Who this policy is for
This policy applies to any school, administrator, teacher, counselor, student, or parent whose data is processed inside a Chaimountworkspace. The school subscribing to Chaimount is the controller of the student and parent data within that workspace. Chaimount acts as the processor.
If you are a parent or student, questions about your specific record should be raised first with the school - because the school owns the record. We support the school in fulfilling that request.
What we collect
The categories of data inside a workspace are:
- Student records: name, grade, section, date of birth, contact, admissions history.
- Attendance: daily present / absent status, reason where recorded.
- Grades: assessment scores, term averages, teacher remarks.
- Parent and guardian contact details for school-parent communication.
- Staff records: name, role, class assignments, login identifiers.
- Operational logs: sign-in events, sensitive-action audit entries.
We do not collect: browsing history, device location, keystroke data, or biometric identifiers. Those categories are outside the scope of what Chaimount does.
Why we hold this data
Every category above exists to serve one of the six operations areas of the product - admissions, timetabling, attendance, gradebooks, communication, or early-warning. If a data point does not serve one of those functions, we do not collect it. If a school stops using an area, the associated data is retired on the school's request.
Who can see what inside the workspace
Chaimount uses role-based access. Teachers see the classes they teach. Administrators see the whole school. Counselors see their assigned cases. Parents see only their own child's record and the communication addressed to them.
Access changes are audited. Grade edits, mass exports, and role changes leave an immutable log entry inside the workspace.
How long we hold it
Active-student data is retained as long as the student is enrolled with the school. Alumni records follow the retention schedule the school administrator configures in the workspace.
On offboarding, the school receives a full data export. Sixty days after the export, all school data is purged from primary storage. Encrypted backups expire on the documented backup schedule.
Where the data lives
Data is hosted with reputable cloud infrastructure in regions selected by the school at onboarding. It does not travel outside those regions without a documented reason and the school's consent. Sub-processors we rely on (transactional email, cloud infrastructure, error monitoring) are listed inside the workspace and updated when the list changes.
Rights of individuals
Students, parents, and staff whose data lives in a school workspace have the following rights, exercised through the school:
- Access to the data held about them.
- Correction of factual errors.
- Deletion, subject to the school's retention obligations.
- Export of their record.
Requests should be raised with the school first. Chaimountsupports the school in fulfilling requests within the workspace tooling.
Security posture
Encryption in transit (TLS 1.2 or higher), encryption at rest (AES-256), per-school logical isolation, encrypted backups, and audit logs on sensitive actions. Detailed controls are described on the security page.
A note on data belonging to children
Chaimount is deployed inside schools, and the majority of records inside a workspace belong to children. We treat that data with the corresponding heightened care - stricter access defaults, no third-party advertising integrations, and no analytics that profile individual students.
When this policy changes
Material changes are communicated to the school administrator in advance. Version history of this policy is available on request.