DANIS

Privacy Policy

Version 2026-10.1 · Effective 6 October 2026

1. Who we are

This Privacy Policy explains how Fingletek Oy ("Fingletek", "we") processes Personal Data when a school uses the Software. It forms part of the User Agreement and Terms and Conditions of Use. Terms defined there have the same meaning here.

For the records a school keeps about its students, staff and guardians, the school is the Data Controller and Fingletek is its Data Processor. For the account and registration details of the school and its owner, Fingletek is the Data Controller.

2. Legal framework

We process Personal Data in accordance with the Nigeria Data Protection Act, 2023 (NDPA), the Nigeria Data Protection Regulation, 2019 (NDPR), the General Application and Implementation Directive (GAID), and the guidance of the Nigeria Data Protection Commission (NDPC).

3. What we collect

• Account data: names, email addresses, phone numbers and roles of the people a school invites.

• School records: the academic, attendance, financial and communication records a school enters into the Software.

• Technical data: IP address, browser type and sign-in times, used to keep accounts secure and to record acceptance of our terms.

4. Why we use it and our lawful basis

We use Personal Data to provide and secure the Software, to send the notifications and emails a school has asked for, to handle billing and licensing, and to meet our legal obligations. Our lawful bases are performance of our contract with the school, our legal obligations, and our legitimate interest in keeping the Software secure.

We do not sell Personal Data and do not use school records for advertising. A school warrants that it has a lawful basis, and has given the required notices to data subjects, for the Personal Data it enters into the Software.

5. Cookies

The Software uses cookies that are strictly necessary to keep you signed in, and optional preference cookies. Details are in our Cookie Policy.

6. Security and breaches

We apply appropriate technical and organizational measures, including encryption, access controls, authentication and regular security reviews. If a Personal Data breach affects data we process for a school, we will notify the school without undue delay and help it notify the NDPC and affected data subjects within seventy-two (72) hours of becoming aware of the breach, where the NDPA requires it.

7. Sharing, sub-processors and transfers

We use carefully selected providers for hosting, file storage and email. They process data only on our instructions, and we remain liable for their acts and omissions.

Where Personal Data is transferred outside Nigeria, we do so only in line with the cross-border transfer requirements of the NDPA.

8. Retention and deletion

Data is kept while the school's License is active. After termination we return or securely delete it at the school's election, except for records the law requires us to retain.

9. Your rights

You can ask for access to, correction, erasure, restriction or portability of your Personal Data, and can object to its processing. Requests about school records are handled together with the school. You may also complain to the Nigeria Data Protection Commission.

10. Contact

Privacy questions can be sent to our support team from within the Software.