Privacy Policy
Last updated: 1 October 2026
This policy explains how New Generation Academy ("NGA", "the school", "we") collects, uses and protects personal data in its digital services at amashuri.com:
- NGA MIS (mis.amashuri.com)
- Task Mentor
- Tendo (attendance and discipline)
- Tupo (messaging and meetings)
Together these are "the Services". They are provided to the school's students, parents and guardians, teachers and staff.
- We use your data to run school life: timetables, lessons, assignments, results, attendance and communication.
- We never sell it.
- We don't use it for advertising.
- If you connect Google Calendar or Telegram, we only use them to send you your own school reminders.
- You can disconnect them at any time.
Contents
- Who is responsible
- Data we collect
- How we use it
- Google user data
- Telegram
- Notifications and devices
- Platform activity and monitoring
- Sharing
- How long we keep data
- Security
- Children
- Your rights
- Changes and contact
1. Who is responsible
New Generation Academy, Rwanda, is the data controller for the Services. We process personal data in line with Rwanda's Law No. 058/2021 of 13/10/2021 relating to the protection of personal data and privacy. Where the Services are used by people in other countries, we apply equivalent protections.
Contact for privacy questions: mis@nga.ac.rw.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account and profile | Name, school email, username, role, class or programme, profile photo, language and theme preference | The school; you |
| Academic records | Enrolled subjects, timetable, lesson plans and notes, quizzes, assignments, submissions, marks and report cards | Teachers, students, the school |
| Attendance and conduct | Attendance marks, excuses, discipline records | Teachers and staff |
| Communication | Messages, posts, files and meeting information in Tupo; in-app notifications | You and other users |
| Reminder settings | Which reminders you want, quiet hours, chosen channels | You |
| Devices | Web Push subscription details (browser, platform, a push address issued by your browser vendor), whether the app is installed | Your browser, when you turn notifications on |
| Connected services | Telegram chat ID and username; for Google Calendar, your Google email address and an access token | Only if you connect them |
| Technical and security logs | Sign-in times and attempts (including the username typed), IP address, browser type, error logs, audit trail of administrative actions | Automatically |
| Platform activity | Which NGA app, feature and page you use and when, how long a page is in use, your device and browser, your full IP address and the approximate place and internet provider derived from it (see section 7) | Automatically, for everyone using the Services, including visitors who are not signed in |
We do not collect payment card data. We do not use advertising or third-party tracking cookies. Cookies and local storage keep you signed in, remember your settings, and hold a random device identifier (nga_did) used only for the platform activity described in section 7.
3. How we use it
- To provide the Services: timetables, teaching and learning, assessment, reporting, attendance, and school communication.
- To sign you in once across the NGA apps (single sign-on), and to sign you out of all of them when you sign out.
- To send reminders and notifications you asked for: lessons, quiz and assignment deadlines, meetings and schedule changes.
- To keep the Services secure, investigate misuse, and meet the school's legal and safeguarding duties.
- To produce aggregated statistics for the school, for example attendance rates. These statistics don't identify you publicly.
Our legal bases are:
- the school's educational mission and legitimate interests;
- our legal obligations;
- for optional features such as Google Calendar, Telegram and email alerts, your consent. You can withdraw it at any time.
4. Google user data
You may choose to Connect Google Calendar on the Reminders page. If you do:
-
What we access: the Google OAuth scope
https://www.googleapis.com/auth/calendar.app.created, plus your basic sign-in identity (email). This scope lets us create one secondary calendar named "NGA · My Timetable" in your Google account and manage only the calendars and events that we created. We cannot see, read or change any of your other calendars or events. - How we use it: only to add, update and remove your own school events in that calendar, with reminder alarms. These are lessons, quiz and assignment deadlines, and meetings.
- How we store it: your Google refresh token is encrypted (AES-256-GCM) in our database. We store the IDs of the events we created so we can update them. We don't store the content of any other Google data.
- Sharing: Google user data is not shared with, sold to or transferred to anyone. It is not used for advertising, and it is not used to develop, improve or train generalized or non-personalized AI or machine-learning models.
- Removing access: press Disconnect on the Reminders page. We then delete the "NGA · My Timetable" calendar, revoke our access with Google and delete the stored token. You can also revoke access at myaccount.google.com/permissions.
NGA's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Signing in with Google, where offered, uses only your Google email and name to find your existing school account.
5. Telegram
If you choose Connect Telegram:
- We store your Telegram chat ID and username so our bot (@nga_reminders_bot) can send you your reminders.
- We receive only the messages and button presses you send to the bot.
- Telegram's own handling of your data is governed by the Telegram Privacy Policy.
- To stop, send
/stopto the bot, block it, or press Disconnect on the Reminders page. We then delete the link.
6. Notifications and devices
When you turn notifications on, your browser gives us a push address. Messages sent to it travel through your browser vendor's push service (for example Google, Apple, Mozilla or Microsoft), end-to-end encrypted with standard Web Push encryption. Turning notifications off, or removing the device on the Reminders page, deletes it.
If you use the optional email alert for missed important reminders, we send it to your school email address. Personal calendar feed links are secret and private to you. You can reset or turn them off at any time.
7. Platform activity and monitoring
To run, secure and improve the Services, the school records how they are used, in the MIS and in Task Mentor, Tendo and Tupo. This applies to everyone, including visitors to public pages who are not signed in.
- What is recorded: the app, feature and page (the type of page, not the record you opened), the time and how long the page was in use, sign-ins and sign-in attempts, your device and browser, your full IP address, and the approximate place and internet provider worked out from it. The place is approximate: on mobile networks it often shows the city of the operator, not where you are.
- What is never recorded: what you type, the content of messages, mail, notes or files, search text, screenshots or recordings of your screen.
- Precise location is off. If the school ever turns it on, this notice will say so and your browser will ask you first; you can refuse.
- Who can see it: a small number of platform administrators. Leaders see only totals for their area. Every time an administrator opens a named person's activity, it is logged.
- Monitoring a specific person: an administrator may watch a person's activity for a stated reason and a limited time (at most 90 days). The person is always told: who, why and until when. Nobody is monitored without being told.
- Your own record: signed-in users can see what is recorded about them, and whether anyone is monitoring them, on the My activity page.
- Not used for marks, appraisal or discipline decisions without a separate process that tells you.
- How long: detailed activity for 13 months; visits, IP addresses and places for 25 months; sign-in records for 24 months; daily totals without IP addresses for up to 5 years.
8. Sharing
We share personal data only as needed to run the Services:
- Within the school: with teachers, staff and administrators according to their role. For example, a teacher sees their own classes, and parents see their own children.
- Service providers acting on our instructions:
- cloud hosting (Amazon Web Services);
- email delivery;
- browser push services;
- Google and Telegram, only when you connect them.
- Authorities: when required by law or to protect the safety of students and staff.
We never sell personal data.
9. How long we keep data
- Academic, attendance and conduct records: for as long as the school must keep them under Rwandan education rules.
- Accounts: for as long as you are part of the school.
- Sent reminders and delivery logs: kept for a short period for troubleshooting.
- Push subscriptions: removed when they stop working.
- Google and Telegram links: deleted when you disconnect.
- Security logs: kept for a limited period.
- Platform activity: as set out in section 7.
10. Security
- All traffic uses HTTPS.
- Access is role-based.
- Passwords and secrets are hashed or encrypted.
- Signing out of NGA MIS ends your sessions in the connected NGA apps.
- Administrative actions are logged.
No system is perfectly secure. If we learn of a breach affecting you, we will notify you and the authorities as the law requires.
11. Children
Many users are students under 18. The school processes their data to educate and care for them. Parents and guardians may exercise the rights below on their child's behalf. Optional connections such as Google Calendar and Telegram are subject to those services' own minimum-age rules.
12. Your rights
Subject to the law, you may:
- ask for a copy of your data;
- have it corrected or, where appropriate, deleted;
- object to or restrict certain processing;
- withdraw consent for optional features;
- ask for data portability.
Contact mis@nga.ac.rw. You may also complain to Rwanda's National Cyber Security Authority (NCSA), the data protection supervisory authority.
13. Changes and contact
We may update this policy. The date at the top shows the latest version. For important changes, we will tell users in the Services.
New Generation Academy · Rwanda · mis@nga.ac.rw