Privacy Policy

Last updated: April 19, 2026

This Privacy Policy explains how Taleemi collects, uses, and protects personal data. Taleemi operates as a Data Processor on behalf of educational institutions ("the School"), who act as the Data Controller. We are committed to processing only the data necessary to deliver our services and to keeping that data safe.

1 Introduction

Taleemi ("the Platform") provides cloud-based school operations software to educational institutions in the United Arab Emirates. This policy applies to all users of the platform, including school administrators, teaching staff, bus monitors, drivers, and parents or guardians.

The School determines what data is collected and for what purpose. Taleemi processes that data strictly to provide the services the School has contracted for. We do not independently decide how personal data is used.

2 Legal Framework

This policy is designed to comply with:

  • UAE Federal Decree-Law No. 45 of 2021 — Personal Data Protection Law.
  • UAE Federal Decree-Law No. 26 of 2025 — Child Digital Safety Law.
  • Regulations issued by regional educational authorities (KHDA, ADEK) as applicable.

3 Data We Process

The platform processes only the data necessary to fulfill its operational functions. Below is a summary of the categories of personal data involved:

Category Data Collected Purpose
Student identity Full name, date of birth, gender, student ID, profile photo Enrollment, classroom assignment, transport roster
Student health Medical conditions (free-text), sick-day reports Safety during transport, daily attendance tracking
Guardian identity Full name, phone number, email, relationship, profile photo Communication, student handoff verification
Staff & teacher Full name, phone number, email, gender, profile photo Platform access, classroom and bus assignment
Driver Full name, phone, license number, license expiry, emergency contact, profile photo Bus assignment, regulatory compliance
Transport logs Pickup/dropoff events with timestamps, caregiver handoff identity Student safety accountability, operational records
Attendance Classroom attendance records, marked-by identity Academic record-keeping
Incident reports Concern descriptions, photos, status, assigned staff Internal school incident management
Device tokens Push notification tokens, device identifiers Delivering operational notifications to mobile apps
Authentication Login credentials (hashed), session tokens Secure platform access

We do not collect browsing history, location data from personal devices, biometric data, or any data unrelated to school operations.

4 How Data Is Used

Data is processed exclusively for the following purposes:

  • Managing student enrollment, classroom assignments, and academic calendars.
  • Logging bus pickup and dropoff events in real time, including which caregiver handed off or received the student.
  • Recording classroom attendance and synchronizing it with bus transport status.
  • Sending push notifications to parents and staff about transport events, schedule changes, and operational updates.
  • Recording and tracking internal school concerns and incidents as directed by staff.
  • Generating timetables and managing subject-teacher-classroom assignments.

We do not use personal data for advertising, profiling, automated decision-making, or any purpose beyond delivering the contracted school operations services.

5 Data Residency

All personal data processed by the platform — including database records, uploaded photos, and incident attachments — is hosted on secure, encrypted infrastructure located physically within the United Arab Emirates. No personal data is transferred to or stored in jurisdictions outside of the UAE.

6 Security Measures

Taleemi employs the following measures to protect data integrity and confidentiality:

Encryption

All data is encrypted in transit using TLS. Passwords are stored using industry-standard one-way hashing and are never stored in plain text.

Authentication

API access is secured with short-lived JSON Web Tokens (1-hour expiry) with automatic rotation of refresh tokens. Expired tokens are blacklisted and cannot be reused.

Tenant Isolation

Each school's data is logically isolated. All queries are scoped to the authenticated user's school, preventing cross-institution data access.

Image Processing

Profile photos and uploaded images are processed entirely on our own servers using open-source software. No images are sent to third-party services for processing or storage.

7 Third-Party Services

The platform does not sell, trade, or monetize user data. We share data with the following third-party service solely as required to deliver platform functionality:

  • Expo Push Notification Service — We transmit device push tokens and notification content (title, message body) to Expo's servers to deliver real-time notifications to mobile apps. Expo does not receive student names, personal data, or school records — only the technical payload needed to deliver the notification.

No other third-party services receive personal data. The platform does not use SMS gateways, third-party analytics, advertising networks, or external email services.

8 Data Retention and Deletion

Retention

Data is retained for the duration of the contract between the School and Taleemi. Transport logs and attendance records are retained as part of the school's operational archive for the contracted period.

Deletion

Upon contract termination, all school data — including student records, photos, transport logs, and incident reports — is either returned to the School in a standard format or permanently deleted, in accordance with an agreed-upon transition period.

Individual Rights

As the Data Processor, Taleemi will assist the School in fulfilling requests from individuals (parents, guardians, or staff) regarding their rights to access, rectify, or delete their personal data, as provided under UAE law.

9 Children's Data

Taleemi processes data about minors exclusively on behalf of educational institutions and under the direction of the School as Data Controller. The platform maintains a strictly ad-free environment and does not engage in any form of profiling, behavioral tracking, or targeted content delivery involving children's data, in compliance with Federal Decree-Law No. 26 of 2025 on Child Digital Safety.

10 Governing Law

This policy is governed by the federal laws of the United Arab Emirates. Any disputes arising from the processing of personal data shall be subject to the exclusive jurisdiction of the competent courts in the UAE.