Hanoled
Legal

Data Protection Policy

Last updated: August 2026

1. Introduction

At Hanoled, data protection is fundamentally important to our service. This Data Protection Policy outlines our commitment to protecting the personal data of students, parents, and staff managed within our platform, ensuring compliance with relevant data protection laws including the Nigeria Data Protection Regulation (NDPR) and other global standards.

2. Scope

This policy applies to all data processed by Hanoled acting as a Data Processor on behalf of educational institutions (the Data Controllers).

3. Data Processing Principles

We adhere to the core principles of data protection:

  • Lawfulness, Fairness, and Transparency: Data is processed legally and transparently.
  • Purpose Limitation: Data is collected for specific, explicit, and legitimate purposes (providing the school management service).
  • Data Minimization: We only collect data that is adequate, relevant, and necessary for the service.
  • Accuracy: We provide tools for schools to keep their data accurate and up to date.
  • Storage Limitation: Data is kept in a form which permits identification of data subjects for no longer than is necessary.
  • Integrity and Confidentiality: Data is processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

4. Role of Hanoled (Data Processor)

When processing student and staff data, Hanoled acts as a Data Processor. The school determines the purpose and means of processing (acting as the Data Controller). We process data solely on the documented instructions of the school.

5. Technical and Organizational Measures

We implement stringent technical and organizational measures to ensure a level of security appropriate to the risk. This includes data encryption at rest and in transit, strict access control, regular security audits, and automated backups.

6. Data Breach Notification

In the event of a personal data breach, Hanoled will notify the affected educational institution (the Data Controller) without undue delay after becoming aware of it, assisting them in meeting their own notification obligations to authorities and data subjects.

7. Contact

For any data protection inquiries or to reach our Data Protection Officer, please contact data-protection@hanoled.com.