Registration for classes and courses is now open. Explore courses & classes →

Legal

Data Protection Policy

This Data Protection Policy describes how CRAM EdTech organises the protection of personal data across our website, Learning Portal, and related education and technology services. It complements our Privacy Policy, which explains what we tell individuals about their information.

Effective date

This policy is effective from 15 September 2026.

For a plain-language explanation of what personal data we collect and your rights, see our Privacy Policy.

Purpose

CRAM EdTech processes personal data to deliver UAE-licensed education and technology services. This policy sets internal standards so that processing is lawful, fair, transparent, and secure under the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”), related regulations, and good international practice for families and clients outside the UAE.

Roles

Controller. CRAM EdTech determines the purposes and means of processing personal data for our website, tuition enrolment, and Learning Portal, unless a written agreement says otherwise for a specific project.

Processors. We use service providers (for example hosting, authentication, storage, email, and AI-assisted document or syllabus tools) that process personal data on our instructions. We select processors that offer appropriate security and contractual commitments for the services they provide.

Staff and contractors. People working with CRAM EdTech who handle personal data must follow this policy, use only the access they need, and report suspected incidents promptly.

Data protection principles

We apply these principles to personal data we control:

  • Lawfulness, fairness, and transparency — process data for clear purposes and inform individuals through the Privacy Policy and related notices
  • Purpose limitation — use data only for stated purposes or compatible ones (for example tuition delivery and fee verification)
  • Data minimisation — collect what is reasonably needed; allow skipped document uploads where the product permits, while noting incomplete verification status
  • Accuracy — encourage correct profile and document information; support correction requests
  • Storage limitation — keep data only as long as needed for the purpose or legal retention
  • Integrity and confidentiality — protect data with appropriate technical and organisational measures
  • Accountability — document our approach, limit access, and review processors and practices as the product evolves

Categories of personal data

In line with our Privacy Policy, we typically process:

  • Account and contact data (name, email, role, profile photo)
  • Education and portal activity (enrolments, classes, assignments, grades, attendance, syllabus progress)
  • Identity documents and related extracted fields used for UAE bank / tuition payment verification
  • Website enquiry, booking, and technical or analytics data where enabled

Sensitive and high-risk data

Government identity documents (Emirates ID / National ID images, passport images) and fields extracted from them are treated as high-risk / sensitive personal data. They are used only for payment verification, related compliance, and account setup checks — not for marketing and not shared with other students.

For students, the passport on file is the parent’s passport (fees usually come from the parent’s bank account). For teachers, documents must belong to the teacher. Automated reading (OCR) may capture document number and expiry to help admins manage verification; images remain in private storage.

Access control

  • Users can access their own profile and, where the product allows, their own uploaded identity documents
  • Authorised CRAM EdTech admins may view identity documents and extracted fields to verify payments and account setup
  • Teachers see education data needed to teach and grade their classes — not student identity document vaults, unless a future product change is clearly disclosed
  • Processor access is limited to what is required to host, store, authenticate, or process data on our behalf

Security measures

Measures appropriate to the risk include, where applicable: private storage buckets for identity documents; role-based access in the portal; encrypted connections (HTTPS); authentication via our identity provider; and operational limits on who inside CRAM EdTech can open sensitive files. We review controls as features change (for example new document workflows).

Retention and deletion

Retention follows the purpose of processing and applicable law. As a working standard:

  • Account and academic records are kept for the active relationship and a defined period afterward for continuity, disputes, and legal retention
  • Identity documents are kept while needed for fee verification and related checks, then deleted or access-restricted when no longer required
  • Website enquiry data is kept for a shorter follow-up window unless it becomes part of an enrolment or client file

Deletion or anonymisation requests are handled as described in the Privacy Policy, subject to legal exceptions.

Cross-border processing

Our operations are centred in the UAE. Infrastructure and tools may process data in other countries. We expect processors to provide appropriate security and contractual safeguards, and we limit transfers to what the service requires. International students and parents are covered by the same protection standards described here and in the Privacy Policy.

Personal data breaches

A personal data breach is a security incident that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. If we become aware of a breach affecting personal data we control, we will assess the risk, contain the incident, and notify affected individuals and/or the competent UAE authority where required by the PDPL and related rules, within applicable timelines.

Staff who suspect a breach or unauthorised access must report it immediately through internal channels so we can investigate.

Individual requests

Access, correction, erasure, restriction, objection, and consent withdrawal requests are handled according to the Privacy Policy. We verify the requester’s identity before releasing or changing personal data, especially where identity documents are involved.

Children

Because many students are minors, we design onboarding and payment verification with parental involvement (including parent passport for bank matching). Staff must treat children’s education and identity data with particular care and only for legitimate tuition and verification purposes.

Updates

We may update this Data Protection Policy as our services, processors, or legal obligations change. The current version is always published on this page with an updated effective date.

Contact

Questions about this policy or our data protection practices: use the contact options on our website, call +971 56 604 0293, or email info@lms.com.