Privacy Policy — The English School (TES)
Effective Date: October 12, 2025
Application Covered: The English School (TES) Mobile Application (“App”)
Organization: The English School (TES), Kuwait
Address: PO Box 379 – Safat, 13004 Kuwait
Email: accounts@tes.edu.kw
Telephone: +965 22271385
Quick Summary (TL;DR)
- We collect parent/guardian account details, student billing identifiers, and payment transaction information.
- Payment card/bank details are processed securely through our payment provider(s). We do not store full card numbers.
- We use personal information to display invoices, process payments, send receipts/reminders, prevent fraud, and secure the App.
- We do not sell personal data and we do not use it for behavioral advertising.
- You may request access, correction, or deletion of your data by contacting: accounts@tes.edu.kw
1. Scope
This Privacy Policy explains how The English School (“TES”, “we”, “us”, “our”) collects, uses, and protects personal information when you use the App to:
- view outstanding balances,
- review invoices and statements,
- make tuition and fee payments, and
- manage your account.
This Policy does not apply to other TES websites, portals, or systems that may have separate privacy notices.
2. Personal Data We Collect
We may collect the following categories of personal information:
A. Parent/Guardian Account Information
- Full name
- Email address
- Phone number
- Billing/postal address
- Relationship to student(s)
- Linked student selection
- Login credentials (stored securely in hashed/encrypted form)
- Account role and permissions
B. Student Billing Identifiers
- Student name
- School ID / registration number
- Class/year and campus
- Tuition ledger/account reference numbers
Important Note:
This App is designed for parents/guardians and authorized payers. Students are not requested to create App accounts.
C. Payment and Transaction Information
- Invoice and statement details
- Payment amounts, currency, and timestamps
- Payment status, refunds, and chargebacks
- Payment method token, last 4 digits, card brand, and expiry (tokenized)
- IP address and payer country (for fraud/security checks)
Payment processing is performed by our authorized provider(s), such as:
[Insert payment provider name(s) e.g., KNET gateway / local bank / Stripe / Adyen]
These providers are responsible for secure processing and PCI DSS compliance.
D. Device and App Usage Data
- Device type, operating system, and App version
- Language settings
- Crash logs and performance metrics
- IP address and coarse location (derived from IP)
- App activity (example: “invoice viewed”, “payment initiated”)
- Push notification token (if enabled)
E. Support and Communications
- Messages you send to TES
- Call notes and customer service records
- Attachments (such as proof of payment)
- Survey responses and feedback (if provided)
Sources of Data
We may collect personal data:
- directly from you,
- from TES billing/student systems,
- automatically through your device, and
- from payment and anti-fraud service providers.
3. Why We Use Your Data (Purposes and Legal Bases)
We use personal data only where permitted under applicable law and for legitimate educational and administrative purposes.
A. Providing the App and Payment Services
We use data to:
- create and manage accounts,
- display invoices and balances,
- process payments,
- send receipts, reminders, and statements, and
- provide customer support.
Legal Basis: Contract performance and legitimate interests.
Where required: compliance with financial/tax regulations.
B. Security and Fraud Prevention
We use data to:
- detect and prevent fraud or misuse,
- secure accounts and school systems, and
- investigate suspicious activity.
Legal Basis: Legitimate interests and legal obligations.
C. Improving the App
We use limited technical information for:
- debugging and troubleshooting,
- improving performance, and
- analyzing service reliability.
Legal Basis: Legitimate interests (and consent where required).
D. Communications
We may send:
- essential service notices (payment confirmation, due dates, policy updates), and
- optional notifications based on your settings.
Legal Basis: Contract, legitimate interests, and consent where required.
E. Compliance
We may retain and process data for:
- accounting, audits, and tax compliance,
- legal reporting requirements.
Legal Basis: Legal obligation.
If any processing is based on consent, you may withdraw consent at any time via App/device settings.
4. How We Share Information
We may share personal information only as needed for operations and compliance.
We may share data with:
- Payment providers and banks for processing transactions, refunds, and fraud prevention
- Technology service providers (hosting, storage, authentication, analytics tools)
- School finance and billing systems for reconciliation and payment posting
- Professional advisers and auditors for compliance purposes
- Government authorities or law enforcement when legally required
- Business successors in the event of restructuring, merger, or transfer
We do not sell personal data.
We also do not share data for cross-context behavioral advertising.
5. International Data Transfers
If personal data is transferred outside Kuwait (for example to the UK, EEA, US, or other regions where vendors operate), we ensure appropriate safeguards such as:
- Standard Contractual Clauses (SCCs)
- UK Addendum (where applicable)
- Vendor compliance reviews and due diligence
You may request additional transfer information by contacting us.
6. Data Retention
We retain personal information only as long as needed.
- Account data: While active, then up to [X years] after closure
- Payment/transaction records: At least 7 years, or longer if required by law
- System logs and diagnostics: Typically 90–365 days, unless required for security investigations
Once data is no longer needed, we delete or anonymize it securely.
7. Security Measures
TES applies reasonable administrative, technical, and physical safeguards, including:
- encryption in transit,
- role-based access controls,
- least-privilege permissions,
- secure development practices,
- monitoring and threat detection, and
- vendor security assessments.
No system can be guaranteed 100% secure. Please protect your device credentials and notify us immediately if you suspect unauthorized access.
8. Your Rights and Choices
A. In-App and Device Controls
You may:
- update account details,
- manage notifications through device settings, and
- manage payment methods through the payment provider’s secure interface.
B. Privacy Rights
Depending on applicable law, you may request:
- access to your personal data,
- correction of inaccurate data,
- deletion of data,
- portability of your information, or
- restriction/objection to certain processing.
How to Submit a Privacy Request
Please email: accounts@tes.edu.kw
Subject line: Privacy Request
We may request verification of identity and authority (especially for student-related information).
9. Children and Student Information
The App is intended for parents/guardians and authorized payers only.
We do not knowingly allow children under the age of 13 (or the applicable local minimum age) to create App accounts.
Student information displayed in the App is limited to billing-related identifiers necessary for tuition administration.
10. Cookies, SDKs, and Similar Mobile Technologies
The App may use SDKs and platform identifiers for:
- authentication
- crash reporting
- performance monitoring
- limited analytics (aggregated)
You may restrict tracking through your device settings.
We do not use advertising SDKs for cross-app behavioral advertising.
11. Third-Party Services and Links
The App may link to third-party services or present payment pages operated by external payment providers. These services operate under their own privacy policies and terms.
TES is not responsible for third-party privacy practices.
12. Automated Decision-Making
TES does not use automated decision-making that produces legal or similarly significant effects without human involvement.
13. Updates to This Policy
TES may update this Privacy Policy from time to time. Updates will be published within the App and on our official channels.
The “Effective Date” will be revised accordingly.
Material changes may also be communicated through email or in-App notifications.
14. Contact Information
The English School (TES)
The English School, Kuwait
PO Box 379 – Safat, 13004 Kuwait
Email: accounts@tes.edu.kw
Phone: +965 22271385
US Notice at Collection (For US Residents Only)
This section applies only if you are a resident of a US state with applicable privacy laws.
Categories of Personal Data Collected
- Identifiers
- Customer records
- Commercial/payment information
- Internet/app usage data
- Education-related billing identifiers
- Sensitive information (account credentials, tokenized payment data)
Purposes
- provide and secure the App
- process payments
- customer support
- limited analytics
- compliance with legal requirements
Sharing/Disclosure
Service providers such as payment processors, hosting providers, support vendors, auditors, and regulators.
Selling/Sharing
TES does not sell personal information and does not share it for behavioral advertising.
Retention
See Section 6 above.
Rights
See Section 8 above.
GDPR / UK Addendum (For EEA and UK Residents Only)
If you are located in the EEA or UK, the following applies:
- Controller: The English School (TES), Kuwait
- Legal Bases:
- Contract (Art. 6(1)(b))
- Legal obligation (Art. 6(1)(c))
- Legitimate interests (Art. 6(1)(f))
- Consent (Art. 6(1)(a)) where applicable
- Recipients: Payment processors, hosting vendors, support vendors, auditors, regulators
- Transfers: SCCs and UK Addendum where applicable
- Rights: Access, rectification, erasure, restriction, portability, objection, and complaint to a supervisory authority
Developer & Vendor Listing (Complete Before Publishing)
Please ensure the following is completed before going live:
- Payment processor(s): [Insert name(s) + privacy policy link]
- Hosting/Cloud provider: [AWS/Azure/GCP + region]
- Crash/Analytics SDKs: [Firebase Crashlytics/Analytics, etc.]
- Support/CRM tools: [Insert tools]
- SIS/Finance integrations: [Insert systems]
Governing Law
This Privacy Policy and any dispute arising from it shall be governed by the laws of the State of Kuwait, without regard to conflict-of-laws principles.