How Semwaki handles your data
Semwaki is built and operated by ELIMUNOVA TECHNOLOGIES. This policy explains what information we collect through the Semwaki platform (web and Android app), why, who we share it with, and the choices available to schools, staff, parents, and students.
Effective date: 26 August 2026
- Who we are, and who this policy covers
- Our role: the school controls the data, Semwaki processes it
- What information we collect
- How we use information
- AI features: what gets sent to OpenAI, and what doesn't
- Who we share information with
- Children's information
- How we protect information
- How long we keep information
- Your rights and choices
- Cookies and tracking
- Where information is stored
- Changes to this policy
- Contact us
1. Who we are, and who this policy covers
Semwaki is a school management platform built by ELIMUNOVA TECHNOLOGIES, based in Nyahururu, Kenya. This policy applies to everyone who uses Semwaki: schools and their staff (School Admin, Principal, Deputy Principal, Registrar, Accountant/Bursar, Teacher), parents and guardians, students, partners who onboard schools onto the platform, and visitors to our public marketing website (semwaki.com) and any school's public website built with Semwaki's Website Builder. It applies equally to the Semwaki web application and the Semwaki Android app, which share the same underlying platform and account system.
2. Our role: the school controls the data, Semwaki processes it
A school signs up for Semwaki and decides what student, staff, and parent information to enter and who at the school can access it. In privacy terms, the school is the data controller for the records it enters — it decides what is collected and why — and ELIMUNOVA TECHNOLOGIES acts as a data processor, running the platform the school uses to store and manage that information. If you are a parent, student, or staff member with a question about a specific record, your school is usually best placed to answer it directly, since they created and control that record; we are also reachable at the contact details in Section 14 for anything platform-related.
3. What information we collect
What is collected depends on your role and what your school chooses to record. In broad terms:
Account and identity information
Name, email address, phone number, role, and — depending on role — employee or admission number, gender, department, subjects/classes taught, or guardian relationship to a student. A profile photo is optional and can be added or changed by the account holder.
Academic records
Attendance, exam results, CBC competency assessments, report cards and teacher remarks, timetables, class and subject assignments, and admissions information — as entered by school staff.
Financial information
Fee structures, student billing records, and payment records including M-Pesa/Tuma transaction codes, phone numbers used to pay, and amounts. Teacher and staff payroll records (gross pay, statutory deductions, net pay) are visible only to the staff member concerned and authorized school finance roles.
Communications
Announcements and notifications sent within the platform, and messages you send us directly (e.g. through the Contact page or support email).
Photos submitted to AI-assisted features
Some optional features let a School Admin or Teacher photograph a paper class roster or mark sheet so Semwaki can read it and draft entries for review — see Section 5 for exactly how these photos are handled.
School website content
Schools that use the Website Builder to publish a public site may add their own text, images, and media through the Media Library; this becomes visible on that school's public website once published.
Technical information
Standard information generated by using a web or mobile application, such as IP address, browser or device type, and basic error logs — used to keep the service running and to investigate problems, not for advertising.
4. How we use information
We use the information above to: operate the core school-management features a school has enrolled in (academics, attendance, exams, finance, communication, admissions); process payments a school or parent initiates; send transactional emails and SMS (e.g. payment confirmations); provide the optional AI-assisted features described below; maintain security and prevent misuse (role-based access checks, audit logging); and respond to support requests. We do not sell personal information, and we do not use student, parent, or staff data for advertising.
5. AI features: what gets sent to OpenAI, and what doesn't
Semwaki includes several optional AI-assisted features (a chat assistant, briefings/insights, photo-based roster and mark-sheet reading, draft report-card comments, and draft teaching content), built using OpenAI's API. A few things are true of every one of these features:
- Nothing is saved automatically. Every AI feature produces a draft or a suggestion — a proposed list of students, a proposed set of scores, a suggested comment. A human reviews it and must explicitly confirm before anything is actually recorded to a student's record.
- Only what's needed for that request is sent. A roster or mark-sheet photo is sent to OpenAI's API only when you deliberately use that feature (e.g. tapping "Upload photo (AI)"), together with the minimum school context (like an existing class roster) needed to match names correctly.
- Access follows the same role rules as everything else. A Teacher's AI assistant can only see and act on that teacher's own classes; a Parent's or Student's AI insights are limited to that parent's own confirmed children or that student's own record.
- OpenAI processes this data only to generate the response, under our API-level agreement with OpenAI — consistent with OpenAI's standard API terms at the time of writing, it is not used to train OpenAI's models.
6. Who we share information with
We use a small number of service providers to operate Semwaki, each processing only what's needed for their specific role:
| Provider | Purpose |
|---|---|
| Google Cloud / Firebase | Core hosting, database, authentication, file storage, and serverless functions that run the platform. |
| OpenAI | Powers the optional AI-assisted features described in Section 5. |
| Safaricom (M-Pesa/Daraja) and Tuma | Process M-Pesa payments a school or parent initiates for fees, subscriptions, or setup costs. |
| Africa's Talking | Delivers SMS notifications, such as payment confirmations. |
| SendGrid | Delivers transactional emails, such as account invites and password resets. |
| Namecheap | Only for schools that connect a custom domain to their public website — used to manage that domain's DNS. |
We do not share personal information with third parties for their own marketing purposes. We may disclose information if required by law, or to protect the rights, property, or safety of Semwaki, our users, or others.
7. Children's information
Semwaki is a business tool built for schools, and it is not marketed directly to children. In practice, though, a school administration platform necessarily holds information about students, some of whom are children. Student accounts and records are created and managed by the school (or by a parent/guardian, for the Parent Portal) — not by a child signing up independently — and a student's own account is limited to their own academic information (results, attendance, timetable, fees) with no public-facing profile, messaging with strangers, or advertising of any kind. As described in Section 2, the school remains responsible for deciding what student information is entered and for obtaining any consent required under its own policies and applicable law before doing so.
8. How we protect information
Every school's data is isolated from every other school's at the database level, and access within a school is checked against both the signed-in user's role and their school, enforced on our servers — not just hidden in the interface — for every read and write. Key actions are recorded in an audit trail. More detail is on our Security page. As noted there, Semwaki does not currently hold a third-party security certification (e.g. SOC 2, ISO 27001) — no system is completely immune to risk, and we cannot guarantee absolute security, but we design and operate the platform with these protections as a baseline, not an afterthought.
9. How long we keep information
We retain school data for as long as a school's account is active, so records like academic history remain available across school years. If a school's subscription ends, we retain data for a reasonable period afterward in case the school wishes to resume service or export records, after which it is deleted or anonymized, unless a longer period is required by law (for example, financial records for tax or audit purposes).
10. Your rights and choices
Depending on your role and applicable law (including Kenya's Data Protection Act, 2019), you may have the right to access, correct, or request deletion of your personal information. You can update most of your own profile details (like your profile photo, and for some roles, your phone number) directly within Semwaki. For anything else — including a request to access, correct, or delete personal information — contact your school directly if the record belongs to them, or reach us using the details in Section 14 and we will route your request appropriately, including to your school where they are the controller of the record in question.
11. Cookies and tracking
Semwaki does not use third-party advertising trackers or web analytics cookies on its website or app. Signing in uses your browser's local storage (not a tracking cookie) to keep you signed in between visits, and the app can optionally work offline by caching some of your own school's data on your device for pages you've already visited.
12. Where information is stored
Semwaki runs on Google Cloud/Firebase infrastructure, which may store and process data outside Kenya. Our service providers (Section 6) are established international companies that process data as part of delivering the specific service described. We take reasonable steps to work with providers who maintain appropriate safeguards for the information they process on our behalf.
13. Changes to this policy
We may update this policy as Semwaki's features change. We'll update the effective date above when we do, and for significant changes we'll make a reasonable effort to let schools know directly.
14. Contact us
Questions about this policy or how your information is handled can be sent to support@semwaki.com or hello@semwaki.com, or by post to ELIMUNOVA TECHNOLOGIES, Nyahururu, Kenya.