1.Introduction
This Privacy Policy explains how Lanka Communication Services (Pvt) Ltd. (“LankaCom”, “we”, “our”, or “us”) handles personal data in connection with the Athena School Management System (“Athena Platform”), including associated web portals, mobile applications, APIs, communication modules, and white-label applications provided to educational institutions.
Athena School Management System is a Software-as-a-Service (SaaS) platform developed and operated by LankaCom for schools and educational institutions.
The platform may be accessed through:
- Athena administrator backend systems
- Tenant-specific portals and subdomains
- Student, parent, and staff portals
- Athena mobile applications
- White-label school mobile applications and portals
- Related websites and communication services
This Privacy Policy supports transparency obligations and applicable data protection requirements including the Personal Data Protection Act, No. 9 of 2022 of Sri Lanka (PDPA).
2.Definitions
- Athena Platform means the Athena School Management System including associated websites, portals, APIs, communication modules, mobile applications, and white-label implementations.
- Institution means the school, educational institution, organization, or tenant using Athena.
- User means any authorized administrator, staff member, student, parent, guardian, or other approved user.
- Personal Data means information relating to an identified or identifiable person as defined under applicable laws.
- Data Controller and Data Processor carry the meanings assigned under applicable data protection legislation.
3.Roles of LankaCom and Educational Institutions
In most implementations:
The educational institution determines:
- Information collected
- Modules enabled
- User permissions and access
- Records maintained
- Retention requirements
Accordingly, the institution generally acts as the Data Controller.
LankaCom generally acts as the Data Processor, processing information solely to provide and support the Athena Platform.
LankaCom may independently process limited operational information relating to:
- Platform administration
- Service support
- Billing and invoicing
- Audit and security monitoring
- Compliance obligations
- Tenant administration
4.Scope of this Policy
This Privacy Policy applies to:
- Athena School Management System
- Administrator portals
- Student / Parent / Staff portals
- Mobile applications
- White-label applications
- Communication services
- Support services
- Associated websites and domains
Example implementations may include school-branded applications and portals such as:
| Institution | White-label App |
|---|---|
| Wycherley International School | MyWycherley |
This schedule may be updated as new institutions are onboarded.
5.Information We Process
Information processed depends on modules enabled by each institution.
Student Information
- Admissions and enrolment records
- Student profiles
- Academic records
- Attendance records
- Timetables
- Examination records
- Discipline records
- Extracurricular activities
- Transport / hostel information
- Health notes entered by authorized users
Parent / Guardian Information
- Names
- Contact details
- Addresses
- Relationship information
- Emergency contacts
- Billing information
Staff Information
- Employee records
- Attendance and leave information
- Timetables
- Administrative records
Account Information
- Usernames
- Email addresses
- Mobile numbers
- Encrypted credentials
- Permissions and roles
- Login activity logs
Communication Data
- Notices
- Messages
- Notifications
- Uploaded files
- Images and documents
Billing Information
Where billing modules are enabled:
- Invoices
- Payment references
- Receipts
- Outstanding balances
Technical Information
- IP addresses
- Browser details
- Device information
- Operating system information
- Session records
- Application version information
- Crash reports
- Push notification identifiers
6.Purpose of Processing
Information is processed only for purposes connected with operating and supporting the service including:
- School administration
- Student management
- Admissions
- Examination administration
- Attendance management
- Timetable management
- Communication services
- Billing administration
- Authentication and access control
- Audit logging
- Technical support
- Security monitoring
- Backup and disaster recovery
- Service improvements
- Fraud prevention
- Legal and regulatory compliance
LankaCom does not use school data for unrelated advertising or third-party marketing.
7.Legal Basis of Processing
Processing may occur based on:
- Contractual obligations
- Legal obligations
- Legitimate operational interests
- Security and fraud prevention requirements
- Protection of vital interests
- Consent where applicable
- Other lawful bases permitted by applicable law
Institutions remain responsible for determining lawful grounds applicable to their implementation.
8.Mobile Applications and Device Permissions
Athena applications may request permissions including:
- Camera access
- File / photo access
- Push notifications
- Local storage
- Biometric authentication
Permissions are used solely for authorized platform functions including:
- Secure authentication
- Uploading documents
- Receiving notices
- Accessing authorized records
Users may manage permissions via device settings.
9.Children’s Information
Athena is designed for educational institutions and therefore processes information relating to minors.
Student information is processed solely for educational and administrative purposes determined by the institution.
LankaCom does not knowingly collect children's information for unrelated commercial purposes.
Parents or guardians seeking access, corrections, or actions relating to student records should contact the relevant institution.
11.Third-Party Providers and International Processing
Athena may use:
- Cloud infrastructure providers
- SMS gateways
- Email services
- Analytics platforms
- Notification services
- Backup systems
- Security monitoring tools
These services may operate inside or outside Sri Lanka.
Where international processing occurs, LankaCom takes reasonable contractual and organizational safeguards.
12.Security Measures
Security controls may include:
- Role-based access controls
- Tenant segregation
- Authentication controls
- Encrypted communications
- Audit logging
- Restricted administrative access
- Monitoring and vulnerability management
- Backup procedures
- Disaster recovery controls
Athena operates as a multi-tenant SaaS platform, and reasonable segregation controls are implemented between tenants.
No online platform can guarantee absolute security.
13.Security Incidents and Data Breaches
LankaCom maintains incident response procedures intended to:
- Detect incidents
- Investigate events
- Contain threats
- Mitigate impacts
Where legally required or contractually applicable, LankaCom may notify affected institutions of confirmed incidents.
Institutions remain responsible for:
- Endpoint protection
- Credential management
- User controls
- Internal security procedures
14.Retention and Data Export
Information is retained according to:
- Contractual obligations
- Operational requirements
- Legal obligations
- Audit requirements
- Backup cycles
Upon termination of services:
LankaCom may provide reasonable export or transition assistance subject to service agreements.
Backup retention and archival periods may continue for legal, operational, audit, or disaster recovery purposes.
15.User Rights and Privacy Requests
Subject to applicable law, individuals may request:
- Access to information
- Correction / rectification
- Restriction of processing
- Objection to processing
- Withdrawal of consent
- Deletion where legally permissible
- Copies of applicable records
Requests concerning school-managed records should first be directed to the relevant institution.
Users may also submit privacy requests to:
Email: privacy@athenaerp.lk
16.Account Deletion and Data Removal
Users wishing to delete accounts or request removal of information should contact the relevant institution first.
Where LankaCom directly administers operational accounts, requests may be submitted to:
Certain records may continue to be retained where required for:
- Legal obligations
- Contractual obligations
- Audit purposes
- Backup systems
- Security investigations
- Operational continuity
Removal of accounts may affect application functionality and service access.
17.AI and Automated Processing
LankaCom does not use student or institutional data processed through Athena for training unrelated public AI systems or unrelated commercial data-mining activities.
Limited aggregated or de-identified technical information may be used for:
- Reliability improvements
- Security monitoring
- Analytics
- Troubleshooting
- Platform enhancement
18.Confidentiality
LankaCom employees, contractors, and authorized service providers are subject to confidentiality and access control obligations where applicable.
20.Changes to this Policy
This Privacy Policy may be updated due to:
- Service changes
- New applications
- Regulatory updates
- Security changes
- Operational improvements
Updates may be published through websites, portals, applications, or notices.
Continued use after updates may constitute acknowledgment subject to applicable law.
21.Contact Information
Athena School Management System
Operated by Lanka Communication Services (Pvt) Ltd.
No. 65C, Srimath Anagarika Dharmapala Mawatha,
Colombo 07, Sri Lanka
Company Registration No: PV 7941