Smart EduSphere by Vicomeg Contact the DPO

Legal · Privacy

Privacy Policy

This notice explains how Vicomeg, the operator of Smart EduSphere, collects, uses, shares, protects, retains, and deletes personal data.

Effective: 15 May 2026 Version: 1.0 Document: VCM-LEG-PRIV-001

This Privacy Policy is governed by the Nigeria Data Protection Act, 2023 ("NDPA") and is supplemented by our Cookie Policy and the Data Processing Agreement we enter with each School.

1. Who We Are

Vicomeg ("we", "us", "our") is the operator of the EduSphere platform, a multi-tenant Software-as-a-Service for K-12 school administration. Our registered office and the contact details of our Data Protection Officer ("DPO") are set out in section 11.

2. Roles: Controller and Processor

Personal data in EduSphere is generally handled in one of two ways. Where personal data is uploaded by a School to operate its tenant — for example, learner records, attendance, grades, parent contacts — the School is the Data Controller and Vicomeg is the Data Processor; we process that data strictly on the School's documented instructions and in line with the Data Processing Agreement we have signed with the School.

Where we process data for our own purposes — for example, account security telemetry, fraud prevention, billing, and aggregate usage analytics that we use to operate and improve the Platform — we are the Data Controller. This Privacy Policy describes those Controller activities in detail. For Processor activities, please refer to your School's own privacy notice.

3. Personal Data We Collect

Category Examples Source
Account & profile Name, email, role, school affiliation, password hash You; your School
School-uploaded records (Processor) Learner details, attendance, grades, exam answers, finance records The School
Authentication & device Login timestamps, IP address, device type, browser, session identifiers Your device
Usage telemetry Pages visited, actions taken, error logs, feature usage Your device
AI feature inputs/outputs Prompts, generated comments, auto-grading outputs, conversational queries You; your School
Billing & payment Invoice records, token purchases, payment status, last 4 digits of the card if returned by the PSP — never the full card number You; the PSP
Support communications Email, chat, or call records when you contact us You

4. How We Use Personal Data (Controller Purposes)

As Controller, we process personal data for the following purposes:

Purpose Lawful basis (NDPA s.25) Categories
Provide and operate accounts, authentication, and session security Performance of a contract; legitimate interest in platform security Account, authentication, device
Detect and prevent fraud, abuse, and security incidents Legitimate interest; legal obligation Authentication, device, telemetry
Bill the School and account for taxes Performance of a contract; legal obligation Billing
Communicate with you about updates, incidents, and service changes Legitimate interest; performance of a contract Account
Operate and improve the Platform using aggregate, de-identified data Legitimate interest Telemetry (de-identified)
Comply with regulatory requests and lawful demands from authorities Legal obligation As required by the request

5. Children's Data

EduSphere is used in schools and processes personal data of children. Where we act as Processor, the School is responsible for obtaining any consents required from parents or guardians under the NDPA and applicable laws. As Controller, we apply heightened safeguards: we collect the minimum data required for the safe operation of the Platform; we do not market to children; we do not use children's personal data to train AI models; and we apply role-based access controls to limit who can see what.

Parents & guardians

If you believe your child's data is being processed unlawfully, please contact the School first (as Data Controller). If the issue persists, contact our DPO using the details in section 11. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).

6. AI Features & Your Data

EduSphere uses third-party large language models and our own AI services to deliver features such as report-card comments, auto-grading, early-warning scoring, and a conversational assistant. We have built the AI layer with the following safeguards:

  • Outputs are advisory. A qualified human must review AI outputs before they affect a student's record.
  • No training by default. We do not use School Content or end-user inputs to train any model, unless the School expressly opts in through a clearly labelled control.
  • Tenant isolation. Prompts and outputs from one School are never made available to another School.
  • Logging. AI calls are logged for security and audit purposes; logs are retained for the period set out in section 9.

7. Sharing of Personal Data

We share personal data only as described here:

Recipient Why What
The School (as Controller) We act on the School's instructions; the School sees its own tenant data. School Content for its tenant
Authorized Users within the same School Role-based collaboration (for example, teachers see their classes; parents see their child). Limited to what the role allows
Sub-processors (cloud, AI, email, PSPs) To deliver the Platform — see the published sub-processor list. Only the data required for the service
Professional advisers Auditors, lawyers, and accountants under confidentiality obligations. As reasonably required
Regulators & law enforcement Where required by lawful demand. Only the data legally required
A successor in a corporate transaction If we are acquired, merge, or sell assets — we will give notice. As required for the transaction

8. International Transfers

Some of our sub-processors operate outside Nigeria. Where personal data is transferred internationally, we rely on one or more lawful bases under NDPA sections 41–43: an adequacy decision by the NDPC where one is in force; standard contractual clauses with the recipient; explicit consent of the data subject; or another lawful basis identified in the DPA Annex IV. Where a School elects an in-region AI configuration, cross-border transfer of AI feature data is avoided.

9. Retention

We retain personal data only for as long as needed for the purpose for which it was collected, or for the period required by law. Indicative retention periods are set out below; the DPA sets out the specific retention rules for School Content.

Category Retention
Account & profile (active) For the duration of the Subscription, plus 90 days for transition or dispute
Authentication and session logs 12 months
Security telemetry and audit logs 24 months
Billing and tax records 7 years (CAMA / FIRS)
AI feature logs 12 months unless a shorter period is set by the School
Support communications 3 years after resolution

10. Your Rights

Subject to the NDPA, you have the following rights in respect of personal data we hold about you as Controller:

  • Right of access — confirmation of whether we process your personal data and, if so, a copy.
  • Right of rectification — correction of inaccurate or incomplete personal data.
  • Right of erasure — deletion in defined circumstances.
  • Right of restriction — pause processing while a dispute is investigated.
  • Right of portability — receipt of your personal data in a structured, machine-readable format where the processing is automated and based on consent or contract.
  • Right to object — to processing based on legitimate interests, on grounds related to your particular situation.
  • Right to lodge a complaint — with the Nigeria Data Protection Commission at ndpc.gov.ng.

Where we act as Processor, we will direct your request to the School (as Controller) and assist the School to respond. We aim to respond to all requests within thirty (30) days, with the possibility of a sixty (60)-day extension for complex requests.

11. Contacting Us

Operator Vicomeg — operator of EduSphere
Registered office Vicomeg (RC7322963), 9, Bode Fapounda, Ago Palace, Lagos, Nigeria
Data Protection Officer dpo@vicomeg.com
Legal Function legal@vicomeg.com
Postal 9, Bode Fapounda, Ago Palace, Lagos, Nigeria

12. Security

We apply administrative, technical, and physical safeguards to protect personal data, including encryption in transit (TLS 1.2+), encryption at rest for storage volumes, role-based access controls, principle of least privilege for engineers, multi-factor authentication for administrators, regular vulnerability scanning, and an incident-response process designed to meet the NDPA's 72-hour notification standard. No system is perfectly secure; we will tell you promptly if a breach affects your personal data.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the new version on our website and, where the change is material, give notice through the Platform. Past versions are available on request.