Skip to content
SDMS
Back to site

//Legal

Privacy Policy

Last updated 4 September 2026

SDMS is an offline desk. Student records live in a file on your own machine, and the only thing that ever leaves it is the result payload an operator deliberately publishes. This page says what that payload contains, what stays behind, and who is answerable for either.

//01

Who this covers

SDMS is a desktop application licensed to institutions. This policy covers two separate things: this website, and the application your centre installs.

They really are separate. The website knows nothing about the records inside the application, and the application does not report back to the website.

//02

Where the records actually live

The application keeps every record in a single database file on the computer it is installed on — inside your own user account, on your own disk. There is no account to create, no tenant to join and no copy of that file held by us.

That is the design, and it is why most of a privacy policy does not apply here: for a centre that never turns on result publishing, no student data leaves the building at all.

//03

The one thing that leaves the machine

Publishing results to the portal is a deliberate action taken by an operator, and it copies a fixed set of columns for the candidates in the published cycle:

  • Symbol number and registration number
  • Candidate name, date of birth and stream
  • Grade, academic year and examination type
  • Subject marks, the computed GPA and the pass or graded remark
  • Certificates issued for that cycle, by serial

//04

What stays behind

Photographs, guardian names, phone numbers, addresses and any internal note attached to a record are not part of that payload. They stay in the file on your machine.

The Settings panel keeps a fingerprint of what was last published, so it can tell you offline whether the portal is still showing the same figures as the desk. That fingerprint is a digest of your own rows; it is not sent anywhere.

//05

Who is answerable for it

Under the Digital Personal Data Protection Act, 2023, the centre is the Data Fiduciary for its candidates: you decide what is collected, why, and how long it is kept. Where we host the published portal we act as a Data Processor, on your instruction and for no other purpose.

We do not sell student data, do not train anything on it and do not use it to advertise to anybody.

//06

Candidates who are children

Most candidates in a cycle are under eighteen. Consent from a parent or lawful guardian is the centre's to obtain and to record, at admission, in the form the Act asks for. The application gives you somewhere to record it; it cannot obtain it for you.

Nothing in the software tracks a candidate's behaviour or shows them advertising, on the desk or on the portal.

//07

What this website collects

The contact form takes a name, a phone number, an email address and a message, and sends them to the desk that answers enquiries. That is the only personal data these pages ask for, and answering you is the only thing it is used for.

There are no analytics, no advertising tags and no third-party trackers here. Two preferences — the theme and the accent colour — are stored in your own browser under sdms-theme and sdms-accent. They never leave it, and clearing site data removes them.

//08

Support, and what we can see

Support is by email and phone. Nobody on our side holds standing access to your machine or your database file.

Where a problem needs eyes on the data we ask for the one record it concerns, or for a screen share at a time you pick, and we work from a sample wherever a sample will do.

//09

Keeping it, and getting rid of it

The database file is yours. It is kept until you delete it, backups are written where you point them, and nothing expires on our schedule.

Published results stay on the portal until the centre unpublishes them or the licence ends. On termination we erase the published copy within thirty days of the last paid period, and will confirm the erasure in writing if you ask.

//10

Security, honestly stated

Between the desk and the portal data moves over TLS, and the credentials the sync uses are held in the application's own configuration rather than typed by an operator.

The rest is machine-level and therefore yours: an operating-system account per operator, disk encryption on the office computer, and a backup you have actually restored from once. No software makes up for a shared login on an unencrypted laptop.

//11

Asking to see, correct or erase a record

A candidate or guardian should ask the centre that enrolled them: the centre holds the record and can act on it the same day. Where the request concerns the published portal, the centre forwards it and we act on the centre's instruction.

A question about this policy, or a grievance about how it has been applied, goes to the support desk at the address below. We answer in writing, within thirty days.

//12

Changes to this policy

Any change is dated at the top of this page. Where a change alters what leaves your machine or who can see it, it is written into the release notes of the version that makes the change as well — not left here to be noticed.

Does something here not match what the software does?

Then one of the two is wrong, and we would rather fix it than argue about it. Write to the desk and say which line.

Email the desk

Also worth reading

Terms of service