Legal · Privacy
Privacy Policy
Effective 18 July 2026. Applies to the National Education Intelligence Platform (NEIP).
1. Scope & our approach
NEIP turns records that schools already keep into aggregated intelligence for accredited Nigerian government ministries and agencies. This policy covers data processed through the NEIP platform — the public site, the agency console, and the data-exchange pipeline that brings school data in.
Aggregate by default. NEIP is designed to answer questions about cohorts, schools, LGAs, wards and states — not about named children. Named-child fields are rejected by the ingestion pipeline itself, in code, not by policy alone. Where a limited operational identifier is unavoidable (for example, an officer's account, or a school's official registration code), it is processed under the safeguards below.
Not an official government service by default. NEIP is developed and operated by MirrorMingo for deployment by accredited Nigerian education authorities. It is not an official Federal Government of Nigeria service unless and until it is formally commissioned by a sponsoring ministry or agency.
2. Controller & processor identities
Under the Nigeria Data Protection Act 2023 (NDPA), the roles for each NEIP deployment are:
| Role | Who | What it means |
|---|---|---|
| Owner of the tenant & its data | The deploying government agency | Each NEIP deployment is a dedicated government instance. The agency owns the tenant, its configuration and all data held in it. |
| Data controller | The deploying government agency | The agency determines the purposes and means of processing for its jurisdiction's data and is the controller under the NDPA. |
| Data processor & software operator | MirrorMingo | MirrorMingo builds, maintains and operates the software and processes data only on the agency's documented instructions under a data-processing agreement. |
| Hosting | The agency's chosen environment | The tenant can run on Galaxy Backbone, an NITDA-accredited Nigerian data centre, the ministry's cloud, or MirrorMingo-managed hosting — the agency chooses, and in-country residency is supported. |
| Encryption keys & administrator access | Governed by the deployment agreement | For agency-hosted deployments the agency controls keys and top-level administrator access. For MirrorMingo-managed hosting, key custody and break-glass access are defined and logged in the agreement. |
In short: the deploying agency is the data controller of its jurisdiction's data, and MirrorMingo is the data processor and software operator, acting only on the agency's documented instructions under a data-processing agreement. A school that grants access is an independent controller of its own records for the purpose of that grant.
3. Categories of data processed
NEIP processes the following categories, and deliberately excludes identifiable learner records:
- Aggregated learning signals — mastery, attempt and completion measures summarised at class, school, LGA, ward and state level.
- School registry data — official registration and codes, census returns, enrolment counts, staffing counts, and facility data (from official registries such as NEMIS/D-NEMIS, or as submitted by the school).
- Curriculum & assessment metadata — topics, subjects and exam-cohort readiness bands (WAEC, NECO, JAMB, BECE, NCEE).
- Intervention records — the gap detected, the action approved, its cost estimate, and before/after measures.
- Officer account data — the name, official email, agency, role and jurisdiction of the authorised officer, plus authentication data (including two-factor).
- Audit & operational logs — grants, approvals, submissions and queries recorded against the officer who performed them, and technical logs needed to run the service securely.
Not processed: NEIP does not seek or store the names, contact details, biometric data or individual records of learners. If a school's export contains such fields, they are dropped at ingestion.
4. Lawful basis
Processing relies on the following NDPA bases, according to the data and the actor:
- Public interest / official authority — for a government agency's processing of aggregated education data to plan and improve public education in its jurisdiction.
- Consent — for a school (or its authorised software provider) granting NEIP access to that school's records, and for the officer account relationship.
- Legitimate interests / contract — for the account, security, audit-logging and service-operation data needed to provide NEIP to the agency, balanced against the rights of the individuals concerned.
The specific basis for a given dataset is fixed in the agency's data-sharing instrument before that data is used (see section 6).
5. School consent & revocation
Consent before data moves. No school's data enters NEIP without that school — or the software provider it has authorised — deliberately granting access with a one-time code. No passwords are shared, and the grant names what is shared and for what purpose.
Revocation at any time. A grant is revocable at any time by the school or its provider, from the same place it was granted. On revocation, NEIP stops ingesting new data from that source immediately, and data already held is handled under the retention terms in section 7 and the agency's agreement.
Schools are never enrolled without consent, and consent is never implied from silence.
6. Data-sharing agreements
Sensitive datasets stay held and unusable until the agency's data-sharing instrument (a data-sharing agreement and, where required, a data-processing agreement) is signed and in force. This gate is enforced in code, not just in policy: without the instrument recorded, the data does not flow into the intelligence layer.
Each instrument documents the purpose, the categories shared, the lawful basis, the retention position and the parties' obligations. MirrorMingo processes the data strictly within it.
7. Children's data
NEIP concerns school-age education, so protecting children is central to its design. The platform's answer is structural: it does not hold identifiable learner records at all, so there is no individual child profile to expose, sell or lose. Measures are aggregated to a level at which individual children are not identifiable, and small-cohort figures are suppressed or banded to prevent re-identification.
8. Retention
Each dataset carries a documented retention position, set in the agency's data-sharing instrument. As a default:
- Aggregated intelligence and intervention records are retained for the life of the deployment and any statutory education-records period the agency is subject to, so trends and before/after evidence remain available.
- Officer account data is retained while the account is active and for a limited period afterwards for audit and security.
- Audit logs are retained for the period the agency's governance and any applicable law require.
- On termination of a deployment, data is returned to the agency and/or deleted per the offboarding terms in the agreement.
9. Data residency & cross-border transfers
In-country hosting is supported for jurisdictions that mandate data residency. A tenant can run on Galaxy Backbone, an NITDA-accredited Nigerian data centre, or the ministry's preferred cloud, so data can stay within Nigeria where required.
Where an agency chooses a configuration that involves any processing outside Nigeria, that transfer is disclosed and takes place only under an NDPA-compliant transfer mechanism agreed with the agency. NEIP is not transferred abroad by default.
10. Subprocessors
MirrorMingo engages a limited set of subprocessors to run the service (for example, infrastructure hosting, and communications delivery for notifications). Every subprocessor is bound by written terms no less protective than this policy and the agency's agreement, and each is engaged only to the extent needed to operate NEIP.
The current list of subprocessors for a deployment, and their locations, is provided to the agency in or alongside the data-processing agreement, and the agency is notified of material changes so it can object. A current list is available on request at privacy@mirrormingo.com.
11. Security safeguards
- Encryption — data is encrypted in transit (TLS) and at rest.
- Access control — access is scoped to a jurisdiction on the server; a state officer cannot reach another state's data by any route. Officer accounts support two-factor authentication.
- Least privilege & audit — every grant, approval, submission and query is recorded against the officer who performed it, and administrator access is governed and logged per the deployment agreement.
- Data minimisation in depth — the ingestion pipeline rejects identifiable learner fields, so the most sensitive data is never collected in the first place.
- Separation — each government tenant is a dedicated instance with its own accounts, audit log and data plane, separate from any consumer product.
No system is perfectly secure, but the design goal is that a breach exposes aggregates and operational metadata, never a register of named children.
12. Data-subject rights
Individuals whose personal data NEIP processes — principally authorised officers — have the rights granted by the NDPA, including access, rectification, erasure, restriction, objection and portability, subject to the agency's obligations as controller and to lawful limits (for example, audit records that must be retained).
Because the agency is the controller, a request about a jurisdiction's data is directed to the agency, and MirrorMingo assists the agency in fulfilling it as processor. Requests can be started via the agency or by contacting us (section 15), and we route them appropriately.
13. Incident reporting
MirrorMingo maintains an incident-response process. On becoming aware of a personal-data breach affecting a deployment, MirrorMingo notifies the affected agency without undue delay and provides the information the agency needs to meet its own NDPA notification duties to the Nigeria Data Protection Commission (NDPC) and, where applicable, to affected individuals.
Suspected security issues can be reported to security@mirrormingo.com.
14. Changes to this policy
We may update this policy to reflect changes in the platform or the law. The effective date at the top of the page shows the current version (18 July 2026). Material changes affecting a deployment are communicated to the agency through its agreement's change process.
15. Contact & complaints
Privacy questions and data-subject requests: privacy@mirrormingo.com. Legal and data-sharing instruments: legal@mirrormingo.com. A correspondence address is available on request.
You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your data has been handled unlawfully.