Legal
Privacy policy
Last updated 15 June 2026
Brim holds information about children, families and staff. This policy explains, plainly, what we collect, why, and how it is protected — and where the school, not Brim, is in control.
Who controls your data
Brim is a platform that schools use to run their operations. For the records a school keeps about its students, guardians and staff, the school is the data controller and Brim is its data processor: we hold and process that data on the school’s instructions, not for our own purposes.
For the information you give us directly through this website — a pilot request, a help enquiry, a download notification — Brim is the controller. This policy covers both, and tells you which is which as it goes.
What we collect, and why
We collect only what a school platform genuinely needs to work:
- Marketing enquiries: the name, school, phone, email and message you submit on the contact, download or help pages — so we can reply and arrange a pilot.
- School records (as processor): student, guardian and staff details, academic and health records, fees and attendance — entered by the school to run its day, never sold or used for advertising.
- Operational logs: a signed, append-only audit trail of governed actions, kept so a school can always account for what happened (see Security).
- Basic technical data: cookieless, privacy-respecting analytics (Cloudflare Web Analytics) that count visits without tracking individuals across the web.
Our lawful basis
We process personal data in line with Uganda’s Data Protection and Privacy Act, 2019. For marketing enquiries, our basis is your consent and our legitimate interest in responding to you. For school records, the basis is the contract between Brim and the school, and the school’s own lawful basis for keeping those records.
We do not use children’s data for marketing, profiling or advertising. Ever.
Cookies and analytics
This site does not use advertising or cross-site tracking cookies. We use Cloudflare Web Analytics, which is cookieless and does not fingerprint or follow you to other sites. A single preference — your light/dark theme choice — is stored locally in your browser, not on our servers.
How your data is protected
Security is built into the platform, not bolted on. Family messages are end-to-end encrypted; medical and safeguarding records are encrypted to a specific role’s key, so even Brim staff cannot read them. Tenant data is isolated at the database level, and every sensitive action is recorded in a tamper-evident audit log.
The Security & trust page explains each mechanism in plain terms.
Who we share it with
We do not sell personal data. We share it only with the service providers needed to run the platform — for example Cloudflare (hosting), Neon (database) and Africa’s Talking (SMS and USSD) — each acting under contract and only to the extent their service requires. We disclose data to authorities only where the law requires it.
How long we keep it
Marketing enquiries are kept only as long as needed to follow up and for a reasonable period afterwards. School records are retained for as long as the school remains a customer and as the school instructs; on the end of a contract, data is returned or deleted according to the agreement with the school.
Your rights
Under the Data Protection and Privacy Act, 2019 you may ask to access, correct, or delete your personal data, and to object to certain processing. For records a school holds, please contact the school as controller; we will support them in responding. For data Brim controls directly, contact us using the details below.
Children’s data
Much of what schools keep on Brim concerns minors. We treat it with corresponding care: it is accessible only to the roles a school authorises, never used for any commercial purpose, and protected by the same encryption, isolation and audit controls described above.
Changes to this policy
If we change this policy, we will update the date at the top of the page and, for material changes, tell the schools we work with. Continued use of the site or platform after a change means the updated policy applies.
Questions about this?
We’d rather you ask. Reach us at hello@brimapp.net or +256 200 904 904.
Contact us