Privacy
Our commitments, in plain language.
This page says what we actually do with data. The formal, signed version of these commitments is part of every engagement contract.
The school’s data belongs to the school
Student, family and staff records entered into Giiki are the institution’s property. Registers and reports export to CSV throughout the product, and nothing about leaving is designed to be hard.
We collect what the product needs
Giiki stores what a school operating system requires to run — enrolment, attendance, fees, library, gate and staff records. Sensitive identifiers are masked by default, and reveals are logged. Attendance detail is auto-summarised after 3 years.
We don’t trade in it
No advertising, no selling data, no training AI models on one school’s data for another’s benefit. AI features are metered per school and the sensitive one — call analysis — runs on-premise.
Providers are the school’s choice
Email, SMS and payment providers are configured per school — your accounts, your contracts. Provider usage is metered and visible.
Questions get answers in writing
Data-processing terms, sub-processors and breach-notification commitments come as documents with the contract. Write to [email protected] for anything this page doesn’t cover.
See the mechanisms
Most of these commitments are enforced by the product itself — masking, isolation, audit trails, retention purges. The security page lists them one by one.