EduPace Privacy Policy

Version 2.0 · Effective 30 July 2026

This Policy replaces all previous versions.

HashData (Pty) Ltd ("HashData," "we," "us," or "our"), a private company incorporated in the Republic of South Africa, provides the EduPace school and curriculum management platform ("EduPace" or the "Service"). This Privacy Policy explains what personal information is processed through EduPace, why, on what legal basis, who it is shared with, how long it is kept, and what rights data subjects have.

It is written to meet the openness requirements of sections 17 and 18 of the Protection of Personal Information Act 4 of 2013 ("POPIA") and should be read together with the EduPace Terms and Conditions, clause 6 of which contains the operator agreement required by section 21 of POPIA.

Read this first: who is responsible for what

EduPace is used by schools, not by learners or parents directly. That gives two different relationships under POPIA:

  • Your school is the responsible party for learner, guardian and staff records. The school decides what is captured and why. HashData is only the operator — we host and process that information on the school's instructions and never for our own purposes. If you are a parent, guardian, learner or employee and you want access to, correction of, or deletion of a school record, contact the school. We will help the school respond, but we may not act on its records without its instruction.
  • HashData is the responsible party for the account, billing, support and website-visitor information of the people who deal with us directly. Those requests come to us, using the contact details in section 13.

Contents

  1. Definitions and the laws that apply
  2. Information Officer and PAIA
  3. What personal information we process
  4. Special personal information and children's information
  5. Where the information comes from
  6. Why we process it and our lawful basis
  7. Cookies and similar technologies
  8. Who we share information with
  9. Where information is stored and cross-border transfers
  10. How we keep information secure
  11. How long we keep information
  12. Your rights and how to exercise them
  13. Contact us and the Information Regulator
  14. Changes to this Policy

1. Definitions and the laws that apply

Terms such as personal information, special personal information, data subject, responsible party, operator, processing, competent person and de-identify bear the meanings given to them in POPIA.

The South African laws most relevant to EduPace are:

  • Protection of Personal Information Act 4 of 2013 (POPIA) and the POPIA Regulations, 2018 — how personal information may be processed.
  • Promotion of Access to Information Act 2 of 2000 (PAIA) — the right of access to records.
  • Electronic Communications and Transactions Act 25 of 2002 (ECTA) — electronic agreements, supplier disclosure and the protection of personal information collected electronically.
  • Children's Act 38 of 2005 — the best interests of the child, and the duty on teachers and other professionals under section 110 to report suspected abuse or neglect.
  • South African Schools Act 84 of 1996 and the National Education Policy Act 27 of 1996 — the school's own duties to keep learner records and report to the Department of Basic Education, including through LURITS and provincial systems such as CEMIS.
  • Employment Equity Act 55 of 1998 and the Basic Conditions of Employment Act 75 of 1997 — employment records and equity reporting for school staff.
  • Consumer Protection Act 68 of 2008, the Companies Act 71 of 2008, the Tax Administration Act 28 of 2011 and the Value-Added Tax Act 89 of 1991 — billing records and their retention.
  • Cybercrimes Act 19 of 2020 — offences relating to unauthorised access to data and computer systems.

2. Information Officer and PAIA

  • HashData has designated an Information Officer as required by sections 55 and 56 of POPIA. All privacy and access requests should be addressed to the Information Officer at info@edupace.co.za.
  • HashData is a private body for PAIA purposes and maintains a PAIA manual in terms of section 51, which is available free of charge on request from the Information Officer.
  • Each school using EduPace has its own Information Officer — ordinarily the principal — who is responsible for the school's own records.

3. What personal information we process

The categories below reflect what EduPace is actually built to store. Not every field is used by every school; schools choose which modules to activate and which optional fields to complete.

3.1 Learners

  • Identity: first, middle and last names; South African identity number (or an indicator that the learner is a foreign national); CEMIS / EMIS / LURITS number; admission number; date of birth; gender.
  • Placement: grade, phase, class, year in grade, learner type, and subject enrolment.
  • Photograph: a learner profile photo and photographs used on reports, where the school chooses to upload them.
  • Academic: baseline and term marks, assessment criteria selections, curriculum differentiation, educator and report comments, progression and DBE schedule comments, certificates, and requested learner adjustments together with who reviewed them.
  • Attendance: daily attendance status, the date, free-text notes, and any supporting document uploaded to substantiate an absence.
  • Behaviour: merit and demerit records, the category and value, the date, the staff involved, and free-text notes and narrative.

3.2 Parents, guardians and authorised persons

  • Names, relationship to the learner, identity or passport number, home, work and mobile numbers, email address, occupation, employer and physical address.
  • For persons authorised to collect a learner: name and contact details.
  • Records of contact with parents captured in a learner's support plan, including meeting dates, attendance, feedback and agreed responsibilities.

3.3 School staff

  • Identity and contact: title, names, initials, identity number, date of birth, gender, photograph, personal and work email addresses, home and cellular numbers, fax, and physical address.
  • Employment: designation, whether the person is an educator, date joined and left, employer, contract type, PERSAL number, SACE registration number, tax reference number, and the phase or class to which they are assigned.
  • Family and emergency: spouse name and telephone number, and up to two emergency contacts (name, number and relationship).
  • Teaching allocations: subjects, grades and classes taught, assessment setup responsibilities, and approvals given.

3.4 User accounts

  • Name, email address, hashed password, email-verification status, profile photograph, assigned roles and permissions, dashboard preferences, and the date the account was invited.
  • Sign-in and technical records: the date and time of each sign-in and the IP address used, together with session records containing IP address and browser user-agent.
  • Audit trail: EduPace keeps an audit record of who created, changed or deleted a record, when, from which IP address and on which screen — including the values before and after the change. Passwords and authentication tokens are excluded from the audit trail.

3.5 School and billing information

  • School name, EMIS number, circuit, address, telephone, email, contact person, emblem and stamp.
  • Subscription and plan selections, invoices, payment references, amounts, payment status, and any proof of payment uploaded for an electronic funds transfer.
  • We do not receive or store full card numbers, CVV codes or PINs — card details are entered on and held by our payment gateway.

3.6 Support interactions

  • Messages you send us by email or through the in-app support widget, together with your name, email address and the page you were on when you started the conversation.

4. Special personal information and children's information

EduPace is built for special needs schools, so it necessarily handles categories that POPIA treats as special personal information under section 26, and it handles them almost entirely about children. We set this out plainly because it carries the highest obligations for both the school and for us.

4.1 Special personal information processed

  • Health, wellbeing and disability — learners: recorded disabilities and barriers to learning; risk factors such as epilepsy, diabetes, asthma or cardiac conditions; allergies; medication, including medication administered at school; medical aid scheme and membership number; treating doctor, school nurse and hospital details; vision and hearing screening results and assistive devices; psychological and psychometric assessment results, including test type, administrator, date and IQ scores; therapy records for psychotherapy, occupational therapy, physiotherapy, speech therapy and general learner support, including barriers, goals, results, action plans, session counts and clinical notes; social-services involvement, including social worker, social grant status and reported challenges; and personal-care dependency such as bathroom assistance and communication needs.
  • Health — staff: medical aid scheme and number, doctor name and number, and any medical condition recorded by the school.
  • Race: recorded for learners and staff, principally to enable schools to meet departmental reporting duties and, for staff, employment equity obligations.
  • Religious or philosophical beliefs: a learner's religion, where the school captures it.
  • Trade union membership: recorded for staff members.
  • Supporting documents: files uploaded to substantiate an absence (which are frequently medical notes) and documents attached to a learner's Individual Support Plan.

EduPace does not collect biometric templates (photographs are stored as ordinary images, not converted into biometric identifiers), and it has no fields for criminal convictions or alleged offences.

4.2 The lawful basis for special personal information

  • Section 26 of POPIA prohibits processing special personal information unless an authorisation in section 27 or sections 28 to 33 applies.
  • For learner health information, schools ordinarily rely on section 32 of POPIA, which permits schools to process information concerning a learner's health where it is necessary to provide special support or to make special arrangements in connection with their health — precisely the purpose of the Individual Support Plan module.
  • Race and trade union membership for staff are processed on the basis of the school's obligations and rights in labour and employment equity law, or with the employee's consent.
  • Where no statutory authorisation applies, the school must obtain the explicit consent of the data subject or their competent person.
  • Everyone who processes special personal information is bound by a duty of confidentiality (section 27(1)(f) of POPIA), and EduPace restricts access to it through role-based permissions.

4.3 Children's information

  • Section 34 of POPIA prohibits processing the personal information of a child unless an authorisation in section 35 applies — most commonly the prior consent of a competent person (a parent or legal guardian), or where processing is necessary to establish, exercise or defend a right or obligation in law, or to comply with an international-law obligation.
  • Obtaining and recording that consent is the school's responsibility. EduPace does not collect consent from parents directly and does not provide a consent-capture feature; schools should obtain and retain consent through their own admission and support processes, and must be able to demonstrate it on request.
  • All processing of children's information through EduPace must serve the best interests of the child as required by the Children's Act 38 of 2005.
  • Learners do not have EduPace accounts and cannot sign in. No information is collected directly from a child through the Service.
  • Nothing in this Policy limits the duty on educators and other professionals under section 110 of the Children's Act to report suspected abuse or deliberate neglect of a child to the designated authorities.

5. Where the information comes from

  • From the school. Nearly all learner, guardian and staff information is captured or imported by school staff. Section 12 of POPIA requires collection directly from the data subject wherever practicable; where a school captures information about a parent, guardian or emergency contact from someone else, the school must ensure that person is notified as section 18 requires.
  • From you. Account, billing and support information you give us directly when registering, subscribing or asking for help.
  • Automatically. Sign-in records, session data, audit entries and technical information generated as the Service is used.
  • Derived. Date of birth and gender may be derived from a South African identity number during capture or import; this is done locally within EduPace and no identity number is sent to any outside service for verification.
  • Public registries. School details may be checked against a departmental EMIS reference lookup.

6. Why we process it and our lawful basis

Section 11 of POPIA requires a justification for every processing activity. Ours are:

Purpose Justification under section 11
Providing curriculum, assessment, attendance, behaviour and learner support functionality to the school Necessary to perform our contract with the school (s11(1)(b)); for the school, necessary for the proper performance of its public-law duty or its legitimate interests (s11(1)(c) and (f))
Providing special support and making special arrangements for learners (Individual Support Plans) Section 32 authorisation for health information, or the consent of a competent person (s11(1)(a) read with s35)
Statutory reporting, DBE schedules, promotion and progression records Compliance with an obligation imposed by law (s11(1)(c))
Creating accounts, authenticating users and controlling access Performance of the contract (s11(1)(b))
Billing, invoicing, VAT and financial record-keeping Performance of the contract and compliance with tax and company law (s11(1)(b) and (c))
Security, audit logging, fraud prevention and troubleshooting Our and the school's legitimate interests in a secure service, and the security safeguards required by s19 (s11(1)(f))
Support, onboarding and service communications Performance of the contract and legitimate interests (s11(1)(b) and (f))
Improving the Service using anonymised, aggregated statistics Not personal information once de-identified, so POPIA does not apply (s6(1)(b))

We do not use learner, guardian or staff information for advertising, and we never sell personal information.

6.1 Direct marketing

  • Section 69 of POPIA restricts unsolicited electronic direct marketing. We send marketing communications only to school representatives who are existing customers or who have asked to hear from us, always about our own similar products, and every message contains an unsubscribe link.
  • We never send marketing to parents, guardians or learners.

6.2 Automated decision-making

  • EduPace calculates totals, averages, percentages and progress indicators, and flags matters such as outstanding capture or repeated absence for a person to look at.
  • These are calculations and prompts, not decisions. No decision with legal consequences for a learner — such as promotion, progression or placement — is made automatically by EduPace; each is made by school staff, as section 71 of POPIA requires.

7. Cookies and similar technologies

EduPace uses only the cookies it needs to work. We do not use advertising cookies, and we do not run analytics or tracking software.

Cookie Purpose Duration
edupace_session Keeps you signed in and links your browser to your session. Encrypted, HTTP-only, secure and same-site. 120 minutes of inactivity
XSRF-TOKEN Protects against cross-site request forgery when submitting forms. Session
remember_web_* Set only if you choose "remember me" at sign-in. Until you sign out or it expires
Support widget Our in-app support chat may set its own cookies or local storage to keep a conversation open. Set by the provider

All of these are strictly necessary for the Service to function or are set only at your election. Blocking them in your browser will prevent you from signing in. Our public web pages also load a web font from Google Fonts, which means Google receives your IP address and browser type when the page loads; no cookie is set by that request.

8. Who we share information with

We do not sell personal information and we do not share it for anyone else's marketing. We use the following operators (sub-processors), each bound to process information only on our instructions and to keep it secure:

Provider What it does What it can access
Amazon Web Services Stores uploaded files — learner and staff photographs and support-plan documents Encrypted, private file storage in the Cape Town region
Amazon Simple Email Service Delivers transactional email such as verification, password reset, approval requests and billing notices Recipient name and email address, and the content of that email
Paystack Processes card payments for subscriptions Payer and school billing details and card data entered on its own secure page; we receive only the reference, status and amount
KiraDesk Provides the in-app support chat widget The signed-in user's name and email address, the page being viewed, and whatever is typed into the chat
Google Fonts Serves the web font used on our public and sign-in pages IP address and browser type only — no account or school data

Reports and PDFs are generated on our own servers; no learner information is sent to an outside service to produce them.

We may also disclose personal information:

  • to the school that owns the records, and to the users it has authorised;
  • to our professional advisers (auditors, accountants, attorneys) under a duty of confidentiality;
  • where required by law, a court order, or a lawful request from a regulator or law-enforcement agency — we notify the school first unless the law forbids it; and
  • to a successor in a merger, acquisition or sale of business, with prior notice to affected schools, and on terms no less protective than this Policy.

9. Where information is stored and cross-border transfers

  • EduPace's database and uploaded files are hosted in the Republic of South Africa. Files such as learner and staff photographs and support-plan documents are stored in Amazon Web Services' Cape Town region (af-south-1) in a private bucket.
  • A small number of supporting services may process limited information outside South Africa — principally our support chat provider, the payment gateway, and the font service described in section 7. What each can access is set out in section 8.
  • Where personal information is transferred outside South Africa, we ensure a ground in section 72 of POPIA is met — ordinarily a binding written agreement requiring the recipient to uphold principles of protection substantially similar to POPIA's, and not to transfer the information onward without equivalent protection.
  • We do not transfer learner health information, support-plan content or other special personal information about children to any recipient outside South Africa.

10. How we keep information secure

In line with section 19 of POPIA we maintain appropriate, reasonable technical and organisational measures, including:

  • encryption of information in transit over public networks, and encrypted, HTTP-only, secure, same-site session cookies;
  • salted one-way hashing of passwords — nobody at HashData can read or recover your password — with minimum-strength requirements and mandatory email verification before access;
  • role- and permission-based access control, so teachers see their own classes and subjects while principals and heads of department see what their role requires;
  • strict separation of each school's data, applied automatically at the database query level, so one school can never see another's records;
  • private storage for uploaded documents and photographs, retrievable only through short-lived expiring links;
  • an audit trail of changes, and records of sign-ins including IP address, to support accountability and investigation;
  • protection against cross-site request forgery, rate limiting on sensitive endpoints, signature verification of payment callbacks, and a restrictive cross-origin policy; and
  • regular backups of the production database.

10.1 If something goes wrong

  • If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will notify the affected school without undue delay, with enough detail for it to meet its own duties to the Information Regulator and to affected data subjects under section 22 of POPIA.
  • Where HashData is the responsible party — for account, billing and support information — we notify the Information Regulator and affected data subjects ourselves.
  • Schools must keep their own devices, networks and user credentials secure, remove access promptly when staff leave, and tell us at once if they suspect an account has been compromised.

11. How long we keep information

Section 14 of POPIA requires that records not be kept longer than necessary for the purpose they were collected for, unless a law requires otherwise. Our approach:

  • While a school subscribes, its records are kept so that they remain available across school years — academic histories, attendance and support plans are of continuing value to the learner and are typically required by the school's own record-keeping duties under the South African Schools Act and provincial policy.
  • Deletion inside EduPace is a two-step process. When a user deletes a record it is archived — removed from view but retained — so that accidental deletions can be reversed. It is permanently erased on the school's instruction or in line with our retention schedule.
  • After a subscription ends, the school has 30 days to export its data (see clause 10.3 of the Terms). Thereafter we delete or de-identify it, except where retention is legally required.
  • Billing and tax records are kept for the periods required by the Companies Act and the Tax Administration Act — generally five to seven years.
  • Security, audit and sign-in records are kept for as long as needed for accountability, investigation and legal-claim purposes, and are then deleted or de-identified.
  • Schools set the rules for their own records. As responsible party, a school may instruct us to delete specific records at any time, and should ensure its own retention policy reflects departmental requirements.

12. Your rights and how to exercise them

Section 5 of POPIA gives every data subject the following rights:

  • To be notified that information is being collected, and that it has been accessed by an unauthorised person (sections 18 and 22).
  • To access the personal information held about you, and to be told who has had access to it (section 23, read with PAIA).
  • To correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained (section 24).
  • To object to processing on reasonable grounds, using Form 1 of the POPIA Regulations (section 11(3)).
  • To withdraw consent where processing is based on consent, without affecting processing already carried out.
  • Not to be subject to a decision based solely on automated processing that has legal consequences (section 71).
  • To complain to the Information Regulator, and to institute civil proceedings (sections 74 and 99).

12.1 How to make a request

  • School records — learners, guardians and staff: send your request to the school. The school is the responsible party and holds the relationship with you; it can also action the request itself inside EduPace. We assist the school on request.
  • Account, billing and support information: email the Information Officer at info@edupace.co.za.
  • Requests to correct or delete may be made on Form 2 of the POPIA Regulations, 2018; objections on Form 1. We accept a plain written request as well.
  • We need to verify identity before acting on a request, and will ask for proof where the request is made on someone else's behalf — including by a parent or guardian for a child.
  • We acknowledge requests promptly and respond within the period allowed by POPIA and PAIA. Access requests under PAIA may attract the prescribed fee; POPIA correction and objection requests are free.

13. Contact us and the Information Regulator

HashData (Pty) Ltd t/a EduPace

  • Information Officer: info@edupace.co.za
  • Telephone: +27 (0)21 330 5784
  • Address: E001, Fairway Square, 23 Fairway Close, Parow Golf Course, Parow, Cape Town, 7500, South Africa
  • VAT number: 4960274779

Information Regulator (South Africa)

You may complain to the Regulator at any time, whether or not you have raised the matter with us first.

14. Changes to this Policy

  • We may update this Policy to reflect changes in the Service, our operators, or the law. The version number and effective date at the top of the page always show the current version.
  • Material changes — for example a new operator with access to learner information, or a new purpose of processing — are communicated to subscribing schools by email or in-app notice at least 14 days before they take effect, so that a school can consider its own notification duties.
  • Continued use of the Service after the effective date constitutes acceptance of the updated Policy.