This draft is not yet an effective legal notice. Prepared for SkyLight Tech Enterprise, South Carolina, USA. The full postal address, effective date, and remaining policy details must be confirmed before adoption.
Who this notice covers
SkyLight Tech Enterprise operates SkolarBase from South Carolina, USA. This draft describes information handled by the SkolarBase website, personal teacher workspaces, and school workspace features. It covers students, parents, teachers, administrators, and visitors.
You can contact SkyLight Tech Enterprise at +1 (803) 849-5555. Its full postal address remains to be confirmed before this becomes an effective notice. For school-directed processing, the school’s decisions and its agreement with the operator determine the parties’ responsibilities. The school may also provide its own privacy notice for education records.
Information used by SkolarBase
The information involved depends on the features you use and the permissions your school assigns.
| Category | Examples | Source |
|---|---|---|
| Identity and profile | Name, email, provider account identifier, email verification status, and profile image when supplied. | You and your sign-in provider. |
| Workspace access | School membership, assigned role, invitations, class enrollment, and parent-to-child links. | Your school and authorized workspace users. |
| Learning records | Classes, assignments, submitted answers, grades, and feedback. | Teachers, students, and authorized school staff. |
| School activity | Hall-pass requests, destinations, status and timestamps, behavior records, and audit events. | Students and authorized staff using those tools. |
| Browser and connection data | Session cookies, saved preferences, locally saved work, and technical request information handled by service providers. | Your browser and its interactions with the service. |
| Connected classroom data | Google Classroom courses, rosters, names, email addresses, and profile photos within approved permissions. | Google, when an authorized user connects an account. |
How information is used
The implemented workspace features use information to authenticate users, determine access, organize classes, deliver assignments, record submissions and feedback, and support school movement and behavior workflows. Audit records help track certain workspace actions.
Browser preferences support settings such as language, theme, and profile presentation. Connected classroom information supports the course and roster features an authorized teacher chooses to use.
The final notice must identify applicable legal bases for these uses, including where school instructions, contract, consent, legal obligations, or legitimate interests apply. This draft does not treat acceptance of terms as blanket consent to every use of personal information.
Who can access information
School workspace access is controlled by membership and role. Teachers access records for the classes they are assigned, students access records available to them, and linked parents access the relevant children’s records. Administrators manage school access and school records. Personal workspaces are separate from school workspaces.
These controls apply to supported server-held workspace records. A browser preference that changes profile presentation should not be assumed to change school record permissions.
Service providers process information needed for their functions. Any additional operator access, support access, legally required disclosures, or organizational transfers must be documented in the finalized notice and relevant agreements.
Sign-in and other providers
- Auth0 and identity providers: Auth0 manages the production sign-in flow. Google, Microsoft, or a school provider may supply identity information when you use that method. Passwords entered on SkolarBase’s sign-in form are sent directly to Auth0 for verification. Provider sign-in and account recovery use the applicable authentication provider.
- Supabase: Connected school workspace records are stored and accessed through the configured database service.
- Google Classroom: The optional connection requests course and roster access, including profile email addresses and photos. Review the permission screen before connecting.
- Translation and page resources: The website loads Google Translate resources. Requests to Google and other externally hosted page resources can disclose technical connection information, such as your IP address and browser information. Translation can involve sending page content to Google.
- Hosting: The hosting service receives website requests. The final notice must identify the active hosting provider, relevant logging practices, processing locations, and any applicable international-transfer safeguards.
Cookies and browser storage
Authentication uses cookies to maintain sessions and complete sign-in transactions. The browser also stores preferences such as theme, language, profile details, and some feature-specific work. Some settings or prototype features may be saved only on the device you are using.
Clearing cookies can sign you out. Clearing local storage can remove preferences and locally saved work. Neither action deletes school records from the server. On a shared device, follow your school’s approved procedure and avoid leaving student information in the browser.
A complete cookie inventory, provider retention periods, and any required consent controls must be verified for the deployed service. A displayed analytics preference alone should not be treated as a complete inventory of third-party processing.
Students and children
Student information requires particular care. Schools and families should understand which features collect information, who can see it, and how it is used before students are onboarded.
Where required, the operator must establish an appropriate parent or school authorization process before collecting children’s information. A user selecting a teacher role is not proof of school authorization. The applicable age thresholds, notice process, and consent records must be confirmed before student deployment.
Parents seeking access to or correction of school-held records should contact their school. These statements do not represent a certification of compliance with children’s privacy or education-record laws.
Retention and deletion
Session data, browser preferences, personal teaching work, and school records have different lifecycles. Signing out does not delete an account or its records. Revoking access to a school also does not automatically delete records associated with that membership.
The retention schedule for account data, learning records, activity records, logs, and backups must be confirmed with the operator and schools. This draft does not promise a deletion deadline or an automatic deletion feature that has not been implemented.
For school records, ask your administrator about the applicable retention requirements and request process. Disconnecting an external account stops access according to that provider’s controls but does not necessarily remove information already imported.
Your choices and requests
Depending on your location and the applicable law, you may have rights to request access, correction, deletion, restriction, portability, or to object to certain uses. Where processing relies on consent, you may have a right to withdraw it. Some records may need to be retained to meet legal or school obligations.
- For school-held information, begin with your school administrator and identify the record or request clearly.
- Manage connected-service permissions in the relevant provider’s account controls.
- Use your browser controls to manage cookies and locally stored information, understanding that this can remove locally saved work.
- Do not rely on a settings PDF export as a complete response to a formal request for all personal information.
For personal-account privacy questions, call SkyLight Tech Enterprise at +1 (803) 849-5555. The formal request-handling process must be confirmed before the final policy takes effect. Depending on your jurisdiction, you may also have a right to complain to the relevant data-protection authority.
Protecting your information
Implemented controls include authenticated access, email-verification checks for school workspaces, database policies that restrict record access, and role-based permissions. No online service can guarantee absolute security.
Protect your sign-in credentials, sign out of shared devices, and report unexpected school access to your administrator. Do not include passwords, verification codes, or unnecessary student information in an issue report. Operational security and incident-response commitments must be confirmed by the operator.
Changes and contact
This draft was prepared on the date shown above. The finalized policy should identify its effective date and how material changes will be communicated.
For help using the app, visit the Help Center. Your school administrator is the first contact for school records. For privacy questions, contact SkyLight Tech Enterprise, South Carolina, USA at +1 (803) 849-5555. Its full postal address remains to be confirmed before adoption.
Looking for practical guidance? Visit the Help Center.