Skip to content

Student Data Protection

Effective 28 September 2026

In short: your institute controls its student data and NXTGEN only processes it on your instructions. Children’s data gets the extra protection Sri Lanka’s PDPA requires, it is never sold or used for ads or AI training, and it is isolated, encrypted and deleted when you leave.

1. Our promise

  • Student data belongs to the institute and, ultimately, to the students and families it describes.
  • We never sell student or guardian data, never show ads in the platform, and never build advertising profiles.
  • We never use student records, marks or submissions to train AI models.
  • No institute can see another institute’s data.
  • We use student data only to provide the Service the institute has asked for.

2. Roles: institute as controller, NXTGEN as processor

Under Sri Lanka’s Personal Data Protection Act, No. 9 of 2022 (as amended) and equivalent laws such as the GDPR, the institute that enrols students is the controller: it decides what data is collected and why. NXTGEN SMS is the institute’s processor. We:

  • process student data only on the institute’s documented instructions (our Terms and its settings in the portal);
  • bind all staff and subprocessors to confidentiality;
  • apply the security measures in section 5;
  • help the institute answer data subject requests and meet its breach, impact-assessment and regulator obligations;
  • delete or return the data when the institute leaves (section 9);
  • make available the information needed to demonstrate compliance, including reasonable audits on request.

3. What data the platform holds

  • Students — name, admission number, date of birth, grade, class and subject enrolments, photo, QR ID card, attendance, marks, assignments and submissions, fee records.
  • Guardians — name, relationship to the student, mobile number, email, and payment status of fees.
  • Teachers and staff — name, contact details, classes taught, earnings statements.
  • Technical data — sign-in times, device information and audit logs of who changed what.

4. Children’s data and guardian consent

The PDPA treats all personal data relating to a child (a person under 16) as a special category that needs additional care, and most students on NXTGEN are minors. For that reason:

  • The institute must obtain the consent of a parent or legal guardian (or have another lawful basis permitted for children’s data) before entering a child’s details, and keep a record of it. NXTGEN links each student to their guardians so guardians can see and receive information about their child.
  • Guardians may exercise their child’s data rights — access, correction, erasure and withdrawal of consent — on the child’s behalf.
  • Student accounts expose only what the student needs; students cannot see other students’ personal data.
  • We collect the minimum data needed and do not use children’s data for marketing of any kind.
  • Outside Sri Lanka, institutes remain responsible for local rules — for example parental consent under the US COPPA or GDPR Article 8, and FERPA for US schools, where NXTGEN acts as a “school official” under the school’s direct control.

5. Security measures

  • Tenant isolation — PostgreSQL row-level security is forced on every tenant table, so each query is scoped to one institute.
  • Encryption — TLS for all traffic; encrypted storage at our database provider; backups encrypted before they leave the server.
  • Credentials — passwords hashed with bcrypt; session and refresh tokens stored only as hashes; password-reset links expire.
  • Access control — role-based permissions for admins, teachers, students and guardians; NXTGEN staff access production data only to resolve a support request or incident.
  • Monitoring — audit logs of sensitive changes, rate limiting at the API gateway, and code review before each release.
  • Resilience — encrypted daily backups kept for 30 days in two separate locations.

6. Subprocessors

We use the following providers to run the Service. Each is bound by a contract requiring confidentiality, security and data-protection terms at least as protective as ours. We will give institutes at least 30 days’ notice (by email or in the portal) before adding a new subprocessor that handles student data, so they can object.

ProviderPurposeLocation
Supabase Inc.Managed PostgreSQL database and file storage (student records, uploads)European Union (Frankfurt, Germany)
Cloud VPS providerApplication servers that run the NXTGEN platformEuropean Union
Google LLC (Firebase, Google Workspace, Google Drive)Marketing-site hosting and analytics, transactional email, encrypted database backupsGlobal (Google data centres)
GitHub, Inc.Source code, deployment pipeline and a secondary encrypted backup copy (30 days)United States
PayHere (Pvt) LtdOnline payment processing in LKR (cards, wallets, bank transfers)Sri Lanka
SMSlenz (smslenz.lk)Guardian SMS delivery (attendance alerts, fee reminders, one-time codes)Sri Lanka
Twilio Inc.WhatsApp / SMS delivery, only where an institute enables itUnited States
Expo (650 Industries, Inc.)Push notifications to the NXTGEN mobile appUnited States

Transfers outside Sri Lanka rely on the safeguards in Section 26 of the PDPA (binding contractual commitments) and, for EEA/UK data, on adequacy decisions or Standard Contractual Clauses.

7. SMS, WhatsApp and email to guardians

Institutes use NXTGEN to send guardians service messages such as attendance alerts, fee invoices and receipts, and login codes. These are sent on the institute’s instructions to the contact details it provided. Promotional messages may only be sent with consent and must include an opt-out, in line with TRCSL rules and the PDPA. Guardians who no longer wish to receive messages should contact the institute, which can change their notification settings.

8. Requests from students and guardians

Students and guardians should send access, correction or deletion requests to their institute, which can action most of them directly in the portal. If a request reaches us, we will pass it to the institute promptly (normally within 5 business days) and help the institute respond within the legal deadline — one month under the PDPA and GDPR, extendable by up to two further months.

9. Retention and deletion

  • Institutes control retention while subscribed and can delete student records at any time.
  • When an institute leaves, it has 30 days to export its data. We then delete it from live systems within a further 60 days.
  • Encrypted backups containing the data expire and are deleted within 30 days after that.
  • We keep only what the law requires us to (for example, our own billing records with the institute).

10. If something goes wrong

If we become aware of a breach affecting student or guardian data, we will notify the affected institute without undue delay and in any event within 48 hours, with what we know about the nature of the breach, the data and people affected, and the steps we are taking. This lets the institute meet its duty to notify the Data Protection Authority of Sri Lanka within 72 hours and to inform families where the risk is high. We will support the institute throughout.

11. Contact

Institutes needing a signed data processing agreement, security questionnaire answers or an audit should email [email protected]. See also our Privacy Policy and Security page.

Questions about this document? Email [email protected] or write to NXTGEN SMS, Galle Road, Colombo 03, Sri Lanka.