Security
How we protect your data
Last updated: 10 October 2026
This page says, in plain words, how The Maktab App protects the information a Maktab trusts it with. It describes what is in place today. We do not claim certifications we do not hold.
What we protect, and our role
The Maktab App holds the records a Maktab keeps about its students, their families and its staff, including records about children. For that information your Maktab is the data controller and we are its processor. We act on your instructions and for no other purpose. Our Data Processing Agreement sets this out.
Where your data is kept
The database is in the United Kingdom, in London. Some supporting services process data outside the UK. The sub-processor list names each one and says where it works.
Encryption
Your data is encrypted in transit, between your device and our servers, and at rest, where it is stored.
Who can see what
Access is by role. A teacher, an office user and an owner each see what their role allows, and the owner decides who gets which role.
Each Maktab's data is kept apart from every other Maktab's. The separation is enforced in the database itself, not only in the application.
Access to your data by our own people is limited to those who need it to run and support the platform, and it is logged. Production secrets can be reached by our director or directors only.
Passwords and connected accounts
If your Maktab connects its own email account, so that emails to parents come from its own address, the password you give us is encrypted with AES-256. The key is kept separately from the database and can be replaced. The password is never displayed or logged, and it is only used to send the emails you write. We delete it when you disconnect the account. Only the staff you choose can connect or disconnect the account.
We recommend an app password from your email provider, and a mailbox that is used only for sending these emails.
Backups
We take care of backups for you. When a subscription ends, your data stays exportable for 30 days and is then deleted from our live systems. Backups are deleted on their normal cycle rather than opened up and edited, and data in a backup is not used for anything.
If something goes wrong
If a personal data breach affects your data, we tell you within 24 hours of confirming it. That is tighter than the 72 hours the law allows.
If an email password, or the key that protects it, may have been exposed, we also stop sending, replace the key and require you to reconnect. The details are in the Data Processing Agreement.
Reporting a vulnerability
If you think you have found a weakness in The Maktab App, please send us a message and say that it is a security report. Please keep the details to yourself until we have had a chance to fix it, and please do not look at anyone else's data.
More detail
We do not publish the detail of our security architecture, and we would not expect a supplier of ours to either. If you need assurance beyond this page, ask and we will arrange it under a confidentiality agreement.
See also our sub-processor list, our Data Processing Agreement and our privacy notice.