We take the privacy of your institution and its students seriously. This policy explains exactly what we collect, how we use it, and how we protect it.
School Desk ERP · BS Learning · Effective: June 1, 2025
This Privacy Policy describes how BS Learning ("we," "us," or "our"), operator of School Desk ERP, collects, uses, stores, and protects information when you use our platform at bslearning.com/schooldesk/ and related services.
School Desk ERP is a multi-tenant SaaS platform serving educational institutions across Pakistan. This policy applies to all subscribers (institutions), their designated users (administrators, teachers, parents, accountants), and visitors to our public-facing pages.
Our Core Commitment: We do not sell, rent, or monetize your institution's data. All data is encrypted at rest, isolated per institution, and used solely to deliver the School Desk ERP service.
We collect data in two categories: information you provide directly, and information generated automatically through your use of the platform.
2.1 — Information You Provide
| Category | Examples | Source |
|---|---|---|
| Institution Identity | Institution name, subscription plan | Registration form |
| Contact Information | Email address, WhatsApp / phone number | Registration & contact form |
| Account Credentials | Username (plain), password (bcrypt hash) | Account setup by administrator |
| Payment Information | Transaction ID (from SadaPay / NayaPay) | Renewal / registration request |
| Academic Data | Student names, class lists, attendance records, timetables, exam seating, course files | Entered by admin / teachers inside the platform |
| Staff Data | Teacher names, subject assignments, session records | Entered by admin inside the platform |
| Parent Data | Parent contact information linked to student profiles | Entered by admin inside the platform |
| Contact Enquiries | Name, email, institution, message text | Contact form (contact.php) |
2.2 — Automatically Collected Information
We do not use tracking pixels, behavioural advertising cookies, or third-party analytics scripts (e.g., Google Analytics) on the core platform pages.
We use the information we collect for the following specific purposes only:
We do not use your data for advertising, profiling, or any commercial purpose unrelated to the delivery of School Desk ERP.
All Institution Data is stored on servers hosted under the bslearning.com domain. We implement the following technical and organizational measures to protect your data:
insData/). Directory listing is disabled and direct web access is blocked via .htaccess rules.password_hash() function (bcrypt algorithm). Plaintext passwords are never stored.Multi-Tenant Isolation: Institution tokens are randomly generated cryptographic identifiers. One institution cannot access, read, or modify another institution's data under any circumstance through the platform's API.
While we implement industry-standard security measures, no system is completely immune to all threats. We encourage you to use strong passwords and report any suspected security issues to us immediately.
We do not sell, rent, trade, or otherwise share your Institution Data with any third parties for commercial purposes.
We may disclose information only in the following limited circumstances:
Email notifications sent by the platform (account creation, renewal, etc.) are delivered via PHP mail() through our server's mail transfer agent. No third-party email marketing services (e.g., Mailchimp, SendGrid) are used.
School Desk ERP uses the following cookie and session mechanisms:
PHPSESSID): A strictly necessary, first-party session cookie used to maintain your authenticated state on the platform. This cookie expires when you close your browser or log out. It contains only a random session identifier; no personal information is stored in the cookie itself.login.html configurator page uses the browser's localStorage to save your institution's Unique Login URL for convenience on future visits. This data remains on your device and is not transmitted to our servers. You can clear it by clearing your browser's local storage.We do not use advertising cookies, third-party tracking cookies, or persistent profiling cookies of any kind.
By using School Desk ERP, you consent to the use of the strictly necessary session cookie described above. This cookie is required for the platform to function and cannot be disabled while using the service.
School Desk ERP is operated as a data processor on behalf of your institution. When you enter student records, attendance data, staff information, or parent contact details into the platform, your institution acts as the data controller for that information.
As the data controller, your institution is responsible for:
We process student and staff data only as instructed by your institution's configuration of the platform, and only for the purpose of providing the School Desk ERP service. We do not access, analyse, or use student or staff data for any purpose other than service delivery.
We retain Institution Data for as long as your subscription is active. The following retention rules apply:
Before Deletion: Please export all necessary data (PDF attendance reports, timetables, etc.) before your account is deleted. Deleted data cannot be recovered under any circumstances.
As a subscriber and data controller for your Institution Data, you have the following rights with respect to the information we hold about your institution:
To exercise any of these rights, please contact us using the details in Section 13. We will respond within 5 business days.
School Desk ERP integrates with or references the following limited third-party services:
No third-party advertising networks, analytics platforms, social media trackers, or CRM tools are integrated into School Desk ERP.
School Desk ERP is designed for use by educational institutions and is not directed at children as end users. The platform's direct users are adults — institutional administrators, teachers, parents, and accountants.
Student data (including names and attendance records) entered into the platform by institutional administrators is processed solely under the authority and responsibility of the subscribing institution, which is the data controller for that information.
Subscribing institutions that enter data relating to minor students are responsible for ensuring compliance with applicable child data protection requirements under Pakistani law and any internal policies of their institution.
We do not knowingly collect personal information directly from children through our registration or public-facing forms. If you believe such data has been submitted, contact us immediately for removal.
We may update this Privacy Policy periodically to reflect changes in our data practices, legal requirements, or platform features. When material changes are made, we will:
We encourage you to review this policy periodically. Your continued use of School Desk ERP after a policy update constitutes your acceptance of the revised terms.
If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact us:
Also see our Terms of Service for the full legal agreement governing your use of School Desk ERP.