SchoolOps by ChalkChest · Privacy policy
Privacy policy
How SchoolOps handles personal data, on the SchoolOps website and in the SchoolOps phone app.
In short
- Your school decides what goes into SchoolOps. We look after it for the school.
- School data is kept on servers in Singapore.
- No advertising, no selling of data, and no tracking across other apps or websites.
- Alerts sent to phones never carry a person’s name or a reason for leave.
- For anything about your own data, ask your school first. You can also email admin@mktr.sg.
Who we are
SchoolOps by ChalkChest is provided by MKTR PTE. LTD. (UEN 202507548M) in Singapore. ChalkChest is the education technology arm of MKTR. In this policy, “we” and “us” mean MKTR.
This policy covers SchoolOps: the SchoolOps website that each school signs in to at its own address, and the SchoolOps phone app. Visits to chalkchest.com are covered in their own section.
Your school decides
A school that uses SchoolOps decides what data goes into it and who in the school can see it. The school is responsible for that data.
We process the data on the school’s behalf and only on its instructions. Under Singapore’s Personal Data Protection Act 2012 (PDPA), this makes us a data intermediary for the school.
If you are a member of staff or a student, please contact your school first about your data.
What SchoolOps keeps
What SchoolOps keeps depends on the parts your school uses.
- Staff details: name, email address, role, staff code, department and appointment.
- Timetables: lessons, classes, subjects and rooms, each teacher’s workload limits, and the periods a teacher cannot teach or would prefer to teach.
- Leave: each leave request, its type and any reason given.
- Relief: relief duties, and the handover notes and files that go with them.
- Room bookings.
- Alerts shown in SchoolOps, such as a new relief duty or a change of room.
- Staff messages sent in the phone app, with any files attached, where your school uses them.
- Students, where your school adds them: each student’s name, the school’s own student reference, class, register number, teaching groups and timetable. There are no fields for NRIC or FIN numbers, contact details, attendance, results or pastoral notes.
- Sign-in records and an audit trail: who signed in or tried to, what they changed and when, and the network (IP) address used.
- On phones: a sign-in key for each phone, and a notification token so that alerts can reach that phone.
Why we use it
We use this data only to provide SchoolOps to your school:
- to build and show timetables, and to handle leave, relief, handovers and room bookings,
- to send the alerts and emails your school has switched on,
- to keep accounts and data secure, and to show the school who changed what,
- to help your school when it asks us for support.
We do not use it for anything else.
Who can see it
- Each person sees what their role allows. Your school’s SchoolOps administrator sets each person’s role.
- Leave reasons are seen only by the people who review leave, such as the relief coordinator and the school’s administrators. Other teachers do not see them.
- If your school switches on the daily absence email, it goes to the addresses your school chooses, and it includes the reasons.
- A teacher sees only the students they teach, and the class list for a lesson they cover, unless the school gives them wider access. A student sees only their own details and timetable.
- A staff message can be read only by the two people in the conversation. Nobody else at the school can read it.
- MKTR staff look at a school’s data only when needed to run SchoolOps, keep it secure, or help the school when it asks.
Where it is kept
SchoolOps keeps school data on servers in Singapore, on Amazon Web Services in its Singapore region. Files that staff upload are kept there too.
Where your school uses email, SchoolOps sends it through Amazon’s email service in Singapore. These emails are invitations to set a password and, if the school switches it on, the daily absence email.
Alerts to phones go through Apple’s and Google’s notification services, which are outside Singapore. So an alert carries only short wording, such as a date, a period, a class and a room. It never carries a person’s name or a reason for leave. An alert about a new message only says that there is one. You open SchoolOps to see the rest.
What we do not do
- We do not show advertising.
- We do not sell personal data, or share it with anyone for their own use.
- We do not track you across other apps or websites.
- The SchoolOps website and phone app contain no analytics, advertising or crash reporting services.
- The phone app does not ask for your location, contacts, camera or photos. It only opens the files you choose.
How we protect it
- Connections to SchoolOps are encrypted (HTTPS).
- Passwords are stored as salted hashes, never as the password itself.
- Each person can do only what their role allows.
- After several wrong passwords in a row, the account is locked for a while.
- Passwords must be changed every 90 days.
- A sign-in on the website ends after 30 minutes without use.
- The phone app keeps its sign-in key in the phone’s secure storage, and the server stores only a hashed copy of it. When you come back to the app after five minutes or more, it checks that it is you before it shows anything.
- An audit trail records who changed what, and when.
How long we keep it
We keep a school’s data for as long as the school uses SchoolOps. When the school’s contract ends, or earlier if the school asks, we delete it.
To have your data corrected or deleted, ask your school’s SchoolOps administrator. The school can change or remove it in SchoolOps, or ask us to. If you write to us instead, we will pass your request to your school.
Signing out of the phone app removes that account from the phone, with its sign-in key and any files it downloaded.
Children
Students’ accounts are created by their school. We do not collect data from children directly. The phone app is for school staff, and students cannot sign in to it.
Visits to chalkchest.com
This part is about the ChalkChest website itself, not SchoolOps.
When you open a page on chalkchest.com, the website records your visit: the pages you open, how long you stay, how far you scroll, what you click or copy, the page or link that brought you here, and your device and browser details, such as screen size and language. It also records your network (IP) address, the rough location that address points to, and the organisation it is registered to, which it looks up in the public internet registry. A random number kept in your browser tells your visits apart.
We use these records to see how the website is used and who opens the links we send. Only MKTR can see them. We keep them for 13 months, then delete them. The website uses no outside analytics or advertising services. It runs on Vercel’s hosting service, and its records may be kept outside Singapore.
Changes to this policy
If we change this policy, we will put the new version on this page with its new date.
Contact
- Staff and students: please ask your school first.
- Schools, and anyone with a question about this policy: email admin@mktr.sg.
- By post: MKTR PTE. LTD., 18 Circular Road, Singapore 049374.
For help with using SchoolOps, see SchoolOps support.