We collect information necessary to provide institutional management services, including student records, faculty details, and financial data provided by the user institution.
Student records typically include names, contact and guardian details, attendance, academic performance, and enrollment history entered by your institution. Faculty details cover staff profiles, roles, and attendance used to administer the platform on your behalf. Financial data includes fee structures, payment records, and invoices processed through the platform. This information is provided directly by the institution or its authorized users during setup and day-to-day use, and is never collected from students or parents independently of the institution's own workflows.
Your data is used solely for the purpose of operating the Ellifo platform for your institution. We do not sell or share your institutional data with third-party advertisers.
In practical terms, this means your data powers features like attendance tracking, report card generation, fee reconciliation, and parent communication within your own institutional account. Limited, aggregated, and de-identified usage patterns may be reviewed internally to improve platform performance and reliability, but this is never used to build advertising profiles or sold to any external party. Where a trusted sub-processor (such as our cloud hosting or payment gateway provider) needs access to perform a specific function, access is limited strictly to what that function requires and is governed by contractual confidentiality obligations.
We employ industry-standard AES-256 encryption and SSL protocols to protect data in transit and at rest on our secure AWS cloud infrastructure.
Access to institutional data within the platform is further restricted through role-based permissions, so staff members only see the records relevant to their responsibilities. Our infrastructure runs on AWS with regular backups and monitoring in place to guard against data loss and unauthorized access. While no system can guarantee absolute security, we continuously review and update our practices to align with current industry standards, and we encourage institutions to pair these protections with strong internal password and account-management habits as described in our Platform Policy.