1. Introduction
Welcome to BRIDGEPATH ("BRIDGEPATH", "we", "our", or "us").
BRIDGEPATH is a cloud-based school management platform designed to help educational institutions efficiently manage academic records, student information, attendance, assessments, communication, fees, learning activities, and other school administration functions.
We recognize the importance of protecting the privacy and security of personal information entrusted to us. This Privacy Policy explains how we collect, use, disclose, store, transfer, and protect personal data when individuals access or use BRIDGEPATH's websites, mobile applications, software, APIs, and related services (collectively, the "Services").
We are committed to processing personal data lawfully, fairly, transparently, and securely in accordance with applicable data protection laws, including the Nigeria Data Protection Act 2023 (NDPA), applicable regulations issued by the Nigeria Data Protection Commission (NDPC), and, where applicable, international privacy standards such as the UK GDPR and EU GDPR.
By using our Services, you acknowledge that you have read and understood this Privacy Policy.
2. Scope
This Privacy Policy applies to:
- Schools using BRIDGEPATH;
- School owners and administrators;
- Teachers and school employees;
- Students;
- Parents and legal guardians;
- Visitors to our websites;
- Prospective customers;
- Individuals contacting our support team;
- Any other person whose personal information is processed through our Services.
This Privacy Policy applies regardless of whether the Services are accessed through a web browser, mobile application, desktop application, API, or any other authorized platform.
3. Definitions
For purposes of this Privacy Policy:
- Account
- means a registered user profile created to access the Services.
- Personal Data
- means any information relating to an identified or identifiable natural person.
- Sensitive Personal Data
- includes information such as biometric data, health information, religious beliefs, ethnicity, or any other category protected under applicable law.
- Processing
- means any operation performed on personal data, including collection, recording, organization, storage, alteration, retrieval, consultation, disclosure, transmission, restriction, deletion, or destruction.
- Data Controller
- means the individual or organization that determines the purposes and means of processing personal data.
- Data Processor
- means an organization that processes personal data on behalf of a Data Controller.
- School
- means any educational institution using BRIDGEPATH.
- User
- means any person who accesses or uses the Services.
4. Our Role
Depending on the circumstances, BRIDGEPATH may act as either a Data Controller or a Data Processor.
When Schools Control the Data
For student records, attendance records, academic reports, disciplinary records, examination results, assignments, and other educational records entered into BRIDGEPATH by schools, the relevant school generally acts as the Data Controller.
In these situations, BRIDGEPATH processes the information solely on the documented instructions of the school and acts as the Data Processor.
When BRIDGEPATH Controls the Data
BRIDGEPATH acts as the Data Controller for information relating to:
- Customer account registration;
- Billing information;
- Website visitors;
- Customer support communications;
- Marketing communications;
- Product analytics;
- Recruitment;
- Vendor management;
- Compliance with legal obligations.
5. Information We Collect
The categories of information collected depend on how the Services are used.
A. Student Information
Where provided by a school, we may process:
- Full name;
- Student identification number;
- Date of birth;
- Gender;
- Photograph;
- Class information;
- Academic records;
- Assessment results;
- Attendance records;
- Behavioural records;
- Learning progress;
- Homework submissions;
- Examination records;
- Library records;
- Transportation information;
- Health or medical information where necessary for school operations;
- Emergency contact information;
- Parent or guardian relationships.
B. Parent or Guardian Information
We may process:
- Full name;
- Residential address;
- Telephone numbers;
- Email address;
- Relationship to student;
- Emergency contact details;
- Payment information;
- Communication preferences;
- Authentication credentials.
C. Teacher and Employee Information
Schools may store:
- Full name;
- Employment information;
- Qualifications;
- Professional certifications;
- Attendance records;
- Payroll-related information (where applicable);
- Contact details;
- Timetable information;
- Performance records;
- Identity verification documents where required by law.
D. School Administrator Information
We may process:
- Name;
- Position;
- Email address;
- Phone number;
- Login credentials;
- Administrative permissions;
- Activity logs;
- Account settings.
E. Visitor Information
When visitors browse our website, we may automatically collect:
- IP address;
- Browser type;
- Device information;
- Operating system;
- Language settings;
- Referral URLs;
- Date and time of access;
- Pages visited;
- Session duration;
- Device identifiers.
F. Payment Information
Where schools purchase paid subscriptions, we may collect:
- Billing contact information;
- Organization name;
- Payment reference numbers;
- Subscription details;
- Transaction history.
For security reasons, payment card details are processed directly by authorized payment service providers and are not stored on BRIDGEPATH servers unless expressly stated.
G. Technical Information
Our systems automatically generate logs including:
- Login history;
- Device identifiers;
- Browser information;
- Error reports;
- Crash reports;
- Security logs;
- API requests;
- Audit logs;
- System diagnostics.
6. How We Collect Information
We collect personal data through several methods, including:
- Information provided directly by users;
- Information entered by schools;
- Registration forms;
- Mobile applications;
- Website forms;
- Customer support interactions;
- Email communications;
- Cookies and similar technologies;
- System logs;
- API integrations;
- Third-party identity providers where authorized;
- Payment providers;
- Educational institutions.
7. Legal Bases for Processing
Where required by applicable law, we process personal data on one or more of the following legal bases:
- Consent;
- Performance of a contract;
- Compliance with legal obligations;
- Protection of vital interests;
- Performance of a task carried out in the public interest where applicable;
- Legitimate business interests that are not overridden by the rights and freedoms of individuals.
Where consent is relied upon, individuals may withdraw consent at any time, subject to legal or contractual limitations.
8. How We Use Personal Information
We use personal information to:
- Provide and maintain the Services;
- Create user accounts;
- Authenticate users;
- Manage school operations;
- Record attendance;
- Generate report cards;
- Process assessments;
- Manage learning activities;
- Facilitate communication between schools, teachers, students, and parents;
- Process subscriptions;
- Improve platform performance;
- Monitor system security;
- Detect fraud and abuse;
- Comply with legal obligations;
- Respond to customer support requests;
- Conduct analytics;
- Develop new features;
- Perform backups and disaster recovery;
- Enforce our Terms of Service.
We do not sell personal information to third parties.
9. Children's Privacy
BRIDGEPATH is designed primarily for use by educational institutions and, as such, processes personal data relating to children under the supervision and authority of schools, parents, or legal guardians.
We recognize that children's personal information requires a higher standard of protection.
BRIDGEPATH does not knowingly collect personal information directly from children for independent commercial purposes. Student information is provided to us by schools or, where applicable, by parents or legal guardians in connection with educational services.
Schools are responsible for ensuring that they have obtained any required parental consent or other lawful basis for processing student information under applicable laws.
Where we become aware that personal information has been collected in violation of applicable law, we will take appropriate steps to investigate and, where necessary, securely delete the information.
10. Communications
We may use personal information to communicate with users regarding:
- Account registration and verification;
- Password resets;
- Security alerts;
- School announcements;
- Academic updates;
- Attendance notifications;
- Fee reminders;
- System maintenance;
- Product updates;
- Customer support;
- Service-related notices;
- Legal or regulatory notifications.
Where marketing communications are sent, recipients will be provided with a means to opt out unless such communications are necessary for the operation of the Services or required by law.
11. Cookies and Similar Technologies
BRIDGEPATH uses cookies and similar technologies to improve user experience, enhance security, and understand how our Services are used.
Cookies may be used to:
- Authenticate users;
- Maintain login sessions;
- Remember user preferences;
- Improve website performance;
- Measure platform usage;
- Detect fraudulent activity;
- Support security monitoring.
Users may configure their browser settings to reject cookies. However, disabling certain cookies may affect the functionality of the Services.
Where required by applicable law, we will request consent before placing non-essential cookies on a user's device.
12. Analytics and Platform Performance
To improve the reliability and performance of our Services, we may collect and analyse technical and usage information, including:
- Device type;
- Browser type;
- Operating system;
- Session duration;
- Error reports;
- Feature usage;
- Performance metrics;
- Crash diagnostics.
Where possible, analytics data is aggregated or pseudonymised to reduce the likelihood of identifying individual users.
13. Location Information
Where enabled by a school, BRIDGEPATH may process location information for specific features such as attendance verification, transport management, field activities, or other school-authorized services.
Location information is processed only:
- where required for the requested feature;
- where permitted by applicable law; and
- after obtaining any required permissions from the device or user.
Location information is not used for advertising purposes and is retained only for as long as necessary to fulfil the relevant educational or administrative purpose.
14. AI Features and Automated Processing
Where BRIDGEPATH offers artificial intelligence or automated features, these technologies may assist users by:
- generating academic insights;
- organising educational content;
- identifying trends;
- supporting administrative tasks;
- assisting with report preparation;
- providing recommendations.
AI-generated outputs are intended to assist users and should not replace professional educational judgment or administrative decision-making.
BRIDGEPATH does not use AI to make solely automated decisions that produce legal or similarly significant effects on individuals without appropriate human oversight, unless permitted by applicable law.
15. Sharing Personal Information
We may share personal information only where necessary and in accordance with applicable law.
Information may be shared with:
- the relevant school or educational institution;
- parents or legal guardians, where appropriate;
- authorised teachers and school staff;
- service providers acting on our behalf;
- payment processors;
- cloud hosting providers;
- communication service providers;
- professional advisers;
- auditors;
- regulators;
- law enforcement agencies where legally required;
- courts or governmental authorities.
We do not sell or rent personal information to third parties.
16. Third-Party Service Providers
BRIDGEPATH works with carefully selected service providers to support the delivery of our Services. These providers may assist with:
- cloud hosting;
- payment processing;
- email delivery;
- SMS notifications;
- customer support;
- analytics;
- infrastructure monitoring;
- cybersecurity;
- backup and disaster recovery.
Each service provider is required to process personal information only on documented instructions and is contractually obligated to implement appropriate security measures and confidentiality protections.
17. International Data Transfers
Personal information may be processed or stored in countries outside the country in which it was originally collected.
Where personal data is transferred internationally, BRIDGEPATH will implement appropriate safeguards, which may include:
- contractual data protection clauses;
- legally recognised transfer mechanisms;
- encryption during transmission;
- access controls;
- vendor due diligence;
- compliance with applicable cross-border transfer requirements.
We take reasonable steps to ensure that any recipient of personal information provides a level of protection consistent with applicable data protection laws.
18. Disclosure Required by Law
We may disclose personal information where we believe such disclosure is necessary to:
- comply with applicable law;
- respond to lawful requests from public authorities;
- protect the rights, safety, or property of BRIDGEPATH;
- protect students, schools, staff, or other users;
- investigate suspected fraud, abuse, or security incidents;
- enforce our contractual rights or Terms of Service.
Where legally permitted, we will seek to notify affected parties before making such disclosures.
19. Business Transfers
If BRIDGEPATH undergoes a merger, acquisition, corporate restructuring, financing, sale of assets, or other business transaction, personal information may be transferred as part of that transaction.
Any successor organisation will be required to continue protecting personal information in accordance with this Privacy Policy or provide notice of any material changes before processing continues.
20. Third-Party Links
Our Services may contain links to third-party websites, applications, or services.
This Privacy Policy does not apply to those third-party services. Users are encouraged to review the privacy policies of any external websites or applications before providing personal information.
BRIDGEPATH is not responsible for the privacy practices or content of third-party services not owned or controlled by us.
21. Data Security
Protecting personal information is a fundamental part of our operations. BRIDGEPATH maintains administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, loss, misuse, or destruction.
Our security measures may include:
- Encryption of data in transit using secure communication protocols.
- Encryption of sensitive data at rest where appropriate.
- Role-based access controls and least-privilege access.
- Strong authentication mechanisms.
- Password hashing and secure credential management.
- Multi-factor authentication for administrative accounts where available.
- Firewall protection and network monitoring.
- Security logging and audit trails.
- Regular software updates and security patching.
- Secure backup and disaster recovery procedures.
- Employee confidentiality obligations and security training.
- Periodic security assessments and vulnerability testing.
While we implement reasonable safeguards, no method of electronic transmission or storage is completely secure. Accordingly, we cannot guarantee absolute security.
22. Data Retention
We retain personal information only for as long as necessary to:
- Provide the Services;
- Fulfil contractual obligations;
- Support educational operations;
- Resolve disputes;
- Comply with legal, accounting, tax, and regulatory requirements;
- Enforce our agreements.
Retention periods vary depending on the category of information and applicable legal requirements.
When personal information is no longer required, we will securely delete, anonymize, or destroy it in accordance with our Data Retention and Deletion Policy, unless continued retention is required by law.
Schools remain responsible for determining the retention period applicable to educational records under their own legal and regulatory obligations.
23. Your Privacy Rights
Subject to applicable law, individuals may have the right to:
- Request access to personal information.
- Request correction of inaccurate or incomplete information.
- Request deletion of personal information where legally permissible.
- Request restriction of processing.
- Object to certain processing activities.
- Withdraw consent where processing is based on consent.
- Request portability of personal information where applicable.
- Request information regarding how personal data is processed.
- Lodge a complaint with a competent supervisory authority.
Where BRIDGEPATH acts as a Data Processor on behalf of a school, requests relating to student educational records should ordinarily be directed to the relevant school, which acts as the Data Controller.
We may require reasonable proof of identity before responding to privacy-related requests.
24. School Responsibilities
Schools using BRIDGEPATH are responsible for:
- Determining the lawful basis for processing personal data.
- Providing privacy notices to students, parents, guardians, teachers, and staff where required.
- Obtaining any necessary consents.
- Ensuring the accuracy of information entered into the platform.
- Managing user permissions within their institution.
- Responding to data subject requests relating to school-controlled information.
- Complying with applicable education, child protection, and data protection laws.
BRIDGEPATH processes school-controlled information only in accordance with documented instructions provided by the relevant school, except where otherwise required by law.
25. Data Breach Notification
BRIDGEPATH maintains procedures for identifying, investigating, managing, and responding to suspected personal data breaches.
Where a breach is likely to result in a risk to the rights and freedoms of affected individuals, we will notify the relevant school and, where required by applicable law, the appropriate regulatory authority without undue delay.
Where legally required, affected individuals will also be notified.
We continually review and improve our security measures following any security incident.
26. International Users
Users accessing BRIDGEPATH from outside the country in which our Services are operated acknowledge that personal information may be transferred to, processed, and stored in jurisdictions where data protection laws may differ from those of their home country.
Where such transfers occur, BRIDGEPATH will implement appropriate safeguards consistent with applicable legal requirements.
27. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- Changes in our Services;
- New features or technologies;
- Changes in applicable laws or regulations;
- Improvements to our privacy practices;
- Operational or business developments.
The updated version will be published through our website or application together with the revised "Last Updated" date.
Where required by law, we will provide appropriate notice of material changes before they become effective.
Continued use of the Services after the effective date of an updated Privacy Policy constitutes acceptance of the revised policy, except where additional consent is required by law.
28. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or our handling of personal information, you may contact us using the details below:
BRIDGEPATH
Email: support@grangerpr.com
Website: https://bridgepathschools.com
Where required by applicable law, you may also contact our designated Data Protection Officer or Privacy Officer using the contact information published on our website.
29. Complaints
If you believe that your personal information has been processed in a manner inconsistent with this Privacy Policy or applicable law, we encourage you to contact us first so that we may investigate and attempt to resolve your concerns promptly.
You also have the right to lodge a complaint with the relevant data protection supervisory authority in the jurisdiction where you reside or where the alleged infringement occurred.
For users in Nigeria, complaints may be submitted to the Nigeria Data Protection Commission (NDPC).
30. Governing Law
This Privacy Policy shall be governed by and interpreted in accordance with the laws applicable to the operation of BRIDGEPATH, including the Nigeria Data Protection Act 2023 and any other applicable data protection legislation.
Nothing in this Privacy Policy limits any statutory rights that individuals may have under applicable law.
31. Contact Regarding Children's Data
Parents, legal guardians, or authorized school representatives who have questions regarding the processing of children's personal information may contact us using the details provided in this Privacy Policy.
Where BRIDGEPATH processes student information on behalf of a school, requests concerning educational records should generally be directed to the relevant school before contacting BRIDGEPATH.
32. Acceptance of this Privacy Policy
By accessing or using the Services, users acknowledge that they have read and understood this Privacy Policy.
Where an individual uses the Services on behalf of a school or other organization, that individual represents that they have the authority to bind that organization to this Privacy Policy.