Effective date: 5 July 2026
1. Who we are and scope
M-Elimu is a brand of FrontL Hawk LTD, a company registered in Kenya. In this policy, “M-Elimu”, “FrontL Hawk LTD”, “we”, “us”, and “our” refer to FrontL Hawk LTD as the owner and operator of the M-Elimu website and platform. This policy applies to this public website, demonstrations, enquiries, platform accounts, support interactions, and our processing in providing the platform.
It does not replace a participating school's own privacy notice. A school may have additional duties and policies governing student, parent, applicant, and staff information. If you access M-Elimu through a school, direct questions about the school's use of your records to that school first.
2. Personal data we may process
Depending on how you interact with M-Elimu and which modules a school enables, we may process:
- Identity and contact data: names, identifiers, email addresses, telephone numbers, postal or physical addresses, photographs, and relationship to a school or learner.
- Account and authentication data: usernames, roles, school memberships, password hashes, authentication events, permissions, and account recovery information.
- School operations data: admission and enrolment records, classes, guardians, attendance, timetables, staff assignments, communications, discipline or welfare records, and other records submitted by an authorised school.
- Academic data: subjects, assessments, marks, reports, teacher comments, learning plans, and related academic records.
- Financial and transaction data: fee structures, invoices, balances, payment status, transaction references, billing contacts, and subscription records. Payment providers may process payment credentials under their own terms; M-Elimu does not need to store full mobile-money or bank credentials to record a transaction.
- Support and content data: messages, uploaded documents, support requests, feedback, and records supplied to diagnose an issue.
- Technical and usage data: IP address, browser and device information, timestamps, requested pages, session and security events, diagnostic logs, and feature usage.
- Enquiry data: school name, location, size, operational needs, and details submitted when requesting information or a demonstration.
Some school records may be sensitive personal data or relate to children. Schools and users should submit only information that is relevant, lawful, and authorised for the intended school purpose.
3. Where data comes from
We receive data directly from you; from the school, school group, or organisation that authorises your access; from parents or guardians acting for learners; from authorised integrations and payment providers; and automatically from devices and systems used to access M-Elimu. We may also receive lawful business contact information from referral partners or public sources.
4. Why we process data and our legal bases
We process personal data only where we have an applicable lawful basis, which may include performing a contract, taking requested pre-contract steps, complying with law, protecting vital interests, performing an authorised public-interest task, pursuing legitimate interests that are not overridden by individual rights, or obtaining consent where consent is required.
Purposes may include:
- providing, configuring, maintaining, and supporting the platform;
- authenticating users, enforcing roles, preventing fraud, and protecting platform security;
- carrying out a school's documented instructions for its records;
- processing subscriptions, billing, payment confirmations, and account administration;
- responding to enquiries, arranging demonstrations, and communicating about requested services;
- monitoring reliability, diagnosing faults, backing up systems, and improving usability;
- meeting legal, regulatory, tax, accounting, safeguarding, and dispute-resolution obligations;
- establishing, exercising, or defending legal claims; and
- sending marketing only where permitted, with a way to opt out of direct marketing.
Where processing relies on consent, you may withdraw consent prospectively. Withdrawal does not invalidate processing already carried out lawfully and may not affect processing supported by another lawful basis.
5. School-controlled data and children's privacy
Institutional customers are responsible for having authority and an appropriate lawful basis to collect, upload, use, disclose, correct, retain, and instruct M-Elimu to process school-controlled data. Schools must give required notices, manage user access, keep data accurate, and respond to data-subject requests where they act as controller.
M-Elimu is not intended for children to create unsupervised consumer accounts. A learner's access, if offered, must be authorised and managed through the relevant school and, where required, a parent or guardian. We do not knowingly profile children for direct marketing. We process children's records only for authorised educational, administrative, safeguarding, support, security, or legal purposes and apply safeguards appropriate to the risk.
A parent or guardian seeking a child's school record should normally contact the school. We may refer a request to the school or require proof of identity, guardianship, and authority before disclosing or changing any record.
6. Automated tools and artificial intelligence
Some optional features may assist users with summaries, suggestions, planning, document processing, or operational insights. M-Elimu does not intend these tools to make final legal or similarly significant decisions about a person without meaningful human involvement. Authorised school personnel remain responsible for reviewing outputs and making educational, disciplinary, employment, financial, safeguarding, or other consequential decisions.
7. Cookies and similar technologies
We use essential cookies and comparable storage needed for secure sign-in, session continuity, request protection, preferences, and platform operation. If we introduce non-essential analytics or advertising technologies, we will provide any notice and choice required by law. Blocking essential cookies may prevent authenticated features from working.
8. When data may be shared
We do not sell personal data. We may disclose only the data reasonably necessary to:
- the school or organisation controlling the account and its authorised users;
- hosting, storage, communications, authentication, payment, security, support, and professional-service providers bound by appropriate obligations;
- approved integrations enabled or requested by the school;
- regulators, courts, law-enforcement bodies, or other authorities where disclosure is lawfully required;
- advisers and counterparties for an audit, financing, restructuring, merger, acquisition, or transfer, subject to confidentiality and lawful safeguards; or
- protect a person, enforce agreements, investigate misuse, or defend legal rights where lawful and necessary.
Service providers may use data only to provide contracted services or as otherwise permitted by law. A current description of material subprocessors may be provided to institutional customers on request or under the applicable service agreement.
9. Cross-border processing
Cloud and support providers may process data outside Kenya. Where personal data is transferred across borders, we and the relevant school will apply the safeguards required by Kenyan law, which may include an adequacy basis, contractual safeguards, documented necessity, or valid consent where appropriate. Institutional agreements may contain additional location and transfer commitments.
10. How long data is retained
We retain personal data no longer than reasonably necessary for the purpose collected, contractual commitments, security, backup integrity, dispute handling, and legal or regulatory requirements. Retention considers the nature and sensitivity of the data, risk of harm, account status, school instructions, limitation periods, and applicable education, tax, employment, and data-protection rules.
At the end of services, school-controlled data is returned, made available for export, deleted, or anonymised as provided in the applicable agreement and subject to lawful retention. Residual encrypted backups may remain until overwritten through normal backup cycles and remain protected from ordinary use. We may retain minimal records needed to prove transactions, enforce rights, prevent fraud, or comply with law.
11. Security and personal data breaches
We use proportionate technical and organisational safeguards designed to protect confidentiality, integrity, and availability. Measures may include role-based access, least-privilege controls, encryption in transit, protected credentials, logging, backups, monitoring, vulnerability management, staff controls, and incident procedures.
No internet or storage system is guaranteed to be completely secure. Users must protect credentials, use authorised devices, assign access carefully, and notify us promptly of suspected compromise. Where a personal data breach occurs, M-Elimu and the relevant school will assess their legal roles and provide notifications required by the Data Protection Act and applicable regulations.
12. Your data-protection rights
Subject to applicable conditions and exemptions, Kenyan data subjects may have the right to be informed about use of their data; access data; object to processing; request correction of inaccurate data; request deletion of false, misleading, unlawfully held, or no-longer-necessary data; request restriction; receive portable data where applicable; withdraw consent; and complain to the Data Commissioner.
Send requests to info@m-elimu.co.ke. Describe the data, school, relationship, and right you wish to exercise. We may request information necessary to verify identity, guardianship, authority, and prevent unauthorised disclosure. If a school controls the record, we will refer or coordinate the request with that school. Rights are not absolute; we may decline or limit a request where law permits and will explain the applicable reason.
13. Third-party sites and services
M-Elimu may link to or integrate with services we do not control. Their privacy terms govern their independent processing. Schools should assess integrations before enabling them, and users should review third-party notices before providing data.
14. Changes to this policy
We may update this policy to reflect legal, operational, or technical changes. The current version will be posted at this URL with its effective date. If a change materially affects existing processing, we will provide additional notice where required by law or contract.
15. Contact and complaints
Privacy questions, requests, and security reports may be sent to info@m-elimu.co.ke. Please do not email passwords, full payment credentials, or unnecessary sensitive records.
You may also lodge a complaint with Kenya's Office of the Data Protection Commissioner. We encourage you to contact us or the relevant school first so the concern can be investigated promptly, but doing so does not remove your right to approach the regulator.