Data & Security

Data & Security

How Destina Edu – Parent App protects accounts and school data, and how we handle security incidents.

Effective date: 21 June 2026 Last updated: 5 September 2026

1. Our approach

We apply a layered set of technical and organisational measures designed to protect information processed through Destina Edu – Parent App. This page describes our general security practices in plain language. We do not claim any specific security certification, such as ISO 27001 or SOC 2, unless such certification has been obtained and verified.

2. Secure authentication

Access to a parent/guardian account requires authentication with the account credentials provided or established for the account. Users are responsible for keeping their credentials confidential and should use a strong, unique password where passwords are used.

3. Access control

Internal access to systems that store personal information is restricted to authorised personnel who need access to perform their role. Access permissions are managed according to the responsibilities of the relevant personnel.

4. Encryption in transit

Data sent between the App and our backend services is encrypted in transit using HTTPS/TLS. We do not make a separate claim about encryption of data at rest unless it has been implemented and verified for the relevant systems.

5. Secure backend communication

Our backend services authenticate and authorise requests before returning protected data. Access controls are designed so that a parent or guardian account can retrieve student information only for students authorised and linked to that account by the relevant school. Our backend infrastructure is hosted with Hostinger.

6. Data retention

We retain information only for as long as necessary for the purposes described in our Privacy Policy, or as required by law. Parent/guardian account information is deleted following a verified deletion request, subject to the applicable deletion process, any required school authorisation, and legal or security retention requirements. Student records shared by a school remain governed by the school's applicable retention policies and instructions. See our Account & Data Deletion page for information about requesting account deletion.

7. Security incident handling

If we become aware of a security incident that affects personal information, we will investigate the incident, take reasonable steps to contain and remediate it, and provide notifications where required by applicable law.

8. Your role in keeping your account secure

  • Use a strong, unique password for your account
  • Do not share your login credentials with anyone
  • Keep your device's operating system and the App itself up to date
  • Contact us immediately at destinainfotech@gmail.com if you notice suspicious activity on your account

9. Contact

To report a suspected security vulnerability or incident, contact destinainfotech@gmail.com.