← Back to Karo

Karo

Safe. Simple. Sorted.

Karo Digital Classics Ltd

Data Protection Impact Assessment

How Karo processes school, staff, guardian and children's data, the risks, the controls, and the gaps.

Version 1.0 · Last updated 15 August 2026

Download as PDF

Prepared by Karo Digital Classics Ltd and read alongside the Agreement and the Privacy Policy.

External, view-only assurance reports

The reports referenced in sections 7 and 9 are published in full and are view-only, with a PDF download on each page.

1. Purpose and scope

This assessment answers one question honestly: does running a school on Karo put children, their families or school staff at a risk that is not properly controlled. It is written for a school's board, a school's lawyer and a supervisory authority, and it is deliberately specific about what is not yet solved.

Karo is an education-operations platform for institutions across Africa: primary and secondary schools, international and comprehensive schools, colleges and universities. It records enrolment, fees and payments, attendance, examinations and report cards, transport, visitor and gate movements, sick bay visits, discipline, staff time and staff leave, and it sends operational messages to guardians over WhatsApp and email. Karo operates across the continent, with Kenya as the jurisdiction of incorporation and the primary operating jurisdiction. This assessment is written against the Kenya Data Protection Act 2019 as the operating standard, applied consistently wherever an institution is based, and is reviewed against local law before the first institution in a new jurisdiction goes live.

The assessment at a glance
FieldPosition
Assessed systemThe hosted Karo platform, all modules, web and installed app
Market servedPrimary and secondary schools, international and comprehensive schools, colleges and universities across Africa
FootprintOperating across Africa, with Kenya as the jurisdiction of incorporation and primary operating jurisdiction
Out of scopeAn institution's own offline records, its other systems, and anything it exports and then handles itself
OperatorKaro Digital Classics Ltd, processor
ControllersEach subscribing school, for the records it enters
Data subjectsChildren, guardians, school staff, gate visitors, the school's signatory
Why an assessment is requiredLarge-scale processing of children's data, health data about minors, biometric-adjacent identity documents, and systematic monitoring of movement on site. Kenya Data Protection Act 2019 section 31 and the Data Protection (General) Regulations 2021, equivalent to GDPR Article 35
Assessment statusIssued and in force. Filed on Karo's data protection record and published to subscribing institutions
Review cadenceAt least annually, and on any change to processors, data categories or purposes

2. Roles and lawful basis

PartyRoleLawful bases relied on
Subscribing schoolControllerContract with the family (enrolment, fees, results); legal obligation (tax and audit retention, safeguarding duties); legitimate interests in the safety of children on site (attendance, gate, transport); vital interests and explicit consent for health data
Karo Digital Classics LtdProcessor, on documented instructionPart B (Data Processing Agreement) of the Agreement, accepted by the school's authorised signatory on first sign-in
Karo Digital Classics LtdController, for its own narrow processingContract performance and its own legal obligations: account creation, signatory identity verification, billing, platform security and fraud prevention

Health information and identity documents are treated as sensitive personal data throughout, with the narrower bases above and the tighter controls in section 6.

3. Data categories actually processed

Verified against the live schema, 155 tables in the application schema.

CategoryWhat is heldSensitivity
ChildrenName, admission number, date of birth, sex, class, stream and class history, photograph, subject choices, marks at component level, aggregated results and positions, report cards, attendance, transport route and stop, authorised pickup persons, fee profile, invoices, payments, receipts, statements, sponsorships, exit status and leaving documentsHigh, minors
Children's healthHealth profile (conditions, allergies, medication, emergency instructions) and sick bay visitsHighest
GuardiansName, relationship, up to two numbers per child, email, WhatsApp and channel preference, consent records, message history, payment history, meeting bookingsMedium
StaffName, role, contact, invitation and join records, passkey credentials and phone, clock events with geolocation against a defined zone, leave and balances, cover assignments, permission scopes, signature imagesMedium to high
Gate visitorsName, phone, identity capture, party members, vehicle plate, carrier contact, host and purpose, item and pickup passesMedium
School signatoryName, role, identity document number and image, phone, email, registration and bank verification documents for payout setupHigh
PaymentsInvoice and receipt detail, amounts, channel, provider reference, allocation, refunds, manual payment approvals, platform fee ledgerMedium
Platform and securityAppend-only audit log, message delivery log, passcode dispatch log, push subscriptions, impersonation log, portal login attemptsMedium

4. Data flows, processors and change notification

Verified from the outbound integrations present in the codebase. This table lists the processors that handle live school data today, and is the published sub-processor list, also available at karoschool.net/legal/sub-processors, last updated 17 August 2026.

ProcessorPurposeData receivedStatus
Lovable Cloud (Supabase infrastructure)Hosting, database, authentication, file storage, backupsAll categories in section 3, at restLive, European Union
Africa's TalkingWhatsApp and message deliveryRecipient phone number, message body, document linkLive, Kenya
PaystackPayment collection and settlement to the schoolPayer name, email or phone, amount, school subaccount referenceLive, Nigeria and South Africa
Mailgun (via Lovable email infrastructure)Transactional email deliveryRecipient email, subject, rendered body, document linkLive, European Union and United States
CloudflareEdge delivery and bot protection (Turnstile) on sign-upRequesting IP address and challenge token. No school recordsLive, Global edge
GoDaddyDomain registration and DNS for karoschool.netNo school or guardian records. Karo's own registrant and billing details only, plus DNS lookupsLive, United States

Change notification commitment. Karo will give every subscribing school at least 30 days' written notice, by email to the school's registered contact and by an update to this page, before a new sub-processor begins processing school data, and before an existing one is replaced. A school that objects on reasonable data-protection grounds may raise the objection within that notice period; if the objection cannot be resolved, the school may terminate the affected service without penalty for the remainder of the paid period. Emergency substitutions to keep the service running are notified within 5 days of the change, with the same objection right.

Verification of the person signing for the institution is manual. A member of Karo's team compares the uploaded National ID, passport or driving licence with the details given, by eye, on the admin console, and approves or asks for a replacement. There is no automated facial matching, liveness scoring or automated approval anywhere in that flow. One-time passcodes are generated and checked by Karo's own store and delivered through the messaging processor above or by email.

Documents (receipts, statements, report cards) are delivered to families as tokenised links, never as attachments or generated images, so document content does not transit the messaging processor.

5. Retention, as enforced by Karo

DataWindowEnforced by
Financial records and audit log7 years minimumNever deleted on a schedule. Committed floor matching Kenyan tax and audit requirements
Academic records, results, class historyRetainedKept so statements, leaving certificates and historic report cards stay reproducible
Archived configuration (draft fee structures, unused streams)30 days after archivingDaily job public.purge_expired_archives. It explicitly does not touch students or guardians
Attendance and staff clock detail90 days for detailScheduled purge, aggregate retained
Sick bay visit detail90 daysScheduled purge
Visitor personal data at the gate45 daysScheduled scrub, leaving an anonymised audit shell
Message content and delivery records45 days by defaultSchool-configurable window, scheduled purge
Single learner's operational history, on requestOn demandpublic.purge_student_history. Requires an owner or administrator, an exact typed confirmation of the learner's name, a written reason of at least ten characters, and it writes an audit entry. Removes attendance, sick bay, gate passes, discipline and health. Does not remove financial or academic records

These windows are the minimum baseline Karo enforces, not a ceiling a school is locked into. A subscribing school may ask Karo at any time to review its retention arrangements, and where a shorter window, a longer window or a different treatment of a category is required by the school's own policy or by its regulator, that is agreed in writing and configured for that school.

The non-cascade guarantee is load-bearing: purges of archived configuration never touch students, guardians, results, fee profiles, sponsorships, discipline or health records, and that boundary is pinned by regression tests.

6. Access controls in place

ControlHow it works
Tenant isolationRow-level security on all 155 application tables with 313 policies. Every record is scoped by school identifier; there is no route by which one school reads another's data
Roster visibilityClass teachers see their own classes, senior leadership sees the school. This replaced a broader read that exposed the full roster to any signed-in member
Health recordsGated separately from the general student record; every read and write is written to the append-only audit log by a database trigger, so access is attributable after the fact
Guardian consentCaptured explicitly as first-class records, consent requests and recorded consents, never inferred
AuthenticationPasskey and device biometric first, one-time passcode fallback. The biometric is the device's own WebAuthn factor; no facial image or biometric template reaches Karo
Privileged accessKaro console access is role-gated and IP-allowlisted, impersonation is logged and swept
Idle sessionsFive minutes of genuine inactivity signs the session out server-side. Returning requires fresh credentials, which establishes a new session rather than resuming the old one
Public document links192 bits of token entropy, rate limited, rendered in a view-only viewer

7. Security controls and practices in place

These are standing practices, run continuously rather than as a one-off exercise. Findings from them are fixed and, where they change the risk picture, carried into sections 8 and 9.

PracticeWhat it means in operationCadence
Tenant-scoping reviewEvery server function and query path is reviewed for school scoping, and automated cross-tenant tests fail the build if a path can read another school's recordsEvery change
Row-level security lintingAutomated checks flag any table without row-level security or without a policy, and any policy that widens access beyond the intended roleContinuous
Least-privilege review of read pathsStudent, health and financial read paths are scoped to the role that needs them, class teachers to their classes and senior leadership to the school, rather than to any signed-in memberContinuous
Regression pinning of safety behavioursBehaviours that protect data (non-cascading purges, link-only document delivery, health access logging) are pinned by tests, so a regression fails the build rather than reaching a schoolEvery build
Access attributionHealth record access, privileged console access and impersonation are written to an append-only audit log, reviewed when anything looks anomalousContinuous
Dependency and platform scanningAutomated dependency and security scanning of the running platform, with findings triaged and fixedContinuous
Platform security assessmentStructured assessment of access control, tenant isolation, data flows, retention and supply chain across all modules, carried out by Classic Talent Optimization (an affiliated party, not an independent assessor). Published in full at karoschool.net/legal/security-assessmentCompleted, published
Rehearsed incident responseTabletop incident exercise run against the section 12 outline, with date, participants, scenario and findings recorded at karoschool.net/legal/incident-drillAt least annually

8. Risk assessment and residual risk

Impact is stated as impact on the data subject. Residual risk is after the mitigations in sections 5, 6 and 9. Green means accepted as low, amber means live and monitored, red means unacceptable and blocking.

RiskImpactMitigationsResidual
Unauthorised disclosure of a child's health dataHighSeparate policy, trigger-based audit of every access, 90-day purge of detail, five-minute session termination limits an unattended deviceAmber
Cross-tenant data leakageHighRow-level security on every table, school-scoped server functions, automated cross-tenant tests that fail the buildGreen
Message sent to the wrong guardianMediumPer-child guardian records with explicit channel preference, delivery logging, delivery centre showing failures and allowing corrected resendsAmber
Compromise of a staff device or accountHighPasskey and biometric primary authentication, full session termination after five minutes of inactivity, scoped permissions, audit logGreen
Payment fraud or misdirected settlementHighBank verification documents reviewed before go-live, maker-checker approval on manual payments and refunds, reconciliation against the provider every 30 minutes, discrepancy digestGreen
Processor failure or breach at a third partyVariesMinimum necessary data per processor, no card data held, no child biometrics sent anywhere, documents delivered as tokenised links, published sub-processor list with notice periodAmber
Excessive retentionMediumEnforced windows in section 5 and the explicit non-cascade guaranteeGreen
Accidental irreversible deletionHighRetention contract, typed confirmation and audit on the deliberate purge path, documented restore request path in section 10Green
Rights request not answered in timeMediumSelf-service intake at /privacy-request, console queue with a response clock, acknowledgement and fulfilment targets in section 11Green
Undetected weakness in the platform itselfHighCompleted platform security assessment with findings closed and regression-tested, plus continuous regression tests, RLS linting and dependency scanning. The assessor is internal and affiliated rather than independent, see section 9Green

The remaining amber lines are honest, not pending paperwork. Health data stays amber because a legitimately authorised staff account can read what it is entitled to read, and no technical control fixes that; detection and attribution are the answer. Wrong-guardian messaging stays amber because the accuracy of the number is the institution's own data entry. Third-party breach stays amber because it is partly outside Karo's control.

9. Data protection controls and assurance

The controls below are implemented and running in the platform today. Nothing appears here as intention.

ControlWhat is in placeStatus
Session termination on inactivityFive minutes of genuine inactivity ends the session server-side. Returning requires a passkey, a device biometric prompt or a fresh passcode, and issues a new session rather than resuming the old one. An unattended device does not stay signed inIn place
Data subject request handlingAnyone may lodge an access, correction, objection or erasure request at karoschool.net/privacy-request. Each request enters a tracked queue with a response clock: acknowledged within 3 days, substantive response within 30 days, as set out in section 11In place
Documented restore request pathA published, step-by-step route for a school to request recovery of lost records, with named acknowledgement and restore targets and a written audit trail. Section 10In place
Published sub-processor list with change notificationEvery processor handling live school data is listed in section 4 and at karoschool.net/legal/sub-processors, with 30 days' written notice before any addition or replacement and a right to objectIn place
Retention enforced, with a school-requestable reviewThe windows in section 5 are enforced by scheduled jobs, not by policy alone, and a subscribing school may ask at any time for its retention arrangements to be reviewed and configured to its own policy or regulatorIn place
Rehearsed incident responseA tabletop exercise against the section 12 outline, recorded with date, participants, scenario and findings, repeated at least annually and published at https://karoschool.net/legal/incident-drillIn place
Platform security assessmentA structured assessment of access control, tenant isolation, data flows, retention and supply chain across all modules, carried out by Classic Talent Optimization, an internal and affiliated assessor rather than an independent one. Findings closed and regression-tested. Published in full at https://karoschool.net/legal/security-assessmentIn place, affiliated assessor

An independent third-party security assessment has not yet been completed; one is being commissioned ahead of scaling beyond the current pilot schools, and its result will be published here alongside the assessment above.

Assurance reports on file. Two reports sit behind this section and may be read in full by any subscribing institution, its lawyer or a supervisory authority.

ReportScope, author and dateWhere to read it
Platform Security AssessmentAccess control, tenant isolation, data flows, retention and supply chain across all modules. Carried out by Classic Talent Optimization, an affiliated assessor, dated 15 August 2026. Findings closed and regression-tested, with no unresolved finding known at the date of the reporthttps://karoschool.net/legal/security-assessment
Incident Response Drill RecordTabletop exercise against the incident response outline in section 12, run by Classic Talent Optimization, an affiliated party, dated 15 August 2026, recorded with participants, scenario and findings, repeated at least annuallyhttps://karoschool.net/legal/incident-drill

Both reports are published view-only under the same access pattern as the Agreement and the Privacy Policy. They are assurance work by an affiliated party; they are not certification by a supervisory authority and are not presented as such.

10. Restore request path

Backups are taken at the hosting layer with point-in-time coverage. A school cannot restore itself; it asks Karo, and Karo restores on the school's written instruction. This is the documented path.

StepWhat happensTarget
1The school owner or an administrator emails info@karoschool.net from the registered school contact, stating what was lost, roughly when, and the last time it was known to be correctAny time
2Karo acknowledges and confirms the identity of the requesterWithin 1 business day
3Karo assesses whether the data can be recovered from the retention windows in section 5, from the audit log, or from a point-in-time backup, and tells the school whichWithin 2 business days
4On written approval from the school, Karo performs a scoped restore of the affected records and reports what was and was not recoveredWithin 5 business days of approval
5The request, the approval and the outcome are written to the audit logSame day
  • Limits stated plainly: a restore may reintroduce records the school deliberately deleted in the same window, so scope is agreed in writing first.
  • Data already purged by a published retention window in section 5 is gone and cannot be restored.
  • A restore never crosses schools. Only the requesting school's records are touched.

11. Data subject rights, what is supported today

RightSupportedHow it works
AccessYesA guardian can view and download the child's receipts, statements over any period within the retention window, and published report cards, through tokenised view-and-download links. A written request can be made at /privacy-request
RectificationYesThe school corrects any record it entered; corrections to student, fee and guardian records are audited
Objection to messagingYesWhatsApp and channel preferences can be turned off per guardian, and email carries one-click unsubscribe
Erasure of operational historyYesThe audited single-learner purge in section 5, exercised by the school
PortabilityYesCSV and PDF export across modules, in practical rather than machine-negotiated form
Request intake and response clockYesPublic form at /privacy-request, acknowledged within 3 days, substantive response within 30 days as required by the Act, tracked in the Karo console queue
Erasure of financial or academic records inside the statutory periodNo, and not claimedRetained for 7 years as a legal obligation. Neither a school nor Karo can override this in the product

12. Breach response outline

Detection through platform logging, the append-only audit log, delivery and reconciliation monitoring, and reports to info@karoschool.net.

StageActionTiming
ContainRevoke affected access, isolate the path, stop the bleedingImmediately
AssessScope the exposure from the audit log and delivery recordsWithin 24 hours
Notify the schoolTell the affected school as controller, with the facts known at that pointWithin 48 hours of confirmation
Support regulator notificationHelp the school notify the Office of the Data Protection Commissioner where the threshold is metWithin 72 hours
RecordIncident, remediation and the preventive change, recorded on the incident registerOn closure

This outline has been rehearsed. The drill record, with date, participants, scenario and findings, is published at https://karoschool.net/legal/incident-drill.

13. Owner, contact and status

Karo Digital Classics Ltd, operator of the Karo school-operations platform. Data protection contact: info@karoschool.net. Reviewed at least annually, and on any material change to processing, processors, or the categories of data collected.

STATUS. This assessment is issued and in force. It is filed on Karo's data protection record, published to subscribing institutions, and read alongside the Platform Security Assessment and the Incident Response Drill Record. It is not a certification issued by a supervisory authority or by an independent assessor, and should not be presented as one.