Security & Compliance
Information Security Policy
How Skoolfly protects the confidentiality, integrity and availability of its systems and data.
1. Policy Statement
Skoolfly is committed to protecting the confidentiality, integrity and availability of the information and systems it manages on behalf of schools, students, parents, teachers and other users. This Information Security Policy establishes the framework of principles, responsibilities and controls that guide how Skoolfly safeguards its platform, data and people.
2. Purpose
The purpose of this policy is to protect Skoolfly's information assets from accidental or deliberate unauthorised access, disclosure, alteration, destruction or disruption, and to establish a consistent, risk-based approach to information security across the organisation.
This policy is the authority under which more specific security policies operate, including the Password Policy, Access Control Policy, Backup Policy, Incident Response Policy and Vulnerability Management Policy.
3. Scope
All information systems, networks, applications, servers and data owned or operated by Skoolfly.
All personal data, academic records and other sensitive information hosted on the Skoolfly platform.
All employees, contractors, interns, consultants and other personnel who access Skoolfly systems.
Third parties and vendors that process data or provide technology services to Skoolfly.
All physical locations and equipment that support Skoolfly operations.
Schools and users are expected to cooperate with the controls described in this policy where they interact with the platform.
4. Information Security Objectives
Protect personal and educational data against unauthorised access and misuse.
Maintain the confidentiality, integrity and availability of the platform and its data.
Prevent, detect and respond to security incidents in a timely manner.
Meet applicable legal, regulatory and contractual security requirements.
Build a culture of security awareness among employees and stakeholders.
Continuously improve security controls through review, testing and lessons learned.
5. Roles and Responsibilities
Information security is a shared responsibility. The following roles are responsible for implementing and enforcing this policy.
6. Security Principles
Confidentiality: information is accessible only to those authorised to access it.
Integrity: information remains accurate, complete and unmodified without authorisation.
Availability: information and systems are available when needed.
Least privilege: users receive the minimum access required to perform their role.
Defence in depth: multiple layers of control protect each asset.
Risk-based approach: controls are proportionate to the sensitivity of data and likelihood of harm.
Accountability: ownership and responsibility for security are clearly assigned.
7. Information Classification
Information should be classified according to sensitivity so that appropriate controls are applied.
8. Physical and Environmental Security
Office areas are access-controlled and visitor access is managed and supervised.
Equipment that stores confidential information is protected and handled carefully.
Servers and infrastructure rely on secure, reputable data-centre providers with appropriate physical and environmental controls.
Personnel are expected to lock or secure devices when unattended, especially when carrying confidential information.
9. Third-Party and Vendor Security
Third parties that process Skoolfly data or provide technology services must meet proportionate security requirements. Vendors are assessed, bound by appropriate contractual terms and monitored on a risk basis, as described in the Third-Party / Vendor Security Policy.
10. Incident Handling
All suspected security incidents, anomalies or breaches must be reported without delay. Incidents are handled in accordance with the Incident Response Policy, which defines detection, containment, investigation, notification and recovery steps.
11. Training and Awareness
Security awareness training is provided to employees and relevant contractors.
Training covers password safety, phishing, data handling, incident reporting and this policy.
Awareness is refreshed periodically and after significant security events.
12. Compliance and Enforcement
Compliance with this policy is mandatory. Failure to comply may result in corrective action, including disciplinary measures, suspension of access, or removal of contractual arrangements, in accordance with applicable law and employment or contract terms.
Compliance is reviewed periodically through internal checks, audits and security assessments.
13. Review
This policy is reviewed at least annually, or more frequently when significant changes to the platform, law or threat landscape require it. Review findings are documented and communicated as appropriate.
14. Contact
Questions about this policy and its implementation may be directed to info@skoolfly.com or the Data Protection Officer.
