Privacy Policy.

Our platforms hold sensitive records — including children's academic and financial data. This policy sets out exactly what we collect, why, who else touches it, how long we keep it, and what you can require us to do with it. Written to comply with Ghana's Data Protection Act, 2012 (Act 843).

Effective 29 July 2026 Last updated 29 July 2026 Version 1.0

01Scope & our role

This policy applies to concepttolive.com and to every RunMy platform we operate, including RunMySchool and RunMyProgram. It covers personal data belonging to our customers, their staff, and the students, participants, parents and guardians whose records are held in our systems.

Two different roles

Which role we play changes what we may lawfully do with data, so it's worth being precise:

We are the controller
For data about our own business relationships — website visitors, enquiries, the staff contacts at customer organizations, and billing records. Here we decide why and how the data is processed.
We are the processor
For everything your organization puts into the platform — student records, staff records, fee data, academic results, participant data. Your organization is the controller of that data. We process it only on your instructions, to run the service for you.
What this means practically

If a parent asks us to delete their child's record, we won't act unilaterally — we refer them to the school, because the school decides. If your school instructs us to delete it, we do so. We don't make decisions about your records on our own initiative.

02What we collect

Data you give us directly

  • Enquiry data — name, organization, email address, phone number, organization size and the content of your message, when you request a quote or demo.
  • Account data — names, work email addresses, phone numbers and roles of the staff you register as users.
  • Billing data — your organization's registered name, billing address, contact person and transaction history. (Not card numbers — see section 5.)

Data your organization enters into the platform

This varies by product, but typically includes:

  • Student / participant records — name, date of birth, gender, admission or enrolment number, class or cohort, photograph, and where your organization records them, health notes and special-needs information.
  • Parent / guardian records — name, relationship, phone number, email address, occupation and address.
  • Staff records — name, contact details, role, subjects or responsibilities, and where applicable employment and payroll-adjacent details.
  • Academic records — attendance, assessment scores, grades, comments and report cards.
  • Financial records — fee structures, invoices raised, payments received, arrears and payment method used.

Data we collect automatically

  • Technical data — IP address, browser type, device type and operating system, for security and troubleshooting.
  • Usage and audit logs — which account performed which action and when. Records of access to student records are logged specifically so schools can audit them.

We do not collect biometric data, location tracking data, or data from third-party advertising networks.

03Why we process it

Under Act 843 we must have a lawful basis for each processing purpose. Ours are as follows:

Providing the platform
Performance of our contract with your organization. Without processing this data there is no service.
Responding to enquiries
Steps taken at your request before entering a contract.
Billing & collecting payment
Performance of contract, and compliance with legal and tax obligations in Ghana.
Support & troubleshooting
Performance of contract, and our legitimate interest in operating a working service.
Security, audit logging & fraud prevention
Our legitimate interest, and our obligation to protect personal data in our care.
Improving the platform
Our legitimate interest — carried out using aggregated, anonymised data that cannot identify any organization or individual.
Legal compliance
Where we are required to retain or disclose data by Ghanaian law or a valid court order.

We never sell personal data, and we never use it to train third-party AI models. Where our platforms include AI-assisted reporting features, those operate on your organization's own data to produce output for you, and that data is not fed back into any third party's general-purpose model training.

04Children's & student data

RunMySchool exists to hold records about minors. We treat that as the most sensitive responsibility we have, and apply stricter rules to it than to anything else in the platform.

Our commitments

  • No direct collection from children. We never collect data directly from a student. All student data reaches us through the school, which holds the relationship with the parent or guardian.
  • Consent is the school's responsibility, and its obligation. Your organization warrants that it has the necessary consent or other lawful basis under Act 843 to hold and share the student data it enters.
  • Strict access limits. A student's record is visible only to staff your school has explicitly authorised, and to the parent or guardian linked to that specific student. Role-based permissions are enforced at the data layer, not just hidden in the interface.
  • Every access is logged. Schools can audit who viewed or changed a student record and when.
  • No marketing, ever. Student and parent data is never used for our marketing, never shared with advertisers, and never disclosed to third parties for their own purposes.
  • No profiling or automated decisions. We do not run automated decision-making that produces legal or similarly significant effects on a student.
  • Deletion on instruction. When a school instructs us to delete a student's record, we delete it from live systems within 30 days and from backups as those age out.
For parents & guardians

If you want to see, correct or delete your child's record, contact your school directly — under Act 843 the school is the data controller and makes that decision. If your school raises it with us we will act on their instruction promptly. You may also write to privacy@concepttolive.com and we will help route the request, though we cannot act on it without the school.

05Payment information

Card and Mobile Money payments are processed by Paystack, a licensed payment service provider operating in Ghana and certified to PCI-DSS.

Concepttolive never receives, processes or stores your full card number, CVV, card PIN, or Mobile Money PIN. Those details are entered directly into Paystack's secure environment and never pass through our systems.

What we do receive and store from a transaction:

  • A transaction reference and status (successful, failed, reversed);
  • The amount, currency and date;
  • The payment method type used (for example "MTN Mobile Money" or "Visa card ending 4242");
  • The billing contact name and email associated with the payment.

That is what we need to issue receipts, reconcile accounts, process refunds and satisfy our tax record-keeping obligations. Paystack's own handling of your payment data is governed by its privacy policy.

06Cookies & analytics

This website

concepttolive.com sets no tracking cookies, no advertising pixels and no third-party analytics. It's a static marketing site. The only third-party request it makes is to Google Fonts to load two typefaces.

The platforms

RunMySchool and RunMyProgram use strictly necessary cookies only — a session cookie to keep you signed in, and a security token to protect against cross-site request forgery. These are essential to the service functioning and cannot be disabled without breaking sign-in.

We do not use cookies for behavioural advertising, cross-site tracking, or third-party profiling. If that ever changes we will ask for your consent first, and update this policy before doing so.

07Who we share with

We share personal data only with the small number of service providers required to operate the platform. Each is bound by contract to process data only on our instructions and to maintain appropriate security.

Cloud hosting provider
Hosts the application and database. Holds Customer Data at rest, encrypted.
Paystack
Payment processing for card and Mobile Money. Receives billing contact details and transaction data.
Email delivery provider
Sends transactional email — receipts, password resets, notifications. Receives recipient email address and message content.
SMS provider
Delivers SMS notifications to parents and staff where your organization enables them. Receives phone number and message content.
Professional advisers
Accountants and legal advisers, where genuinely necessary and under a duty of confidence.

We will also disclose data where

  • Required by Ghanaian law, a court order, or a lawful request from a competent authority — and where we are legally permitted to tell you, we will;
  • Necessary to protect the rights, safety or property of an individual, your organization or ours;
  • Our business is transferred to another entity — in which case your data moves under the same protections, and we will notify you in advance.

We do not share personal data with advertisers, data brokers, or AI model developers.

08International transfers

Some of our infrastructure providers operate data centres outside Ghana. Where personal data is transferred abroad, we ensure it is protected by contractual safeguards at least equivalent to the standard required by Act 843, and that the receiving provider is subject to a recognised data protection regime.

You may ask us at any time where your organization's data is currently hosted, and we will tell you.

09How long we keep it

Customer Data in the platform
For as long as your Subscription is active, plus 90 days after termination so you can retrieve it. Then deleted from live systems.
Encrypted backups
Aged out within a further 90 days after deletion from live systems.
Billing & transaction records
Retained for 6 years to meet Ghanaian tax and accounting record-keeping requirements.
Enquiry data (no contract formed)
Deleted within 24 months of last contact.
Security & audit logs
Retained for 12 months, then deleted.
Support correspondence
Retained for 24 months after the issue is closed.

You may instruct us in writing to delete your Customer Data earlier than the periods above, and we will do so — except where we are legally required to retain specific records, such as transaction data for tax purposes.

10How we secure it

  • Encryption in transit. All traffic to and from our platforms runs over HTTPS/TLS. Plain HTTP is redirected, never served.
  • Encryption at rest. Databases and backups are encrypted on disk.
  • Password handling. Passwords are hashed with a modern, salted algorithm. We cannot see or recover your password — we can only reset it.
  • Tenant separation. Every organization's data is separated so that no customer can access another's records, enforced at the data layer.
  • Role-based access control. Users see only what their role permits, with tighter restrictions on student records.
  • Restricted production access. Access to production systems is limited to personnel who need it, authenticated individually, and logged.
  • Daily encrypted backups stored separately from the live database, with restores tested periodically — an untested backup is not a backup.
  • Prompt patching of the platform and its dependencies when security updates are released.

No system is perfectly secure, and we won't claim otherwise. What we commit to is appropriate technical and organisational measures, honest disclosure if something goes wrong, and prompt remediation.

11Your rights

Under the Data Protection Act, 2012 (Act 843) you have the right to:

  • Be informed about how your personal data is used — this policy is part of meeting that.
  • Access the personal data we hold about you.
  • Correct data that is inaccurate or incomplete.
  • Delete data where there is no continuing lawful reason for us to hold it.
  • Object to processing carried out on the basis of legitimate interest.
  • Restrict processing while a dispute about accuracy or legitimacy is resolved.
  • Portability — receive your data in a structured, commonly used format.
  • Withdraw consent at any time, where processing relies on consent.
  • Complain to the Data Protection Commission of Ghana.

How to exercise them

Write to privacy@concepttolive.com. We respond within 30 days and do not charge a fee. We may need to verify your identity before acting, to make sure we're not disclosing someone's data to the wrong person.

Important: where the data concerned sits inside a customer's platform account — a student, parent or staff record — your organization is the controller and we will refer your request to them rather than acting on our own. See section 1.

12Data breach notification

If a personal data breach occurs that is likely to affect your organization or the individuals whose records you hold, we will:

  1. Notify the affected customer organizations without undue delay, and in any case within 72 hours of becoming aware of it;
  2. Tell you what happened, what data was involved, what we assess the likely consequences to be, and what we are doing about it — without waiting until the investigation is complete;
  3. Notify the Data Protection Commission where the law requires it;
  4. Support you in meeting your own notification obligations to affected individuals;
  5. Publish a post-incident summary of what we changed to prevent recurrence.

We will not conceal a breach or delay telling you in order to manage reputational risk.

13Marketing communications

We may send occasional product and service updates to the business contacts at customer organizations, and to people who have asked us about our products. These are infrequent and directly relevant to the service.

Every such message includes a one-click unsubscribe, and you can opt out at any time by replying or writing to hello@concepttolive.com. Opting out of marketing does not stop essential service messages such as invoices, security notices, or maintenance announcements.

We never market to students, parents or guardians through data held in a customer's account.

14Changes to this policy

We update this policy as our platforms and the law develop. Where a change materially affects how we handle personal data, we will notify customer organizations by email at least 30 days before it takes effect.

The "last updated" date at the top of this page always reflects the current version. Previous versions are available on request.

15Contact & complaints

For any question, request or concern about how we handle personal data:

Data protection contact
privacy@concepttolive.com
General enquiries
hello@concepttolive.com
Phone / WhatsApp
+233 50 918 8506
Post
Concepttolive, Spintex Road, Accra, Greater Accra Region, Ghana
Response time
Within 30 days, and usually within 3 business days

If you're not satisfied with our response

You have the right to complain to the supervisory authority in Ghana:

Data Protection Commission, Ghana
Website: dataprotection.org.gh

We'd rather you came to us first — most concerns are resolved with a conversation — but that route is always open to you.