1. Who we are and what this notice covers
eSlate is a product of Hinet Technologies Limited, Nigeria (“Hinet”, “we”, “us” or “our”). This notice describes personal information handled through the eSlate website, QuizDesk assessment service, and any mobile, desktop or API client expressly covered by this notice. “You” includes visitors, test creators, school administrators and participants.
SchoolDesk is currently described as a forthcoming service. Advertising a planned feature does not mean that we already collect the admissions, attendance, fee or other records associated with it. Additional notices and institution agreements must be provided before those activities begin.
2. Our role and your school’s role
Hinet determines the purposes of processing needed to operate accounts, protect the platform, maintain its billing records and respond to support or legal requests. For those activities Hinet generally acts as a data controller. For assessment records handled on an institution’s documented instructions, Hinet may act as a processor and the institution may be the controller. Roles depend on the actual arrangement, not merely the label “school” or “administrator”.
A school or independent creator decides which questions to ask, whom to invite, the test schedule, marking keys and how results are used. Ask that organisation for its own privacy notice and assessment rules. Where we process records on its behalf, we may refer an access, correction or deletion request to it and assist as required. School instructions do not authorise unlawful processing. Written processing agreements should specify instructions, security, authorised personnel, retention and assistance with rights requests.
3. Information collected and its sources
- Account information: name, email address and/or phone number, account role, password hash, registration time and any contact-verification status. Passwords are hashed; the application is not designed to store a readable password.
- Organisation information: school names and codes, school membership, subjects, banks, creator identities and administrative actions. A school or creator may supply information about your participation.
- Assessment information: questions and options, marking keys, points, test instructions, visibility, invitations, join requests, approvals, schedules, session identifiers, start and completion times, submitted answers, scores and pass/fail results.
- Billing information: wallet balance, credit/debit ledger, payment reference, amount, currency, payer email, payment status and provider transaction identifier. Payment details entered into Paystack checkout are handled by Paystack; our application does not ask you to submit a card PIN, CVV or full card number to our own API.
- AI explanation information: the requested question, its options and answer key, the resulting explanation, the requesting account and attempt references, charge and request identifier.
- Technical and support information: requests to the service, IP-related security counters, server error records, browser storage described below, and information you choose to provide in support correspondence. Hosting and delivery providers may also receive network and device metadata.
Do not include health records, identity documents, biometric information or other sensitive personal information in question text or uploads unless an expressly supported workflow and a lawful basis have been agreed. Free-text questions can themselves contain personal information even when the platform does not request it.
4. Purposes and lawful bases
We must identify a lawful basis for each purpose under applicable data-protection law. The proposed allocation below is subject to confirmation against the service contracts and actual processing arrangements:
- Account access and requested services: steps requested before a contract and performance of a contract with the account holder, where that basis properly applies.
- Institution-directed assessments: the institution’s documented lawful basis and instructions. An institution’s contract with Hinet does not, by itself, establish a contract basis for every participant’s data.
- Fraud prevention, access controls and service diagnostics: legitimate interests in protecting accounts and operating a reliable service, after assessing necessity and the impact on individuals.
- Accounting, lawful requests and required records: compliance with applicable legal obligations.
- Optional communications or activities requiring permission: specific consent, where appropriate. Consent must be distinguishable from acceptance of commercial terms and can be withdrawn prospectively.
We will not rely on a blanket statement that using the website gives consent to every activity. If required information is withheld, we may be unable to register an account, process a payment or run the requested test. Optional AI explanations are not required to view an otherwise available result.
5. Who can see assessment information
Participants can access their own permitted attempts and results. A test creator can view participant names, contact details, attempt status, submitted answers and scores for that creator’s test, and can export available reports. Authorised school members may have access to shared school subjects and question banks. A creator is responsible for protecting downloaded reports and restricting subsequent disclosure.
“Public test” refers to test availability; it does not mean that participant contact details or individual answer sheets should be publicly accessible. Private invitations and QR links can be forwarded by their recipients. A link alone must not bypass account, schedule or access-approval checks. Questions copied from a bank into a test become separate assessment records.
6. Payments and service providers
Paystack processes payment instructions through its own checkout and related infrastructure. Hinet receives information needed to verify the transaction and maintain a wallet ledger. A browser payment-success screen is not sufficient to credit a wallet; provider verification is required. Paystack may act independently for payment compliance, security and other purposes explained in its own notice.
Other recipients may include hosting, infrastructure, email/SMS delivery when enabled, professional advisers, and suppliers necessary to operate the service. Access should be limited to the purpose, protected by suitable terms, and subject to applicable transfer requirements. We may disclose information when required by law, to establish or defend legal claims, or to investigate misuse, subject to necessity and proportionality. A proposed corporate transaction must include appropriate confidentiality and notification safeguards.
The current application is not designed to sell participant records or use them for targeted advertising. New advertising, analytics or materially different uses require a fresh assessment and appropriate notice or consent before introduction.
7. Optional AI explanations
When you confirm an Explain request, the server sends the question, its options and answer key to OpenAI to generate an educational explanation. The current integration does not intentionally include your name, contact details, wallet balance or complete attempt history in that request. However, personal information written into a question or option will travel with that content.
The request uses store=false. This is not a promise of zero retention: provider security or abuse-monitoring records may still apply. OpenAI describes its API data practices, including default training and retention arrangements, in its API data-controls documentation. These arrangements must be checked against the provider contract and configuration used by Hinet.
Hinet stores completed explanations and purchase records linked to the requester to deliver the service and handle retries or disputes. AI output can be inaccurate. It is not used by the current explanation feature to change the official score. Declining the explanation avoids this optional AI request and its associated charge.
8. Browser storage, cookies and external assets
The current web client uses browser session storage for its bearer login token, account metadata, an active attempt, local answer/navigation/bookmark state, temporary notices and explanation retry identifiers. These records support sign-in, navigation and recovery within a browser session. Browser settings, closing a tab or clearing storage can remove local state; server-held account, assessment and billing records are separate.
On a shared device, sign out and close the browser session after use. The current client is not a promise of cross-device synchronisation or permanent offline answer storage. Other first-party clients must explain any additional device storage they introduce.
Pages currently request fonts and libraries from third-party services such as Google Fonts, jsDelivr and code.jquery.com; Paystack resources are loaded for checkout. Those providers can receive IP addresses and request metadata. Their delivery logs or cookies are governed by their own arrangements. A production inventory must verify all cookies and storage; this notice does not claim that all external resources are cookie-free. Non-essential tracking must not be introduced without the applicable notice and consent controls.
9. Children and school-managed use
Educational users may be children. Their information requires particular care. Institutions and Hinet must establish the applicable legal basis, provide age-appropriate information, minimise data, and obtain and verify parent or guardian authorisation where the law requires it. An educator’s role does not automatically replace a required parent or guardian authorisation.
The current build does not yet provide a complete age-verification or parental-consent workflow. Email/phone verification may also be bypassed while delivery services are being configured. Neither registration nor a verification status proves age or guardianship. Child-facing deployment requires these gaps to be resolved or an appropriate documented, lawful institution-managed process before collection. Do not use a child’s question content with an external AI provider unless the required safeguards and permissions apply.
A parent or guardian with concerns may contact Hinet and the relevant school. We may request proportionate evidence of authority before disclosing a child’s information, without collecting excessive identity documents.
10. Automated grading and meaningful review
QuizDesk calculates scores automatically against the creator’s stored answer key and point values, and applies the configured pass threshold. Server time determines whether submissions meet the deadline. Incorrect question wording, incorrect keys, timing settings or technical events can affect results.
Contact the test creator to challenge a question, answer key or educational decision; contact Hinet for a platform fault. Institutions should provide meaningful human review and must assess the legal requirements before relying solely on automated scores for admissions, progression, employment or similarly significant decisions. The existence of a score or pass label does not itself authorise such use. AI explanations are learning aids, not the appeal process.
11. International processing
Some suppliers, including AI, payment and content-delivery services, may process information outside Nigeria. Hosting location and onward transfers depend on the actual deployment and contracts. No representation is made in this draft that all information remains in Nigeria or in any particular country.
Before a restricted international transfer, the responsible organisation must establish the applicable protection and lawful transfer mechanism, assess relevant risks and document required safeguards or exceptions. Clicking Explain is not a blanket waiver of transfer rights. Hinet’s final notice and supplier schedule should identify material processing locations and explain how information about relevant safeguards can be requested.
12. Retention and deletion
Retention should be limited to what is necessary for the stated purpose, lawful instructions, accounting requirements, security and dispute resolution. Account records are needed while an account operates; assessment records depend on the institution’s legitimate retention needs and applicable requirements; payment and dispute records may need to survive account closure. Local attempt state and uploaded source files must be distinguished from questions saved in the database.
The current release does not implement a complete automatic retention/deletion schedule. A fixed deletion deadline is therefore not promised here. Hinet must approve and implement category-specific periods, backup expiry and legal-hold rules before adopting the final notice. Requests are handled through contact channels rather than a self-service deletion screen.
Deleting a bank question does not necessarily delete copies already used in assessments or records that must lawfully be retained. Where deletion is restricted, Hinet should explain the reason and duration or review criteria, limit further use, and erase or anonymise information when the justification ends. A legal hold must not become indefinite retention without review.
13. Security and incident handling
The application includes hashed passwords, signed bearer tokens, server-side permission checks, prepared database queries, selected rate limits and server-side payment verification. These controls reduce risk but cannot guarantee that an incident will never occur. Production deployment also requires HTTPS, restricted infrastructure and database access, protected secrets, maintained dependencies, suitable backups and an incident-response process.
Report suspected account misuse or disclosure promptly through the contact below. Where a breach occurs, Hinet and any responsible institution must assess it, contain it, preserve relevant evidence, and make notifications to affected individuals, regulators or contractual partners when legally required. This draft does not claim security certification, regulatory registration or a completed compliance audit.
14. Your rights and requests
Subject to applicable law and its exceptions, you may request information about processing, access to your personal data, correction, erasure, restriction or objection to certain uses, and portability where applicable. You may withdraw consent for consent-based processing without invalidating earlier lawful processing. Rights concerning significant solely automated decisions may also apply.
Use the contact below, identify the account and explain the request. Hinet should verify identity and authority proportionately, locate the relevant controller, and respond within the applicable legal timeframe. If a request cannot be fulfilled in full, the response should explain the applicable reason and available complaint route. Exercising rights should not require sending your password or making a wallet payment.
15. Complaints, updates and legal references
You can raise concerns with Hinet or the relevant institution and may complain to the Nigeria Data Protection Commission or pursue other remedies available under applicable law. Contacting us first is helpful but is not a condition that removes your regulatory or court rights.
The final notice should display its effective date and version. Material changes should be communicated through appropriate channels, with new consent where required. A new notice must not retrospectively authorise a previously incompatible use.
Review references: the Nigeria Data Protection Act 2023 and applicable NDPC instruments, including the current General Application and Implementation Directive. Consult the NDPC resources and official explanatory guidance. These references support legal review and do not constitute an assertion that every compliance obligation has already been met.
Contact details
Hinet Technologies Limited, Nigeria
Operator and owner of the eSlate product ecosystem.
Published studio address: No 13, Osipitan Street, Saraki Odemo, Abeokuta, Ogun State, Nigeria.
Business contact: hello@hinetgroup.xyz.
Source: Hinet’s contact page.
Use “Privacy request”, “Billing dispute” or “Legal notice” in the subject, as appropriate. Do not send passwords, API keys, full card numbers or unnecessary identity documents.
To be confirmed before adoption: whether the published studio is the registered office, the CAC registration number, designated privacy/DPO contact (where applicable), and formal legal-notice address. The business email must be confirmed as authorised to receive these requests.