Privacy Policy

Effective date: 2 July 2026 · Last updated: 2 July 2026

Swan is a school-management application ("Swan", the "Service") that schools and educators use to manage learner records, behaviour and recognition tracking, and staff and parent communication. This policy explains what personal information we collect, why we collect it, how we protect it, and the rights you have over it.

This policy is written to comply with South Africa's Protection of Personal Information Act 4 of 2013 ("POPIA") and the Promotion of Access to Information Act 2 of 2000 ("PAIA"). Where a school or user is also subject to the EU or UK General Data Protection Regulation ("GDPR") or the United States Children's Online Privacy Protection Act ("COPPA"), the additional protections in this policy apply to them as well.

1. Who we are

The responsible party (the "controller" under GDPR) for personal information processed under this policy is:

Robert Dullaart, trading as Swan Schools — a sole proprietor (a natural person).
52 Mile End Road, Diep River, Cape Town, 7800, South Africa
Phone: +27 79 139 8201
Email: robert.dullaart@gmail.com

Information Officer. For a sole proprietorship the owner is the Information Officer by default. Robert Dullaart is our Information Officer for the purposes of POPIA and PAIA, and handles all privacy enquiries, data requests, and complaints at the contact details above.

2. The two roles Swan plays

Swan processes personal information in two distinct capacities, and your rights differ depending on which applies.

As responsible party (controller). For information about the people who hold Swan accounts — administrators, teachers, and other staff, and individual Teacher Pro and Parent Pro subscribers — we decide why and how that information is processed. This covers the account, billing, and usage data described below.

As operator (processor). For learner information and behaviour records that a school enters into Swan, the school is the responsible party and decides why and how that information is processed. We process it only on the school's documented instructions, as its operator under section 20 of POPIA. We do not use learner information for our own purposes. Where a school uses Swan, a written operator agreement is in place between the school and us, as section 21 of POPIA requires (and, where GDPR applies, a data-processing agreement meeting Article 28).

Why this split matters: if you are a parent or learner and want to access, correct, or delete learner information, your child's school is the first point of contact, because the school controls that information and holds the consents behind it. We will always help the school give effect to such a request.

3. Personal information we collect

Account data (we are responsible party): school or organisation name, administrator and staff names, email addresses, role, and the authentication identifiers created at registration.

Learner data (we are operator; the school is responsible party): learner names, class or year group, and behaviour, discipline, and recognition records entered by authorised school staff. Because this concerns children, it receives the heightened protection described in section 6.

Billing data (we are responsible party): the billing contact, plan and seat information, transaction references, and partial card information (such as card type and last four digits) needed to identify a payment. We do not store full card numbers — these are handled by our payment providers (section 8).

Communication data (we are operator or responsible party depending on context): messages sent between staff within Swan, and the content of parent-facing notifications where a school uses those features.

Usage and technical data (we are responsible party): log data such as IP address, device and browser type, and in-app actions, collected automatically to operate, secure, and improve the Service. See the cookies section (section 9) for how this is collected in the browser.

We collect information directly from the account holder, from the school's authorised staff, and automatically through use of the Service. We do not buy personal information about you from third parties.

4. Why we process personal information, and our lawful basis

We process personal information only for the purposes below. Under POPIA we rely on one or more of the justifications in section 11: performance of a contract with you; your consent, or the consent of a competent person where a child's information is involved; our legitimate interests or those of the school in running the Service; and compliance with a legal obligation. Under GDPR the equivalent bases are Article 6(1)(b), (a), (f), and (c).

We process personal information to:

We do not use learner information for advertising, profiling, automated decision-making with legal effect, or any purpose unrelated to school management. We do not sell personal information.

5. Google API services (optional)

Swan can, at a school's or user's choice, connect to Google services. A connection is made only when a user explicitly authorises it through Google's own consent screen, and only the specific services the school enables are connected.

When connected, we access Google data solely to perform an action the user explicitly requests within Swan — for example, reading Google Classroom course and roster data to synchronise class lists, or authenticating a user through their Google account.

We store only the OAuth token needed to maintain the connection. We do not retain the content of Google files, messages, or documents beyond what is needed to complete the specific action requested, and we do not use Google user data for advertising, for training AI or machine-learning models, or for any purpose unrelated to the feature the user is using.

Swan's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We request the narrowest scopes needed for the features a school actually uses; where a scope is one that Google classifies as sensitive or restricted, our use is confined to the school-management purposes described here.

You may disconnect a Google account at any time from within Swan or from your Google account's security settings. Disconnecting revokes our access and deletes the stored token.

6. Children's information

Learner records concern children — natural persons under 18 — and POPIA gives their information heightened protection. Under section 34 of POPIA, processing a child's personal information is prohibited unless one of the grounds in section 35 applies; the most common ground is the prior consent of a competent person (a parent, legal guardian, or other person legally entitled to consent on the child's behalf).

Swan processes learner information as the school's operator, on the school's instructions. The school is the responsible party and is responsible for establishing a lawful basis before learner information is entered into Swan — in practice, obtaining any competent-person (parental or guardian) consent required under section 35 of POPIA and, where applicable, under GDPR (including Article 8, which governs a child's consent to an online service) and COPPA (under which a school may, for a school-authorised educational purpose, consent on a parent's behalf). Our written operator agreement with each school records this allocation of responsibility. We do not ourselves obtain competent-person consent; we rely on the school having done so.

We support the school by: restricting learner information to the school's authorised staff; not using it for our own purposes; giving schools the means to review, correct, export, and delete learner information so they can honour a competent person's request; and not encouraging children to disclose more information than a school needs.

If you are a parent or guardian and have a concern about your child's information in Swan, please raise it with your child's school first, as the school controls that information. We will assist the school promptly.

7. When information leaves South Africa

Swan's infrastructure is provided by Google Cloud / Firebase, and personal information — including learner information — may be stored and processed on servers outside South Africa.

Section 72 of POPIA permits a cross-border transfer only on a recognised ground. Our primary ground is section 72(1)(a): our infrastructure providers are bound by a written data-processing agreement that provides a level of protection substantially similar to POPIA and restricts onward transfer. The transfer is also necessary to perform our contract with you and with the school (section 72(1)(c)). Where GDPR applies, transfers rely on an appropriate safeguard such as the European Commission's Standard Contractual Clauses. We remain accountable for personal information even after it leaves South Africa.

8. Who we share information with

We do not sell, rent, or trade personal information. We share it only as follows:

Infrastructure providers. Google Cloud / Firebase host our database, authentication, and application, and process personal information as our operator under their data-processing terms.

Payment providers. Payments made through our website are processed by Paystack. Payments made through the Apple App Store or Google Play are processed by Apple or Google. These providers handle card and payment data under their own security standards and privacy policies; we receive only the limited billing data described in section 3.

Communication delivery. Where a school uses parent-notification features, messages are delivered through the relevant messaging or email provider, solely to deliver the notification.

Legal and protective disclosures. We may disclose information where required by law, court order, or lawful request by a public authority, or where necessary to establish, exercise, or defend a legal claim, or to protect the rights or safety of a person.

Business transfer. If the Service is transferred to another operator, we will transfer information subject to this policy and give account holders reasonable notice.

No learner information is shared with advertisers or advertising-analytics companies.

9. Cookies and similar technologies

We use a small number of cookies and similar browser technologies, limited to what the Service needs to function and stay secure:

We do not use advertising cookies, and we do not allow third-party advertising networks to track you through Swan. You can block or delete cookies in your browser settings, but strictly necessary cookies must remain enabled for you to sign in and use the Service.

10. How long we keep information

We keep school and account data for as long as the account is active. When a school or individual account is closed, we delete or de-identify the associated personal information within 30 days, except where we are required to retain limited records (such as transaction records for tax or accounting purposes) for the period the law requires.

An authorised school administrator can delete individual learner records at any time from within Swan.

11. How we protect information

We meet the security duty in section 19 of POPIA: we encrypt personal information in transit (TLS) and at rest, restrict each school's data to that school's authorised users, apply role-based access controls, identify and review risks, and follow generally accepted information-security practices. We require our operators to maintain comparable safeguards. No system is perfectly secure, but we take appropriate, reasonable technical and organisational measures to protect your information.

If a security compromise occurs. Where we act as operator, we will notify the responsible party (the school) immediately, as section 21(2) requires. Where we are the responsible party, we will notify the affected data subjects and the Information Regulator as soon as reasonably possible after discovering the compromise, as section 22 requires. POPIA does not set a fixed hour deadline; we act without undue delay.

12. Your rights

POPIA gives every data subject the rights summarised in section 5. Subject to the role distinction in section 2, you have the right to:

To exercise a right over account, billing, or usage data, contact us using the details in section 15. To exercise a right over learner information, contact the relevant school, which controls that data; we will assist the school.

You also have the right of access to records under PAIA. Our PAIA manual explains how to make a request; it is available on request from the Information Officer. We do not charge for reasonable requests and aim to respond within a reasonable period, and in any event within any timeframe the law requires.

13. Complaints

If you believe we have not handled your personal information lawfully, please contact us first so we can try to resolve it. You also have the right to complain to the Information Regulator.

Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
POPIA complaints: POPIAComplaints@inforegulator.org.za
PAIA complaints: PAIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Phone: 010 023 5200 · Toll-free: 0800 017 160
Website: https://inforegulator.org.za

If you are in the EU or UK, you may complain to your local data-protection authority.

14. Business transfer

Covered in section 8.

15. Contact

For any privacy question, data request, PAIA request, or to report a concern:

Robert Dullaart, trading as Swan Schools
52 Mile End Road, Diep River, Cape Town, 7800, South Africa
Phone: +27 79 139 8201
Email: robert.dullaart@gmail.com

16. Changes to this policy

We may update this policy from time to time. If we make a material change, we will notify account holders by email or in-app notice before it takes effect. The "last updated" date above always reflects the current version.