Data Privacy & Compliance

How SchoolHero.io OÜ approaches privacy, security, retention, and data rights across our school app suite

Last reviewed: April 28, 2026

Our Commitment

SchoolHero.io OÜ processes personal data to provide school management, education, communication, support, billing, and website services across products such as River SIS and Peekadoo. We use technical and organisational safeguards designed to protect personal data, limit access, support responsible retention, and help schools handle privacy obligations under the laws that apply to their use of our services.


Data Classification
ClassificationDescriptionExamples
PIIPersonally identifiable informationSchool records, guardian contact details, user profile images
ConfidentialSensitive operational dataWorkspace settings, integration settings, environment secrets
AuditAccess and activity recordsDatabase audit logs, admin activity
InternalNon-personal operational dataApplication logs, deployment metadata, service health records

Security Measures
Encryption at Rest
  • DocumentDB: KMS encryption at cluster level
  • S3 buckets: AWS KMS server-side encryption
  • CloudWatch Log Groups: KMS encryption
  • Container registry (ECR): KMS encryption
Encryption in Transit
  • HTTPS only; TLS 1.2 minimum, TLS 1.3 preferred
  • Application to database: TLS enforced, plaintext rejected

Data Retention
Data CategoryStorageRetentionDeletion
Customer files and images (current)S3IndefiniteManual on request
Customer files and images (superseded)S330 daysAutomatic (S3 Lifecycle)
Database backupsDocumentDB30 daysAutomatic
Application logsCloudWatch7 daysAutomatic
Database audit logsCloudWatch90 daysAutomatic

Your Data Rights
Right of Access

Individuals may request confirmation of whether personal data is being processed and, where applicable, ask for access to that data. When SchoolHero.io acts for a school customer, we may coordinate with that school so the request is handled through the correct record owner.

Right to Erasure

Individuals may request deletion of personal data where a lawful basis for erasure applies. Some records may need to be retained for security, legal, contractual, school-accountability, or fraud-prevention reasons before final deletion can occur.

Right to Rectification

Individuals may request correction of inaccurate or incomplete personal data. Change history, administrative controls, and school workflows help support verified corrections.

Right to Data Portability

Where applicable, individuals may request a portable copy of certain personal data in a structured format. The available export path depends on the product context, customer relationship, and technical feasibility.

Right to Restrict or Object

Depending on the circumstances, individuals may request restriction of processing or object to certain uses of personal data. Access controls, role restrictions, and workflow review support how such requests are assessed and implemented.


Governance Schedule
Monthly

Review data classification, retention settings, access permissions, subprocessors, and operational changes that may affect privacy risk.

Quarterly

Conduct least-privilege access reviews, verify key security controls, and document material changes to processing activities, product workflows, or vendor arrangements.

Annually

Perform a fuller review of data inventories, test data-rights handling and deletion workflows, review incident-response readiness, and update this page.


Exercise Your Data Rights

To exercise any of your data rights or for privacy-related enquiries, please contact SchoolHero.io OÜ at info@schoolhero.io or by post at Harju maakond, Kuusalu vald, Pudisoo küla, Männimäe, 74626, Estonia. For school-managed records, we may direct the request to the relevant school administrator or institution.