Legal

Privacy Policy

How SomaPlus Learning Management Systems collects, uses, stores, shares and protects personal data across our website, our school management platform and the SomaPlus mobile applications.

Effective date: 27 August 2026 Version 3.0

In short

  • Your school owns its data. We hold and process it on the school's instructions.
  • We never sell personal data. We show no adverts and we do not track you across other apps or websites.
  • Data is encrypted with AES-256 and TLS, access is role-restricted, and every school's records are kept separate.
  • You can request access, correction or deletion at any time — see Account and data deletion.

What this policy covers

This policy applies to the somaplus.net website, the SomaPlus School Management System web platform, and the SomaPlus mobile applications published by SomaPlus Learning Management Systems Ltd on Google Play and the Apple App Store (together, the "Services"). It is the privacy policy referenced in our Google Play Data safety declaration and our Apple App Privacy details, and it applies to every version of the app on both stores.

1. Who we are

SomaPlus Learning Management Systems Ltd ("SomaPlus", "we", "us") provides a school management system used by schools to run academics, finance, communication and day-to-day operations. We are the developer and publisher of the SomaPlus mobile applications and the operator of somaplus.net.

You can reach us at info@somaplus.net or at our offices on Mombasa Road, Syokimau, Kenya. Full contact details are in section 19.

2. The laws we work under

Our data protection programme is built to satisfy the data protection regimes across the markets we serve:

  • The Kenya Data Protection Act, 2019 and its regulations
  • The EU General Data Protection Regulation (GDPR)
  • The South Africa Protection of Personal Information Act (POPIA)
  • The Uganda Data Protection and Privacy Act, 2019

Where children's data is involved we also observe the Children's Online Privacy Protection Act (COPPA) where it applies, the Google Play Developer Programme Policies including the Families policy, and the Apple App Store Review Guidelines.

3. Controller and processor roles

The distinction matters because it determines who you should contact about your data.

Your school is the data controller

For student, parent and staff records entered into the platform, the school decides what is collected and why. We act as its data processor under a written processor agreement and act only on its documented instructions. Requests about those records should go to the school first.

SomaPlus is the data controller

For data you give us directly — demo bookings, contact and sales enquiries, support conversations, newsletter sign-ups, app crash reports and website analytics — we decide the purpose, so you can contact us directly.

4. Information we collect

a. Information you give us directly

  • Name, job title, school name, email address and phone number
  • Account credentials, stored only as a salted one-way hash — we never see your password
  • Demo and booking details, including your preferred date and time
  • The content of enquiries, support tickets and live chat conversations

b. School data processed on your school's behalf

  • Student records: names, admission numbers, class and stream, dates of birth, guardian contacts
  • Academic records: attendance, assessment scores, reports and transcripts
  • Finance records: fee structures, invoices, payments and balances
  • Staff records: employment details, roles and platform permissions
  • Photographs, where a school stores student or staff profile images
  • Health, disciplinary or welfare notes, where a school chooses to record them

Some of this is sensitive personal data, and much of it belongs to children. We treat it accordingly — see sections 8 and 9.

c. Information collected automatically

  • IP address, browser and device type, operating system and app version
  • Pages or screens visited, referring pages and time spent, for analytics
  • Crash reports and diagnostic logs, used to fix faults in the apps
  • Security and audit logs recording sign-ins and significant actions
  • A device push notification token, if you enable notifications

We do not collect precise location, contacts, calendar, call logs, SMS content, microphone audio, or any advertising identifier.

5. Mobile app permissions

The SomaPlus apps request device permissions only when a feature needs them, and each is optional — declining one disables only that feature, never the app. You can change or revoke any permission at any time in your device settings.

Permission Why we ask
Camera To take a profile photo or scan a code. Images upload only when you confirm.
Photos and files To attach documents or images to a record, and to save reports you download.
Notifications To deliver fee reminders, results announcements and school messages.
Network access To sync your data securely with the SomaPlus platform.

6. How we use information

  • To provide, operate and support the Services for your school
  • To authenticate you and keep your account secure
  • To respond to enquiries, schedule demos and provide customer support
  • To send the notifications and school communications you or your school have enabled
  • To secure the Services, investigate incidents and prevent fraud or abuse
  • To diagnose crashes and improve reliability, using aggregated or de-identified usage data
  • To meet legal, accounting and regulatory obligations

We do not sell, rent or lease personal data. We display no advertising, we build no advertising profiles, and we do not track users across other companies' apps or websites. Our iOS apps therefore do not request App Tracking Transparency permission, because no tracking takes place.

7. Legal basis for processing

Depending on the data, we rely on:

  • Contract — to deliver the Services under our agreement with your school
  • Consent — for marketing emails, push notifications and non-essential cookies, withdrawable at any time
  • Legal obligation — where retention or disclosure is required by law
  • Legitimate interests — to keep the Services secure and to improve them, balanced against your rights

8. Children's data

A school management system necessarily holds records about learners under 18. We process children's data only on the documented instructions of the school, which is responsible for obtaining any consent required from a parent or guardian under applicable law.

  • Children's data is never used for marketing, advertising, profiling or tracking
  • We do not knowingly collect personal data directly from a child through our website
  • Student accounts, where a school issues them, are created and controlled by the school
  • Our apps contain no third-party advertising SDKs and no analytics that profile children
  • A parent or guardian may ask the school, or us, to review or delete their child's data

The SomaPlus apps are designed for school administrators, teachers, parents and guardians. Where a school makes an app available to students, it is operated under that school's authority and in line with the Google Play Families policy and Apple's requirements for apps used by children.

9. Security

We take the security of personal data seriously and apply layered technical and organisational measures, benchmarked against CIS, NIST, ISO 27001 and the OWASP Top 10:

  • All traffic encrypted in transit using HTTPS and TLS 1.2 or higher
  • AES-256 encryption for data in transit and at rest, including backups
  • Passwords stored only as salted one-way hashes
  • Role-based access control, so users see only what their role requires
  • Logical separation of each school's data, and network segregation between the external, application and database layers
  • Firewalled network perimeter with intrusion detection and prevention
  • Audit logging of sign-ins and significant record changes
  • Code obfuscation and secure coding practices in our mobile applications
  • Regular backups with periodic restore testing
  • Monthly vulnerability assessments and annual penetration testing
  • Staff access restricted to those who need it to operate or support the Services

No system can be guaranteed completely secure. If a breach affects your personal data, we will notify the affected school, the Office of the Data Protection Commissioner, and affected individuals, within the timeframes the law requires.

10. Sharing and disclosure

We share personal data only with:

  • Service providers who help us run the Services — hosting, email delivery, SMS gateways, push notification delivery, payment processors, crash reporting and support tooling. Each is bound by a written processor agreement, is subject to due diligence, and may use the data only to provide their service to us.
  • Your school and the users it authorises
  • Regulators, courts or law enforcement where we are legally required to do so
  • A successor entity in the event of a merger or acquisition, subject to this policy

We do not share personal data with data brokers or advertising networks, and we do not give any third party permission to use it for their own purposes.

11. International transfers

Personal data is primarily stored and processed in Kenya. Where data is transferred outside your operational jurisdiction, we apply safeguards required by the Kenya Data Protection Act, 2019, the GDPR, POPIA and the Uganda Data Protection and Privacy Act, as applicable. Transfers are carried out over encrypted and secure communication channels and are covered by contractual data protection terms.

12. Data retention

We keep personal data no longer than necessary for the purpose it was collected. School data is retained while the school's account is active, and afterwards only for the period agreed with the school or required by law, such as statutory academic and financial record-keeping. On termination, a school may request a full export of its data, after which we delete or anonymise it within the agreed window. Enquiry and marketing records are kept only as long as needed. Crash and diagnostic logs are retained for up to 90 days.

13. Account and data deletion

You may request deletion of your SomaPlus account and the personal data associated with it at any time, whether you signed up on the web or through our mobile apps. There is no charge.

In the app

Open Profile → Settings → Delete account and confirm. No separate request is needed.

By email

Write to info@somaplus.net from the address on your account, with the subject "Account deletion request". We verify your identity before acting on the request.

What happens next

  • Your account, profile and login credentials are deleted
  • Personal data linked to your account is deleted or irreversibly anonymised within 30 days
  • Copies held in encrypted backups are erased within 90 days as backups rotate
  • We keep only what the law requires us to retain, such as financial transaction records, and nothing further

If your account was created for you by a school, that school controls the underlying student, academic or staff record. We will delete your personal account, and pass any request to erase the school-held record to the school, which decides as the controller.

14. Your rights

You have the right to:

  • Know what personal data we hold about you and the purposes of the processing
  • Know the categories of data concerned and the recipients it has been or will be disclosed to
  • Know how long we intend to store it, and its source if we did not collect it from you
  • Have incomplete or inaccurate data corrected or completed
  • Request erasure of your personal data, or restriction of processing, where the law allows
  • Object to processing, including any direct marketing from us
  • Be informed about any automated decision-making we use
  • Receive a copy of your data in a portable format
  • Withdraw consent at any time, without affecting processing already carried out
  • Lodge a complaint with a supervisory authority or seek a judicial remedy

Where the data sits in a school's account, please contact the school, as it is the controller, and we will support the school in responding. Otherwise, write to info@somaplus.net. We respond to subject access requests within 30 days and free of charge. You may also lodge a complaint with the Office of the Data Protection Commissioner of Kenya, or with the supervisory authority in your own jurisdiction.

15. Cookies and similar technologies

On the web we use cookies that are strictly necessary to keep you signed in and to secure sessions, plus analytics cookies that help us understand how the site is used. You can block or delete cookies in your browser settings, though disabling essential cookies will prevent parts of the platform from working. Our mobile apps use local device storage for the same purposes and do not use advertising identifiers.

16. Third-party links and tools

Our Services include third-party components, such as our live chat widget, push notification delivery and crash reporting, and may link to other websites. We do not control how those parties handle data within their own services, and this policy does not apply to them. Please review their privacy statements.

17. Marketing preferences

If you have opted in to updates from us, you can opt out at any time using the unsubscribe link in any email, by turning off notifications in the app, or by writing to us. We will continue to send essential service notices about your account.

18. Changes to this policy

We may update this policy as the Services or the law change. The effective date at the top always reflects the current version, and we will notify schools and app users of material changes before they take effect.

19. Contact us

Questions about this policy, or about how your data is handled, can go to our IT Risk and Compliance team:

Office

Eens Business Park, Mombasa Road

Syokimau, Kenya