Privacy Policy — Mini School
1. Who we are
Mini School is built and operated by Tazzanda Company Limited. For anything concerning personal data, contact info@tazzanda.com.
2. Mini School is a school's system
Mini School is the information system a school uses to run student records: attendance, conduct, documents, timetables and contact with guardians. The school decides what is recorded, why, and who may see it. We act only as the school directs. We do not sell personal data, do not use it for advertising, and do not use a school's data for our own purposes.
3. What is collected, by role
Students: identity (titles, names, student code, citizen ID, nationality, sex, date of birth); contact and address, including home coordinates, distance and travel mode; family and living circumstances (parents' marital status, who the student lives with, siblings, religion, province of birth, special needs, teacher notes); academic records (class, subject enrolment, grades, exams, homework submissions, library loans); attendance by day and by period, leave and absence; conduct records, conduct scores, supporting files, and home-visit records with coordinates; health records (blood type, allergies, chronic conditions, emergency contact, notes, growth measurements); screening and assessment answers and results covering behaviour, emotion and mental health; uploaded documents; and face data (section 4).
Guardians: name, relationship to the student, phone, occupation, address, whether they have an account, sign-in details (section 6) and notification settings.
Staff: name, position, email, phone, permissions, subjects and rooms taught, timetable and duty roster, an append-only audit trail of who changed what and when, and — if the school enables staff face clock-in — face photos and face templates.
4. Face data
Face data is used only to identify a person for attendance and conduct records. The school obtains guardian consent first and the consent is recorded in the system. A student's face template is deleted when the school removes that student from the system, or when the guardian withdraws consent.
- The enrolment photo and the cropped face image are stored in our private AWS storage in Bangkok.
- The face template — a set of numbers, not an image, and not reversible into one — is stored in the system database and pushed to the school's scan terminal so scanning works without internet.
- One verification snapshot per scan is stored in the same private AWS storage, for resolving disputes, kept for as long as the service is in use. It is not shown anywhere in the school's own screens.
A school terminal holds templates, never photographs, and never computes a template itself: templates are produced at our office at enrolment time only.
5. Location
The app requests location only when a user performs one of two actions: recording a home visit (which stores the student's home coordinates) and a check-in that must confirm where it happened. There is no continuous or background location tracking.
6. Device data and sign-in
We store a push notification token (Firebase Cloud Messaging), the platform, and the app id and version, so notifications reach the right device and build. Users may sign in with LINE or Google (Apple sign-in is planned and not yet enabled); the provider gives us an opaque user reference and possibly an email or display name, and nothing else from that account. A one-time code may be sent by SMS through SMSOK to a phone number the school already holds; SMS is used for login codes only, never for notifications, and the send record is kept for 30 days. In-app searches and the items opened are logged to power "recently opened" and are deleted after 180 days.
7. How data is used
To provide the service the school has configured (attendance, conduct, grades, documents, timetables); to notify guardians and teachers (for example absence, leave status, school announcements); to identify a person at sign-in and at a face scan; to produce the school's reports and statistics; and to keep the system secure and diagnose faults. Files a school uploads to import data (for example student lists or timetables) are read by an AI text interpreter only to help fill in the data automatically; they are never used to train any model.
8. Where data is stored
Databases and files are hosted on Amazon Web Services in the Bangkok, Thailand region. File storage is private; access is through short-lived links issued to authorised users. The school's own face terminal stores its roster and face templates locally so it keeps working offline.
9. Retention
Search log: 180 days. Superseded or deleted file versions: 30 days, then permanently removed. Student, guardian, staff, attendance, conduct and academic records: kept while the school uses the service, deleted within 90 days after the school ends its contract unless the school asks for a copy first. Face templates: deleted when the school removes the student, or when the guardian withdraws consent. Verification snapshots: kept for as long as the service is in use. Login SMS records: 30 days. Backups: 30 days.
10. Sharing
We do not sell or trade personal data. We disclose it only to the processors the service needs, each acting on our instructions: Amazon Web Services (servers and file storage, Bangkok region); Google Firebase Cloud Messaging (push notifications); SMSOK (login SMS); and LINE, Google and Apple for the sign-in step when a user chooses that account. We may also disclose data where the law requires it, or where the school instructs us to.
11. Security
Each school's data is separated inside the database itself — a query that does not state which school it is for returns nothing. Traffic is encrypted with HTTPS/TLS, and device channels carry their own encryption. File storage is private, encrypted at rest, and readable only through time-limited links. Access follows role and relationship: a homeroom teacher sees their own room, a guardian sees their own child. Password sign-in is restricted to the school's own network.
12. Questions or requests
For any question about personal data, or a request to correct, delete, or get a copy of it, contact your school first, or write to info@tazzanda.com. We respond within 30 days.
13. Children
Most student users are minors. Student accounts are created by the school; there is no self-registration. Where consent is required — face data in particular — the school obtains it from the guardian or legal representative.
14. Changes
If this policy changes we will update the effective date above and inform schools of any significant change.