. Children's data
Much of the data on the Platform relates to minors, entered and managed by the School on behalf of parents/guardians as part of the school's administrative records. Schools are responsible for ensuring they have the appropriate basis (such as parental consent under their own enrollment process) to provide this information to the Platform.
8. Your rights
Parents, guardians, staff, and students may request access to, or correction of, their personal data by contacting their School, which can action most changes directly, or submit a request to us on the School's behalf.
9. Changes to this policy
We may update this policy as the Platform evolves. Material changes will be reflected in the "Last updated" date above.
10. Contact
For a question about this policy directed at the Platform itself (rather than a specific School's use of it), your School's administrator is the first point of contact, as they hold the account relationship with us.