Application Name: ST Waves (ST Waves - School ERP)
Operated by: ST Waves Educational Technologies / CodeWave Solutions
Contact Email: privacy@stwaves.com
1. Introduction & Overview
ST Waves ("we," "our," or "us") provides a cloud-based multi-tenant school enterprise resource planning (ERP) platform and mobile application. This Privacy Policy governs the manner in which ST Waves collects, uses, maintains, and discloses information collected from users (each, a "User") of the ST Waves mobile application, web portal, and associated services (collectively, the "Platform").
The Platform serves educational institutions ("Schools"), administrators ("School Admins" and "Super Admins"), supervisors ("Supervisors"), educators ("Teachers"), students ("Students"), and parents or legal guardians ("Parents").
2. Information We Collect
We collect information directly from Users, through educational institutions subscribing to our services, and automatically via application usage.
A. Account and Profile Information
Authentication Data: Full name, institutional or personal email address, username, encrypted password hashes, and user roles (Super Admin, School Admin, Supervisor, Teacher, Student, Parent).
Institutional Association: Associated School Tenant ID, assigned academic stages, grades, classrooms, sections, subjects, and student roster enrollments.
Family Linkage: Parent-student relationships, guardian contact telephone numbers, and secondary emergency contacts.
B. Academic & Operational Data
Classroom Records: Daily attendance, tardiness logs, behavioral notes, and excellence/kudos records.
Curriculum & Materials: Weekly study plans, lesson diaries, homework assignments, uploaded attachments (PDFs, images, documents), and student assignment submission files.
Assessments & Evaluations: Exam schedules, moderation statuses, examination scores, formal report cards, teacher feedback, and academic grading metrics.
C. Real-Time Collaboration & Virtual Classroom Data
Microsoft Teams Integration: Organization tenant IDs, meeting unique identifiers, scheduled session times, subject names, virtual meeting links (joinWebUrl), and attendance confirmation timestamps.
Realtime Communication: Classroom-scoped WebSocket metadata, moderation queue updates, in-app notifications, and instant alerts.
D. Device & Automated Usage Information
Technical Telemetry: Device model, operating system version (iOS/Android), application build number, preferred locale/language settings, IP address, and network connectivity state.
Local Storage & State: Authentication tokens (stored securely in iOS Keychain / Android EncryptedSharedPreferences) and unread notification state flags (via local app cache).
3. Children’s Privacy (COPPA & FERPA Compliance)
The Platform processes personal data relating to minors under the age of 18 ("Students") strictly on behalf of the contracting educational institution:
School Consent: The educational institution acts as the agent for parents and grants authorization for the collection and processing of student data solely for educational purposes under the Family Educational Rights and Privacy Act (FERPA) and the Children’s Online Privacy Protection Act (COPPA).
No Commercial Exploitation: Student data is never used for behavioral advertising, profiling, commercial monetization, or sale to third parties.
Parental Rights: Parents and legal guardians have the right to inspect their child's academic records, request corrections, or request deletion of personal information through their school's administrative office.
4. How We Use Collected Information
We process personal and operational data exclusively to operate, maintain, and enhance educational workflows:
Authenticating and verifying user identities across distinct role-based access levels.
Delivering classroom administration, daily attendance tracking, exam scheduling, homework submissions, and academic evaluations.
Facilitating real-time updates and notifications for exams, weekly schedules, and moderation alerts.
Enabling integration with third-party tools (such as Microsoft Teams for remote lectures).
Diagnosing technical issues, resolving bugs, and ensuring platform security and system uptime.
5. Multi-Tenant Data Isolation & Security Architecture
ST Waves enforces enterprise-grade architectural isolation across schools:
Tenant Scoping: Every database query, API transaction, and file storage path is programmatically bounded by the user's specific institutional identifier (schoolId). Users cannot access, modify, or view data from another educational institution.
Real-Time Isolation: WebSocket events are segmented into strict tenant-scoped rooms (e.g., classroom:{schoolId}:{classRoomId}). Unauthorized cross-tenant subscription attempts are systematically blocked.
Access Governance: Fine-grained Role-Based Access Control (RBAC) ensures teachers can only grade their designated classes, while students and parents maintain read-only access to published, classroom-specific records.
Data in Transit and at Rest: All client-server communications use TLS 1.3 encryption. Passwords and sensitive tokens are hashed using cryptographic industry standards (such as bcrypt).
6. Information Sharing & Third-Party Processors
We do not sell, trade, or rent personal information to third parties. We disclose data solely under the following parameters:
Within the Educational Institution: Data submitted by students or teachers is accessible to authorized school administrators, supervisors, and relevant parents.
Service Providers & Cloud Infrastructure: Trusted third-party vendors who provide essential infrastructure (cloud hosting, database management, real-time message brokering, and media storage). All processors are bound by strict confidentiality and data protection agreements.
Microsoft Corporation: When using Microsoft Teams integrations, relevant meeting metadata is transmitted to Microsoft Graph APIs to facilitate online classroom sessions.
Legal Compliance: When required by law, subpoena, or valid legal order, or to protect the safety, rights, and security of our users and the public.
7. Data Retention & Account Deletion
Retention Period: We retain institutional and academic data for the duration of the educational institution's active subscription contract, or as mandated by applicable education records laws.
Data Purging: Upon contract termination or formal request by a school administrator, institutional databases are scrubbed and permanently deleted within ninety (90) days, except where retention is legally mandated.
User Data Deletion: Individual users (teachers, students, parents) seeking account deletion or modification must coordinate directly with their school administrator, who manages the authoritative school directory.
8. Changes to this Privacy Policy
ST Waves reserves the right to update this Privacy Policy at any time. Material changes will be communicated via in-app notifications, web portal banners, or direct notices to registered institutional administrators. Continued use of the Platform following any modifications constitutes acceptance of the revised terms.