Data Policy
How AthenaStar protects your school's data and who can access it.
Last updated: 28 June 2026
1. Multi-Tenant Separation
AthenaStar is multi-tenant: every school that signs up gets its own separate, isolated data store. A school's records — students, staff, fees, academics — are never mixed with another school's, and one school's users cannot query or browse another school's data.
2. Storage & Backups
School data and uploaded files are kept on secure, professionally managed infrastructure, with regular backups maintained so information can be recovered if something goes wrong. We do not publish technical details about our storage or backup systems, in keeping with standard security practice.
3. Access Control
- Role-based permissions — every user (Admin, Accountant, Teacher, Secretary, HR, Parent, etc.) only sees the modules and data their role and explicit permissions allow.
- Platform-level access — used only for support/maintenance, and every such access is logged for accountability.
- Audit logging — security-relevant actions (logins, failed logins, force-logouts, permission changes) are logged per school.
4. Security Practices
AthenaStar follows industry-standard practices to protect data in transit and at rest, including encrypted connections, hashed passwords (never stored in plain text), and protections against common web attacks. As a matter of policy, we do not disclose the specific technical measures in place.
5. Third-Party Processors
Payments are processed by Paystack; SMS messages, where enabled, are sent through our SMS gateway partner. Neither receives more data than is strictly necessary to complete that specific transaction or message.
6. Data Deletion
A school that closes its account may request deletion of its data and uploaded files. Requests should be sent in writing to the email below; we will confirm once deletion is complete.
7. Reporting a Security Concern
If you believe you've found a security vulnerability, please report it responsibly to the email below rather than testing it against live school data. We take all reports seriously and will respond promptly.
8. Contact
Data-handling questions: [email protected].