Edutrace logo Edutrace
Back to Home
Legal

Terms of Service & Privacy Policy

This document explains how Edutrace is used by schools, teachers, students and parents — and how we handle the data entrusted to us.

Effective: October 2026 Last updated: October 2026 Governing law: Republic of Uganda
Part 1 — Terms of Service

1. Introduction

Edutrace ("we", "us", "our") provides a school management platform for Ugandan secondary schools. The platform helps schools manage student rosters, teacher assignments, assessment marks, term reports and report cards.

By accessing or using Edutrace — including the website at edutraceug.com, any school subdomain under *.edutraceug.com, and any related services — you agree to these Terms of Service. If you do not agree, please do not use the platform.

Who operates Edutrace

Edutrace is operated from Uganda and serves Ugandan schools. All content, services and data processing described in this document are provided under the laws of the Republic of Uganda.

Section 2

Eligibility & Accounts

2.1 Who can use Edutrace

Edutrace accounts are created for four user roles:

  • School administrators — account created by Edutrace staff on behalf of a school.
  • Teachers — self-register using details that match the school's official roster.
  • Students — self-register using details that match the school's official roster.
  • Parents or guardians — self-register by matching their child's record, and must give explicit consent.

2.2 Accurate information

You agree that the information you provide during registration is accurate and current. If your details change, you must update them through your school's office or contact us at support@edutraceug.com.

2.3 Account security

You are responsible for keeping your password confidential. Do not share your account. If you suspect your account has been accessed by someone else, reset your password immediately and notify your school administrator.

2.4 Age

Students under the age of 18 may only use Edutrace through an account created by their school or with the consent of a parent or guardian (see Section 18 — Children & parental consent).

Section 3

Roles & Responsibilities

3.1 School administrators

School administrators are responsible for:

  • Maintaining accurate student and teacher rosters.
  • Assigning teachers to classes, streams and subjects.
  • Setting scoring modes, assessment types and grading rules.
  • Handling parent consent records and any report holds.
  • Deciding who within the school can access which data.

The school administrator acts as the school's data controller for the information held under their school's account. Edutrace acts as a data processor on the school's behalf.

3.2 Teachers

Teachers agree to:

  • Only enter marks for classes and subjects they have been assigned.
  • Enter accurate marks and use the correct status flags (Absent, Excused, N/A) where appropriate.
  • Not share access to their account with anyone else.
  • Respect the confidentiality of student data.

3.3 Students

Students agree to view only their own results and not attempt to access another student's records. Sharing a report card publicly is the student's own decision and responsibility.

3.4 Parents & guardians

Parents agree to:

  • Only access the results of the child linked to their account.
  • Provide truthful information when linking their account.
  • Give informed consent for their child's data to be processed.
Section 4

Acceptable Use

You agree not to:

  • Attempt to gain unauthorised access to any part of Edutrace, including other schools' data.
  • Upload files containing viruses, malware or anything harmful.
  • Use Edutrace to send spam, bulk unsolicited messages or communications unrelated to school business.
  • Reverse-engineer, scrape, or attempt to extract data from the platform beyond normal use.
  • Impersonate another user, teacher, student or school.
  • Use Edutrace for any activity that is illegal under Ugandan law.
Uploading files

All uploaded files pass through a virus scan. Uploads that fail the scan are rejected and logged. Attempting to upload harmful files may result in account suspension.

Section 5

Subscriptions & Fees

Edutrace is offered to schools on a subscription basis. Some features — such as bulk emails to parents, students or teachers — depend on an active school subscription.

5.1 Active subscription requirement

Certain features require the school's subscription to be active. If a school's subscription lapses, those features will be disabled until the subscription is renewed. Existing data will not be deleted because of a lapse.

5.2 Pricing and payment

Subscription pricing and payment arrangements are agreed directly between the school and Edutrace. Inquiries: schools@edutraceug.com.

5.3 Communication limits

Bulk email features may be subject to daily limits and per-message credit allowances to protect email deliverability. Limits are shown in the admin dashboard.

Section 6

Intellectual Property

6.1 Our property

The Edutrace platform — including its source code, design, structure, brand, logos and documentation — is owned by Edutrace and its licensors. You may not copy, redistribute or resell any part of the platform without written permission.

6.2 Your data

All data you upload or enter — rosters, marks, comments, notes, school information — belongs to the school. You retain ownership. We only process it to provide the service.

6.3 Illustrations

Illustrations used on our public website are provided by Storyset under their licensing terms.

Section 7

Suspension & Termination

7.1 By us

We may suspend or terminate an account if:

  • These terms are breached.
  • The account is used for illegal activity.
  • We are required to do so by law or by a valid request from a competent authority.

7.2 By the school

A school administrator may request closure of their school's account at any time by emailing schools@edutraceug.com. We will export the school's data on request and delete it in line with Section 17.

7.3 By you

You may stop using Edutrace at any time. Individual accounts (teacher, student, parent) can be removed on request by contacting your school administrator or us directly.

Section 8

Disclaimers

Edutrace is provided on an "as available" basis. While we work to keep the platform running reliably, we do not guarantee that the service will be uninterrupted, error-free, or free from data loss caused by factors outside our control.

  • We do not verify the accuracy of any marks, roster entries or reports entered by a school.
  • We do not produce the school's results — we provide the tool that the school uses to record and compute them.
  • We do not guarantee that a report card generated by the platform will be accepted by any specific exam board or ministry — the school is responsible for compliance with NCDC and other regulations.
Section 9

Limitation of Liability

To the maximum extent permitted by Ugandan law, Edutrace is not liable for:

  • Any indirect, incidental or consequential damages arising from use of the platform.
  • Loss of data caused by the school failing to maintain backups.
  • Losses arising from decisions made by the school, a teacher, a student or a parent based on information shown by Edutrace.
  • Service interruptions caused by third-party providers (hosting, email, database, virus scanning) or by internet connectivity issues.

Nothing in these terms excludes liability that cannot be excluded under the laws of the Republic of Uganda.

Section 10

Changes to These Terms

We may update these terms as the platform evolves. Material changes will be announced on the platform and reflected in the "Last updated" date at the top of this document. Continued use of Edutrace after changes are posted means you accept the updated terms.

Part 2 — Privacy Policy

11. Overview

This Privacy Policy explains what personal data Edutrace collects, why we collect it, who can see it, and how we protect it. It is written to comply with the Uganda Data Protection and Privacy Act, 2019 and its accompanying regulations.

Our commitment

We collect only what is needed to run a school management platform. We do not sell personal data. We do not use student data for advertising. Parents and students can see exactly what the platform holds about them.

Section 12

What We Collect

12.1 Account information

Email address
Used to identify you at login.
Password
Stored in hashed form by Firebase Authentication. We never see your plain password.
Role
One of: school administrator, teacher, student, parent.
School affiliation
Which school you belong to.
Linked record
For students and parents — which roster record your account is connected to.

12.2 Student data (uploaded by the school)

Schools upload their official rosters, which may include:

  • Student name, class, stream, gender.
  • Subjects taken.
  • Optional notes ("extraDetail") used by the school to disambiguate similar records.

12.3 Teacher data (uploaded by the school)

  • Name, gender, subjects taught, classes assigned.
  • Permissions assigned by the school administrator.

12.4 Assessment data

  • Marks entered by teachers (scores or CBC levels).
  • Status flags: entered, absent, excused, not applicable.
  • Assessment type, maximum score, and the term they belong to.

12.5 Report data

  • Class teacher comments and conduct notes written by teachers.
  • Report holds (e.g. fee arrears) placed by the school administrator.

12.6 Parent consent records

  • The fact that a parent has consented, and when.
  • The relationship (mother, father, guardian).

12.7 Technical and usage data

  • Basic connection metadata (IP address, browser, device type) collected automatically by our hosting provider for security and diagnostics.
  • Cookies set by our platform (see Section 16).
  • Audit log entries showing who changed what, when.
Section 13

How We Use Data

We use personal data only to:

  1. Authenticate users and secure accounts.
  2. Show students, teachers, parents and administrators the data they are entitled to see.
  3. Compute term reports and generate report cards.
  4. Send transactional emails (welcome messages, password resets).
  5. Send school-authorised bulk communications (only when the school has an active subscription).
  6. Detect and prevent fraud, abuse and security threats.
  7. Comply with legal obligations.

We do not:

  • Sell personal data to third parties.
  • Use student or parent data for advertising.
  • Share data with other schools.
  • Use personal data to train external AI models.
Section 14

Who Can See What

Access to data is strictly controlled by role and by school. A user from one school cannot see another school's data — this is enforced by the platform.

School administrator
Full access to their own school's rosters, teachers, marks, reports, notes, holds and audit log.
Teacher
Only the classes and subjects they are assigned. Class teachers see additional reports for their own class.
Student
Only their own marks, term reports and report card.
Parent
Only their linked child's marks, term report and report card — and only after giving consent.
Edutrace staff
Limited technical access, only when necessary to operate, maintain or support the platform. All access is logged.

14.1 Report holds

A school may place a hold on a student's report (for example, for unpaid fees). When a hold is active, the student and parent cannot view the report until the school removes the hold. The reason for the hold is shown to the student or parent.

Section 15

Third-Party Processors

We use the following trusted service providers to operate Edutrace. Each acts as a data processor under our instruction and under their own terms.

Google Firebase
Authentication and database (Firestore). Stores account credentials and the school data. Google operates under its own data processing terms.
Cloudflare
Hosting and edge network for all platform traffic. Cloudflare processes requests to serve pages and prevent abuse.
Cloudmersive
Virus scanning for uploaded spreadsheets. Files are transmitted to Cloudmersive's virus-scan API and are not retained by Cloudmersive after the scan.
Cloudinary
Storage of archived roster uploads and school images (logos, hero photos). Files are stored on our Cloudinary account and are only accessible to authorised users.
Resend
Transactional and bulk email delivery. Resend receives the recipient email address and message contents in order to deliver the email.
Storyset
Illustrations used on our public website. No personal data is shared with Storyset.
Section 16

Cookies

We use a small number of cookies and browser storage keys. You can accept or reject non-essential cookies at any time using the banner at the bottom of the page.

Essential
Session cookies and Firebase authentication tokens. Required to keep you signed in. These cannot be disabled.
Preferences
A local storage key that remembers your cookie choice. Stored on your device only.
Analytics
Loaded only if you choose "Allow". Used to understand how the platform is used so we can improve it.

You can clear cookies at any time from your browser settings. Clearing essential cookies will sign you out.

Section 17

Data Retention

  • Active account data is retained for as long as the school's account is active.
  • Marks and reports are retained for as long as the school chooses to keep them.
  • Audit logs are retained for at least 12 months to support security and dispute resolution.
  • Uploaded files archived on Cloudinary are retained indefinitely unless the school requests removal.
  • Deleted accounts — when a school closes its account or requests deletion, we remove the school's data within 30 days, except where we are required to retain it by law.
Section 18

Children & Parental Consent

Most users of Edutrace are students under 18. We take the protection of their data seriously.

18.1 Parental consent

When a parent registers on Edutrace, they must explicitly consent to their child's data being processed. Consent is recorded on the platform and can be withdrawn by contacting the school or us.

18.2 School responsibility

Schools are responsible for informing parents that student data will be processed on Edutrace and for obtaining any consent required by Ugandan law before uploading that data.

18.3 Withdrawing consent

A parent may withdraw consent at any time by contacting their school or emailing support@edutraceug.com. Withdrawing consent may prevent the parent from accessing their child's results on Edutrace. It does not automatically remove the child's record — the school controls that data.

Section 19

Security

We protect data using:

  • Encrypted HTTPS connections for every request.
  • Firebase Authentication with industry-standard password hashing.
  • Role-based access controls enforced at the API level, not just in the interface.
  • Virus scanning of every uploaded file.
  • An audit log recording significant changes to marks, rosters and settings.
  • Secure, server-side handling of service-account credentials — never exposed to the browser.

No system is perfectly secure. If you notice a security issue, please report it to support@edutraceug.com.

Section 20

Your Rights

Under the Uganda Data Protection and Privacy Act, 2019, you have the right to:

  1. Access the personal data we hold about you.
  2. Correct any inaccurate data.
  3. Request deletion of data we no longer have a legitimate reason to keep.
  4. Object to processing in certain circumstances.
  5. Withdraw consent where processing is based on consent.
  6. Complain to the Personal Data Protection Office of Uganda if you believe your rights have been violated.

To exercise any of these rights, contact support@edutraceug.com. Where the data belongs to a school, we may need to refer your request to the school as the data controller.

Section 21

International Transfers

Some of our service providers (Google, Cloudflare, Cloudinary, Cloudmersive, Resend) operate servers outside Uganda. When data is transferred internationally, we rely on the providers' standard contractual protections and security measures. We do not transfer personal data to jurisdictions that do not provide adequate protection without such safeguards in place.

Section 22

Changes to This Policy

We may update this Privacy Policy to reflect changes in the platform, our practices, or legal requirements. Material changes will be posted on the platform and the "Last updated" date at the top of this page will change. We encourage you to review this page periodically.

Section 23

Contact Us

For any question about these terms, our privacy practices, or your data, please reach out:

Edutrace — Uganda

General support: support@edutraceug.com
Schools and onboarding: schools@edutraceug.com