Privacy Policy
Version: 1.1 Effective date: 30th July, 2026
1. Introduction
Skooly Pte. Ltd. (Singapore, UEN 201621842G) ("Skooly", "we", "us") operates the Skooly platform — our web applications, mobile applications, public storefronts, attendance kiosks, and related services (the "Services") — used by education businesses ("Organizations") and the families and staff connected to them.
This policy explains:
- what personal data we collect and where it comes from;
- how we use it and who we share it with;
- how long we keep it and how we protect it;
- your rights and how to exercise them.
It is written to comply with the data-protection laws applicable to the Services, including the Singapore Personal Data Protection Act 2012 (PDPA), the Malaysia Personal Data Protection Act 2010, and the South Africa Protection of Personal Information Act, 2013 (POPIA). Terms capitalized here (Organization, Customer, Attendee, Organization Data) have the meanings given in our Terms of Service.
2. Our Role: Platform vs Organization
Skooly is a multi-tenant platform. Who "controls" your data depends on who put it there:
- Data the Organization manages. Records that an Organization and its staff enter or collect about students, children, families, and staff (enrollment details, attendance, daily reports, photos, invoices, observations) are controlled by that Organization. For this data Skooly acts as the Organization's data intermediary (processor) and handles it only to provide the Services, under the Data Protection Terms annexed to our Terms of Service. Questions or requests about this data should go first to your Organization; we support them in responding.
- Data Skooly controls. Account and sign-in data, Organization subscription and billing data, device and usage data, and support communications are controlled by Skooly and governed directly by this policy.
3. Information We Collect
3.1 Information you provide directly
Account data — name, email address, phone number, password (stored hashed — see Section 11), preferred language, and profile photo if provided.
Organization data (entered by Organization admins/staff) — business name, branches and locations, staff profiles, payroll and clock-in records, tax and billing configuration, and — where the Organization enables e-invoicing — tax identification numbers.
Customer and Attendee data (entered by Organizations and parents) — student/child name, date of birth, guardian relationships, enrollment and class records, attendance records (including kiosk check-ins), progress reports, and for preschools: daily reports, photos and media, learning observations and portfolios, and program/subsidy information. Organizations may record health-related notes (e.g. allergies) where their operations require it.
Payment data — invoices, payment history, and payment status. We do not store full card numbers; card and bank payments are handled by our payment providers (Section 6.2).
Communications — support requests, and messages and announcements sent through the platform.
Agreement records — when you sign or accept an agreement in-app, we record the version accepted and a digital signature (name, timestamp, IP address, device fingerprint).
3.2 Information collected automatically
- IP address, browser and device type, operating system, and app version
- Pages and features used, and diagnostic logs of requests to the platform
- Mobile push-notification tokens
- Session information needed to keep you signed in
We do not collect precise device location.
3.3 Information from third parties
- Google Sign-In — if you sign in with Google, we receive your name, email address, and Google account identifier.
- Payment providers — transaction outcomes and payment-method metadata (never full card numbers).
- reCAPTCHA — abuse-prevention signals about the interaction (Section 6.2).
4. Cookies & Local Storage
The web applications use only essential browser storage: session tokens that keep you signed in and preferences such as language. We do not use advertising cookies, and we do not currently use third-party analytics cookies. Google reCAPTCHA, where shown (e.g. on signup), may set its own cookies under Google's policy. If we ever add analytics, this section and the platform's consent behavior will be updated first.
5. How We Use Your Information
- Provide and operate the Services — accounts, scheduling, enrollment, attendance, billing, communications, reports, and the parent/student portals.
- Process transactions and send transactional messages (invoices, receipts, booking confirmations, reminders, announcements) by email and push notification.
- Keep the platform safe — authenticate users, verify devices, prevent fraud and abuse (including CAPTCHA), and screen announcements for spam and unsafe content (Section 5.1).
- Support you — respond to questions and troubleshoot issues.
- Improve the Services — monitor performance, diagnose technical problems, and analyze usage in aggregate.
- Comply with law — including tax, accounting, and e-invoicing obligations.
- Onboard Organizations — contact the business signatory of a new Organization about setup and our services (Section 6.2, CRM).
We do not sell personal data. We do not use it for third-party advertising. We do not profile children for any commercial purpose.
5.1 AI-assisted features
We use AI in narrow, disclosed ways:
- Skooly CoPilot (optional add-on): generates operational briefs (e.g. daily, weekly, and monthly summaries), suggested message drafts for admin review, and attention flags from your Organization's data, using the Anthropic (Claude) API.
- Announcement screening: announcement text is screened for spam and unsafe content via the same provider before delivery; excerpts are capped in length and not logged by us.
- Support: our help desk (Zendesk) may use an AI agent to answer support questions, drawing on your support conversation and our help content.
- Non-personal lookups: we also use AI for lookups involving no personal data (e.g. public holidays).
Data sent to AI providers is used to provide the feature under our agreements with them, not to train the providers' own models. AI output can be inaccurate — the Terms of Service (Section 11) require reviewing it before relying on it, and the platform's underlying records remain authoritative. If we launch further AI-assisted features, we will describe them here and in-product before they process personal data.
6. How We Share Information
6.1 Within the Services, as designed
- Organization admins and staff see the Customer and Attendee records their role permits for their Organization (role- and branch-based access).
- Parents/guardians see their own children's information through the parent portal and app.
- Nothing is visible across Organizations: each tenant's data is isolated.
6.2 Service providers
We share personal data with the providers below, each only to perform its function, under its own terms and our agreements with them:
| Provider | Data involved | Purpose |
|---|---|---|
| Amazon Web Services (Singapore region) | All platform data and files | Cloud hosting, storage, and backups |
| HitPay | Payer name, invoice and payment details | Payment processing for Organizations that connect HitPay |
| Stripe | Payer name, invoice and payment details | Payment processing for Organizations that connect Stripe |
| Sign-in identity (name, email); reCAPTCHA interaction signals | Google Sign-In authentication; abuse prevention | |
| Expo (and Apple/Google push infrastructure) | Device push tokens, notification content | Mobile push-notification delivery |
| Resend | Recipient email address, message content | Transactional email delivery |
| Zendesk | Name, email address, support conversation history | Customer support and help desk |
| Anthropic | For Organizations with CoPilot enabled: the Organization data needed to generate briefs, drafts, and attention flags; announcement text excerpts for screening | AI features and content-safety screening (Section 5.1) — not used to train Anthropic's models |
| Freshsales (CRM) | New-Organization business contact details (name, business email, phone, organization name) | Onboarding and sales follow-up — Organization signups only, never parents, students, or children |
| MyInvois (LHDN, Malaysia) | Invoice details and required tax identifiers | E-invoice submission to the Malaysian tax authority, where a Malaysian Organization enables it |
| QuickBooks | Invoice and payment data | Accounting sync to the Organization's own QuickBooks account, where the Organization connects it |
These providers act as our sub-processors only where they handle Organization Data (hosting, email, push notifications, payments, AI features, e-invoicing, accounting sync); Freshsales, Zendesk, and Google Sign-In process data Skooly controls in its own right.
6.3 For legal reasons
We may disclose personal data where required by law or where we believe in good faith it is necessary to comply with a legal obligation (court orders, lawful government requests), protect the rights, property, or safety of Skooly, our users, or the public, or detect and prevent fraud or abuse.
6.4 Business transfers
If Skooly is involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction. We will provide notice before personal data becomes subject to a different privacy policy.
6.5 With your consent
We share personal data for any other purpose only with consent.
6.6 Aggregated and de-identified data
We may use and share aggregated or de-identified information that cannot reasonably identify anyone (e.g. platform usage statistics) to operate and improve the platform.
7. Children's Privacy
Our preschool and academy Services necessarily involve information about children. What counts as a "child" depends on local law — under 13 for some purposes, and anyone under 18 under laws such as South Africa's POPIA:
- Children under 13 never hold Skooly accounts; older students may hold accounts only with parent/guardian consent (see the Terms of Service). A child's information is otherwise entered and managed by their Organization and their parents/guardians.
- The Organization is responsible for having a lawful basis and the consents its law requires for the child data it records — including the consent of a parent/guardian (a "competent person" under POPIA) and consent for photos and media in daily reports and portfolios (see the Data Protection Terms in our Terms of Service).
- Parents/guardians can view their child's information through the parent portal and can direct correction or deletion requests to the Organization; we support the Organization in fulfilling them.
- We use children's data only to provide the Services to the Organization and family — never for advertising or profiling.
8. Data Retention
- Active accounts and Organizations — retained while the account or subscription is active.
- Records archived in the course of business (e.g. a departed student's profile) — retained in archived form for 18 months, then purged; linked financial records are anonymized rather than deleted, preserving a de-identified accounting trail. If your Organization must retain records for a longer period to comply with laws that apply to it (e.g. childcare licensing or tax rules), contact support@getskooly.com before the purge and we will arrange a longer retention period for those records.
- Organization termination — a full data export is made available; the Organization's data is retained for a 30-day grace period (export download, recovery from accidental termination) and then permanently deleted.
- Agreement and financial records — signed-agreement records and records we must keep by law are retained for the legally required period.
- Generated exports and temporary upload files — deleted automatically on short schedules (days, not months).
- Backups — deleted data may persist in encrypted backups for a limited period before those backups are aged out.
9. Your Rights
Subject to applicable law, you may:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Delete your data;
- Export a copy of your data;
- Object to processing of your data;
- Withdraw consent to processing (which may limit your ability to use the Services).
How to exercise them: email dpo@getskooly.com. We may need to verify your identity before acting on a request, and we respond within the timelines the PDPA requires. Where the data is controlled by your Organization (Section 2), we may redirect the request to the Organization and assist it in responding — for children's records, requests go to the Organization or through the parent portal.
10. Territorial Scope & International Transfers
Our systems are hosted in Singapore (AWS ap-southeast-1). If you use the Services from other countries (e.g. Malaysia or South Africa), your data is transferred to and processed in Singapore, and by the providers in Section 6.2 in their respective locations, with protections consistent with applicable data-protection law. For data we process on behalf of an Organization, the transfer commitments in the Data Protection Terms (Terms of Service, Annex) apply — including, for South African Organizations, terms intended to support the binding-agreement ground in POPIA section 72(1)(a).
The Services are operated from Singapore and intended for Organizations and users in Singapore, Malaysia, and South Africa. We do not direct the Services at the European Union/EEA or the United Kingdom, and this policy is not a representation of GDPR/UK-GDPR compliance. If you access the Services from elsewhere, you do so on your own initiative and your data will be processed in Singapore as described here — the rights in Section 9 are available to all users regardless of location.
11. Data Security
11.1 What we do
- Encryption — data encrypted in transit (TLS) and at rest.
- Tenant isolation — every Organization's data is partitioned and every data access is scoped to the requesting tenant.
- Access control — role- and branch-based permissions; staff and parents see only what their role allows.
- Authentication — passwords hashed with Argon2 (a modern memory-hard algorithm); email OTP and device-verification checks; optional Google Sign-In.
- File security — uploads stored in access-controlled cloud storage and served through time-limited pre-signed links, not public URLs.
- Operational security — security-relevant events are logged; sessions expire and refresh automatically.
11.2 Limitations
No method of transmission or storage is 100% secure. We work to protect personal data with the measures above, but we cannot guarantee absolute security.
11.3 Your part
Keep your password confidential and unique, log out of shared devices (especially shared kiosk or front-desk devices), and report suspected unauthorized access to us immediately.
11.4 If a breach occurs
We assess data breaches when we become aware of them and, where a breach is notifiable under the PDPA — likely significant harm to affected individuals, or significant scale — we notify the Personal Data Protection Commission and affected individuals within the statutory timelines. Where South African law applies to data we control, we notify the Information Regulator (South Africa) and affected individuals as soon as reasonably possible, as POPIA section 22 requires. We comply with equivalent breach-notification obligations under other laws that apply to us. Where a breach affects data we process for an Organization, we notify that Organization without undue delay so it can meet its own obligations. Notifications describe what happened, what data was involved, what we are doing, and what you can do.
12. Changes to This Policy
We may update this policy by publishing a new version; the current version is always available on the platform's Privacy Policy page and applies from publication. The platform may prompt you in-app to acknowledge a new version, and each accepted version is recorded against your account with a timestamped digital signature. Please review this page from time to time.
13. Contact / Data Protection Officer
- Data Protection Officer: dpo@getskooly.com
- Support: support@getskooly.com