Skip to main content
Privacy

Privacy policy

This policy explains what IEMS does with the information a school entrusts to it — in the web platform and in the IEMS mobile app — and what you can ask for.

On this page

Last updated 22 August 2026

Who this policy is from

IEMS is operated by VitalClick Technologies (Pty) Limited. It covers the IEMS platform at iems.africa, every school’s own site on that domain, and the IEMS mobile app for Android and iOS. Write to privacy@iems.africa about anything in this policy.

Your school decides; we carry it out

Your school is the responsible party for its learners’ and staff’s information — the controller, in European terms. It decides what is recorded, who at the school may see it and how long it is kept. IEMS is the operator: we hold and process that information on the school’s written instruction, under a data processing agreement signed with the school, and for no purpose of our own.

That split answers most questions about your own record. We cannot show you your child’s marks, change an attendance mark or delete a learner on request, because those are the school’s decisions and its records. Ask your school first; if it needs us, it will ask us.

What is held

A school switches on only the modules it needs, so not every school holds every category below. Categories marked as special are treated as special personal information under POPIA and its equivalents, and are restricted to specific roles rather than to staff in general.

  • Identity and contact — name, role, school, learner or staff number, email address, phone number, date of birth, photograph, and a national identity number where the school records one.
  • Academic — classes, subjects, timetable, attendance, marks, assessments, reports and conduct remarks.
  • Family — the link between a learner and their guardians, and the relationship recorded for each.
  • Financial — fee accounts, invoices, payments, exemptions and wallet balances.
  • Medical (special) — allergies, chronic conditions, medication, immunisations and clinic visits, where a school runs the medical module.
  • Pastoral (special) — incidents, counselling records, referrals and disciplinary matters, where a school runs the pastoral module.
  • Biometric (special) — see the section on fingerprint attendance below, which is the one place this platform deliberately holds less than it could.
  • Technical — the times you sign in, the IP address a consent or an administrative action was recorded from, the app version in use, and an entry in an audit log for every change to a sensitive record.

Where it comes from

Almost all of it comes from your school, which enters it or imports it from the records it already keeps. Some comes from you: an admission application, a message you send, a consent you record, a register a teacher marks. A small amount comes from the device you use, described under the app section below. We do not buy personal information, and we do not obtain it from data brokers, social networks or public scraping.

Why it is held

To run the school: enrol learners, take registers, record marks, produce reports, bill fees, and let a school reach the right guardian at the right time. Every use traces back to the school’s instruction. We do not profile learners, we do not sell personal information, we do not use it to target advertising, and we do not train machine-learning models on it.

We send messages on the school’s behalf — an absence alert, a fee reminder, a notice from the principal — through email, SMS, WhatsApp or a push notification, depending on what the school has enabled and what you have chosen to receive. IEMS itself writes to a school’s administrators about the service and its billing.

The mobile app

The app holds no advertising SDK, no analytics SDK and no crash-reporting SDK. Nothing on your device reports your behaviour to us or to anyone else, and there is no tracking across other companies’ apps or sites. What the app keeps is kept on the device:

  • Your signed-in session, in the device’s own protected storage — the Keychain on iOS, the Keystore on Android.
  • A copy of your class registers, so a teacher can mark a register with no signal at all. It is stored in the app’s private storage, scoped per school, and syncs when the network returns. Signing out clears it.
  • A push token, if you allow notifications, so the school’s messages can reach your device. It is registered per school and removed when you sign out of that school.
  • If you lock the app with Face ID or a fingerprint, the check happens entirely on your device and returns nothing more than a yes or a no. Your face and fingerprint never leave the device, never reach IEMS, and are never stored by us.
  • The app asks for no location, camera, microphone, contacts or photo-library access. Uninstalling it removes everything it kept on the device; it does not remove your record at your school, which is the school’s to keep or erase.

Fingerprint attendance, where a school uses it

Some schools clock arrival and departure with a fingerprint scanner at the gate. That system is built so the sensitive part never reaches us: the fingerprint template is created and matched on the scanner itself and stays there. What reaches IEMS is the result — that a named learner or staff member arrived or left, at a time, at a device. We do not hold, transmit or store a fingerprint image or any template from which one could be reconstructed.

A learner cannot be enrolled on a scanner without a guardian’s recorded consent, which the school captures with the guardian’s name, the time and the address it was given from. Withdrawing consent deletes that learner’s template from every school device and stops the scanning; a teacher-marked register takes over. Staff give consent for themselves. Grant, withdrawal and re-grant are all written to the audit log.

Where it is stored

Today the platform’s database and its uploaded documents are hosted in the European Union, in France. We say so plainly because it is the question schools ask most and the one most often answered vaguely: the data is not currently hosted in Africa.

Cross-border storage is lawful on that basis. POPIA does not require that South African personal information stay in South Africa; section 72 permits transfer to a jurisdiction whose law offers substantially similar protection, and EU law under the GDPR does. Nigeria’s NDPA, Ghana’s Data Protection Act and Kenya’s Data Protection Act each allow transfer on a comparable footing.

We intend to move the platform to South Africa, and this page will be changed when it happens rather than in advance of it. Where a school’s own regulator requires storage in its country, tell us before signing — that is a contractual matter, not something this policy can decide for you.

Who else sees it

Inside your school, only the roles the school has granted access. Nobody at another school can see it: each school’s data is isolated in the platform and enforced again in the database itself, so a query that names the wrong school returns nothing rather than the wrong answer.

Outside it, we use a small number of suppliers to run the service — hosting and database, document storage, email delivery, SMS and WhatsApp delivery, push notification delivery through Apple and Google, and a payment provider for the school’s own subscription to IEMS. Each is bound by contract to process only on our instruction. The current list is part of every school’s data processing agreement and is available from privacy@iems.africa.

We do not sell personal information, share it with advertisers or data brokers, or disclose it to anyone else except where a school instructs us to, or where a law or a court order compels us. If we are compelled, we tell the school unless we are forbidden to.

How long it is kept

For as long as your school needs it. School records carry statutory retention periods — financial records, academic results and disciplinary matters typically for years after a learner leaves — and the school, not IEMS, decides when its retention period has run. The audit log is kept for at least seven years. When a school leaves the platform, its data is exported to it and then deleted on the schedule in its agreement.

Deleting a record inside the platform usually marks it deleted rather than erasing it immediately, so that a mistaken deletion can be undone and an audit trail survives. Permanent erasure is a separate, deliberate step.

Your rights

You may ask what is held about you, ask for it to be corrected, ask for it to be deleted, object to a use of it, and complain to your country’s regulator. Because your school is the responsible party, the fastest route is your school’s office, which can act on most requests the same day. If your school asks us, we help it; if you write to privacy@iems.africa directly, we pass the request to your school and tell you we have.

The regulators are the Information Regulator in South Africa, the Nigeria Data Protection Commission, the Data Protection Commission in Ghana and the Office of the Data Protection Commissioner in Kenya.

Accounts and deletion

You cannot create a IEMS account yourself. Schools issue accounts to their staff, learners and guardians, and there is no self sign-up in the app or on this site. That is why the app offers no delete-my-account button: the account is not yours to create, and deleting a learner’s record is a decision with academic and legal consequences for the school that holds it.

To have your account closed and your personal information erased, ask your school, or write to privacy@iems.africa and we will route it to your school and follow up. Records the school must keep by law are retained for their retention period and nothing more is done with them.

Children

Most learners on this platform are children, and their information is handled as such. A guardian’s consent stands behind the processing of a learner’s information, and anything sensitive is gated on it being recorded rather than assumed: a learner cannot be enrolled on a fingerprint scanner without it, and features that would show a child’s details to the whole school rather than to the staff who teach them are off until a guardian turns them on. Learners under 13 are not given their own logins. We do not advertise to children, profile them, or use their information for any purpose beyond their school’s.

How it is protected

Everything travels over TLS and is encrypted where it is stored. Access follows the role your school gave you, and is checked on every request rather than only in the screen you are looking at. Identity numbers, medical detail and pastoral notes are encrypted a second time at the application layer, so reading them needs the running service and not merely the database. Sessions are short-lived and refresh tokens are rotated, so a stolen one stops working and its whole family is revoked. Every change to a sensitive record is written to an immutable audit log with the person and time behind it.

No system is beyond compromise. If personal information is breached we notify the affected schools and the relevant regulator as the law requires, with what we know and what we are doing about it.

Changes to this policy

We will change this page when the service changes — including when the hosting move above happens. The date at the top is the date of the current version. Material changes are also sent to the school administrators on each account.

Contact

Privacy questions and requests: privacy@iems.africa. Anything else: support@iems.africa. Post reaches us through VitalClick Technologies (Pty) Limited; ask for the registered address and the details of our information officer and we will send them.