Data Privacy Policy
1. Overview
Alpas is a multi-tenant school management platform. We are committed to protecting the personal data of students, faculty, and administrative staff entrusted to us by institutions ("Tenants"). This policy describes how data is collected, used, stored, and safeguarded.
2. Data we process
On behalf of Tenants, we process the following categories of personal data:
- Student records — names, enrollment status, grades, and academic history.
- Staff and faculty information — contact details, roles, and employment records.
- Financial records — tuition, fee payments, and billing information.
- Platform usage data — login activity and feature interaction logs.
Alpas acts as a data processor. Each Tenant is the data controller responsible for the lawful basis of processing their users' data.
3. Tenant data isolation
All tenant data is logically isolated. Every record carries its institution's tenant identifier, and that scope is enforced centrally in the data layer rather than left to each query, so no tenant can access another tenant's data. Each institution's data remains within its own security perimeter.
4. How we use data
Data is used solely to provide and improve the platform services contracted by the Tenant. We do not sell, share, or use student or staff data for advertising or third-party profiling.
5. Mobile apps
Alpas has two Android apps. Alpas Parent lets parents and guardians follow their children at their school. Alpas Staff is for school employees, whose accounts the school creates and manages.
Alpas Parent collects:
- Your name and email address, to create and run your account.
- Messages you send to school staff, which go to your child's school.
- The reasons and notes you write in an excuse slip. These may include health details about your child, and are shared only with your child's school.
- A push notification device token, so the app can tell you about attendance, grades, messages and school notices.
What you see about your children (attendance, grades, schedules, balances) comes from the school's own records, shown only after the school gives you a code for each child.
Anyone can use Alpas Parent to search school names. We show only a school's official name, town and level. What you type in the search is processed only to return results, and your IP address is used only to limit abuse. If a school leader asks us for a demo in the app, we collect their name, mobile number and email so our team can contact them. If a parent or teacher adds their voice for a school, we store the school, their role, an anonymous install id so each install counts once, and their email only if they give it, to tell them when the school joins. A parent or teacher who asks us to add a school gives their name and email. None of these need an account; to remove a voice or a request you made without one, email us at support@quirae.com. For a voice given without an email, include the app ID the app shows after you add it (it is also under Account). What you type in the search is left out of our server logs. The app still does not use your location.
Alpas Staff uses the camera to scan campus QR codes and to attach photos to reports the employee chooses to file.
Push notifications for both apps are delivered through Expo's push service and Google Firebase Cloud Messaging, which act as our service providers: they receive the device token and the notification text only to deliver it. The apps show no ads, do not use the advertising ID, do not collect your location, and we never sell personal data. Data travels to our servers encrypted.
6. Data retention
Tenant data is retained for the duration of the active subscription. Upon contract termination, Tenants may request a full data export within 30 days, after which data is securely deleted from all systems.
A parent can delete their Alpas Parent account at any time: in the app, where it takes effect at once, or by email, which we complete within 30 days. Their profile, contact details, links to their children, notifications and device tokens are deleted. Messages already sent, excuse letters, requests to the school office, payments, the log of text messages the school sent, and the school's own guardian contact record stay with the school as part of the student's record. Where they show the account, they read “Deleted parent”. Receipts, absence notes and the guardian contact card the school keeps are the school's own records, so they may still show the parent's name; the school can correct them. The steps are on our account deletion page.
7. Security measures
We implement the following technical and organizational safeguards:
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Role-based access controls limiting staff access to minimum necessary data.
- Regular security audits and penetration testing.
- Incident response procedures with Tenant notification within 72 hours of any breach.
8. Your rights
Individuals whose data is processed have the right to access, correct, or request deletion of their personal data. These requests should be directed to the Tenant (the institution), who as data controller will coordinate with us as necessary.
Parents can delete their own Alpas Parent account without going through the school, in the app or by email. See how to delete your account.
9. Contact
For privacy-related enquiries, contact us at support@quirae.com. Alpas is operated by Quirae Trading Industry OPC, San Luis, Batangas, Philippines.