CampusOS

Draft — pending legal review. This policy describes how CampusOS is designed to handle data during the pilot phase. It has not yet been reviewed by counsel and should not be relied on as a final legal document. Contact us at hello@campusos.ink with questions.

1. Who this applies to

CampusOS is a workspace that private universities in Nigeria use to run academic coordination — structure, users, courses, timetables, attendance, announcements and related records. This policy covers the data CampusOS itself processes to provide that workspace to a subscribing university (a “tenant”) and its staff, lecturers and students.

CampusOS is being designed around privacy-by-design principles and controls intended to support universities' obligations under the Nigeria Data Protection Act 2023and applicable guidance from the Nigeria Data Protection Commission. We don't claim CampusOS is fully compliant with that Act — that status depends on a qualified legal and privacy review this policy hasn't yet had (see the notice above).

2. What we collect

Depending on your role, CampusOS may process:

  • Institutional identity — name, institutional email address, role, department, and identifiers such as a matriculation or staff number.
  • Academic records — enrolments, courses, timetable assignments, and results your university chooses to record.
  • Attendance records — time-stamped attendance entries tied to a course session.
  • Account activity — sign-in timestamps, and an audit trail of administrative actions taken within the workspace.
  • Communications — announcements, materials and messages sent through the platform.

CampusOS does not process payment card data directly — pilot and licence fees are agreed and settled outside the platform.

3. Who controls this data

Your university is the data controller for the institutional data in its workspace — it decides who gets access, what gets recorded, and how long it's kept. CampusOS acts as a data processor, handling that data only as instructed by the university and only to operate the service.

4. How access is restricted

Access within a workspace is role-based — a lecturer sees their own courses, a student sees their own record, and university leadership sees what their configured role permits. CampusOS staff do not access a university's data except to provide support the university has requested, or where necessary to maintain the security of the service.

5. Data retention and deletion

Data is retained for as long as your university's workspace is active. If a university ends its agreement with CampusOS, it can request export or deletion of its institutional data, subject to any legal retention obligations that apply to academic records.

6. Your rights

If you're a student, lecturer or staff member and want to access, correct, or request deletion of your data, the first step is to contact your university's administrator — they control your record. How we approach these requests is informed by the Nigeria Data Protection Act 2023 and applicable guidance from the Nigeria Data Protection Commission.

7. Changes to this policy

As CampusOS moves from pilot to general availability, this policy will be revised and formally reviewed. We'll note material changes here.