Karo
Safe. Simple. Sorted.
Karo Digital Classics Ltd
Version 1.0 · Last updated 13 July 2026
Download as PDFThis Policy is maintained by Karo Digital Classics Ltd, operator of the Karo school-operations platform, and is supported by the Agreement (Part B of which is the Data Processing Agreement) . The Data Protection Impact Assessment sets out the data categories, processors, retention and risk controls behind this Policy.
This policy describes how Karo handles information about schools, staff members, students, and guardians whose records the school enters into the platform.
Each school is the data controller for the records it enters. Karo Digital Classics Ltd, operator of the Karo platform, is the data processor and acts only on the school's documented instructions. The controller and processor obligations are set out in full in Part B of the Agreement, which every school owner accepts on first sign-in.
We do not process special-category data (health, religion, biometrics) in the ordinary course of business. Payment card and mobile-money credentials are never stored on Karo; those are held by the regulated payment processor.
Karo collects only what fee collection needs. A guardian's name and phone number are enough to send an invoice, take a payment, and return a receipt. Karo does not ask parents for identity documents, addresses, or income. Parents pay through a regulated payment processor. Card and mobile-money details are never stored on Karo.
Solely to operate the platform for the school. Karo does not sell information. Karo does not share it with advertisers. Karo does not train third-party AI on it.
To run the platform we engage the following categories of sub-processor, each bound by a written data-protection agreement no less protective than our DPA:
Karo notifies schools at least thirty (30) days before adding or changing a sub-processor.
Every school's data is sealed in its own tenant. Row-level rules apply to every read and write. A staff member from one school cannot see another school's students, invoices, payments, or reports. Support access follows the same rules and is logged.
All traffic between browsers, phones, and Karo is encrypted in transit. Databases, backups, and file storage are encrypted at rest. Passwords are stored as one-way hashes and are never legible to staff, support, or the platform itself.
Two-step verification is on for every account. A one-time code is sent to the registered phone at every sign in. Biometric sign-in (Face or fingerprint) is available as a fast alternative on the user's own device. Sensitive actions, such as adding or changing a bank account, require a fresh verification code every time.
Invoices and receipts are permanent once issued. Corrections are made by cancelling and re-issuing, so the original record survives. Every action that touches money is written to an append-only audit trail with the user, timestamp, and change. Auditors can be given a read-only export.
Only the school owner can add or change bank details. Every change requires a password re-entry and a fresh code to the registered phone. New bank accounts sit on an activation hold before they can receive funds. All owners are notified by email each time a bank change is initiated or completed.
We apply the maximum lawful retention period, so records are available for as long as auditors and courts might reasonably need them:
Records held for legal reasons persist beyond the archive window. A school may request earlier deletion of its own operational records at any time.
If Karo confirms a personal-data breach affecting a school's data, we notify that school within 72 hours of confirmation with a written description of the incident, the data affected, and the mitigations taken, so the school can meet its own notification duties under the Act or GDPR.
Where personal data is transferred outside Kenya, or outside the European Economic Area for GDPR-subject schools, Karo relies on an adequacy decision, the European Commission's Standard Contractual Clauses (2021/914), or the Office of the Data Protection Commissioner-approved safeguards, whichever apply. A copy of the applicable safeguard is available on request.
To access, correct, export, or delete personal information held about you, or to raise a privacy question, write to info@karoschool.net . Requests from parents about their own or their children's records are routed to the school that entered the data, since the school is the data controller. Karo assists that school in responding.
See also the Agreement (Terms of Service and Data Processing Agreement).