Safe by construction.
The safe thing is the only thing the system can do. Not a policy, not a setting. Here is what that means, in plain English.
POPIA
Retention you can tighten, never loosen.
Medical records are kept for five years after a pupil leaves and other records for seven. Academic history is kept permanently and cannot be edited. A head can shorten either window; nobody can lengthen one or switch it off.
- Medical records
- 5 years after leaving
- Other records
- 7 years after leaving
- Academic history
- Kept permanently
- Direction
- Shorten only
- Lawful basis
- Sections 11, 19, 26
Encryption
Sensitive records are encrypted separately.
Medical, pastoral and legal notes sit in their own encrypted store with their own key, and are excluded from anything that leaves the system. Everything else is encrypted at rest and in transit.
- Sensitive store
- AES-256-GCM, separate key
- At rest
- Encrypted
- In transit
- TLS
- Exports
- Sensitive excluded, always
Access log
Every view, entry and share is written down.
Marks, notes and the access log are append-only, and that is enforced by database grants rather than by application code. Corrections keep the original beside them. We cannot edit the log either.
- Type
- Append-only
- Enforced by
- Database grants
- Corrections
- Original kept
- Who can edit
- Nobody
Parents
What a parent can and cannot see.
A parent receives a PIN for one child and sees whichever of six details the teacher ticks: marks, progress, and the teacher's own notes about that child. Never another pupil, never a note shared between staff, never a sensitive record. The link expires after fourteen days and a head can revoke it in one tap.
- Can see
- Ticked details, the teacher's own notes
- Cannot see
- Other pupils, staff-shared notes, sensitive
- Link expires
- 14 days
- Access
- 6-digit PIN, unique to one pupil
- Revoke
- One tap, logged
Backups
A complete backup, restorable.
A backup of every record in your school can be taken, and a school can be restored from it. Nightly encrypted backups are being built, and this page will say so when they are running rather than before.
- Scope
- Every record
- Backup
- Restorable
Where data lives
Hosted in the EU, under POPIA safeguards.
Your records are hosted in the EU, encrypted in transit and at rest, under POPIA's cross-border safeguards. South African hosting is available on request for schools that need it. Report drafting runs on our own servers using your phrase bank, so no pupil's work is sent to a third party to be written about.
- Region
- European Union
- Processing abroad
- None beyond the EU host
- South African hosting
- On request
- Sub-processors
- Listed below
Sub-processors
Who else touches your data.
Four companies handle school data on our behalf, each for one job. A fifth is wired up and switched off. Report drafting uses none of them: it runs on our own servers from your phrase bank.
-
Railway
Application hosting and the Postgres database
European Union
-
Cloudflare
File storage in R2, and serving this website
European Union
-
Resend
Transactional email, such as an invitation or a reset
European Union
-
Stripe
Payments
Payment data only, never pupil records
-
Anthropic Switched off
Reading details out of a new-starter admission PDF
Switched off in production. The driver is a stub, no pupil data reaches it, and this page will say so before that changes.
Assurance
Tested before every release.
The promises on this page are covered by an automated test suite, 1478 tests in all, and every one of them must pass before a change reaches a school.
- Automated tests
- 1478 across 135 files
- Run
- In full, every change
- Failing test
- Blocks release
- Coverage
- Includes the promises on this page
What Bhala will never do
Enforced in the database, not by a setting anyone can switch off.
- Store an absence as a zero
- Label a child
- Generate text about a pupil
- Let a sensitive record reach a share
- Delete history