Legal documents
Privacy Policy | Educational Portal Escola Vereda
Last updated:
This Privacy Policy describes how Escola Vereda (“School”, “we”) processes the personal data collected through the Educational Portal app (“App”), available for web browsers and in its iOS and Android versions, and also accessible at portal.escolavereda.com.br. The App is intended for guardians (parents) and students, and is used in the context of the educational relationship between the family and the School.
We process personal data in compliance with Law No. 13,709/2018 (the Brazilian General Data Protection Law, LGPD).
1. Who is the data controller
The controller of the personal data processed in the App is Escola Vereda, the entity that maintains the Santo André and São Bernardo do Campo units. To exercise your rights or ask questions about this Policy, use the channels listed in the “How to contact us” section.
2. Data we collect
We collect only the data necessary to provide educational services and operate the App:
- Guardian identification and registration data: name, CPF, RG, e-mail, telephone/mobile, marital status, occupation, photo and access credentials (password).
- Student data: name and social name, date of birth, gender, CPF, enrollment number (RA), academic e-mail, telephone, photo, class and grade/year.
- Academic data: grades, report cards, absences and attendance, disciplinary records, essays and other pedagogical records.
- Student health data (sensitive data): blood type, allergies, continuous-use medication, illnesses, disabilities and ICD codes, history of surgeries and hospitalizations, vaccination schedule, dietary restrictions, health insurance information and authorizations. This data is provided by the guardian and used exclusively for the student’s safety and care.
- Financial and contractual data: installments, amounts, due dates, receipts, payment information via PIX/bank slip, and data from the educational services agreement.
- Contract signing data: when digitally signing documents, we record the date and time, IP address and device/browser information (user-agent), to ensure the validity and integrity of the signature.
- Usage and access data: records of login, logout, pages accessed and session identifier, for security, auditing and support.
- Location (only when you authorize it): in the student pick-up/release feature, the App may request your location to confirm that you are near the school unit at the moment of pick-up. Location is used only at that moment and is not used for continuous tracking.
- Documents and images you upload: when attaching files (for example, medical certificates, vaccination card, student photo), we process the images and files you choose to send.
3. Device permissions
In the iOS and Android versions, the App may request the following permissions, always with your consent and only when necessary:
- Location: used only in the student pick-up/release feature, to confirm proximity to the unit. It is requested at the moment of use and can be denied.
- Camera / photos / files: used to allow uploading photos and documents (for example, student photo, medical certificates). We only access the files you choose to send.
The App does not collect contacts, does not record audio and does not use the camera for continuous capture. You can revoke permissions at any time in your device settings.
4. How we use the data
We use personal data for the following purposes:
- Authenticate access and keep the account secure (login by e-mail or CPF and password; institutional login via Microsoft account for students; password recovery via a code sent by SMS or e-mail).
- Perform the educational services agreement and enable academic, financial and administrative follow-up by the family.
- Enable features such as report cards, attendance, disciplinary records, essays, meeting scheduling, enrollment and student pick-up release.
- Look after the student’s health and safety, based on the information provided by the guardian.
- Comply with legal and regulatory obligations and exercise rights in any proceedings.
5. Legal bases
Data processing is grounded in the LGPD hypotheses, as applicable: performance of a contract and preliminary procedures (art. 7, V); compliance with a legal or regulatory obligation (art. 7, II); regular exercise of rights (art. 7, VI); protection of health (art. 11, II, “f”, for sensitive health data); and consent (art. 7, I / art. 11, I), where applicable, such as in the use of location.
6. Data sharing
We do not sell your personal data. We share data only when necessary, with:
- Infrastructure and technology providers that host and operate our systems (Microsoft Azure cloud servers).
- Microsoft, for institutional student authentication (login with a Microsoft account).
- Technical support services, such as QR Code generation and IP address verification at the moment of contract signing.
- Public authorities, when required by law or court order.
7. Data of children and adolescents
The App processes student data, including that of children and adolescents, always in the best interest of the student and within the context of the educational relationship. Access to and provision of this data are carried out by legal guardians. We adopt additional safeguards in processing this data, in compliance with the LGPD.
8. Data retention and deletion
You may request, at any time, the termination of your access to the App (access account) through the channels listed below.
However, because this is a school relationship, certain data cannot be deleted upon request and will be retained for the applicable legal and contractual periods, even if your account is terminated. This includes, among others, the academic transcript and academic records, contractual and financial data, and documents required by law. The LGPD expressly provides for the retention of data for compliance with a legal or regulatory obligation and for the exercise of rights (art. 16). Once the retention period ends, the data is securely deleted or anonymized.
9. Your rights
Under the LGPD, you may request: confirmation of the existence of processing; access to the data; correction of incomplete or outdated data; anonymization, blocking or deletion of unnecessary data (subject to mandatory retention); portability; information about sharing; and withdrawal of consent. To exercise your rights, use the channels in the “How to contact us” section.
10. Information security
We adopt technical and organizational measures to protect your data, including access control through authentication, encrypted communication (HTTPS) and access audit logs. No system is entirely immune to incidents, but we work continuously to reduce risks.
11. Changes to this Policy
This Policy may be updated to reflect changes in the App or in legislation. The date of the last update is always shown at the top of this page. Relevant changes may be communicated through the School’s official channels.
12. How to contact us
To exercise your rights, request termination of access or clarify questions about this Policy and data processing, contact the office of your unit:
- Santo André unit: secretaria.sta@veredaeducacao.com
- São Bernardo do Campo unit: secretaria.sbc@veredaeducacao.com