Effective September 11, 2026
Privacy Policy
This policy describes the information CivoraED processes for school workspaces and how that information is used to operate the platform.
Information We Process
CivoraED may process school organization details, administrator accounts, teacher accounts, parent and guardian profiles, student profiles, enrollment records, class records, grades, invoices, payment checkout metadata, prospects, campaign records, social post drafts, CRM notes, and audit logs.
The exact information depends on what each school chooses to enter and which integrations it configures.
How Information Is Used
Information is used to provide school CRM, student progress reporting, parent access, billing workflows, campaign planning, tenant-level reporting, security auditing, and support for authorized users.
Campaign data, including WhatsApp, SMS, email, phone, and social planning fields, is used to help schools manage outreach with consent and compliance context.
Student and Family Privacy
Student and family records should be accessed only by authorized school users and linked parents or guardians. The platform uses role-aware access patterns and organization scoping to separate school tenants.
Schools remain responsible for complying with applicable student privacy, education records, child privacy, communications, and payment laws.
Third-Party Providers
CivoraED may connect to third-party providers such as hosting, database, email, payment, and messaging services when configured by the platform operator or school.
Examples include Railway for hosting, PostgreSQL for data storage, Stripe for checkout, and Twilio for WhatsApp/SMS/phone workflows when credentials are configured.
Security
The platform uses authenticated sessions, role-aware server routes, tenant-scoped queries, audit logs, secure password hashing, and production health checks to support responsible operations.
No system can be guaranteed perfectly secure. Schools should use strong passwords, limit user access, review audit activity, and remove users who no longer need access.
Data Retention and Deletion
Schools should define their own retention rules for student, parent, academic, billing, and campaign records. Records may be retained as needed for service delivery, auditability, legal obligations, and dispute resolution.
Deletion or export workflows should be reviewed before commercial launch so they match the operator's customer agreements and legal requirements.
Contact
Privacy requests should be directed to the school or organization operating your CivoraED workspace. Platform operator privacy contact details should be added before commercial launch.