School Data Agreement

Data Processing Agreement between the School and Kryft. Version 2026-10.

This agreement applies automatically when a school (the School) registers for ClassGuard and its administrator accepts it. It explains how Kryft (an LLP registered with the SECP, CUIN 0347008, hello@kryft.dev) handles personal data on the School's behalf. It is written to meet Article 28 of the EU and UK General Data Protection Regulation (GDPR) and to work under other laws, including Pakistan's.

1. Roles

  • The School is the controller of its students', staff's and parents' data in ClassGuard. It decides why the data is used.
  • Kryft is the processor. Kryft processes the data only to provide ClassGuard, on the School's documented instructions (this agreement, the School's settings, and its written requests).
  • Parents and staff also hold their own ClassGuard accounts, for which Kryft is controller as described in the Privacy Policy.

2. The School confirms that

  • it has a lawful basis to use ClassGuard for its students, and it has informed parents and obtained their permission where the law requires it (the administrator confirms this in the app before students can be added);
  • it will give parents the parent summary or its own equivalent notice;
  • it understands that focus tracking also needs each parent's own consent in the app, and stays off until given;
  • the data it enters is accurate and limited to what is needed.

3. What Kryft processes

People Students, parents/guardians, teachers, school administrators
Data Names, emails, roll numbers, classes; attendance and class activity; focus numbers (never images or audio); homework, marks, notes; phone status and lock events; chat and polls; support requests
Special care Children's data. No biometric data is collected: face detection runs on the phone and produces only numbers
Purpose Running online classes, the class lock, reports and communication for the School
Duration While the School uses ClassGuard, then deletion as in section 9

4. Kryft's commitments

Kryft will:

  1. process the data only on the School's instructions, and tell the School if an instruction seems to break the law;
  2. make sure everyone at Kryft with access is bound to confidentiality;
  3. keep the security measures in our security overview;
  4. use only the service providers listed, bind them to equivalent data protection terms, give the School 30 days' notice of a new one, and let the School object;
  5. help the School answer requests from students, parents and staff (access, correction, deletion, objection) — ClassGuard's export and delete features handle most of these directly;
  6. help the School with data protection impact assessments and consultations with authorities, including by sharing our focus-tracking assessment;
  7. tell the School without undue delay, and within 48 hours, after becoming aware of a personal data breach affecting its data, with what is known and what we are doing;
  8. at the end of the service, delete the School's data as in section 9;
  9. make available the information needed to show compliance, and allow reasonable audits (normally by written questionnaire, once a year, at the School's cost).

5. Things Kryft will never do

  • Sell or rent the data, or use it for advertising.
  • Use the data to train AI models.
  • Collect or store images, video or audio of students (live class media is relayed and never recorded).
  • Use the data for any purpose of its own, other than keeping the service secure and working.

6. International transfers

ClassGuard runs on Cloudflare's global network. Where data leaves the EU/UK, Kryft relies on the European Commission's Standard Contractual Clauses (and the UK addendum) through its providers' agreements.

7. Retention during the service

Data is deleted on the schedule in our retention table (for example, detailed focus data after 90 days, reports after 1 year).

8. Security incidents

See section 4.7. Kryft keeps a record of every incident and the actions taken.

9. End of service

When the School closes its ClassGuard account, it can first export its records. Kryft then deletes the School's data within 30 days (including backups), unless the law requires us to keep something (for example invoices), which we will keep only for that purpose.

10. Liability and order

Each party is responsible for its own compliance. This agreement takes priority over the Terms of Use for anything about personal data. It is governed by the laws of Pakistan, except where EU or UK data protection law requires otherwise for the data concerned.

11. Contact

Data protection contact at Kryft: hello@kryft.dev.