Version 2.3 · Effective 17 September 2026
This Policy replaces all previous versions.
HashData (Pty) Ltd ("HashData," "we," "us," or "our"), a private company incorporated in the Republic of South Africa, provides the EduPace school and curriculum management platform ("EduPace" or the "Service"). This Privacy Policy explains what personal information is processed through EduPace, why, on what legal basis, who it is shared with, how long it is kept, and what rights data subjects have.
It is written to meet the openness requirements of sections 17 and 18 of the Protection of Personal Information Act 4 of 2013 ("POPIA") and should be read together with the EduPace Terms and Conditions, clause 6 of which contains the operator agreement required by section 21 of POPIA.
EduPace is used by schools, not by learners or parents directly. That gives two different relationships under POPIA:
Terms such as personal information, special personal information, data subject, responsible party, operator, processing, competent person and de-identify bear the meanings given to them in POPIA.
The South African laws most relevant to EduPace are:
The categories below reflect what EduPace is actually built to store. Not every field is used by every school; schools choose which modules to activate and which optional fields to complete.
EduPace is built for special needs schools, so it necessarily handles categories that POPIA treats as special personal information under section 26, and it handles them almost entirely about children. We set this out plainly because it carries the highest obligations for both the school and for us.
EduPace does not collect biometric templates (photographs are stored as ordinary images, not converted into biometric identifiers), and it has no fields for criminal convictions or alleged offences.
Section 11 of POPIA requires a justification for every processing activity. Ours are:
| Purpose | Justification under section 11 |
|---|---|
| Providing curriculum, assessment, attendance, behaviour and learner support functionality to the school | Necessary to perform our contract with the school (s11(1)(b)); for the school, necessary for the proper performance of its public-law duty or its legitimate interests (s11(1)(c) and (f)) |
| Providing special support and making special arrangements for learners (Individual Support Plans) | Section 32 authorisation for health information, or the consent of a competent person (s11(1)(a) read with s35) |
| Statutory reporting, DBE schedules, promotion and progression records | Compliance with an obligation imposed by law (s11(1)(c)) |
| Creating accounts, authenticating users and controlling access | Performance of the contract (s11(1)(b)) |
| Billing, invoicing, VAT and financial record-keeping | Performance of the contract and compliance with tax and company law (s11(1)(b) and (c)) |
| Security, audit logging, fraud prevention and troubleshooting | Our and the school's legitimate interests in a secure service, and the security safeguards required by s19 (s11(1)(f)) |
| Support, onboarding and service communications | Performance of the contract and legitimate interests (s11(1)(b) and (f)) |
| Improving the Service using anonymised, aggregated statistics | Not personal information once de-identified, so POPIA does not apply (s6(1)(b)) |
| Measuring which of our own adverts bring a school to our public website and on to registration (section 3.7) | Our legitimate interest in knowing whether our own advertising works, weighed against the interests of a visitor and limited to our public pages, to visit information, and to our own advertising (s11(1)(f)). You may object at any time; section 7 explains how to switch it off, and section 12 how to object formally |
| Measuring how our public web pages are found and used, so that we can improve them (section 3.7) | Our legitimate interest in understanding and improving our own website, weighed against the interests of a visitor and limited to our public pages and to visit information (s11(1)(f)). It is never applied to anything inside the application. You may object at any time; section 7 explains how to switch it off, and section 12 how to object formally |
We do not use the learner, guardian or staff records held in EduPace for advertising — the advertising measurement described in sections 3.7 and 7 runs only on our public web pages, never inside the application — and we never sell personal information.
Inside the EduPace application we use the cookies the Service needs in order to work, and the analytics cookies described in section 3.7, which tell us which parts of EduPace are used. There is no advertising cookie and no advertising measurement on any signed-in screen, and the sign-in and password-reset pages, the Learners screen and the Staff Members screen carry no measurement of any kind. The analytics that does run there is told the shape of a screen and never its address, so it receives no learner, guardian or staff identifier and nothing you type.
On our public web pages — the EduPace website, this Policy, the Terms, the registration page and the email-verification steps — we additionally run two measurement tools: the Meta Pixel, so that we can tell which of our own adverts bring a school to us, and Google Analytics, so that we can tell how those pages are found and used. They are the only two such tools we use, they run on those public pages and nowhere else, and both are described in the table below and in section 3.7.
| Cookie | Purpose | Duration |
|---|---|---|
| edupace_session | Keeps you signed in and links your browser to your session. Encrypted, HTTP-only, secure and same-site. | 120 minutes of inactivity |
| XSRF-TOKEN | Protects against cross-site request forgery when submitting forms. | Session |
| remember_web_* | Set only if you choose "remember me" at sign-in. | Until you sign out or it expires |
| Support widget | Our in-app support chat may set its own cookies or local storage to keep a conversation open. | Set by the provider |
| _fbp_fbc | Advertising measurement, public pages only. Set by the Meta Pixel to recognise the same browser across our public pages, so that a registration can be attributed to the advert that led to it. _fbc is set only if you reached us by clicking one of our adverts, and records the click identifier that Meta added to the link. Neither is set on any signed-in screen, nor on sign-in or password reset. These are the only cookies in this table that are not necessary for the Service — see 7.1 to refuse them. | Up to 90 days |
| _ga_ga_* | Website analytics, public pages and signed-in screens. Set by Google Analytics to tell one browser from another and to group a visit into a session, so that we can count visitors rather than page loads and see which parts of the Service are used. On signed-in screens it records the shape of the screen only (section 3.7) — never a record identifier and never anything typed — and it is set on neither the sign-in flow, the Learners screen nor the Staff Members screen. It is never used for advertising. Like the two above, it is not necessary for the Service — see 7.1 to refuse it. | Up to 2 years |
Apart from _fbp, _fbc, _ga and _ga_*, all of the above are strictly necessary for the Service to function or are set only at your election, and blocking them in your browser will prevent you from signing in. Our public web pages also load a web font from Google Fonts and an icon library, which means those providers receive your IP address and browser type when the page loads; no cookie is set by those requests.
You can stop the measurement described above at any time, and doing so has no effect on your use of EduPace — you can still browse our website, register a school and sign in normally:
We do not currently ask for consent before the pixel or the analytics tag loads on our public pages, because we rely on the legitimate-interest ground set out in section 6 rather than on consent. Should the Information Regulator issue guidance or a code of conduct requiring prior consent for non-essential cookies, we will introduce a consent choice and update this Policy before doing anything further.
We do not sell personal information and we do not share it for anyone else's marketing. We use the following operators (sub-processors), each bound to process information only on our instructions and to keep it secure:
| Provider | What it does | What it can access |
|---|---|---|
| Amazon Web Services | Stores uploaded files — learner and staff photographs and support-plan documents | Encrypted, private file storage in the Cape Town region |
| Amazon Simple Email Service | Delivers transactional email such as verification, password reset, approval requests and billing notices | Recipient name and email address, and the content of that email |
| Paystack | Processes card payments for subscriptions | Payer and school billing details and card data entered on its own secure page; we receive only the reference, status and amount |
| KiraDesk | Provides the in-app support chat widget | The signed-in user's name and email address, the page being viewed, and whatever is typed into the chat |
| Google Fonts | Serves the web font used on our public and sign-in pages | IP address and browser type only — no account or school data |
| Font Awesome | Serves the icon set used on our public and sign-in pages | IP address and browser type only — no account or school data |
| Meta Platforms | Measures which of our own adverts bring a school to our public website and on to registration (sections 3.7 and 7) | Visits to our public pages only: IP address, browser and device type, the page and referring page addresses, and a browser identifier. No account, learner, guardian, staff or school record, and nothing at all from inside the application |
| Google Analytics | Measures how our public web pages are found and used, and which parts of the Service are used once signed in, so that we can improve both (sections 3.7 and 7) | On our public pages: IP address, browser and device type, the page and referring page addresses, approximate location derived from the IP address, and a browser identifier. On signed-in screens: the same, except that the page is reduced to its shape (/app/learners/:id/edit) with record identifiers removed and query strings discarded. No learner, guardian, staff or school record, no marks, attendance, support plans or documents, and nothing typed into the Service. Nothing at all from the sign-in flow, the Learners screen or the Staff Members screen |
One qualification about Meta and Google. The first four providers in this table are operators in the POPIA sense: they process only on our instructions and for no purpose of their own. Meta is not in that position — it determines its own purposes for the visit information it receives and is therefore itself a responsible party for that processing, governed by its own terms and privacy policy rather than only by ours. Google undertakes to process Google Analytics information on our instructions, but it operates the service on its own infrastructure and terms, and we treat the visit information it receives on the same conservative footing. We say so plainly because it is the reason we keep both tools off every page that touches school records, and the reason section 7.1 tells you how to refuse each. It is also why we neither send nor upload any personal information from inside EduPace to Meta or Google, and do not use their tools to match, target or build audiences from learner, guardian or staff information.
Reports and PDFs are generated on our own servers; no learner information is sent to an outside service to produce them.
We may also disclose personal information:
In line with section 19 of POPIA we maintain appropriate, reasonable technical and organisational measures, including:
Section 14 of POPIA requires that records not be kept longer than necessary for the purpose they were collected for, unless a law requires otherwise. Our approach:
Section 5 of POPIA gives every data subject the following rights:
You may complain to the Regulator at any time, whether or not you have raised the matter with us first.