This Data Processing Agreement ("DPA" or "Agreement") is entered into between the school that has subscribed to the OPERASCH platform (the "School" or "Data Controller") and ScalMint, the operator of OPERASCH (the "Data Processor" or "OPERASCH"). This DPA forms an integral part of the OPERASCH Terms of Service and is effective from the date the School accepts those Terms.
1. Parties to This Agreement
This Agreement is made and entered into between the following parties:
- The School ("Data Controller") — the educational institution that has subscribed to OPERASCH and determines the purposes and means of the processing of personal data through the platform.
- ScalMint ("Data Processor") — the operator of OPERASCH, a multi-tenant cloud-based school management platform designed to help educational institutions in Ghana manage their academic, administrative, and financial operations, with its registered office in Accra, Ghana. ScalMint processes personal data on behalf of the School strictly in accordance with the School's documented instructions.
This DPA is incorporated into and forms part of the OPERASCH Terms of Service. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to the processing of personal data.
2. Definitions
In this Agreement, unless the context otherwise requires, the following terms shall have the meanings ascribed to them below. These definitions are read together with, and consistent with, the definitions set out in the Data Protection Act, 2012 (Act 843) of the Republic of Ghana (the "Ghana DPA").
- Personal Data — has the meaning given in section 96 of the Ghana DPA: any information that relates to a data subject who can be identified directly or indirectly, including by reference to an identifier such as a name, identification number, location data, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of the data subject.
- Data Controller — a person who either alone, jointly with other persons or in common with other persons or as a statutory duty determines the purposes for and the manner in which personal data is processed (section 96, Ghana DPA). For the purposes of this Agreement, the School is the Data Controller.
- Data Processor — a person who processes personal data on behalf of a data controller (section 96, Ghana DPA). For the purposes of this Agreement, ScalMint, operating as OPERASCH, is the Data Processor.
- Data Subject — an individual who is the subject of the personal data, including students, parents or guardians, teaching and non-teaching staff, and any other natural person whose personal data is processed through OPERASCH.
- Processing — has the meaning given in section 96 of the Ghana DPA: any operation or set of operations which is performed on personal data, whether or not by automatic means, including collection, recording, organisation, storage, adaptation, alteration, retrieval, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure, or destruction.
- Security Breach — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed by OPERASCH.
- Sub-processor — any third party engaged by OPERASCH to process personal data on behalf of the School, including infrastructure providers and platform service providers.
- Ghana DPA — the Data Protection Act, 2012 (Act 843) of the Republic of Ghana, and any regulations, guidelines, or codes of practice issued thereunder by the Data Protection Commission.
3. Roles and Responsibilities
The parties acknowledge and agree that, in respect of the personal data processed through OPERASCH, the School acts as the Data Controller and OPERASCH acts as the Data Processor. The respective responsibilities of each party are as follows:
3.1 Responsibilities of the Data Controller (School)
As the Data Controller, the School is responsible for and shall:
- Determine the purposes and means of the processing of personal data through OPERASCH, and provide OPERASCH with documented instructions accordingly;
- Ensure that it has a lawful basis under the Ghana DPA for the processing of personal data, including obtaining and documenting the consent of data subjects where consent is the lawful basis relied upon;
- Inform data subjects of the processing of their personal data and uphold their rights as set out in the Ghana DPA;
- Be responsible for the accuracy, quality, and legality of the personal data provided to OPERASCH for processing; and
- Respond to and fulfil data subject rights requests, with the reasonable assistance of OPERASCH as provided in this Agreement.
3.2 Responsibilities of the Data Processor (OPERASCH)
As the Data Processor, OPERASCH shall:
- Process the personal data only on the documented instructions of the School, including with regard to transfers of personal data to a third country, unless required to do so by a law to which the Processor is subject;
- Treat all personal data processed on behalf of the School as strictly confidential, in accordance with section 29 of the Ghana DPA;
- Implement and maintain appropriate, reasonable technical and organisational security measures to protect personal data, in accordance with sections 28 and 30 of the Ghana DPA;
- Assist the School, by appropriate technical and organisational means, in fulfilling the School's obligation to respond to data subject rights requests under the Ghana DPA;
- Notify the School without undue delay upon becoming aware of any Security Breach, in accordance with section 31 of the Ghana DPA and the provisions of this Agreement; and
- At the choice of the School, delete or return all personal data to the School after the end of the provision of services relating to processing, and delete existing copies, unless retention is required by law.
4. Scope and Purpose of Processing
OPERASCH processes personal data on behalf of the School solely for the purpose of providing the OPERASCH platform and the associated services subscribed to by the School. The processing activities undertaken by OPERASCH on behalf of the School include the following:
- Student records management — collection, storage, and management of student biographical data, enrolment status, class placement, and academic history;
- Attendance tracking — recording and reporting of student and staff attendance, absences, and punctuality;
- Academic performance management — recording, calculation, and reporting of continuous assessment scores, examination results, grades, and report cards;
- Fees and financial management — recording of fee schedules, invoices, payments, and outstanding balances relating to students and their parents or guardians;
- Payroll management — processing of staff salary data, deductions, payslips, and statutory contributions, on the instructions of the School;
- Communication — sending of notices, announcements, fee reminders, and academic reports to students, parents, guardians, and staff via the platform's communication features; and
- Reporting and analytics — generation of reports, dashboards, and aggregated statistics to assist the School in monitoring academic, administrative, and financial performance.
All processing carried out by OPERASCH is for legitimate educational and administrative purposes, as determined and authorised by the School. OPERASCH shall not process the personal data for any purpose other than as instructed by the School, save where required to do so by the laws of the Republic of Ghana.
5. Security Measures
In accordance with sections 28 and 30 of the Data Protection Act, 2012 (Act 843), OPERASCH implements and maintains appropriate, reasonable, technical and organisational measures to safeguard personal data processed on behalf of the School against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Section 28 of the Ghana DPA requires that these measures take into account the state of the art, the costs of implementation, and the nature of the data, as well as the harm that would result from a Security Breach.
The technical and organisational measures implemented include:
- Encryption in transit — all personal data transmitted between the School, data subjects, and OPERASCH infrastructure is protected using Transport Layer Security (TLS 1.2 or higher);
- Encryption at rest — personal data stored in the OPERASCH databases and backups is encrypted at rest using industry-standard encryption algorithms;
- Role-based access control — access to personal data is restricted on a strict need-to-know basis, with role-based permissions assigned to OPERASCH personnel and to the School's authorised users within the platform;
- Authentication — strong authentication mechanisms, including multi-factor authentication for administrative access, are enforced to prevent unauthorised access to systems processing personal data;
- Audit logs — comprehensive audit logging of access to and actions performed on personal data, retained for an appropriate period to support investigation and accountability;
- Regular security reviews — periodic security assessments, vulnerability scanning, and penetration testing of the OPERASCH platform to identify and remediate security risks;
- Staff training — all OPERASCH personnel with access to personal data receive regular training on their obligations under the Ghana DPA, including data protection, security, and confidentiality;
- Incident response plan — a documented incident response and breach management procedure that enables OPERASCH to detect, investigate, contain, and report Security Breaches in accordance with section 31 of the Ghana DPA; and
- Business continuity — regular data backups and a disaster recovery plan to ensure the availability and integrity of personal data in the event of a system failure.
OPERASCH shall review and, where appropriate, update these security measures from time to time to maintain an appropriate level of security, taking into account developments in technology and the evolving risks to personal data.
6. Confidentiality
In accordance with section 29 of the Data Protection Act, 2012 (Act 843), OPERASCH and its staff shall treat all personal data processed on behalf of the School as strictly confidential. OPERASCH shall not disclose personal data to any third party except:
- Where the School has provided prior written authorisation for such disclosure;
- Where disclosure is to an authorised Sub-processor in accordance with Section 7 of this Agreement; or
- Where disclosure is required by the laws of the Republic of Ghana, in which case OPERASCH shall, to the extent permitted by law, inform the School of the legal requirement before making the disclosure.
All OPERASCH personnel, including employees, contractors, and agents, who have access to personal data are bound by written confidentiality obligations that survive the termination of their relationship with OPERASCH. OPERASCH ensures that access to personal data is limited to those personnel who require such access to perform their duties in providing the OPERASCH services.
7. Sub-processors
In accordance with sections 29 and 30 of the Data Protection Act, 2012 (Act 843), OPERASCH may engage third-party Sub-processors to process personal data on behalf of the School only with the prior authorisation of the School. The School grants OPERASCH general written authorisation to engage the Sub-processors listed in this Section, provided that OPERASCH remains liable for the acts and omissions of its Sub-processors as if those acts or omissions were carried out by OPERASCH itself.
Before engaging any Sub-processor, OPERASCH shall ensure that the Sub-processor is bound by written contractual obligations that impose confidentiality and security requirements equivalent to those set out in this Agreement, and that require the Sub-processor to protect personal data to a standard no less stringent than the standard maintained by OPERASCH under this Agreement.
The current Sub-processors engaged by OPERASCH in the provision of the OPERASCH services are:
- Clerk — authentication and identity management services, including sign-in, session management, and access control;
- Cloud hosting provider — infrastructure services providing the servers, databases, and networking used to host and operate the OPERASCH platform; and
- Self-operated language-model service — the AI features of the services (the Assist helper and report-remark drafting) are powered by an open-weights language model running on cloud infrastructure operated by OPERASCH itself under its own account. It is not a third-party AI service: no data is disclosed to any AI provider, the model receives only the minimum data required for each task, prompt and response content are not retained by the inference server, and every AI-drafted report remark remains a draft until a school user reviews and publishes it.
OPERASCH shall notify the School of any intended addition or replacement of a Sub-processor, giving the School the opportunity to object to such changes. Where the School objects and OPERASCH is unable to provide an alternative, the School may, as its sole remedy, terminate the affected portion of the services by providing written notice to OPERASCH.
8. Cross-Border Transfers
The School acknowledges that certain Sub-processors engaged by OPERASCH may process personal data outside the Republic of Ghana, as their infrastructure or operations may be located in other jurisdictions. Where personal data is transferred to, or processed in, a country outside Ghana, OPERASCH shall ensure that such transfer complies with section 18(2) of the Data Protection Act, 2012 (Act 843) and with the data protection laws applicable in the receiving country.
To ensure an adequate level of protection for personal data transferred outside Ghana, OPERASCH shall put in place appropriate safeguards, which may include:
- Contractual clauses with the Sub-processor imposing obligations equivalent to those set out in this Agreement;
- Reliance on Sub-processors that are subject to data protection regimes recognised as providing an adequate level of protection for personal data; and
- Implementation of technical measures, such as encryption, to protect personal data during transfer and while processed abroad.
OPERASCH shall, upon request, provide the School with information regarding the countries to which personal data is transferred and the safeguards applied to such transfers.
9. Data Subject Rights Assistance
OPERASCH shall assist the School in fulfilling the School's obligation to respond to and fulfil data subject rights requests made under the Data Protection Act, 2012 (Act 843), including the rights of access, rectification, erasure, and objection as provided in sections 32 to 44 of the Ghana DPA.
Without limitation, OPERASCH shall:
- Provide the School with the personal data of the relevant data subject, and any other information reasonably required, to enable the School to respond to a data subject access request within the statutory period of forty (40) days as required by section 32(10) of the Ghana DPA;
- Rectify inaccurate personal data promptly upon instruction from the School, to enable the School to comply with a rectification request;
- Erase or restrict personal data as instructed by the School, to enable the School to comply with an erasure or objection request; and
- Provide such other reasonable assistance as the School may require to demonstrate compliance with the Ghana DPA in respect of the processing carried out by OPERASCH on behalf of the School.
Where OPERASCH receives a data subject rights request directly from a data subject in respect of personal data processed on behalf of the School, OPERASCH shall, without undue delay, inform the School of the request and shall not respond to the request itself except as instructed by the School or as required by law.
10. Data Breach Notification
In accordance with section 31 of the Data Protection Act, 2012 (Act 843), OPERASCH shall notify the School without undue delay, and in any event within seventy-two (72) hours, after becoming aware of any Security Breach affecting personal data processed on behalf of the School. The notification shall, to the extent then known, describe:
- The nature of the Security Breach and, where possible, the categories and approximate number of data subjects and personal data records concerned;
- The likely consequences of the Security Breach; and
- The measures taken or proposed to be taken by OPERASCH to address the Security Breach and to mitigate its possible adverse effects.
OPERASCH shall take all reasonable steps to investigate, contain, and remediate any Security Breach, and shall cooperate with the School and the Data Protection Commission in any investigation into the breach.
11. Data Return and Deletion
Upon termination or expiry of the School's subscription to OPERASCH, or upon receipt of written instructions from the School,OPERASCH shall, at the choice of the School:
- Provide the School with a complete export of the personal data processed on the School's behalf, in a structured, commonly used, and machine-readable format, within a period of thirty (30) days from the date of termination (the "Export Window"); and
- Following the expiry of the Export Window, securely delete or permanently anonymise all personal data processed on behalf of the School, including existing copies, from OPERASCH production systems and backups.
OPERASCH shall retain personal data beyond the Export Window only where retention is required by the laws of the Republic of Ghana, or to comply with a lawful order of a court or other competent authority. In such cases, the personal data shall be retained only for the period and to the extent required, and shall be kept secure and not processed for any other purpose.
12. Audit Rights
The School has the right to audit OPERASCH's compliance with the obligations set out in this Agreement and with the Data Protection Act, 2012 (Act 843). To exercise this right, the School shall provide OPERASCH with reasonable prior written notice of not less than thirty (30) days, and the audit shall be conducted during normal business hours and in a manner that does not unreasonably interfere with OPERASCH's operations.
In lieu of an on-site audit, and where appropriate, OPERASCH may provide the School with independent third-party audit reports, certifications, or attestations (such as security certifications) that demonstrate OPERASCH's compliance with its security and data protection obligations. Such reports shall be treated as confidential by the School and used solely for the purpose of verifying OPERASCH's compliance with this Agreement.
Where an audit reveals a material non-compliance by OPERASCH with its obligations under this Agreement, OPERASCH shall, at its own cost, take all reasonable steps to remedy the non-compliance within a mutually agreed timeframe.
13. Term and Termination
This DPA takes effect on the date the School accepts the OPERASCH Terms of Service and remains in effect for so long as the School uses the OPERASCH platform. This DPA terminates automatically upon termination of the School's subscription to OPERASCH, or upon termination of the Terms of Service, whichever occurs first.
The following provisions shall survive the termination or expiry of this DPA:
- The confidentiality obligations set out in Section 6;
- The data return and deletion obligations set out in Section 11;
- The data breach notification obligations set out in Section 10, in respect of any Security Breach that occurred before termination; and
- Any other provision that, by its nature, is intended to survive termination.
The termination of this DPA shall not affect the rights and obligations of the parties accrued prior to the date of termination.
14. Governing Law
This DPA shall be governed by and construed in accordance with the laws of the Republic of Ghana. The Data Protection Act, 2012 (Act 843) is the primary legislation governing the processing of personal data under this Agreement, and the parties acknowledge the supervisory authority of the Data Protection Commission of Ghana.
Any dispute arising out of or in connection with this DPA, including any question regarding its existence, validity, or termination, shall be referred to and finally resolved by the courts of the Republic of Ghana, subject to the jurisdiction of the High Court of Ghana sitting in Accra.
15. Contact
For any questions, requests, or notices relating to this Data Processing Agreement or to the processing of personal data by OPERASCH, the School may contact OPERASCH's Data Protection Officer using the details below:
- Data Protection Officer, ScalMint
- Email: mwinisaviour87@gmail.com
- Address: Accra, Ghana
- Website: https://smartsos.cloud
ScalMint is compliant with the Data Protection Commission of Ghana (registration status: DPC/GH/CC-2026/PENDING). The School may also contact the Data Protection Commission of Ghana directly regarding any matter concerning the processing of personal data under the Ghana DPA.