Privacy
SuGes processes data about children and families. This page says which data, why, and for how long.
Who is responsible for what
The school is the data controller: it decides what data it collects about its pupils and staff, and what it does with it. SuGes is a processor: it hosts and processes that data on the school's behalf, following its instructions, and for no other purpose.
We sell no data, we transfer none to third parties for commercial purposes, and we train no model on schools' content.
Data processed
- Pupils
- Identity, date and place of birth, sex, registration number, class, marks, remarks, fee status.
- Staff
- Identity, contact details, position, permission role, credentials.
- Billing
- School contact details, licences, payments.
- Audit log
- Author, date and nature of sensitive actions: documents printed, payments taken, configuration changes.
- Contact form
- Name, email address, phone and message — to reply to you.
What we do not collect
- No advertising trackers, no third-party analytics cookies.
- Only two cookies: your session, which keeps you signed in and disappears when you sign out, and your display language. Both are necessary for the service to work and therefore need no consent.
- No health data, no biometric data.
Where the data is
PostgreSQL database hosted on the same private server as the application, at Hostinger.
Application: Hostinger International Limited · 61 Lordou Vironos str., 6023 Larnaca, Cyprus
Security
- End-to-end encryption of exchanges (HTTPS).
- Passwords stored as hashes, never in clear text.
- Strict isolation between schools: no query crosses a space's boundary, not even for a platform administrator.
- Permissions by role: each person reaches only what they are allowed to.
- Named, timestamped audit log on sensitive actions.
Retention periods
- School data
- Kept while the school is a customer, then for three months after the contract ends, to allow the export.
- Audit log
- Three years, to allow administrative checks.
- Billing
- Ten years, in line with accounting obligations.
- Contact requests
- Two years from the last exchange.
Individual rights
A pupil, a parent or a member of staff may request access to, correction of, or erasure of their data. That request goes to the school, which decides; we carry it out on its behalf. If you do not know whom to address, write to us at [email protected] and we will point you in the right direction.
Some data cannot be erased on request: a mark carried on a report card already issued is an administrative record, subject to the school's archiving obligations.
Sub-processors
We use a hosting provider, bound by a confidentiality undertaking, which hosts the application and its database, and payment providers (Stripe for bank cards, an aggregator for Mobile Money), which receive only the data needed for the transaction. This list is kept up to date here.
In the event of a data breach
Should a breach likely to affect individuals occur, the schools concerned would be informed without delay, with the nature of the incident, the data affected and the measures taken.
This policy describes practices actually in place. It must nevertheless be reviewed by a lawyer against the applicable personal data protection laws — those of Canada, where the publisher is based, and those of the client schools' countries — before going publicly live.