Data-protection pack
This is the hand-over document for a school’s governing body, parent body, or legal advisor: every data-protection fact about MySentinel in one place, in plain language. Each section carries the whole answer here; the linked pages hold the deeper technical detail. It is written to be printed and attached to a service agreement as-is.
Responsible party and operator. Under POPIA, your school is the responsible party for its learners’ and guardians’ personal information; MySentinel (operated by Binary Solutions) is the operator, processing that information only to run the service on the school’s behalf and on its instructions. MySentinel’s named information officer is Abe Moshou (am@binary-solutions.co.za) — the contact for any privacy question a school cannot answer itself, and the person who decides and performs breach notification.
What is collected, and why
| Information | Why it is needed |
|---|---|
| Learner name, class, grade, and the school’s own learner number | To run the register: who is on the roster, who came through the gate. |
| Learner photo (optional, per school) | So the officer at the gate confirms the right child leaves with the right adult. Encrypted with a key belonging to that school alone. |
| SA identity number (optional, never required) | Solely to resolve a transfer between schools and de-duplicate a re-import. Stored only as an encrypted value plus a one-way match code — there is no plaintext copy, no screen shows it, and a school may decline to supply it with no loss of function. |
| Guardian name, relationship, phone, email | To tell the right family the right thing: check-ins, check-outs, emergencies. Contact details are encrypted at rest. |
| Check-in / check-out records | The service itself — an immutable register of arrivals and departures. |
| Visitor name and reason (ID number is never stored — only a partial one-way fingerprint) | The on-site register a school must be able to produce. |
Collection is minimised by design: no birth dates, no addresses, no financial information about families, and nothing is collected “in case it is useful later”.
Lawful basis
Processing rests on the school’s mandate as responsible party: performing its duty of care to learners (safety and attendance) and the legitimate interest of telling a child’s own guardians about that child’s movements. Where consent is the right basis — messaging a guardian on a paid channel — the product enforces it mechanically: a WhatsApp or SMS is sent only to a number whose owner has verified it, and a guardian’s STOP reply is honoured everywhere, immediately, with no urgency exception.
Where the data lives
There is no South African database region, so the databases and file stores holding school records are pinned to the European Union — chosen deliberately because the EU’s data-protection regime is the closest analogue to POPIA among the available regions. This is a POPIA section 57 transborder arrangement and it is disclosed, not buried. A small amount of operational data (delivery logs with identifiers hashed, configuration caches) rides the provider’s global network without a region pin. The current position is South Africa only: onboarding a school outside South Africa would require a new residency decision before contract.
Sub-processors
| Processor | What it processes |
|---|---|
| Cloudflare | All hosting: application, databases, file storage, message queues. |
| Meta Platforms (WhatsApp Business) | WhatsApp message delivery — the guardian’s number and the message content, at send time. |
| The email delivery provider | Email delivery — the guardian’s address and message content, at send time. |
| BulkSMS | SMS delivery — the guardian’s number and message content, at send time. |
Each sees only what delivery requires, only at delivery time. The full technical detail is on Trust & POPIA.
How long it is kept
The platform position is two years of data available at any time is enough. Retention is enforced, not displayed: expired records are archived encrypted, then deleted, on each school’s own schedule within platform-enforced floors and ceilings. Defaults: check-in/out records 13 months; audit history 2 years; delivery logs 14 days; parent messages 1 year; visitor records 2 years (the one class a school may deliberately extend, to 10 years, for its own legal or insurer duty). Every database table — 128 at last count — carries a recorded retention decision, and the build fails if a new one ships without one.
Subject rights, and how they are exercised
A guardian or learner exercises POPIA rights through the school (the responsible party), and the school executes them in the product, each as a first-class, audited action gated behind a passkey step-up:
- Access — a subject-access request assembles everything held about a person, ready to export.
- Correction — records are corrected through the same audited flow.
- Erasure — runs as a durable job with a cool-off window, then cascades across every store that holds a copy; it reports complete only when every part succeeded, and the platform carries an automated proof that an erased subject can no longer be found in any database, file store, or cache.
- Objection — a guardian can switch any notification channel off at any time from the parent portal, without asking anyone.
If the school does not respond, the escalation contact is the information officer above, and every data subject retains the right to complain to the Information Regulator of South Africa.
Security posture, in one paragraph
One school can never see another (isolation is derived from the verified login, never from anything a browser sends); every action is role-checked on the server, with passkey step-up on sensitive ones; contact details, photos, and learner identity numbers are encrypted at rest with per-school keys; the audit trail is append-only and redacted (identifiers, never contact details); backups are encrypted and mirrored to a separate account. The full description, including what is on the roadmap rather than shipped, is on Trust & POPIA.
Breach procedure
On a suspected compromise: internal triage within 4 hours. On a confirmed breach of personal information: the information officer — Abe Moshou — decides and performs the notification to the Information Regulator and every affected school’s administrators within 24 hours, with a plain-language statement of what was accessed, when, and what has been done. The school, as responsible party for its own community, notifies its parents, supported by MySentinel’s prepared communication and facts. Engineering escalates TO the information officer’s decision; it does not make it.
The parent-facing version
Parents and guardians have their own plain-language privacy policy at the public site (/privacy on the MySentinel launch site), naming the same facts in the same words — what is collected, where it lives, their rights, and the same named contact.