Imaginary University School information & policies
Your information

Privacy Notice

How the school uses and protects student, guardian, staff, attendance, messaging, and account information.

Last reviewed: July 18, 2026

Who is responsible for the information?

Imaginary University operates this system and decides why and how school records are used. In data-protection terms, the school is the personal information controller. Questions and privacy-rights requests can be sent through the Contact & Data Rights page.

Information handled by this system

Student records

Name, photo, RFID UID, username, grade, section, enrollment status, and school-year history.

Contact details

Residential address and the guardian name and phone number recorded by the school.

Attendance

Tap date and time, IN or OUT event, RFID reader or gate location, attendance calculations, and verified manual corrections.

Communications

Student–administrator messages, announcements, guardian SMS content, and delivery status.

Security records

Account identifiers, password hashes, login lockouts, session records, and administrative audit trails.

Support records

Internal support tickets, comments, and attachments submitted by authorized staff.

Why the information is used

  • Record and review school attendance and enrollment history.
  • Show each student their own profile and attendance record.
  • Notify the recorded guardian about eligible RFID attendance events.
  • Prepare authorized reports, summaries, and attendance analytics.
  • Allow school communications and publish public announcements.
  • Correct verified attendance errors while preserving an audit history.
  • Protect accounts, investigate misuse, maintain backups, and support system operation.

The school must use an appropriate lawful basis for each activity and follow the principles of transparency, legitimate purpose, proportionality, and data minimization. Consent is used only when consent is the appropriate basis; it is not treated as the basis for every school record.

Who may receive information

Access is limited according to role. A student sees their own portal record; authorized admins manage school records and protected settings; and an RFID monitor account can use only the scanner.

Information may also be provided to the recorded guardian, authorized school personnel, the SMS delivery provider (Semaphore), hosting or technical service providers working for the school, and public authorities when disclosure is required or permitted by law. The website also loads interface resources from external content-delivery and font providers. These services may receive ordinary connection information such as an IP address and browser details.

Retention and deletion

Records are kept only for as long as necessary for attendance, education, safeguarding, accountability, school operations, and applicable recordkeeping obligations. Specific periods are governed by the school's approved records-retention schedule and applicable law. Backups may retain a protected copy for a limited recovery period. A student or guardian may ask the Data Protection Officer which period applies to a particular record.

Cookies and local device data

The system uses essential session data to keep signed-in users authenticated and to protect forms and accounts. Authorized scanner stations may use a persistent authentication token so a dedicated reader can remain connected. These technologies are used for operation and security, not behavioral advertising.

Your privacy rights

Depending on the circumstances, data subjects may request information, access, correction, erasure or blocking, object to certain processing, request portability, seek damages, or file a complaint. Parents or guardians exercise these rights for minors under their care. Requests must be verified so one person cannot obtain another student's record.

Contact the school or DPO