Records, roles, workflows and communications stay in one accountable workspace.
Trust centre · privacy
Privacy Notice
This notice explains how SchoolSuite365 handles information across the web portal, mobile application, offline synchronisation, communications and support workflows.
Schools govern their data and permissions; the platform provides the controls and evidence.
Automation can assist operations, but authorised people remain responsible for outcomes.
Scope and responsibility
SchoolSuite365 is a school operations platform from MBTS NIG. LTD. Each subscribing school decides what information it enters, why it uses it, who may access it, and how long it keeps it. In that relationship, the school will generally be the data controller or equivalent responsible organisation, while MBTS NIG. LTD. provides the hosted software and acts on the school’s documented instructions.
Information we process
- Account and identity information such as name, email, phone number, role, school affiliation, sign-in history and audit events.
- Education and safeguarding records entered by authorised school users, including learner profiles, family links, attendance, results, behaviour, welfare, communications and documents.
- Finance and operations information such as fee assignments, payment references, payroll, inventory, transport, admissions and approval history.
- Technical and security information such as device type, browser, IP address, session identifiers, diagnostics, synchronisation state and rate-limit events.
- Information provided in support, security, privacy or rights requests. Never include passwords, one-time codes, card numbers or secret keys in a request.
How and why information is used
Information is used to provide and secure school administration, authenticate users, enforce role and tenant boundaries, maintain accurate records, process authorised transactions, deliver notices, synchronise approved mobile work, diagnose faults, prevent abuse, meet legal or safeguarding obligations, and improve reliability. The school determines the appropriate local lawful basis; common bases include contract, legal obligation, legitimate interests, vital interests and consent where required.
Access, tenancy and confidentiality
Access is designed around least privilege, school membership and role permissions. Audit trails record important administrative and security events. Schools are responsible for assigning appropriate roles, reviewing access, protecting credentials and promptly disabling accounts that no longer need access. No system can guarantee absolute security, but we maintain layered technical and organisational safeguards and investigate suspected misuse.
Processors and connected services
A school may enable payment, email, SMS, WhatsApp, push, hosting, analytics or other integrations. Those providers process limited information needed for the enabled feature and may publish their own terms and privacy notices. The school should review its enabled integrations, contracts and local notices before activating a provider. MBTS NIG. LTD. does not sell school records or use them for advertising.
Retention, export and deletion
The school sets retention periods for its records, subject to statutory, accounting, safeguarding, dispute, security and operational requirements. When an account or school relationship ends, the school may request an export or deletion subject to verification, legal holds, backups and documented retention schedules. Technical logs may be retained for a shorter security and reliability period.
Your rights and choices
Depending on local law, individuals may have rights to access, correct, export, restrict, object to or delete their information, and to withdraw consent where consent is the basis. Submit a request to the school or authorised administrator first so identity, safeguarding and school-authorisation checks can be completed. We support the school in responding to valid requests.
Cookies, devices and offline work
Essential cookies and local device storage may be used for sign-in, security, preferences and approved offline queues. Offline records remain subject to the device’s security and the user’s role. Do not use an unmanaged or shared device for sensitive work; lock the device, install updates and report a lost device or unexpected synchronisation promptly.
Children and safeguarding
The platform may contain information about children and vulnerable people because schools use it for education and safeguarding. School administrators must use age-appropriate notices, lawful processes and trained staff. If you believe information has been exposed or misused, use the Security page immediately and alert the school’s safeguarding or privacy lead.
Changes and governing notices
We may update this notice when the platform, integrations, law or security practices change. The effective date and version above identify the current platform notice. A school’s local privacy notice, data-processing agreement, retention schedule and statutory obligations may provide additional or different details for its community.
Have a privacy request?
Start with the school that controls your account or record. Platform security concerns should be reported privately through Security.