Privacy policy
What this platform keeps, and what it never does
Plain words about the records a school keeps here, who controls them, and what never happens to them. No legal fog: if a sentence here does not match what the product does, the sentence is the bug.
Last updated: 7 September 2026
Who does what
EduOnPoint is a school management platform for Cameroon schools running any section from nursery to high school, operated from the address in the footer. The school that registers is responsible for the records it keeps here: it decides what is entered, who on its staff may see it, and how long it stays. In data-protection terms, the school is the controller of its own register.
The platform operator hosts those records on the school's behalf and uses them for nothing except running the school's own portals. This page covers both roles, and the public site as well as the signed-in application.
What a school records
A school using EduOnPoint enters what a school register has always held: pupils' names, dates of birth, classes, guardians and their phone numbers; attendance; marks, report cards and examination entries; fee invoices and the payments that settle them, including mobile-money references. Staff records carry the job, department and payroll figures the school enters.
None of this is collected from the pupil or the family by the platform itself. It is entered by the school, under the school's authority, exactly as it was in the paper register this replaces.
Accounts and enquiries
An account holds a name, an email address or phone number, a role, and a hashed password. Sign-ins, failed attempts and the lockouts they trigger are logged. When someone asks a school for access, the request — name, contact, requested role — is stored until the school approves or declines it.
The contact form on this site keeps what you type in it — name, school, phone or email, message — so the operator can answer. Ask for that to be deleted at any time using the address in the footer.
Children in the data
Most of the people described in a school's records are minors. That data exists here because the school has the authority and the duty to keep a register of its own pupils; the platform adds nothing to it and reads it only to draw the school's own screens.
A guardian's account sees their own children and nobody else's. A pupil's account sees their own record. That scoping is enforced by the server on every request, not by hiding links.
What never happens
There is no advertising on the platform, no sale or sharing of records, no analytics service watching pages, and no tracking pixel from anyone. The only requests a page makes are to this installation.
Schools on the same installation are isolated from each other: every query the application runs is bound to the school in session, and the platform's own console writes an audit entry every time the operator reads a school's data.
Cookies and this device
Signing in sets one session cookie, which is how the server knows the next click is yours. Ticking "remember me" sets a second, longer-lived one that signs this device back in. Neither is readable by scripts, and neither exists for a visitor who only reads the public pages.
Your theme and language choices are kept in the browser's own storage, on your device, and are sent nowhere.
Messages and payments
Messages a school composes — an absence notice, a fee reminder — are queued in the school's own outbox. Out of the box, a person presses send in WhatsApp; if the school connects a messaging provider, that provider carries the message under its own terms. Either way, delivery happens on networks the platform does not run.
Mobile-money payments happen on MTN's or Orange's network, between the family and the school. The platform stores the reference, the amount and who confirmed receipt. It never sees or stores a PIN.
Security
Passwords are stored hashed, never in clear. Every form is protected against request forgery, repeated failed sign-ins lock the account for a while, and each school's data is walled off from every other's at the query level.
The honest part: security also depends on how the installation is deployed. Serve it over HTTPS, keep backups, and give accounts only the roles they need. The published limits on the FAQ apply here as everywhere.
Keeping and deleting
The school decides how long its register is kept, the same way it decided for paper. Excel exports exist so a school can take its records with it, and a school that closes its account can ask for its data to be deleted once those exports are in hand.
Individual corrections — a misspelt name, a wrong guardian number — are made by the school's own administrator in the ordinary screens. Requests sent to the operator are passed to the school, unless they concern the operator's own records, such as an enquiry you sent from this site.
Your rights and the law
Cameroon's Law No. 2024/017 of 23 December 2024 on the protection of personal data gives the people in these records rights of access, correction and erasure. Exercise them through the school first — it holds the register — or write to the address in the footer and the request will reach the right place.
Every account is shown this policy and the terms at its first sign-in and asked to accept them; the platform records which version was accepted and when, and asks again when the words change. This page changes only when the product's behaviour changes, and the date under the title moves when it does. Who operates the platform, and where, is on the legal notice.
Questions, corrections or complaints: hello@eduonpoint.cm
Set up your school and look around
Registration creates an empty school that only you can see. Nothing is shared with any other school on the platform, and there is nothing to cancel.