Nezam is an educational management platform for community schools and language institutes. It brings together online enrolment, attendance, grades and report cards, student progress tracking, payments, two-factor authentication and a bilingual mobile app for parents and students, with data hosted in Europe. Because it handles data relating to learners, underage students and their legal guardians, Nezam places data protection at the heart of its design ("privacy by design"). This page describes Nezam's commitments under the General Data Protection Regulation (GDPR) and complements the privacy policy.
1. Our GDPR commitments
Nezam undertakes to process personal data lawfully, fairly and transparently, for specified purposes limited to educational management. Concretely:
- data is collected only for educational management purposes (enrolments, attendance, grades, payments, communication with families);
- consents, authorisations (photo, outings) and mandatory documents are collected and kept in the learner's record;
- data is only accessible to authorised people, according to each person's role (management, teacher, legal guardian, student);
- legal guardians retain control over the information relating to their children;
- no data is resold or used for advertising purposes.
2. Our commitments on your data
Your learners' and families' data belongs to your organisation. Nezam hosts and protects it on your behalf, and makes the following commitments:
- your data is used only to run the service for your organisation, and for nothing else;
- it is never resold, exploited for advertising purposes, or used to train artificial intelligence models;
- it is protected by industry-standard security technologies (encryption, two-factor authentication, strict separation of each organisation's data, daily backups) — see section 5 for details;
- you can obtain an export of your data, or request its deletion, at any time;
- Nezam supports you in responding to families' requests (access, rectification, erasure) and provides, on request, the compliance documents your organisation needs.
Contractually, Nezam acts as a processor within the meaning of Article 28 of the GDPR: in practice, this means we may only process your data on your behalf and on your instructions, never for our own purposes. The corresponding data processing agreement is provided on request at contact@nezam.fr.
3. Record of processing
Nezam keeps a record of the processing activities carried out via the platform, as provided for in Article 30 of the GDPR. The main categories of processing are:
- management of enrolments and re-enrolments (learners, legal guardians, subjects, time slots, waiting list);
- attendance tracking (roll call, reasons for absence and lateness, behaviour, validation of the roll call);
- educational tracking (grades by sub-skill, averages, comments, report cards);
- payment management (transactions, due dates, statuses);
- communication with families (messaging, announcements, push notifications);
- management of accounts and user roles.
4. Sub-processing
To provide the Service, Nezam may use sub-processors (for example for hosting, sending notifications or payments). These providers are selected for their compliance guarantees and are bound by contractual commitments that meet the requirements of Article 28 of the GDPR.
The list of sub-processors is kept up to date and can be provided to customer organisations on request at contact@nezam.fr.
5. Security & hosting
Protecting school data is our responsibility, and we rely on industry-standard security technologies to do so. Nezam implements technical and organisational measures designed to protect data against loss, unauthorised access, disclosure or alteration, in particular:
- encryption of data in transit (TLS) and at rest;
- individual user authentication, with two-factor authentication (2FA);
- passwords never stored in plain text, protected by proven hashing functions;
- role-based access management, with each user only accessing the data needed for their function;
- strict separation of data: each organisation only ever accesses its own;
- logging of access and changes, to ensure operations can be traced;
- automatic daily backups, allowing data to be restored in the event of an incident;
- maintenance and security updates of the platform, applied continuously and included in the subscription.
Data is hosted in Europe. Data is never resold or used for advertising purposes. Further details appear in the legal notice.
6. Individuals' rights
In accordance with the GDPR, any data subject (legal guardian, adult student, team member) has rights over their data:
- right of access to their data;
- right to rectification of inaccurate or incomplete data;
- right to erasure ("right to be forgotten"), within the limits of legal retention obligations;
- right to restriction of processing;
- right to object on legitimate grounds;
- right to data portability.
These rights are exercised primarily with the teaching organisation, which manages the learner's record, and Nezam supports them in responding. Any request can also be sent to contact@nezam.fr; it will be forwarded to the relevant organisation. In the event of a disagreement, the data subject may lodge a complaint with the competent supervisory authority.
7. Protection of minors
Nezam's learners are, in most cases, underage students. The processing of their data relies on the legal guardian, who gives the necessary consents and authorisations (for example for photos or outings) and exercises rights on behalf of the child. Nezam collects and keeps these consents in the learner's record and only exposes the child's data to the legal guardian and the organisation's authorised members.
The mobile app for families gives the legal guardian read-only access to their child's schooling (attendance, grades, report cards, homework) and to messaging with the team, further strengthening their control over the information.
8. Data breach
In the event of a personal data breach, Nezam undertakes to inform the relevant customer organisation without undue delay, and to assist them with the steps provided for in Articles 33 and 34 of the GDPR.
9. Data protection & contact
For any question relating to the protection of your data, you can write to contact@nezam.fr or contact Nezam on WhatsApp at +33 6 84 86 52 73. Your request will be forwarded, where applicable, to the relevant teaching organisation.
10. Changes to this page
This page may be updated to reflect changes to the Service, to sub-processors or to the regulations. The applicable version is the one published on the date of consultation, the last update of which is indicated at the top of the document.