1. Introduction
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between School Ledger ("we", "our", "us", the "Data Processor") and the Tenant school subscribing to the platform ("you", the "Tenant", the "Data Controller"), together the "Parties".
This DPA reflects the Data Processor role described in Section 2 of our Privacy Policy and sets out, in binding contractual terms, how personal data submitted to the School Ledger platform is collected, processed, protected, and returned or deleted, in accordance with the Cyber and Data Protection Act [Chapter 12:07] of Zimbabwe (the "Act") and its subsidiary regulations.
Where this DPA conflicts with the Terms of Service on matters of data protection, this DPA prevails. Where this DPA conflicts with the Act, the Act prevails.
2. Definitions
Terms used in this DPA carry the meanings given to them in the Act. For convenience:
- "Act" means the Cyber and Data Protection Act [Chapter 12:07] of Zimbabwe, as amended from time to time.
- "Authority" means the Cyber and Data Protection Authority (the body designated under the Act to regulate and enforce data protection in Zimbabwe, referred to in the Act as the Data Protection Authority).
- "Personal Information" (referred to elsewhere in this DPA as "Personal Data") means information relating to an identified or identifiable natural person (a "Data Subject"), including students, guardians, staff, and platform users, that is processed by School Ledger on the Tenant's behalf.
- "Processing" means any operation performed on Personal Information, including collection, storage, use, disclosure, and deletion.
- "Data Controller" means the person who, alone or jointly with others, determines the purposes and means of processing Personal Information — here, the Tenant.
- "Data Processor" means the person who processes Personal Information on behalf of, and under the instructions of, a Data Controller — here, School Ledger.
- "Sub-Processor" means any third party engaged by School Ledger to process Personal Information on the Tenant's behalf, as listed in Section 9.
- "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Information.
3. Roles of the Parties
The Tenant is the Data Controller, as defined under the Act, for all Personal Information relating to its students, guardians, staff, and other individuals that it inputs into the platform. The Tenant determines the purposes and means of processing that data and is responsible for the lawfulness of its collection (including any consents required from parents or guardians under the Act).
School Ledger is the Data Processor, as defined under the Act, and processes Personal Information solely on the Tenant's documented instructions, as set out in this DPA, the Terms of Service, and the Tenant's ordinary configuration and use of the platform.
4. Subject Matter & Scope
This DPA applies for as long as School Ledger processes Personal Information on the Tenant's behalf in connection with the platform. The subject matter, nature, and duration of processing are as follows:
| Category | Description |
|---|---|
| Subject matter | Provision of the School Ledger school management SaaS platform to the Tenant. |
| Duration | For the duration of the Tenant's active subscription, plus the retention period described in Section 15. |
| Nature of processing | Storage, retrieval, structuring, generation of reports/receipts, and secure transmission of data as directed by the Tenant's use of the platform. |
| Categories of Data Subjects | Students, parents/guardians, teaching and non-teaching staff, and Tenant-authorised platform users. |
| Categories of Personal Information | As listed in Privacy Policy Section 3 — student records, staff records, financial and billing data, transport data, attendance data, and account information. |
5. Lawful Basis for Processing
The Act requires that Personal Information be processed lawfully, fairly, and for specified, explicit purposes. As between the Parties:
- The Tenant, as Data Controller, is responsible for establishing and documenting a lawful basis for collecting and inputting Personal Information into the platform — including obtaining any consent required from parents, guardians, or staff under the Act before doing so.
- School Ledger processes Personal Information strictly to deliver the services the Tenant has subscribed to (student records, billing, attendance, transport, and reporting), and for no incompatible purpose.
- Personal Information is collected and processed only to the extent adequate, relevant, and limited to what is necessary for those purposes, consistent with the data minimisation principle in the Act.
6. Processing Instructions
- School Ledger will process Personal Information only on the Tenant's documented instructions, which are constituted by the Terms of Service, this DPA, and the Tenant's configuration and use of platform features.
- If School Ledger believes an instruction infringes the Act or other applicable data protection law, it will promptly inform the Tenant before carrying it out.
- School Ledger will not process Personal Information for its own purposes, for advertising, or for profiling, and will not sell Personal Information — consistent with Privacy Policy Section 4.
- Access to Tenant data by School Ledger personnel is limited to what is strictly necessary to operate, maintain, and support the platform, and is subject to confidentiality obligations under Section 7.
7. Confidentiality
School Ledger ensures that any personnel authorised to process Personal Information are bound by confidentiality obligations, whether contractual or statutory, and receive appropriate training on handling Personal Information securely before being granted access, consistent with the confidentiality obligations imposed on Data Processors under the Act.
8. Security Measures
In line with the security safeguards required of Data Processors under the Act, School Ledger implements the technical and organisational measures described in Privacy Policy Section 6, including:
- Encryption in transit and at rest — TLS for all data in transit; AES-256 or equivalent for sensitive data at rest.
- Tenant data isolation — application-level tenant filtering combined with database-level Row-Level Security, so that no Tenant can access another Tenant's data.
- Role-based access control — platform users only access data within their assigned role and Tenant; production database access is restricted to authorised personnel and requires multi-factor authentication.
- Audit logging — significant data mutations are logged with user ID, timestamp, and action type.
- Regular backups — data is backed up to geographically redundant storage on a regular schedule.
- Vulnerability and patch management — dependencies and infrastructure are kept current with security patches.
These measures are reviewed periodically and updated as the platform and threat landscape evolve.
8. Sub-Processors
The Tenant provides general authorisation for School Ledger to engage the categories of Sub-Processors described in Privacy Policy Section 5 and 12: cloud infrastructure and hosting providers, transactional email delivery providers, and — where the Tenant enables them — payment gateway integrations (e.g., Paynow).
- All Sub-Processors are bound by written data processing terms that impose data protection obligations no less protective than this DPA.
- School Ledger remains liable for a Sub-Processor's performance of its data protection obligations.
- School Ledger will notify Tenants of any intended addition or replacement of Sub-Processors, giving the Tenant a reasonable opportunity to object on legitimate data protection grounds before the change takes effect.
- Sub-Processors do not access Personal Data for any purpose other than delivering the specific service they were engaged for, and are not permitted to use it for their own purposes.
9. Data Subject Rights
Taking into account the nature of the processing, School Ledger will assist the Tenant, insofar as reasonably possible, in fulfilling its obligation to respond to Data Subject requests to exercise the rights described in Privacy Policy Section 10 (access, correction, portability, erasure, restriction, and objection).
Where a Data Subject contacts School Ledger directly regarding their Personal Data, School Ledger will promptly forward the request to the relevant Tenant and will not respond substantively on the Tenant's behalf, except to acknowledge receipt.
10. Personal Data Breach Notification
- School Ledger will notify the affected Tenant without undue delay, and in any case within 72 hours of becoming aware of a Personal Data Breach affecting that Tenant's data.
- Notification will include, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.
- School Ledger will cooperate with the Tenant and provide reasonable further information as it becomes available to support the Tenant's own regulatory notification obligations, where applicable.
11. International Transfers
Where Personal Data is transferred to, or accessed from, a country outside the Tenant's jurisdiction (including by Sub-Processors under Section 8), School Ledger ensures such transfers are subject to appropriate safeguards, such as standard contractual clauses, an adequacy decision, or an equivalent legally recognised transfer mechanism, and are made only to the extent necessary to deliver the platform.
12. Audits & Compliance
Upon reasonable written request, and no more than once per year (except following a Personal Data Breach), School Ledger will make available to the Tenant information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant security measures and audit reports where available.
Where a documentary review is insufficient, the Parties will agree on the scope, timing, and confidentiality terms of an on-site or remote audit, conducted in a manner that minimises disruption to School Ledger's operations and other Tenants' data.
13. Return & Deletion of Data
- The Tenant may export its data in machine-readable format (CSV/JSON) at any time via the platform's export tools, consistent with Privacy Policy Section 10.
- Upon termination of the Tenant's subscription and at the Tenant's request, School Ledger will delete or return all Personal Data processed on the Tenant's behalf, except where retention is required by applicable law.
- Absent a specific request, Tenant data associated with a terminated subscription is retained for a limited grace period to allow for reactivation or export, after which it is permanently deleted in line with our standard retention schedule.
- Backups containing deleted Tenant data are purged in the ordinary backup rotation cycle following deletion.
14. Liability
Each Party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Nothing in this DPA relieves either Party of its own direct obligations under applicable data protection law.
15. Term & Termination
This DPA takes effect on the date the Tenant first accepts the Terms of Service and remains in effect for as long as School Ledger processes Personal Data on the Tenant's behalf. It terminates automatically upon completion of the deletion or return of data described in Section 13, without prejudice to any provisions that by their nature should survive termination (including confidentiality and liability).
16. General Provisions
- This DPA is incorporated into, and governed by the same governing law and jurisdiction clauses as, the Terms of Service.
- If any provision of this DPA is found unenforceable, the remaining provisions continue in full force and effect.
- We may update this DPA to reflect changes in our practices, sub-processors, or legal requirements, following the same notice process described in Privacy Policy Section 13.
17. Contact Us
For questions about this Data Processing Agreement, or to request a countersigned copy for your records, please contact us:
If you are unsatisfied with our response, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.