Last updated: 24 July 2026
This Madrasah Management System (“MMS” or “the System”) is operated by the madrasah administration. The madrasah is the data controller responsible for your personal data. For any privacy-related enquiries, contact the administration through the in-app messaging system or by speaking to an administrator directly.
We collect the following categories of personal data, and only what is necessary for each purpose:
Identity and account data
Full name, email address, ITS community registration number, profile photo (optional), account status, and hashed password. Used to authenticate you and identify you within the madrasah community.
Role and permission data
Your assigned role(s) (e.g. Teacher, Parent, Student). Used to determine what data you can access.
Student academic records
Date of birth, gender (optional), class enrolments, attendance records, assignment submissions. Collected only for users with a Student profile. Used to manage education delivery and communicate progress to parents.
Financial records
Fee amounts, payment status, and descriptions. Used to manage madrasah billing and communicate outstanding balances.
Communications
Messages sent through the in-app messaging and announcement system. Used to facilitate communication between staff, students, and parents.
Security and audit data
IP addresses (logged with significant actions), session tokens, login attempt history, and an audit log of administrative actions. Used for account security, fraud prevention, and accountability.
Cookies and technical data
A single session cookie is set when you sign in. This cookie is strictly necessary for the System to function — it identifies your authenticated session. No advertising or tracking cookies are used.
We process your personal data on the following legal bases:
Access is strictly role-based and enforced at the application level on every request:
Third-party services used to operate the System include: Neon (database hosting, EU/US), Vercel (application hosting), Resend (email delivery), and Twilio (SMS notifications). Each processes only the data necessary to provide their service and is bound by their own privacy terms.
Academic and financial records are retained for the duration required by the madrasah's administrative and legal obligations. Audit logs are retained for at least one academic year. Session tokens expire automatically after inactivity. When an account is scheduled for deletion, all associated personal data is permanently removed.
Passwords are hashed using a secure one-way algorithm and are never stored in plain text. All connections are encrypted in transit (HTTPS/TLS). Sessions are database-backed and can be revoked by administrators at any time. Significant actions are logged with IP addresses for accountability. Access to the database and hosting infrastructure is restricted to authorised administrators.
The System manages records for students who may be minors. Student accounts are created and managed under the oversight of the madrasah administration. Parents and guardians are linked to their children's accounts and can view their records. We do not knowingly collect data from children directly for purposes beyond those described above.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Signed-in users can download their personal data directly from My Data and update their name, email, and ITS number from their profile page. For other requests — including deletion — contact the madrasah administration through the in-app messaging system or speak to an administrator directly. We will respond within 30 days.
In the event of a data breach that poses a risk to the rights and freedoms of individuals, the madrasah will notify affected users and, where required by applicable law, the relevant supervisory authority within 72 hours of becoming aware of the breach. Notification will be sent to the email address on your account.
This policy is designed to comply with the General Data Protection Regulation (GDPR), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and British Columbia's Personal Information Protection Act (BC PIPA), as applicable to the madrasah's operations. If you believe your rights have not been respected, you may file a complaint with the relevant privacy commissioner or data protection authority in your jurisdiction.
We may update this policy from time to time. The date at the top of this page reflects the most recent revision. For material changes, we will notify users via the in-app notification system. Continued use of the System after changes are posted constitutes acceptance of the updated policy.