Data Processing Agreement
Between the School as data controller and Fleetr Edge Technologies Ltd as data processor.
Effective from 24 August 2026.
In short
Section 42 of the Data Protection Act 2019 requires a processor to act under a written contract with the controller. This is that contract. A school does not need to draft one to buy School Run — but it does need to sign one, and its procurement team will ask for it.
Most of what is processed here is data about children. Clause 3 says so explicitly rather than burying it in a category list.
Status of this document
This agreement is incorporated into the Terms of Service and takes effect when a school begins using School Run. A school that requires a signed counterpart, or that wants to negotiate a clause, should write to hello@fleetr.co.ke.
"The Act" means the Data Protection Act, No. 24 of 2019 (Kenya), together with regulations made under it. "ODPC" means the Office of the Data Protection Commissioner. Terms such as personal data, data subject, controller, processor and personal data breach carry the meanings given in the Act.
1. Roles
The School is the data controller. It determines the purposes and means of the processing: which children ride which route, who among its staff may see the roll, which guardians are contacted, what they are told, and whether photographs are collected at all.
Fleetr Edge Technologies Ltd is the data processor. It processes personal data on the School's behalf and on its documented instructions, and for no purpose of its own.
Each party is independently responsible for complying with the Act in respect of its own role, including any registration obligation it has with the ODPC.
2. Scope, purpose and duration
Subject matter. The provision of the School Run school transport management service.
Nature of the processing. Collection, recording, organisation, structuring, storage, retrieval, consultation, transmission, restriction, erasure and destruction, by automated means.
Purposes. Only those necessary to provide the service:
- maintaining the School's register of children, guardians, routes and stops;
- recording boarding and alighting on a school run, and producing the manifest and reports built from it;
- showing the position of the School's buses to authorised School staff;
- sending transport notifications to the guardians of the child concerned, and operational alerts to School staff;
- authenticating users, and maintaining audit and security records;
- providing support to the School at its request.
Fleetr Edge Technologies Ltd does not process the School's personal data for marketing, profiling, advertising, resale, or for training machine-learning models.
Duration. For the term of the School's subscription, plus the wind-down period in clause 12.
3. Data subjects and categories of data
The majority of the personal data processed under this agreement relates to children. Section 33 of the Act requires that processing of a child's personal data safeguards the best interests of the child and is carried out with the consent of a parent or guardian. Establishing and evidencing that lies with the School as controller; clause 6 lists what the software does to support it.
Categories of data subject
- Children enrolled on the School's transport service.
- Parents and guardians of those children.
- School staff — administrators, transport managers and matrons.
- Drivers assigned to the School's buses.
Categories of personal data
- Child identity: name, admission number, class or stream, enrolment status.
- Child transport data: assigned route, home stop, and — for each run — whether the child boarded or alighted, at which stop, at what time, who confirmed it, any note recorded, and the bus's position at that moment.
- Child image: a photograph, where the School chooses to upload one. Optional.
- Guardian data: name, phone number, email address, relationship to the child, primary-contact status, notification preferences, and a record of messages sent.
- Staff and driver data: name, email address, phone number, role, account status, and a record of actions taken (attendance confirmations, report exports).
- Authentication data: password hashes and passkey credentials. Plaintext passwords are never stored.
- Vehicle and location data: vehicle identity, and the latest reported position, speed, bearing and ignition state of each bus, received from core Fleetr.
- Technical data: session records including IP address and user-agent, and application logs.
Not processed
School Run has no field for a child's health, medical, religious, ethnic, biometric or genetic data, and no payment card or bank details of any kind. A School that types such information into a free-text note is placing it outside the design of the system and does so as controller, at its own risk.
4. Processing on documented instructions
Fleetr Edge Technologies Ltd processes personal data only on the School's documented instructions. The instructions are: this agreement, the Terms of Service, the configuration the School sets in the application, and any further written instruction the School gives.
If Fleetr Edge Technologies Ltd believes an instruction infringes the Act, it will tell the School and may suspend that instruction until the matter is resolved.
If Fleetr Edge Technologies Ltd receives a request from a public authority for the School's personal data, it will refer the request to the School and will not disclose the data unless legally compelled to do so — in which case it will tell the School, unless the law forbids it.
5. Confidentiality
Personnel of Fleetr Edge Technologies Ltd authorised to process the School's personal data are bound by an obligation of confidentiality, are granted access only where they need it to perform their duties, and lose that access when they no longer do.
6. Technical and organisational measures
The measures currently implemented include:
- Transport encryption. All access is over HTTPS.
- Storage encryption. Records are encrypted at rest on the hosting provider's volumes, so a detached or decommissioned disk does not disclose them.
- Least privilege. Production access is held only by the named individuals who carry out a school's setup and support, and by the engineers at Loopy Labs Ltd who maintain the infrastructure, each under their own account. There is no blanket staff access to school data, and no access at all for personnel who do not work on that school.
- Credential protection. Passwords are hashed with bcrypt; passkeys are supported. SMS gateway credentials are encrypted at rest, excluded from serialised output and never written to a log.
- Tenant isolation. Each school's records carry a school identifier and are filtered by a database-level scope that fails closed — a query executed with no school in context returns nothing. The largest tables are physically partitioned per school.
- Layered authorisation. Access is gated on the route and re-checked in the request handler and the policy behind it. Staff-only surfaces refuse a guardian before any page renders.
- Private storage for children's photographs. Photographs are stored on a private bucket, never served from a public address, and re-authorised on every fetch.
- Data minimisation in logs. Notification message bodies are never stored or logged; the log retains a short summary line, a masked recipient and a delivery status.
- Authenticated ingest. Events from core Fleetr are verified by HMAC signature with a timestamp tolerance; unsigned, altered or stale deliveries are rejected.
- Outbound endpoint guard. A school-configured SMS endpoint is checked against a guard that refuses private and internal network addresses, both when saved and again immediately before each send.
- Rate limiting on sign-in, invitation and test-send endpoints.
- Integrity of the record. Attendance is append-only: a correction is a new entry and no route in the application edits or deletes an existing one. Staff and children with history are deactivated or marked as left, never deleted out from under the records that reference them.
- Auditability. Report exports record who asked, and the record of the request survives the deletion of the file itself.
- Expiry. Scheduled jobs delete the notification log, abandoned uploads and export files on the periods set out in the retention schedule.
These measures may be updated as the service develops, provided the level of protection is not reduced.
7. Sub-processors
The School gives Fleetr Edge Technologies Ltd general authorisation to engage sub-processors. The current list, with what each one processes and where, is published at https://schoolrun.co.ke/legal/sub-processors and forms part of this agreement.
Fleetr Edge Technologies Ltd imposes on each sub-processor it engages data protection obligations no less protective than those in this agreement, and remains fully liable to the School for that sub-processor's performance.
Notice of change. Fleetr Edge Technologies Ltd will give the School at least thirty (30) days' written notice before adding or replacing a sub-processor. The School may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the School may terminate the affected part of the service without penalty for the unexpired term.
The School's own SMS gateway is not a sub-processor of Fleetr Edge Technologies Ltd. The School selects, contracts with and pays that provider, and configures it in the School's own settings. School Run transmits the message to the endpoint the School named. The School is the controller in relation to that provider and needs its own written processor agreement with it. Fleetr Edge Technologies Ltd gives no notice of, and accepts no responsibility for, changes at a provider it did not choose.
8. International transfers
Section 48 of the Act permits a transfer of personal data outside Kenya where the controller or processor has given proof of appropriate safeguards, or where the transfer is necessary for the performance of a contract with the data subject, among other grounds.
School Run's application, database and object storage run on infrastructure that may be located outside Kenya. The current locations are stated in the sub-processor list, which reads the region actually configured on this deployment rather than restating one from memory.
Fleetr Edge Technologies Ltd relies on contractual safeguards with each infrastructure provider, on encryption in transit and at rest, and on the access controls in clause 6. The School, as controller, remains responsible for satisfying itself that the transfer is permitted for its own purposes, and for recording its assessment.
A School that requires the data to remain in Kenya must raise it before signing, so that the deployment can be assessed against that requirement.
9. Personal data breach notification
Fleetr Edge Technologies Ltd will notify the School without undue delay, and in any event within forty-eight (48) hours of becoming aware of a personal data breach affecting the School's personal data.
The notification will describe, so far as it is known at the time:
- the nature of the breach, and the categories and approximate number of data subjects and records affected;
- the likely consequences;
- the measures taken or proposed to address it and to mitigate its effects; and
- a point of contact for further information.
Where the full picture is not available immediately, information is provided in phases as the investigation proceeds rather than withheld until it is complete.
The School, as controller, is responsible for notifying the ODPC — section 43 of the Act requires notification within seventy-two hours of becoming aware, where the breach is likely to result in real risk of harm — and for notifying affected data subjects where the Act requires it. Fleetr Edge Technologies Ltd will provide the information and cooperation the School reasonably needs to do so. It will not notify the ODPC or data subjects on the School's behalf unless the School asks it to in writing.
10. Assistance with data-subject requests
Taking into account the nature of the processing, Fleetr Edge Technologies Ltd will assist the School by appropriate technical and organisational measures, so far as possible, in fulfilling the School's obligation to respond to requests to exercise rights under Part IV of the Act.
- Self-service first. Much of what a request asks for, the School can retrieve itself: a child's page shows their record, a guardian's page shows their contacts and links, the notification log shows what was sent, and the reporting surface exports a range.
- Where it cannot. Fleetr Edge Technologies Ltd will help the School locate, export, correct or delete data that the application does not expose directly, on written request from an authorised School contact.
- Requests received directly. A request that reaches Fleetr Edge Technologies Ltd from a data subject is referred to the School, promptly and without being answered on the School's behalf.
- Impact assessments. Fleetr Edge Technologies Ltd will provide the School with the information it reasonably needs for a data protection impact assessment and for any prior consultation with the ODPC.
11. Audit and information
Fleetr Edge Technologies Ltd will make available to the School the information reasonably necessary to demonstrate compliance with this agreement, and will allow for and contribute to audits, including inspections, conducted by the School or an auditor it mandates.
Audits are on reasonable written notice of at least thirty days, no more than once in any twelve-month period unless a breach or a regulator requires otherwise, during business hours, subject to confidentiality, and conducted so as not to disrupt the service or the data of other schools.
12. Deletion or return on termination
On termination of the subscription, Fleetr Edge Technologies Ltd will, at the School's election:
- return the School's personal data in a structured, machine-readable format; or
- delete it.
Absent a contrary written instruction, the default is the sequence in clause 12 of the Terms of Service: a thirty-day export window, followed by deletion from live systems, with encrypted operational backups ageing out on the ordinary backup cycle and remaining subject to clauses 5 and 6 until they do.
Deletion is confirmed to the School in writing on request. Fleetr Edge Technologies Ltd may retain personal data to the extent required by law, and only for as long as the law requires it.
This is an operational commitment carried out by Fleetr Edge Technologies Ltd on the School's instruction. It is not an automated function of the software.
13. Liability and precedence
Where this agreement conflicts with the Terms of Service or any other agreement between the parties on a data protection matter, this agreement prevails.
This agreement is governed by the laws of Kenya, and the courts of Kenya have exclusive jurisdiction.
Data protection contact for the processor: hello@fleetr.co.ke.