BrightCampus Privacy Policy

Effective Date: 10/10/2026 Last Updated: 23/08/2026

1. Introduction

BrightCampus respects the privacy of students, parents, guardians, teachers, staff, school administrators, school owners, website visitors and other users.

This Privacy Policy explains how personal data may be collected, used, disclosed, protected, retained and otherwise processed when individuals interact with BrightCampus.

BrightCampus is designed to support educational institutions while recognising that school information, particularly information relating to children, requires careful protection.

2. Scope

This Privacy Policy applies to personal data processed through:

- the BrightCampus website; - BrightCampus school-management applications; - school portals; - parent portals; - student portals; - staff and teacher workspaces; - BrightCampus-hosted school websites where BrightCampus is responsible for relevant processing; - demonstration and enquiry forms; - support channels; and - related BrightCampus services.

A participating school may also provide its own privacy notice explaining how that school uses personal data.

3. Our Roles

The legal role of BrightCampus depends on the processing activity.

For many school-management activities, the participating school determines why and how personal data is used. In those circumstances, the school will generally act as the data controller and BrightCampus will process information on its behalf as a data processor or in an equivalent service-provider role.

For certain activities relating directly to BrightCampus's own business operations — such as managing demonstration requests, subscriptions, platform security, business contacts and certain service analytics — BrightCampus may act as a data controller.

The exact allocation of responsibilities may also be defined in an agreement between BrightCampus and the school.

4. Personal Data We May Process

Depending on the services enabled, BrightCampus may process information including:

Student Information

- name; - student or admission number; - date of birth; - gender where lawfully required; - photograph; - class; - academic session and term; - subjects; - attendance; - assignments; - assessments; - examination scores; - grades; - results; - teacher comments; - disciplinary or pastoral information where enabled; - educational history; - transport information; - library records; - emergency information; and - other school records.

Parent and Guardian Information

- name; - relationship to student; - telephone number; - email address; - address; - linked children; - communication preferences; - account information; and - relevant financial or payment information.

Teacher and Staff Information

- name; - employee or staff identifier; - contact information; - photograph; - job title; - department; - assigned classes and subjects; - attendance or operational records; - account permissions; and - other employment-related information provided by the school.

School Administration Information

We may process information about:

- school owners; - administrators; - principals; - heads of department; - academic officers; - accountants; - librarians; - transport personnel; - medical personnel; - ICT personnel; and - other authorised users.

Financial Information

Depending on enabled features, information may include:

- invoices; - school fees; - payment status; - balances; - transaction references; and - payment-related records.

Payment card or banking information may be processed directly by authorised third-party payment providers rather than stored by BrightCampus.

Sensitive Personal Data

Where necessary and lawfully authorised, BrightCampus may process sensitive information such as:

- health information; - medical conditions; - allergies; - disabilities; - emergency medical information; and - other information afforded special protection under applicable law.

Access to such information should be restricted to authorised persons.

Technical Information

We may process:

- IP address; - browser type; - device information; - login records; - timestamps; - session information; - authentication events; - security events; - audit logs; - error logs; and - related technical information.

Website and Enquiry Information

When someone visits our public website or requests a demonstration, we may collect:

- name; - school name; - email address; - telephone number; - school type; - approximate student population; - enquiry details; and - information voluntarily submitted.

5. How We Obtain Personal Data

Information may be obtained:

- directly from users; - from participating schools; - from authorised school administrators; - from parents or guardians; - through use of the Platform; - from authorised integrations; - through demonstration or contact forms; and - automatically through security, technical and operational systems.

6. Why We Process Personal Data

Depending on the context, personal data may be processed to:

- provide BrightCampus services; - create and administer accounts; - maintain student and staff records; - manage classes and subjects; - manage attendance; - prepare and publish authorised academic results; - enable parent-child relationships; - facilitate school communication; - manage fees and payment records; - operate transport, library or health features; - provide school websites; - process admissions enquiries; - provide customer support; - maintain security; - investigate suspicious activity; - maintain audit records; - improve reliability and performance; - fulfil contractual obligations; - comply with applicable laws; and - protect the rights and safety of users and institutions.

7. Lawful Bases

BrightCampus and participating schools must ensure that personal data is processed under an appropriate lawful basis.

Depending on the circumstances, processing may be based on:

- performance of a contract; - compliance with a legal obligation; - consent; - legitimate interests where permitted and appropriately balanced; - protection of vital interests; - performance of tasks carried out in the public interest where applicable; or - another lawful basis recognised by applicable data-protection law.

The appropriate lawful basis depends on the specific processing activity and the respective role of BrightCampus and the participating school.

8. Children's Privacy

BrightCampus is designed for educational environments and may therefore process personal data relating to children.

We apply heightened care to children's information.

Where consent is the applicable lawful basis, the responsible controller must obtain any consent, parental or guardian authorisation, age verification or other protection required by applicable law.

Schools should provide appropriate privacy information to students and parents or guardians.

BrightCampus does not knowingly sell children's personal data.

BrightCampus does not use student personal data for behavioural advertising.

Children's information should only be accessible to authorised persons with a legitimate educational, administrative, safeguarding or other authorised purpose.

9. Parent and Guardian Access

Parent or guardian accounts must only be linked to children for whom access has been properly authorised.

BrightCampus is designed to prevent unrelated parents or guardians from accessing another child's private information.

Schools are responsible for establishing and maintaining accurate family relationships and access permissions.

10. School Isolation

BrightCampus is designed as a multi-school platform with institutional data isolation.

A user belonging to one school should not be able to access another school's private records unless an expressly authorised cross-institutional function exists.

Access controls are applied according to institutional membership, role and authorised relationships.

11. How We Share Personal Data

Personal data may be disclosed to:

Participating Schools

Information is made available to authorised users within the relevant school according to their permissions.

Service Providers

We may use carefully selected providers for:

- cloud hosting; - databases; - file storage; - email delivery; - authentication; - monitoring; - customer support; - payment processing; - analytics; and - other infrastructure.

Providers should receive only the information reasonably necessary to perform their services and should be subject to appropriate data-protection obligations.

Legal and Regulatory Authorities

Information may be disclosed where reasonably necessary to:

- comply with law; - respond to lawful regulatory or court processes; - investigate fraud or security incidents; - protect individuals from harm; or - establish, exercise or defend legal rights.

Business Transfers

If BrightCampus undergoes a merger, acquisition, restructuring or sale of relevant assets, information may be transferred subject to appropriate confidentiality and data-protection safeguards.

12. We Do Not Sell Personal Data

BrightCampus does not sell student, parent, teacher or school personal data.

Personal data processed through BrightCampus is not intended to be a commodity for sale to advertisers or data brokers.

13. Advertising

BrightCampus will not use students' school records for behavioural advertising.

If BrightCampus conducts marketing directed to school owners, administrators or other business contacts, such activities will be handled separately and in accordance with applicable law and communication preferences.

14. Cookies and Similar Technologies

The BrightCampus public website may use cookies or similar technologies for:

- essential website functionality; - security; - remembering preferences; - performance measurement; and - analytics where enabled.

Where consent is legally required, non-essential cookies will not be activated until appropriate consent has been obtained.

Users will be provided with appropriate controls to accept, reject or manage non-essential cookies.

15. International Data Transfers

Some technology providers used by BrightCampus may process or store information outside Nigeria.

Where personal data is transferred internationally, BrightCampus will seek to ensure that an appropriate lawful transfer mechanism and safeguards are in place as required by applicable data-protection law.

16. Data Retention

BrightCampus does not intend to retain personal data indefinitely.

Retention periods depend on:

- the type of information; - the school's instructions; - educational record requirements; - contractual requirements; - security needs; - backup requirements; - dispute-resolution needs; and - applicable law.

When information is no longer required, it will be deleted, anonymised or otherwise handled in accordance with applicable retention requirements.

Schools should establish appropriate retention schedules for institutional records under their control.

17. Data Security

BrightCampus uses technical and organisational measures intended to protect personal data against:

- unauthorised access; - unlawful processing; - accidental loss; - alteration; - disclosure; - destruction; and - misuse.

Measures may include:

- authentication; - role-based access control; - school-level data isolation; - secure communications; - encryption where appropriate; - password protection; - access logging; - audit trails; - backup and recovery measures; - vulnerability management; - restricted administrative access; and - security monitoring.

No internet-based system can guarantee absolute security, and BrightCampus therefore does not claim that security risks can be completely eliminated.

18. Personal Data Breaches

BrightCampus maintains procedures for identifying, investigating, containing and responding to suspected personal-data breaches.

Where a breach triggers notification obligations under applicable law, BrightCampus and/or the relevant school will make required notifications to affected parties and regulatory authorities according to their respective legal responsibilities.

Schools should notify BrightCampus promptly when they become aware of a suspected compromise affecting BrightCampus accounts or data.

19. Data Subject Rights

Subject to applicable law and relevant exceptions, individuals may have rights concerning their personal data, including rights to:

- receive information about processing; - request access; - request correction of inaccurate information; - request deletion in appropriate circumstances; - object to certain processing; - request restriction of processing; - withdraw consent where processing relies on consent; - request data portability where applicable; - raise concerns regarding certain automated decisions; and - lodge a complaint with the appropriate data-protection authority.

Where BrightCampus processes information solely on behalf of a school, a request may need to be directed to or handled in cooperation with that school.

BrightCampus will reasonably assist participating schools in responding to valid requests where required.

20. Automated Decision-Making and Artificial Intelligence

BrightCampus may introduce automation or artificial-intelligence-assisted features.

BrightCampus will seek to clearly identify significant automated functionality where appropriate.

We will not intentionally make solely automated decisions producing significant legal or similarly serious effects concerning students or users without an appropriate lawful basis, safeguards and human oversight where required by applicable law.

Schools remain responsible for official academic, disciplinary, admissions and other institutional decisions unless expressly stated otherwise.

21. Accuracy of Information

Schools and users should ensure that personal information supplied to BrightCampus is accurate and kept reasonably up to date.

Authorised users may be provided with mechanisms to correct information, subject to institutional controls.

22. Privacy by Design

BrightCampus seeks to incorporate privacy considerations into the design and development of new features.

This includes consideration of:

- data minimisation; - access boundaries; - purpose limitation; - secure defaults; - retention; - auditability; - children's privacy; - sensitive information; and - data-protection impact assessments where appropriate.

23. Third-Party Links

BrightCampus websites may contain links to third-party websites or services.

Their privacy practices are governed by their own policies, and BrightCampus is not responsible for independent third-party websites merely because a link appears on our Platform.

24. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

- changes to BrightCampus; - new legal requirements; - new features; - new service providers; or - improvements to our privacy practices.

Material changes will be communicated through appropriate channels.

25. Nigeria Data Protection

For individuals in Nigeria, BrightCampus seeks to process personal data consistently with the Nigeria Data Protection Act 2023 and applicable regulations, directives and guidance issued by the Nigeria Data Protection Commission.

Nothing in this Privacy Policy is intended to reduce rights provided by applicable law.

26. Complaints

We encourage users to contact BrightCampus or their school first so that privacy concerns can be investigated promptly.

Individuals also retain the right to complain to the appropriate supervisory authority where applicable.

In Nigeria, the relevant supervisory authority is the Nigeria Data Protection Commission.

27. Contact Us

Privacy enquiries and requests may be directed to:

BrightCampus Privacy Team

Website: [www.brightcampushq.com](http://www.brightcampushq.com)

Phone: (+234) 905 012 5594

Phone: (+234) 706 577 7078

Privacy Email: [support@brightcampushq.com](mailto:support@brightcampushq.com)