Effective from 18 July 2026

Privacy statement

Madrassa helps schools organise their teaching and communication securely. In this statement we explain which data is processed through the mobile app and the platform.

This is an English translation for convenience. If it differs from the Dutch version, the Dutch version prevails. Nederlandse versie

In short

The school is responsible

For student, parent and education data, the school decides the purpose. Madrassa processes that data on the school’s behalf.

No tracking

No advertising ID, cross-app tracking, session recordings or product analytics. We do not sell personal data.

Your rights

Request access, correction or deletion of school data from the school, and of your account from us.

This summary is a reading aid. The full text below is what counts.

01Who is responsible?

For most student, parent and education data, the school you belong to decides why and how that data is used, and is the data controller for it. Madrassa processes this data on behalf of the school. Madrassa is independently responsible for our own account security, service delivery, support and necessary diagnostics.

02What data do we process?

  • Account, contact, school and role data.
  • Education data such as classes, attendance, assignments, results, planning and progress.
  • Messages, appointments, activities, files and payment information needed within a school function.
  • Technical security data such as sessions, request references, app version and limited error diagnostics.

We do not use an advertising ID, cross-app tracking, session recordings or product analytics. Passwords and verification codes are not stored by the mobile app.

04Sharing and transfers

Data is only available to authorised users of the selected school and to carefully chosen processors for hosting, storage, email, payments and error diagnostics. We do not sell personal data. International transfers only take place with appropriate GDPR safeguards.

05Retention periods

The school determines the retention period for school data according to its policy and legal obligations. Security and operational logs are kept as briefly as possible. Backups have a rolling retention period of at most 30 days, unless an incident or legal obligation temporarily requires longer retention.

06Security

We use encryption in transit, protected storage, short-lived access tokens, rotating sessions, tenant authorisation, malware scanning of uploads, logging without sensitive content, backups and periodic restore tests.

07Your rights and deletion

You can request access, correction, deletion, restriction, portability or object to processing. For school and student data, please contact your school first. For a Madrassa account or a technical request, use info@madrassa.nl or our support page. You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

08Changes

Material changes are announced through the website or the app. The effective date is always shown at the top.

Questions about this document?

Email us at info@madrassa.nl. For school and student data, please contact your school first.