This Privacy Policy explains how OPERASCH (OPERASCH), operated by ScalMint and based in Accra, Ghana, collects, uses, stores, and protects your personal data when you use our school management platform. OPERASCH is DPC/GH/CC-2026/PENDING.
This policy applies to all users of the platform — students, parents and guardians, teachers and administrative staff, and school administrators — and to all personal data processed through OPERASCH on behalf of schools in Ghana.
1. Introduction
ScalMint (“we”, “us”, or “our”) is the company that operates OPERASCH, a multi-tenant cloud-based school management platform designed to help educational institutions in Ghana manage their academic, administrative, and financial operations. We are committed to protecting the privacy and personal data of every individual whose information is processed through the platform, in accordance with the Data Protection Act, 2012 (Act 843) of the Republic of Ghana and other applicable laws.
This Privacy Policy describes:
- The categories of personal data we process and why;
- The legal basis on which we rely for each type of processing;
- How data is shared, stored, secured, and retained;
- The rights you have over your personal data and how to exercise them; and
- How to contact us or the Data Protection Commission of Ghana.
By creating an account on OPERASCH or by having your personal data entered into the platform by your school, you acknowledge that your data will be processed as described in this policy.
2. Data Controller and Data Processor
Under the Data Protection Act, 2012 (Act 843), particularly Sections 29 and 30, a distinction is drawn between a Data Controller — the entity that determines the purposes and means of processing personal data — and a Data Processor — the entity that processes personal data on behalf of, and on the instructions of, the controller.
Your school is the Data Controller
The school that subscribes to OPERASCH is the Data Controller of the personal data of its students, parents, guardians, and staff. The school decides what data is entered, why it is processed, and how long it is kept. The school is responsible for obtaining the necessary consents and for ensuring it has a lawful basis for the processing it instructs OPERASCH to carry out.
OPERASCH (ScalMint) is the Data Processor
ScalMint, as the provider of OPERASCH, acts as a Data Processor. We process personal data strictly on the documented instructions of each school (the Data Controller) and only for the purposes of delivering the OPERASCH platform. We do not process personal data for our own independent purposes, and we do not sell personal data to any third party.
The formal terms of this controller-processor relationship are set out in our Data Processing Agreement, which every school enters into before using OPERASCH.
3. Personal Data We Collect
The specific data processed through OPERASCH depends on the role of the individual and the modules the school has enabled. Below is a breakdown by role of the categories of personal data the platform is designed to store. A school may not use every field, and only data entered by authorised school staff is processed.
3.1 Students
- Full name, date of birth, gender, and nationality;
- Photograph (for identification, ID cards, and class lists);
- Home address and contact details of the student (where applicable);
- Admission/enrolment number, class, grade level, and academic stream;
- Academic records: continuous assessment scores, examination results, report cards, and grades;
- Attendance and punctuality records;
- Behavioural and disciplinary records (where the school chooses to record them);
- Health information provided for the student’s welfare (e.g. known conditions, allergies, emergency medical instructions) — only where the school requires it; and
- Biometric data (e.g. fingerprints for attendance) only where the school has expressly enabled this feature and obtained the requisite consent under Act 843; where biometrics are not enabled, no such data is collected.
3.2 Parents and Guardians
- Full name and relationship to the student;
- Phone number, email address, and physical/home address;
- Occupation and employer (where collected by the school);
- Financial and fee records: invoices, payment history, outstanding balances, and payment method references;
- Communication logs (messages sent to and from the school via the platform); and
- Next-of-kin and emergency contact details.
3.3 Teachers and Staff
- Full name, date of birth, and national identification details (e.g. Ghana Card number) where required for employment administration;
- Photograph;
- Contact details: phone number, email, and address;
- Qualifications, subjects taught, classes assigned, and employment records;
- Performance and appraisal records (where the school uses OPERASCHfor staff management); and
- Banking or payment details — only where the school uses OPERASCH to process payroll or stipends. These are stored securely and access-restricted.
3.4 School Administrators
- Full name, email address, and phone number;
- Role/position within the school and the permissions granted to them on the platform;
- Account credentials and authentication data (managed securely by our authentication provider, see Section 6); and
- Audit log entries: actions taken within the platform, timestamps, and IP addresses, retained for security and accountability.
3.5 Technical and Usage Data
When you interact with OPERASCH, we also process limited technical data necessary for the operation and security of the platform:
- IP address, browser type, and device information;
- Login timestamps, session identifiers, and authentication events; and
- Platform usage logs used for diagnosing faults and detecting unauthorised access.
4. Lawful Basis for Processing
Under Section 20 of the Data Protection Act, 2012 (Act 843), the processing of personal data must be lawful. We rely on the following lawful bases for the processing we carry out on behalf of schools:
- Consent (Section 20): The data subject has given clear and informed consent to the processing of their personal data for one or more specific purposes. This applies, for example, to the use of student photographs and to any biometric data.
- Contract: Processing is necessary for the performance of a contract to which the data subject is a party, or for steps taken at the data subject’s request before entering into a contract. This covers the provision of educational services, fee management, and the core academic operations of the school.
- Legal obligation: Processing is necessary to comply with a legal obligation to which the school or ScalMint is subject — for example, retaining financial records for tax purposes under Ghana’s tax laws, or producing records where required by an education authority.
- Legitimate interest: Processing is necessary for the legitimate interests of the school or ScalMint, provided it does not override the rights and freedoms of the data subject. We rely on this basis for security monitoring, fraud prevention, audit logging, and platform improvement.
- Vital interests / protection of the data subject: Processing is necessary to protect the vital interests of the data subject or another person — for example, using emergency contact and health information to respond to a medical situation at school.
Before processing any personal data, we (and the school as controller) ensure that the purpose of the processing is specified, explicit, and legitimate, in line with the principle of specification of purpose under Act 843. Data collected for one stated purpose is not used for an incompatible purpose.
5. How We Use Your Data
We process personal data through OPERASCH for the following specified purposes, in line with the principle of specification of purpose under Act 843:
- Academic management: recording enrolment, class placement, assessment scores, examination results, and generating report cards and academic transcripts.
- Attendance tracking: recording daily attendance and punctuality, flagging absences, and notifying parents.
- Fee and financial management: issuing invoices, recording payments, tracking outstanding balances, and generating financial reports for the school’s administration.
- Communication: sending notices, announcements, result notifications, and fee reminders to parents, students, and staff via the platform, email, or SMS.
- Reporting and analytics: producing aggregate, de-identified statistics that help schools assess performance, attendance trends, and operational efficiency.
- Security and integrity: authenticating users, enforcing role-based access controls, maintaining audit logs, and detecting or preventing unauthorised access to the platform.
- Compliance: meeting record-keeping obligations under Ghanaian education and tax legislation, and responding to lawful requests from competent authorities.
- Platform operation and improvement: diagnosing technical faults, maintaining service availability, and improving the features of OPERASCH.
6. Data Sharing and Disclosure
We may share personal data in the following circumstances:
6.1 With the school (the Data Controller)
All personal data processed through OPERASCH is accessible to the authorised staff of the school that entered it, in accordance with the role-based permissions the school configures. The school is itself responsible for ensuring it only accesses and uses the data for lawful purposes.
6.2 With our sub-processors
We engage reputable sub-processors to provide specific parts of theOPERASCH service. Each sub-processor is bound by written terms that require them to protect personal data to a standard consistent with Act 843 and to process data only on our instructions. Our current sub-processors are:
- Clerk — provides user authentication and identity management. Clerk processes account credentials (email address, password hashes, multi-factor tokens) and session data necessary for secure sign-in. Clerk’s Privacy Policy applies to the data it processes.
- Cloudinary — provides image and file storage for photographs (e.g. student and staff photos) and documents uploaded to the platform. Files are transmitted to and stored by Cloudinary on our behalf. Cloudinary’s Privacy Policy applies.
- Our hosting and database infrastructure providers — we host OPERASCH on managed cloud infrastructure and use a Prisma-managed database. These providers process only the data necessary to store and serve the application and do not access personal data for their own purposes.
AI-assisted features involve no third-party AI provider. The OPERASCH Assist helper and report-remark drafting use a language model running on infrastructure we operate under our own cloud account. School data is never sent to an external AI service; the model receives only the minimum data needed for the specific task (for example, aggregate dashboard counts, or a single student’s own report figures when drafting a remark that a teacher reviews before publication). AI usage analytics store the question text and school slug only — never a user identifier, and never the model’s answer — and are purged on the schedule in Section 7.
We will update this list whenever a new sub-processor is engaged, giving schools the opportunity to raise objections before any transfer of data.
6.3 To protect rights, safety, and the law
We may disclose personal data where required to do so by law, or where we believe in good faith that disclosure is necessary to: comply with a lawful request from a competent Ghanaian authority; protect the rights, property, or safety of ScalMint, our users, or the public; investigate or prevent fraud; or respond to a verified request from a data subject exercising their rights under Act 843.
6.4 Cross-border transfers
Some of our sub-processors (including Clerk and Cloudinary) may transfer or store personal data outside Ghana. See Section 11 for the safeguards we apply to such transfers in accordance with Section 18(2) of Act 843.
7. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, or reporting requirements under Ghanaian law. This reflects the data retention obligations set out in Act 843, which require that personal data not be kept longer than is necessary.
- Student academic records: retained for the duration of the student’s enrolment and for a period thereafter as required by the school’s record-keeping policy and applicable educational regulations, so that transcripts and academic histories remain available.
- Financial and fee records: retained for the period required by Ghana’s tax and financial laws (typically a minimum of six years) to support audits and tax compliance.
- Audit and security logs: retained for a defined period to support security investigations and accountability, after which they are automatically purged.
- Account credentials and session data: retained for as long as the user’s account is active, and deleted or anonymised shortly after account closure.
On termination of the school’s contract
When a school ends its subscription to OPERASCH, we will, at the school’s choice and subject to the Data Processing Agreement, return the school’s data to it in a portable format and then delete or anonymise that data from our production systems within a reasonable, contractually-defined period. We may retain limited data where required by law (for example, financial records for tax purposes) or to back up our systems securely during the transition.
8. Data Security
Under Section 28 of the Data Protection Act, 2012 (Act 843), we are required to take appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or unlawful processing. We take this duty seriously and implement the following measures:
- Encryption in transit: all data exchanged between your device and OPERASCH is encrypted using Transport Layer Security (TLS).
- Encryption at rest: personal data stored in our database and file storage is encrypted at rest.
- Access controls: access to personal data is role-based and restricted to authorised ScalMintpersonnel who need access to operate and support the platform, and to authorised school staff according to the permissions the school sets.
- Authentication: user authentication is managed by Clerk, which supports multi-factor authentication. We encourage schools to enable MFA for all administrator accounts.
- Audit logging: significant actions within the platform are logged to support accountability and investigation of incidents.
- Regular reviews: we periodically review our security posture, access lists, and sub-processor arrangements, and we apply security updates promptly.
- Staff training and confidentiality: ScalMint’s personnel who handle personal data are subject to confidentiality obligations and receive training on their responsibilities under Act 843.
- Network and infrastructure protection: our infrastructure is configured with firewalls, monitoring, and intrusion detection, consistent with good practice and the Cybersecurity Act, 2020 (Act 1038).
Despite our best efforts, no system can be guaranteed to be completely secure. If a security incident occurs, we will respond in accordance with our incident response plan and our obligations under Section 12 of this policy.
9. Your Data Protection Rights
The Data Protection Act, 2012 (Act 843) gives you, as a data subject, specific rights over your personal data. Because OPERASCH acts as a Data Processor, some of these rights must be exercised through your school (the Data Controller); however, we will assist you and route your request to the right party. The rights include:
- The right to be informed (openness): you have the right to be told, in a clear and accessible way, what personal data is being processed and why. This Privacy Policy is part of how we meet that obligation.
- The right of access (Sections 32–35): you may request a copy of the personal data we hold about you, together with certain information about how it is being processed.
- The right to rectification or correction (Section 33): if personal data we hold about you is inaccurate or incomplete, you may request that it be corrected.
- The right to object (Section 20(2)): you may object to the processing of your personal data on grounds relating to your particular situation, where processing is based on legitimate interests or for direct marketing.
- The right to erasure: in certain circumstances you may request that your personal data be deleted — for example, when it is no longer necessary for the purpose for which it was collected.
- The right to prevent direct marketing (Section 40): you have the right to object to the use of your personal data for direct marketing purposes. We do not use your data for direct marketing, but this right is noted here for completeness.
- The right to lodge a complaint: if you believe your personal data has been processed in breach of Act 843, you have the right to lodge a complaint with the Data Protection Commission of Ghana (see Section 15).
How to exercise your rights
To exercise any of these rights, contact us at mwinisaviour87@gmail.com with a clear description of your request. Where you are a student or a member of staff, your request may also be directed to your school’s administration.
We will respond to verified requests within forty (40) daysof receipt, in accordance with Section 32(10) of Act 843. We may need to verify your identity before disclosing personal data, to protect your privacy.
10. Children’s Data
Because schools handle the personal data of minors, the following safeguards apply:
- Parental or guardian consent: the consent of a parent or legal guardian is obtained by the school before a child’s personal data — including photographs and any biometric data — is processed. The school acts on behalf of, and with the authority of, parents and guardians in this regard.
- The school acts on behalf of parents: the school, as Data Controller, enters and manages children’s data and is responsible for ensuring that the data is necessary and appropriate for the child’s education and welfare.
- Educational purpose only: children’s data is processed solely for the purposes of running the school’s academic, administrative, and welfare functions — not for any independent commercial purpose of ScalMint.
- Restriction on disclosure: in line with Section 62 of Act 843, personal data relating to a pupil at an educational institution shall not be disclosed except where the disclosure is required by or under any enactment, or is made for the purpose of, and is necessary for, the performance of the educational institution’s functions.
- Minimisation: we encourage schools to collect only the children’s data that is genuinely necessary, and to avoid recording sensitive data (such as health details) unless it is needed for the child’s welfare.
If you are a parent or guardian and you believe your child’s data is being processed in a way that is not in their best interests, please contact us at mwinisaviour87@gmail.com or raise the matter with your child’s school.
11. Cross-Border Data Transfers
OPERASCH is operated from Accra, Ghana and serves schools in Ghana. However, some of our sub-processors — including Clerk (authentication) and Cloudinary (image storage) — may transfer or store personal data on infrastructure located outside Ghana. Under Section 18(2) of the Data Protection Act, 2012 (Act 843), such transfers must be made in compliance with the laws of the foreign jurisdiction and must not undermine the protection of the data subject.
To safeguard personal data that may be transferred outside Ghana, we apply the following measures:
- We engage only reputable sub-processors that are subject to recognised data protection obligations in their operating jurisdictions, and we require written assurances that they will protect personal data to a standard consistent with Act 843.
- Our sub-processor contracts include confidentiality, security, and data-protection clauses that flow down our obligations as Data Processor.
- We limit the data transferred to only what is necessary for the sub-processor to provide its service (for example, authentication credentials to Clerk, image files to Cloudinary).
- We review our sub-processors periodically to confirm they continue to meet these standards.
Where a sub-processor’s arrangements change such that data would be transferred to a jurisdiction without an adequate level of protection, we will take steps to implement additional safeguards or, if necessary, to suspend the transfer, and we will inform affected schools.
12. Data Breach Notification
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Under Section 31 of the Data Protection Act, 2012 (Act 843), we are required to notify the Data Protection Commission of Ghana, and in certain cases the affected data subjects, of any personal data breach.
Our approach to data breaches is as follows:
- Detection and containment: we monitor our systems for signs of unauthorised access or misuse, and we act quickly to contain any incident we identify.
- Assessment: we assess the scope and severity of the breach, the types of data involved, and the likely impact on data subjects.
- Notification of the Commission: where a breach is likely to result in a risk to the rights and freedoms of data subjects, we notify the Data Protection Commission of Ghana without undue delay, in accordance with Section 31.
- Notification of affected data subjects: where a breach is likely to result in a high risk to the rights and freedoms of data subjects, we also notify the affected individuals without undue delay, describing the nature of the breach and the steps they can take to protect themselves.
- Notification of the school: because the school is the Data Controller, we will inform the affected school(s) promptly so that they can fulfil their own obligations to their students, parents, and staff.
13. Cookies and Tracking
OPERASCH uses a limited number of cookies and similar technologies to keep you signed in, remember your preferences, and operate the platform securely. We do not use cookies to track you across other websites for advertising.
For full details of the cookies we use, what each does, and how to manage or disable them, please see our Cookie Policy.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the features of OPERASCH, or the requirements of Ghanaian data protection law. When we make material changes, we will update the “Last updated” date shown at the top of this page and, where appropriate, notify schools of the change.
We encourage you to review this policy periodically. Your continued use of OPERASCH after a change to this policy takes effect constitutes your acceptance of the updated policy. Where a change requires fresh consent (for example, a new use of a child’s photograph), we will obtain that consent before proceeding.
15. Contact Us
If you have any questions about this Privacy Policy, about how your personal data is handled, or if you wish to exercise any of your data protection rights, please contact our Data Protection Officer:
- Data Protection Officer, ScalMint
- Email: mwinisaviour87@gmail.com
- Support: mwinisaviour87@gmail.com
- Address: Accra, Ghana
- Website: https://smartsos.cloud
If you are a member of a school community (student, parent, staff), you may also raise your concern with your school’s administration in the first instance.
Complaints to the Data Protection Commission of Ghana
If you believe that your personal data has been processed in breach of the Data Protection Act, 2012 (Act 843), and you have not received a satisfactory response from us or your school, you have the right to lodge a complaint with the Data Protection Commission of Ghana:
- Data Protection Commission
- Pawpaw Street, East Legon, Accra, Ghana
- Email: info@dataprotection.org.gh
- Telephone: +233 256 301 533
- Website: www.dataprotection.org.gh
We will cooperate fully with the Data Protection Commission in the investigation and resolution of any complaint.