Last updated: 29 July 2026

Privacy Policy

What personal data Smart Edu Hub collects, why we process it, who we share it with, and the rights you have over it.

This Privacy Policy ("Policy") explains how Smart Edu Hub ("Smart Edu Hub", "SMeH", "we", "our", "us") collects, uses, stores, shares and protects personal data when you use our website, mobile applications and related services (together, the "Services").

It covers both school-linked users — students, teachers, guardians and administrators whose accounts are provisioned by a school — and Individual Accounts, created directly by learners who use Smart Edu Hub outside a school enrolment. By using the Services you acknowledge that you have read and understood this Policy.

The short version

We collect what we need to run your account and deliver the features you use, and nothing we cannot justify. We do not sell your personal data. Schools remain in control of their students' records. Individual learners can ask us to delete their account and data at any time — see section 2 for how.

1.Definitions

  • Personal Data: any information relating to an identified or identifiable natural person, including names, contact details, student records, academic performance data and digital identifiers.
  • Processing: bears the meaning given under applicable data protection legislation, including the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Regulation (NDPR), and other applicable national data protection laws.
  • Controller: the school, educational institution or entity that determines the purposes and means of processing Student Data through the Services.
  • Processor: Smart Edu Hub, in its capacity of handling Personal Data on behalf of a Controller.
  • Student Data: Personal Data relating specifically to students — educational records, attendance, grades, assessments and related academic information.
  • Individual Account: a personal Smart Edu Hub account created by a learner through our mobile application, not provisioned by a school. The account holder is the primary data subject for personal data processed under that account.
  • Individual User: a natural person who registers for or signs in to an Individual Account to access personal learning features such as AI books, video lessons and exam practice.

2.Individual accounts

In addition to school-managed accounts, Smart Edu Hub offers Individual Accounts for learners who create their own account. This section applies to Individual Users and to personal data processed in connection with those accounts.

Individual and guardian accounts sign in through the mobile app

Individual learner and guardian accounts are designed for the mobile experience and are used through the Smart Edu Hub app rather than the web dashboard. If you attempt to sign in on the website, we direct you to download the app — no account data is processed by that redirect beyond the sign-in attempt itself.

2.1 Information we collect for Individual Accounts

  • Registration and profile: first name, last name, email address, phone number (if provided), and password — stored in hashed form only, never in plain text.
  • Verification: email verification status and one-time codes sent to confirm your email address or secure account changes.
  • Referral code: if you enter a partner referral code at registration, we store it and, where it matches an active partner, the attribution to that partner. See section 9.
  • Learning activity: progress in video lessons, AI book usage, exam practice attempts and scores, study streaks, chat history with AI features, and related learning analytics needed to operate the Services.
  • Personal uploads: if you upload your own study material (for example a PDF), we process the file and its metadata to provide study and chat features on it.
  • Payment data: where you purchase content or a plan, our payment provider processes your payment details and returns to us a transaction record and, where you authorise recurring payment, a reusable payment token together with the card brand, last four digits and expiry. We never receive or store your full card number.
  • Technical and device data: app and web usage logs, device type, IP address and similar technical information, used for security, troubleshooting and service improvement.

2.2 How we use Individual Account data

We process Individual Account data to create and manage your account, authenticate you, deliver learning features in the app, save your progress, process payments, provide customer support, maintain security, comply with the law, and improve the Services. We do not sell your personal data.

2.3 Deleting your Individual Account

Individual Users may request deletion of their account and associated personal data. Contact us from the email address registered on your account:

Include your full name and the email address (or phone number, if used to register) tied to your account so we can verify your identity. We will confirm receipt and process verified requests within the timeframes required by law, typically within thirty (30) days. Some data may be retained where required by law or for legitimate purposes such as fraud prevention, dispute resolution, financial record-keeping or backup cycles, after which it is deleted or anonymised.

If you are a school student using credentials issued by your school, your account is managed by your school. For deletion or correction of school-linked student data, contact your school administrator first — not the Individual Account deletion channel above.

3.Categories of data we collect

We collect and process the following categories of personal data:

  • Account information: names, email addresses, telephone numbers, school or institutional affiliation, role (administrator, teacher, student, guardian, individual learner) and authentication credentials. For Individual Accounts this includes the fields described in section 2.
  • Educational records: enrolment data, attendance, grades and assessment results, assignment submissions, curricula, lesson plans and related academic outputs and performance metrics.
  • Communication data: messages exchanged through the platform, notifications, enquiries, support tickets and interactions between teachers, students, guardians and administrators.
  • Learning and usage data: features accessed, time spent, practice attempts, progress and streaks, and interactions with AI features.
  • Technical data: IP addresses, device identifiers and types, operating system, browser type and version, system logs, session data and usage analytics.
  • Financial and billing data: subscription details, transaction records and billing information, collected and processed through third-party payment providers in compliance with PCI-DSS.
  • Profile and preference data: settings, language preferences, notification preferences and other choices you make.

4.Why we process your data

  • To deliver, administer and maintain the Services and provide access to their features.
  • To fulfil our contractual obligations to schools, teachers, guardians, students and individual learners.
  • To facilitate communication between teachers, students, guardians and school administrators.
  • To record and report student academic progress, attendance and performance.
  • To provide and personalise Individual Account features, including AI books, video lessons, exam practice and progress tracking.
  • To process payments, manage subscriptions and entitlements, and maintain financial records.
  • To safeguard the security, integrity and lawful use of the Services, and to prevent fraud and unauthorised access.
  • To provide customer support, respond to enquiries and resolve technical issues.
  • To improve the Services, including through aggregated and anonymised analytics.
  • To send service announcements and administrative messages, and — only with your consent — marketing communications.
  • To comply with statutory, regulatory and legal obligations.

5.Lawful basis for processing

  • Performance of a contract: where processing is necessary to perform a subscription agreement, service agreement or terms of use with a school, institution or individual user.
  • Legal obligation: where processing is required by legislation, court order, regulatory directive or governmental authority.
  • Legitimate interest: where processing is necessary for the efficient operation, improvement, security or protection of the Services, fraud prevention or internal administration, provided that interest does not override your fundamental rights and freedoms.
  • Consent: for optional activities such as direct marketing, non-essential cookies and analytics, and push notifications. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

6.AI features and automated processing

Parts of the Services use artificial intelligence to explain concepts, answer questions about learning material, summarise documents and assist with content and administrative tasks.

  • What is processed: the content of your request and the relevant portion of the material you are asking about — for example the chapter you have open, or a document you uploaded — along with limited context needed to produce a useful answer.
  • Third-party AI providers: to deliver these features we transmit that content to third-party AI processing providers acting under contract to us. They are permitted to process it only to return a response to us, and are bound by confidentiality and security obligations.
  • Retention: we retain your AI conversation history on your account so you can return to it, and usage counts so we can apply plan limits fairly. Deleting your account removes this history in accordance with section 11.
  • No solely automated decisions with legal effect: we do not use AI to make decisions producing legal or similarly significant effects about you without human involvement. AI output is a study and productivity aid and should be verified — see our Terms and Conditions.
  • What not to submit: do not enter passwords, financial account details, health information or other sensitive personal data into AI chat features. They are not designed to hold that kind of information.

7.Disclosure and transfer of data

We may disclose or transfer personal data in these circumstances:

  • Within educational institutions: to authorised administrators, teachers, support staff or school representatives acting as Controllers or as personnel with legitimate access rights.
  • To guardians: where a guardian is linked to a student, information about that student relevant to their guardianship may be made visible to them.
  • Service providers: cloud hosting and storage, payment processors, AI processing providers, email and messaging gateways, push notification services and analytics platforms, each engaged under binding agreements imposing confidentiality and security obligations equivalent to those in this Policy.
  • Legal and regulatory authorities: to regulators, law enforcement, courts or other competent bodies on valid legal demand, or where disclosure is necessary to comply with the law or protect the rights and safety of Smart Edu Hub, our users or third parties.
  • Business transfers: in a merger, acquisition, restructuring or sale of assets, personal data may transfer to the successor entity, subject to lawful safeguards and confidentiality obligations.
  • International transfers: where personal data is transferred outside your jurisdiction, we implement adequate safeguards — such as standard contractual clauses or an equivalent mechanism recognised under applicable data protection law — to ensure an adequate level of protection.

8.Competitions and public results

Where you or your school enters a competition or academic programme run through the Services, additional processing applies.

  • We process entry details, attempts, scores and results in order to run the competition and determine outcomes.
  • Leaderboards, results, participant or school names, and certificates may be published as part of the competition, including on publicly accessible pages, where the applicable competition rules say so.
  • Where an entrant is a minor, the entering school or the parent or guardian is responsible for ensuring the necessary consent for that publication has been obtained.
  • If you wish results relating to you to be withdrawn from public display, contact us at support@smart-edu-hub.com. Verified results may be retained internally for integrity and audit purposes.

9.Referral codes and partners

  • If you enter a referral code when registering, we store the code and, where it matches an active partner, record that your registration is attributed to that partner.
  • We share with that partner only what is necessary to administer the programme and calculate any commission — for example that a registration or subscription occurred against their code. We do not share your learning activity, assessment results or AI conversations with partners.
  • Partners are independent third parties and are responsible for their own handling of any data you give them directly.

10.Children and minors

We recognise the sensitivity of student data, particularly data relating to children. Such data is processed under the lawful authority of schools, educational institutions or parents and legal guardians, and in accordance with applicable child protection and data protection law, including:

  • the Nigeria Data Protection Act 2023 and NDPR provisions relating to children;
  • the General Data Protection Regulation (GDPR) provisions on children's data, where applicable;
  • the Children's Online Privacy Protection Act (COPPA), where applicable;
  • other applicable child data protection regulations.

Direct registration by children under the age of thirteen (13) is not permitted unless facilitated by a school, parent or legal guardian. Schools and institutions warrant that they have obtained all necessary parental or guardian consents before providing student data to us.

11.Data retention and deletion

We retain personal data only for as long as necessary for the purposes set out in this Policy and to meet statutory retention periods. Retention varies by data type:

  • Individual Account data is retained while the account is active. Following a verified deletion request we delete or anonymise it within the periods described in section 2.3, except where longer retention is legally required.
  • School account data is retained for the duration of the subscription plus a reasonable period for backup and audit.
  • Educational records may be retained longer where required by educational regulation or institutional policy.
  • Technical and security logs are retained for shorter periods necessary for security and troubleshooting.
  • Financial records are retained in accordance with applicable tax and accounting law.

On expiry of the applicable retention period, personal data is securely deleted, anonymised or otherwise irreversibly destroyed using industry-standard methods, unless extended retention is required by law, court order or contract.

12.Security measures

We apply technical and organisational measures consistent with industry standards to protect the confidentiality, integrity and availability of personal data, including:

  • encryption of data in transit using TLS, and of data at rest using AES-256 or an equivalent standard;
  • passwords stored using one-way hashing — never in recoverable form;
  • role-based access control applying the principle of least privilege;
  • regular vulnerability assessment, security review and patching;
  • network protections including firewalls and abuse and rate limiting;
  • secure backup and disaster recovery procedures;
  • staff training on data protection and confidentiality obligations;
  • incident response procedures for the timely detection, containment and notification of security breaches.

No system can be entirely immune from compromise. We disclaim liability for incidents arising from factors beyond our reasonable control, including user negligence, credentials shared or reused by a user, or sophisticated attacks exploiting previously unknown vulnerabilities.

13.Biometric authentication

Our mobile applications may offer biometric authentication (such as fingerprint or face recognition) to unlock the app.

  • Purpose: biometric verification is used solely to unlock the app and streamline access. It is not used for any other purpose.
  • Storage: biometric data is stored and processed locally on your device by the operating system. Smart Edu Hub does not collect, transmit or store biometric data on our servers, and has no access to the underlying biometric template.
  • Optional: the feature is entirely optional. You may use a password instead, and can enable or disable biometric unlock at any time in your device or app settings.
  • Third-party handling: verification is performed by your device's secure enclave or equivalent system, such as Apple Touch ID / Face ID or the Android biometric APIs.

This disclosure is provided to meet the transparency requirements of the Apple App Store, Google Play and applicable data protection law.

14.Push notifications

With your consent, we send push notifications to your device. The primary reasons we request notification permission are:

  • Transaction and payment alerts: subscription renewals, payment confirmations, failed payments and billing updates, so you can avoid interruption to your access.
  • Support messages: replies to your support requests and updates on tickets, so you receive help when you need it.
  • Security and account updates: sign-in activity, password or security changes and account verification, to help protect your account from unauthorised access.

We may also send optional notifications such as assignment reminders, result releases or school announcements where you have opted in. You can control which notifications you receive through your device settings and in-app preferences at any time. Declining notifications does not affect your use of the core Services, but you may miss time-sensitive alerts.

15.Cookies and tracking technologies

We use cookies and similar technologies on our website and platform to keep you signed in, remember preferences and understand usage. Full details — including each category, how long cookies last and how to control them — are in our Cookies Policy. Our mobile applications do not use browser cookies.

16.Your rights

Subject to applicable law, you have the following rights over your personal data:

  • Access: to confirm whether we process your personal data and to obtain a copy of it and information about the processing.
  • Rectification: to have inaccurate, incomplete or outdated data corrected without undue delay.
  • Erasure: to request deletion of your personal data, subject to legal or contractual retention requirements.
  • Restriction: to request that processing be limited in certain circumstances, such as while accuracy is being verified.
  • Objection: to object to processing based on legitimate interests, and to direct marketing at any time.
  • Portability: to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller where technically feasible.
  • Withdrawal of consent: where processing is based on consent, to withdraw it at any time without affecting the lawfulness of prior processing.
  • Complaint: to lodge a complaint with a competent data protection authority — in Nigeria, the Nigeria Data Protection Commission — if you believe your rights have been infringed.

Submit requests using the contact details in section 19. Individual Users requesting account deletion should follow the process in section 2.3. We respond to verified requests within the timeframes required by law, typically within thirty (30) days.

17.Responsibilities of schools

Smart Edu Hub acts primarily as a Processor in respect of student data and educational records. Responsibility for lawful collection, consent management and provision of that data rests with the Controller — the school, educational institution, or parent or legal guardian.

Schools, institutions and users warrant that:

  • they have obtained all requisite parental, guardian or other legal consents for the collection and processing of student data;
  • all personal data provided to Smart Edu Hub has been collected lawfully and in compliance with applicable data protection law;
  • they have the legal authority to share that personal data with us for the purposes set out in this Policy.

Schools and institutions agree to indemnify and hold harmless Smart Edu Hub, its officers, directors, employees and agents against claims, penalties, fines, liabilities, damages, costs and expenses (including reasonable legal fees) arising from unlawful or unauthorised collection, provision or processing of personal data, breach of data protection obligations, or failure to obtain necessary consents.

18.Amendments and updates

We may update this Policy to reflect changes in applicable law, regulatory requirements, technology or our practices. Material changes will be notified through:

  • a prominent notice within the Services or on our website;
  • an email to the address registered against your account;
  • an in-platform notification.

The revised Policy takes effect on the date specified in the notice, and the "last updated" date at the top of this page will change. Continued use after that date constitutes acceptance. If you do not agree with the amended Policy, you should stop using the Services and may request deletion of your personal data.

19.Contact and Data Protection Officer

For questions about this Policy, our data protection practices, or to exercise your rights, contact us at:

We will make every reasonable effort to respond within the timeframes prescribed by applicable law.

Smart Edu Hub is powered by Accessible Publishers Limited.