Compliance

Data governance built for institutional trust

RedeemOS is designed to meet the data protection requirements of schools, ministries of education, and enterprise buyers. This page documents our data governance principles, security controls, and approach to regulatory compliance.

Note on certifications: RedeemOS is a growing platform. We do not currently hold ISO 27001, SOC 2, or similar third-party certifications. We are committed to pursuing these certifications as we scale. This page documents our current implemented controls — not aspirational standards we have not yet validated.

Data protection principles

Data Minimisation

RedeemOS collects only the personal data necessary to deliver school management services. Schools control what data is entered into the platform. We do not add data fields for commercial purposes.

Purpose Limitation

Data entered into RedeemOS is used exclusively for school administration purposes as directed by the subscribing school. We do not process school data for advertising, profiling, or sale to third parties.

Storage Limitation

School data is retained for the duration of the active subscription plus a 90-day post-cancellation window for data export. After this period, data is permanently deleted. Retention periods are documented and enforced technically.

Transparency

Schools are informed of all data processing activities in our Privacy Policy and Data Processing Agreement. Material changes to data processing practices are communicated with 30 days notice.

Accountability

RedeemOS maintains records of data processing activities. We enter into Data Processing Agreements with subscribing schools on request, clearly defining controller and processor responsibilities.

Data Subject Rights

We support schools in responding to data subject access requests, correction requests, and deletion requests through platform tools and direct support.

Implemented security controls

Authentication

Session-based authentication with opaque tokens. Passwords hashed with bcrypt (cost factor ≥12). HttpOnly, Secure, SameSite=Lax session cookies.

Access Control

Role-based access control (RBAC) with granular module-level permissions. Each user sees only the data their role requires. Roles are configured by the school administrator.

Audit Logging

All actions — login, create, edit, delete, export, payment — are written to tamper-evident audit logs. Logs record user, action, timestamp, IP address, and affected record. Logs cannot be modified or deleted by school staff.

Data Isolation

Every school has a dedicated PostgreSQL database. Cross-school data access is architecturally impossible. Database credentials are unique per school.

Encryption

TLS 1.3 in transit. AES-256 at rest for database and file storage. Encryption is enforced universally — not configurable.

Backup

Daily encrypted database snapshots retained for 30 days. Backups stored in geographically separate regions. Restoration is tested periodically.

Incident Response

Documented incident response procedures. Affected schools notified within 72 hours of a confirmed data breach. Root cause analysis provided within 14 days.

Vendor Management

Third-party services (payment processor, cloud infrastructure, email) are bound by data processing agreements. Sub-processors are reviewed annually.

Regulatory readiness

Data Processing Agreements: RedeemOS enters into Data Processing Agreements (DPAs) with subscribing schools on request. DPAs clearly define the school as data controller and RedeemOS as data processor, with explicit obligations for both parties.

Ministry and Government Procurement: Schools procuring under ministry or government frameworks may request our security documentation package, which includes this compliance page, our Privacy Policy, our Security Architecture overview, and a completed supplier security questionnaire. Contact sales@redeemos.com to request this package.

Ghana Data Protection Act: RedeemOS operates in alignment with the principles of Ghana's Data Protection Act, 2012 (Act 843), including lawful processing, data subject rights, and security obligations. Schools are responsible for registering their use of personal data with the Data Protection Commission where required by law.

GDPR: Where RedeemOS processes data of individuals in the European Economic Area, we comply with GDPR requirements including lawful basis for processing, data subject rights, and appropriate safeguards for international transfers.

Need compliance documentation?

We provide security questionnaires, DPA templates, and compliance documentation packages for procurement processes.