Effective September 11, 2026

Privacy Policy

This policy describes the information CivoraED processes for school workspaces and how that information is used to operate the platform.

Important: These policies are product-ready working drafts for launch preparation and should be reviewed by qualified legal counsel before broad commercial use.

Information We Process

CivoraED may process school organization details, administrator accounts, teacher accounts, parent and guardian profiles, student profiles, enrollment records, class records, grades, invoices, payment checkout metadata, prospects, campaign records, social post drafts, CRM notes, and audit logs.

The exact information depends on what each school chooses to enter and which integrations it configures.

How Information Is Used

Information is used to provide school CRM, student progress reporting, parent access, billing workflows, campaign planning, tenant-level reporting, security auditing, and support for authorized users.

Campaign data, including WhatsApp, SMS, email, phone, and social planning fields, is used to help schools manage outreach with consent and compliance context.

Student and Family Privacy

Student and family records should be accessed only by authorized school users and linked parents or guardians. The platform uses role-aware access patterns and organization scoping to separate school tenants.

Schools remain responsible for complying with applicable student privacy, education records, child privacy, communications, and payment laws.

Third-Party Providers

CivoraED may connect to third-party providers such as hosting, database, email, payment, and messaging services when configured by the platform operator or school.

Examples include Railway for hosting, PostgreSQL for data storage, Stripe for checkout, and Twilio for WhatsApp/SMS/phone workflows when credentials are configured.

Security

The platform uses authenticated sessions, role-aware server routes, tenant-scoped queries, audit logs, secure password hashing, and production health checks to support responsible operations.

No system can be guaranteed perfectly secure. Schools should use strong passwords, limit user access, review audit activity, and remove users who no longer need access.

Data Retention and Deletion

Schools should define their own retention rules for student, parent, academic, billing, and campaign records. Records may be retained as needed for service delivery, auditability, legal obligations, and dispute resolution.

Deletion or export workflows should be reviewed before commercial launch so they match the operator's customer agreements and legal requirements.

Contact

Privacy requests should be directed to the school or organization operating your CivoraED workspace. Platform operator privacy contact details should be added before commercial launch.