Privacy Policy
Last updated: 16 May 2026
Ibdaa Ltd ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share personal data when you use the Tawaasal platform — including the tawaasal.com website, the customer portal, and the Tawaasal mobile applications for iOS and Android (together, "the Service").
1. Data Controller
The way personal data is controlled depends on which part of the Service you are using.
-
Ibdaa Ltd is the data controller for personal data we process directly — including the public website (tawaasal.com), the billing and customer portal, sales and marketing communications, and our own staff and contractor records.
-
Schools are the data controller for personal data processed within their own Tawaasal environment — including student, guardian, teacher, and staff records, attendance, grades, messages, homework submissions, and any other content created or stored within the school's tenant. In this context, Ibdaa Ltd acts as a data processor under a Data Processing Agreement with the school.
This Privacy Policy describes both sets of processing activities. Where we act as a processor on behalf of a school, you may also wish to consult that school's own privacy notice.
2. Data We Collect
Account Data (website and portal)
- Full name, email address, phone number
- Organisation name and country
- Language and theme preferences
- Profile photo (optional)
Billing Data (portal)
- Subscription plan, billing period, and renewal status
- Payment history (card numbers are processed by Stripe — we do not store them)
- School registrations and provisioning status
- Tax identifiers where required by law
Mobile App Data
- Authentication tokens stored securely on the device
- Push notification token (provided by Apple Push Notification service or Firebase Cloud Messaging) so we can deliver notifications to your device
- Crash and diagnostic data captured by Firebase Crashlytics (stack traces, device model, OS version, language)
- Anonymous error and performance events
- Biometric authentication preferences — the biometric template itself never leaves your device; iOS or Android returns only a "match / no match" result
- Content you choose to submit, including messages, comments, photographs, files, and homework submissions
- Profile photographs you choose to upload
- App settings such as language, theme, and notification preferences
Usage Data
- Login timestamps and IP addresses
- Browser type, device model, and operating system
- Pages or screens visited and features used
Consent Records
- Records of your acceptance of our Terms of Service, including version, timestamp, and IP address
- Records of your marketing email choices — each opt-in and opt-out per topic, with its source (which form or page), language, timestamp, and IP address
Marketing Email Data (optional)
If you opt in to our product update or company news emails — via the website, at checkout, or in the customer portal — we collect your email address, preferred language, and per-topic subscription choices. Subscribing is always optional, is never pre-selected, and is separate from the transactional emails we send about your account and orders.
School Tenant Data (where Ibdaa acts as processor)
Within each school's Tawaasal environment, the school instructs us to process personal data including, depending on configuration: student records (names, dates of birth, contact details, enrolment information), guardian records, teacher and staff records, attendance and behaviour records, grades and assessment data, homework and submissions, calendar and timetable data, messages and announcements, photographs and files uploaded by users, and audit and access logs.
The categories, retention, and sharing of school tenant data are defined by the Data Processing Agreement between Ibdaa Ltd and the school. The school is the controller for this data and is responsible for the lawful basis on which it is collected.
3. How We Use Your Data
We use data we control to:
- Provide and maintain the Service
- Process payments and manage subscriptions
- Communicate with you about your account and the Service
- Send push notifications and emails you have asked to receive
- Send optional marketing emails (product updates and company news) to subscribers who opted in — every such email includes an unsubscribe link and a link to a preference page where you can manage topics or leave entirely
- Detect and prevent fraud, abuse, and security incidents
- Investigate crashes and improve the reliability of our applications
- Comply with legal and regulatory obligations
- Improve the Service using aggregated, anonymised data
We process school tenant data only on the documented instructions of the school, as set out in the Data Processing Agreement.
4. Legal Basis for Processing
We process personal data under UK GDPR on the following legal bases:
- Contract: Processing necessary to provide the Service you have subscribed to.
- Consent: Where you have given explicit consent (for example, marketing communications, cookie preferences, optional notifications).
- Legitimate Interest: For fraud prevention, security, service improvement, and maintaining the integrity of the Service.
- Legal Obligation: To comply with applicable laws and regulations.
For school tenant data, the lawful basis is determined by the school as data controller. The school is responsible for obtaining any necessary consents — including parental consent for minors — before that data is provided to the Service.
5. Data Sharing and Third-Party Processors
We do not sell your personal data and we do not share it for advertising purposes. We share data only with the following categories of recipients.
Within a school
Users within a school's Tawaasal environment will see data relevant to their role. School administrators have visibility across the school; teachers see data for the classes and students they are assigned to; guardians see data for their own children; students see their own data. Access is controlled by the school's configuration and by our role-based permission system.
Service providers (sub-processors)
We use the following sub-processors to deliver the Service:
| Provider | Purpose | Region | |---|---|---| | Stripe | Payment processing | United States, with UK and EU representatives | | Google LLC (Firebase Cloud Messaging) | Mobile push notifications | Global Google infrastructure | | Google LLC (Firebase Crashlytics) | Crash and diagnostic reporting for the mobile app | Global Google infrastructure | | Google LLC (Sign in with Google) | Optional social sign-in | Global Google infrastructure | | Apple Inc. (Apple Push Notification service, Sign in with Apple) | iOS push notifications and optional social sign-in | United States | | Cloud infrastructure providers | Hosting, storage, and content delivery | United Kingdom and European Economic Area | | Email and messaging providers | Transactional email and SMS | United Kingdom and European Economic Area | | Resend, Inc. | Marketing email delivery and subscription list management for opted-in recipients | United States |
All sub-processors are bound by data processing agreements and process personal data only on our documented instructions. An up-to-date list of sub-processors is available on request from [email protected].
Law enforcement and legal compliance
We may disclose personal data where we are required to do so by law, court order, or other lawful request from a competent authority.
6. Data Retention
- Account data: Retained for the duration of your account plus 6 years.
- Billing records: Retained for 7 years as required by financial regulations.
- Consent records: Retained for the duration of the customer relationship plus 6 years.
- Marketing email data: Your subscription preferences are kept until you unsubscribe or ask us to delete them. The underlying opt-in and opt-out records are retained for 6 years as evidence of consent.
- Usage logs: Retained for 90 days, then anonymised.
- Crash and diagnostic data: Retained for 90 days.
- School tenant data: Retained for as long as the school's subscription is active. Following cancellation or termination, the school is given a 30-day window to export its data, after which the school's data is permanently deleted from our production systems within a further 30 days. Backups containing school data are retained for up to 90 days and are then deleted in the normal course of our backup rotation.
7. Your Rights
Under UK GDPR you have the right to:
- Access: Request a copy of your personal data.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your data ("right to be forgotten").
- Portability: Receive your data in a machine-readable format.
- Restriction: Request that we limit processing of your data.
- Objection: Object to processing based on legitimate interest.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time. For marketing emails, use the unsubscribe or preference link in any email, or the Preferences page in the customer portal — withdrawal takes effect immediately.
To exercise these rights against data we control, visit our Data Rights page or email [email protected].
For data held within a school's Tawaasal environment, please contact your school directly — the school is the controller and decides how to respond. We will support the school in fulfilling your request.
8. Children's Data
Tawaasal is used by schools and may be used by pupils under the age of 18, including in some cases pupils under the age of 13.
We process children's data only on the documented instructions of the school. The school is the data controller and is responsible for:
- Determining the lawful basis for processing children's personal data
- Obtaining any consents required by law from a parent or guardian
- Ensuring that any data shared with Tawaasal is necessary and proportionate to its educational purpose
We do not knowingly collect personal data directly from children outside of the school environment. We do not use children's data for advertising, marketing, profiling, or any purpose other than providing the Service as instructed by the school.
We design the Service to be safe for children:
- No third-party advertising of any kind, anywhere in the Service
- No behavioural profiling or targeted content
- No cross-app or cross-site tracking
- Access to a child's data is limited to authorised users within their own school
- Strong account security, including multi-factor authentication for staff accounts
We design our practices to align with UK GDPR (age of consent: 13), the EU GDPR-K framework (with the relevant member-state age threshold, between 13 and 16), the US Children's Online Privacy Protection Act (COPPA) where applicable, the Saudi Personal Data Protection Law (PDPL), and the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).
If you believe we hold personal data about your child that we should not, please contact [email protected] and we will work with you and your school to investigate.
9. Mobile App Permissions
Our mobile applications may request the following device permissions. You can deny or revoke each one at any time from your device settings; if you do, some features may not work as expected.
- Notifications: to deliver push notifications about messages, attendance, homework, and other school activity.
- Camera: to take photographs for profile pictures and homework submissions.
- Photos / Media: to attach files and images to messages and homework.
- Biometrics (Face ID, Touch ID, Android biometric): to sign you in securely without typing your password. The biometric template never leaves your device.
- Microphone: only if you choose to record voice or video.
We do not collect device location, contacts, calendar entries, or health data.
10. Tracking and Advertising
We do not display advertising in the Service and we do not use your data for advertising on or off the Service. We do not engage in cross-app or cross-site tracking. On Apple devices, our app does not request the IDFA (Identifier for Advertisers) and does not present the App Tracking Transparency prompt.
We use cookies and similar technologies on our website to provide essential functionality and, with your consent, for analytics. See our Cookie Policy for details.
11. Security
We implement industry-standard security measures, including:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Multi-factor authentication for administrator accounts
- Role-based access control with the principle of least privilege
- Audit logging for security-sensitive events
- Regular security assessments and penetration testing
- Automated daily backups with geo-redundancy
No system is perfectly secure. If you become aware of a security issue, please report it to [email protected].
12. International Transfers
Your personal data is primarily processed in the United Kingdom and the European Economic Area. Some of our sub-processors (notably Stripe and Google) operate global infrastructure and may process data outside these regions. Where we transfer personal data outside the UK and EEA, we rely on appropriate safeguards — including the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, and the EU Standard Contractual Clauses — supported by transfer risk assessments where required.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated by email and, where appropriate, by an in-app or in-portal notice.
14. Contact Us
| | | |---|---| | Data protection enquiries | [email protected] | | General enquiries | [email protected] | | Registered office | Ibdaa Ltd, 128 City Road, London, EC1V 2NX, United Kingdom | | Company number | 11658668 |
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data protection rights have been violated. Customers in other jurisdictions may also contact their local supervisory authority.