Skip to content

Legal

Privacy Policy

Last updated: 14 August 2026

This Privacy Policy explains how 1410 Technologies ("we", "us", "our") handles personal data in connection with the 1410SMS platform ("Service"). It applies to information we process as the operator of the Service. For the school data a school uploads, the school is the data controller and we act as its processor under our Terms.

1. Information we process

  • Account and school data. School name, contact details, branding, and the administrator's name, email and phone number.
  • School records. Students, staff and parents, including names, contact details, classes, grades, attendance, fees and related records. This may include data about minors, entered by the school.
  • Staff location. Where a school uses staff attendance, a single location reading is taken at the moment a member of staff taps to clock in or out in the mobile app. Separately, an administrator setting the school's own pin may ask their browser or phone to read where they are standing. See section 3.
  • Staff devices. Where a school uses staff attendance, we keep a record of the phone each member of staff clocks in from. See section 3.
  • Usage and technical data. Audit records of actions taken in the Service, each including the IP address of the request and what it was made with: whether the mobile app or a web browser, which one, the operating system, and, for the app, the installed version.
  • Payment data. Billing is handled by our payment processor. We receive and store transaction references and status, never card details.

2. How we use it

  • to provide, secure, and improve the Service;
  • to send transactional messages (e.g. email verification, invoices, receipts, exam and fee notifications) and school communications you initiate;
  • to process subscriptions and payments;
  • to monitor, troubleshoot, and protect against abuse and fraud;
  • to comply with legal obligations.

3. Staff location and staff devices

A school may turn on staff attendance, which lets its staff clock in and out from the 1410SMS mobile app. Where it is used, three things follow: a location reading at each clock-in, a record of the phone it was made from, and a record of any attempt that was refused.

The clock-in reading

  • A reading is taken only when a member of staff taps the clock-in or clock-out button. Nothing is read at any other time.
  • The app never reads location in the background. It cannot: it does not hold the background location permission on either platform, and it is not able to read your location while it is closed or while you are using another app. This is a deliberate limit on what the feature can do, not a setting.
  • What is stored is the coordinates and accuracy of that single reading, how far it was from the school's recorded location, and the result of the checks that ran. It is kept as the evidence behind that attendance record, so a staff member can query a mark against what was actually recorded.
  • Who sees it. The staff member themselves, and administrators at their school holding the relevant permission. It is never shown to parents or students, it is not shared with any other school, and we do not use it for advertising or sell it.
  • Declining is possible. If location permission is refused, the app does not clock you in and says so. A school can still record attendance for you by hand.

A clock-in that was refused

When a check fails, no attendance is recorded: there is no clock-in, and nothing is added to that person's hours. The attempt itself is still kept, in the school's own event log, and it carries the same information the reading would have done: the coordinates, how accurate they were, and which checks passed and which did not.

It is kept because a school with its pin in the wrong place, or a radius set too tight, only ever finds out from the pattern of refusals. One person saying they could not clock in is a story about one person; the log is what shows it is happening at the same gate every morning.

Its retention is that of the school's event and audit history rather than that of an attendance record, since there is no attendance record for it to sit behind: it is kept while the school's account is active and is removed with the rest of that history when the account is deleted, as described in section 6.

Setting the school's own location

An administrator setting the school's pin can type coordinates, or press Use my current location and have the browser or phone read where they are standing. That is the one place the web app asks for location, it is asked only on that press, and it is asked of an administrator configuring the school rather than of anybody being checked.

What is saved from it is the school's pin and radius, not a record of where that administrator was: the reading fills in two fields on a form, and the accuracy figure is shown so a poor reading can be spotted and taken again. Declining leaves the coordinates to be typed in, and nothing else changes.

The phones staff clock in from

Where staff attendance is used, we keep a register of the devices each member of staff clocks in from. For each one we store an identifier the app generates for that installation, the platform (iOS or Android), the model, the operating system version, the app version, when it was last used to clock in, and its approval history: who approved or revoked it, and when.

This is what closes buddy-punching. A device belongs to one member of staff, and no two staff accounts at a school may hold the same approved device. Without that rule, location alone constrains the phone rather than the person, and one phone at the gate can clock in a whole department, every reading genuinely inside the radius and every check genuinely passing. The model and operating system are stored so that an administrator approving a device can tell it is the handset they were told about, which matters because reinstalling the app looks like a new device.

A revoked device's record is kept rather than deleted. It stops being able to clock anybody in, but the entry remains, because it is what tells a school which handset made the records already on somebody's timesheet, and what lets the same phone be recognised when it is passed to another member of staff.

Students and parents are never asked for location, on the web or in the app.

4. Service providers

We share data only with providers that help us run the Service, and only under appropriate safeguards. Those are our hosting provider, email delivery (SMTP), WhatsApp messaging (Meta), our payment processor (Paystack) and error-monitoring tooling (Sentry). They process data on our instructions and only as needed to provide their service.

5. Cookies & local storage

The Service uses essential browser storage (such as your login token) to keep you signed in and to operate core features. We do not use advertising cookies.

6. Data retention

We keep personal data for as long as a school's account is active and as needed to provide the Service. Generated documents (such as invoice and receipt PDFs) are transient and are deleted automatically after a short period. On account termination, we delete or anonymise data after a reasonable period, unless we must retain it to meet a legal obligation.

7. Security

We use technical and organisational measures to protect personal data, including encryption in transit, hashed passwords, tenant isolation, and access controls. No system is perfectly secure, but we work to protect your information and to respond promptly to incidents.

8. Children's data

The Service is used by schools to manage student records, which may include minors. Schools are responsible for obtaining any consent required by law before entering such data. We process it only on the school's behalf to provide the Service.

9. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict the use of your personal data. If your data is held by a school using 1410SMS, please contact that school (the data controller) first; we will support them in responding. You can also contact us using the details below.

10. Changes

We may update this Policy from time to time. Material changes will be notified through the Service or by email.

Still have questions?

We're happy to help, so reach us whichever way is easiest.