Back to site

Terms and Conditions

Vertex LabsVersion 2.1Effective 9 October 2026

These Terms and Conditions govern your access to and use of the websites, applications, hardware products and services provided by Vertex Labs, including under our SkyMobility brand and our robotics lines. Please read them carefully. By accessing or using our Services you agree to be bound by them.

1. About these Terms

1.1 “Vertex Labs”, “we”, “us” and “our” refer to Vertex Labs, a technology company based in Kenya. “You” means the individual or organisation that accesses or uses the Services.

1.2 If you use the Services on behalf of an organisation, such as a school, you confirm that you have authority to bind that organisation, and “you” includes that organisation.

1.3 Order of precedence. Where we have signed a separate written agreement, quotation or order form with you (an “Order”), that document applies together with these Terms. If there is a conflict, the following order applies, highest first: (a) the Order; (b) any data processing agreement signed by both parties; (c) these Terms, including the Schedules.

1.4 Terms you propose, including those in a purchase order or procurement form, do not apply unless we agree to them in writing.

2. Definitions

  • Services means our websites, web and mobile applications, platforms, Products and related support, installation, maintenance and hosting services, including Exeat, StaffSync, Meal Tracker, E-Portfolio, SkyMobility, our robotics offerings, and any other product or service we make available.
  • Products means physical goods we make, sell, lease, loan or otherwise supply, such as vehicles, robots, drones, sensors, controllers, batteries, chargers and accessories, together with the firmware and embedded software that runs on them.
  • Device Data means data generated or collected by a Product, such as telemetry, diagnostics, location, route and mission logs, and sensor, image, video or audio data.
  • Customer means the school, institution, business or other organisation that subscribes to or is provided with the Services.
  • Authorised User means an individual permitted by the Customer to use the Services, such as staff, teachers, students, parents or guardians, operators and administrators.
  • Customer Data means all data, including personal data, that the Customer or its Authorised Users submit to or generate through the Services.
  • Data Protection Laws means the Data Protection Act, 2019 of Kenya, the regulations made under it (including the Data Protection (General) Regulations, 2021), and any other data protection law that applies to the processing concerned.
  • Personal Data Breach has the meaning given in the Data Protection Laws.
  • Security Incident means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Customer Data in our control.

3. Our Services

3.1 We provide the Services as described on our website or in the applicable Order. We may improve, modify, add or retire features from time to time. Where a change materially reduces the core functionality you have paid for, we will give reasonable notice and, where the reduction is significant, you may end the affected Service and receive a pro-rata refund of prepaid fees for the unused period.

3.2 Some Services, Products or features are in development, prototype, pilot, beta or research stages. Where we describe a product or concept that way, it is not a commitment to deliver that product or any particular feature or date, and it is provided without the service commitments in section 13. Our announcing a new product line, such as mobility or robotics, is not an offer to supply it.

3.3 You are responsible for the devices, internet access and connectivity you use to reach the Services.

3.4 Additional terms for individual products are set out in Schedule A. They form part of these Terms.

3.5 Where we supply Products, sections 23 to 25 also apply.

4. Accounts and authorised users

4.1 Access to certain Services requires an account. You must give accurate and current information and keep it up to date.

4.2 You are responsible for all activity under your accounts, for keeping credentials confidential, and for ensuring that Authorised Users comply with these Terms. Tell us promptly at the address in section 26 if you suspect unauthorised access.

4.3 The Customer must manage access sensibly: give each Authorised User only the access they need, disable accounts of people who leave, and use multi-factor authentication where we offer it.

4.4 We may rely on instructions given through a Customer’s administrator accounts as instructions from the Customer.

5. Schools, students and minors

5.1 Many of our Customers are schools, and our Services may process the personal data of children. The Customer is responsible for ensuring that it has the authority, and any parental or guardian consent, required by law (including the Data Protection Act, 2019 and the Children Act, 2022) to allow that use and to process that data.

5.2 Under the Data Protection Act, 2019, personal data of a child may be processed only where that is in the child’s best interests and in line with the consent and safeguards the law requires. The Customer decides what student data is entered into the Services and why, and must not enter more than it needs.

5.3 We do not provide the Services directly to children for their own personal use, and we do not use children’s data for advertising or profiling.

5.4 The Customer must give parents, guardians and staff the privacy notices the law requires and must tell them that we act as its processor.

6. Customer Data and data protection

6.1 Ownership. As between you and us, you retain all rights in Customer Data. We do not claim ownership of it.

6.2 Roles. For personal data contained in Customer Data, the Customer is the data controller and Vertex Labs acts as data processor on the Customer’s behalf, except where we process personal data for our own purposes, such as managing the customer relationship, in which case we act as a controller. Schedule B describes the processing.

6.3 Our commitments as processor. We will:

  • process personal data only on the Customer’s documented instructions and for the purpose of providing the Services, unless the law requires otherwise (in which case we will tell the Customer first where the law allows);
  • ensure that personnel with access to personal data are bound by confidentiality and have a need to access it;
  • apply the security measures described in section 7;
  • assist the Customer, to a reasonable extent and taking into account the nature of the processing, in responding to requests from data subjects and in meeting its obligations under Data Protection Laws;
  • make available information reasonably necessary to show compliance with this section and allow audits as set out in 6.10; and
  • on termination, and at the Customer’s choice, return or delete Customer Data within a reasonable period, subject to any retention required by law and to routine backup cycles.

6.4 Customer responsibilities. The Customer is responsible for having a lawful basis for processing, for giving the notices and obtaining the consents that Data Protection Laws require, for registering with the Office of the Data Protection Commissioner where required, for carrying out any data protection impact assessment the law requires, and for the accuracy and lawfulness of the data it submits.

6.5 Sub-processors. We may use trusted sub-processors, such as hosting and infrastructure providers, to deliver the Services. We will bind them to data protection obligations no less protective than this section, we remain responsible for their performance, and we will give the Customer a current list on request. We will give reasonable notice of a new sub-processor that will handle personal data, and the Customer may object on reasonable data protection grounds.

6.6 Location and international transfers. Where Data Protection Laws require certain Customer Data to be processed or stored in Kenya, we will comply with those requirements for the Services you use. We will transfer personal data outside Kenya only in line with Data Protection Laws.

6.7 Personal Data Breach. If we become aware of a Security Incident affecting the Customer’s personal data, we will notify the Customer without undue delay and, where practicable, within 72 hours of becoming aware, with the information we then have and updates as we learn more. We will take reasonable steps to contain and remediate it. The Customer, as controller, is responsible for any notice to the Data Commissioner and to affected individuals that the law requires, and we will reasonably assist.

6.8 Aggregated data. We may use anonymised and aggregated data that does not identify any person or Customer to operate, secure and improve the Services.

6.9 Data subject requests. If we receive a request directly from an individual about Customer Data, we will refer them to the Customer where we can identify the Customer, and will not respond except to say that we have done so, unless the law requires otherwise.

6.10 Audit. No more than once a year, or after a Security Incident, the Customer may on 30 days’ written notice review our relevant security and data protection documentation, and may ask reasonable questions. Any on-site audit needs our agreement, must be during business hours without disrupting operations, and is at the Customer’s cost. Auditors must be bound by confidentiality.

7. Security

7.1 We maintain technical and organisational measures appropriate to the risk, including:

  • encryption of data in transit using current TLS;
  • role-based access controls and least-privilege access for our personnel;
  • logging and monitoring of access to production systems;
  • regular, tested backups to support recovery;
  • timely application of security updates to systems we manage;
  • controls on how connected Products receive firmware updates and remote commands; and
  • separation of production and development environments.

7.2 No system is completely secure. We do not promise that the Services will be free of vulnerabilities, but we will act promptly on those we become aware of.

7.3 Responsible disclosure. If you find a security issue, please report it privately to info@vertexlabs.co.ke, give us reasonable time to fix it before disclosing it, and do not access or change data that is not yours. We will not take action against good-faith research that follows this paragraph.

8. Acceptable use

You must not, and must not permit others to:

  • use the Services unlawfully, or in breach of any person’s rights, including privacy and intellectual property rights;
  • upload content that is unlawful, defamatory, abusive, discriminatory, sexually explicit involving minors, or that promotes violence;
  • attempt to gain unauthorised access to the Services, other accounts, servers or networks, or probe, scan or test their security without our written permission;
  • introduce malware or interfere with or disrupt the integrity, performance or availability of the Services;
  • reverse engineer, decompile or copy the Services or their source code, except to the extent the law permits despite this restriction;
  • use automated means such as bots or scrapers to extract data from the Services, other than as we expressly allow;
  • resell, sublicense or make the Services available to third parties except as agreed in an Order;
  • use the Services to build a competing product, or to benchmark them for publication without our consent;
  • tamper with a Product, remove or bypass its safety features, or modify its hardware, firmware or software except as we allow in writing;
  • use a Product to harm people or property, as a weapon, or for surveillance without the lawful basis the law requires; or
  • use the Services in breach of the Computer Misuse and Cybercrimes Act, 2018 or any other applicable law.

9. Intellectual property

9.1 We and our licensors own all rights in the Services, including software, firmware, mechanical and electronic designs, interfaces, text, graphics, logos, trade marks and documentation, and in all improvements and derivative works of them. Nothing in these Terms transfers any of those rights to you.

9.2 Subject to these Terms and payment of applicable fees, we grant you a limited, non-exclusive, non-transferable, revocable licence to access and use the Services for your internal purposes during the term of your agreement with us.

9.3 If you give us feedback or suggestions, you grant us a free, perpetual licence to use them to improve our products, without obligation to you. This does not give us any right to Customer Data.

9.4 “Vertex Labs” and our logos are our marks. You may not use them without our prior written consent.

10. Customer Content

10.1 You grant us a limited, non-exclusive, worldwide licence to host, store, process, display and transmit Customer Data solely to provide, secure and support the Services for you.

10.2 You are solely responsible for Customer Data and warrant that you have all rights and permissions needed to submit it and to grant the licence above, and that doing so does not breach any law or third-party right.

10.3 We may remove or disable access to content that we reasonably believe breaches these Terms or the law, and will where practicable tell the Customer why.

10.4 You are responsible for keeping your own copies of any data you consider critical. We make backups to support service recovery, but those are not a substitute for your own records.

11. AI-assisted features

11.1 Some Services include features that use artificial intelligence or machine learning to generate, suggest, summarise or analyse content, or to assist or automate the operation of devices, robots or vehicles (see section 24).

11.2 AI-generated output may be inaccurate, incomplete, biased or unsuitable for your purpose. It is provided for assistance only and must be reviewed by a competent person before it is relied on. AI output must not be the sole basis for decisions that significantly affect a student or staff member, such as grades, discipline, promotion, health or safety.

11.3 AI output is not professional, legal, medical or educational advice.

11.4 You are responsible for how you use AI output and for telling the people affected that AI is being used where the law or good practice requires it.

11.5 Unless an Order says otherwise, we do not use Customer Data to train general-purpose AI models for the benefit of other customers. Where we use third-party AI providers to deliver a feature, they are sub-processors under section 6.5.

12. Fees and payment

12.1 Fees, billing cycles and payment terms are set out in the applicable Order or quotation. Unless stated otherwise, fees are quoted in Kenya Shillings and exclude value added tax and other applicable taxes, which you must pay in addition. If withholding tax applies, you must give us the withholding certificate and pay the balance so that we receive the full amount owed after the lawful deduction.

12.2 Invoices are payable within the period stated on the invoice, or within 30 days of the invoice date if none is stated. If you dispute an invoice in good faith, tell us in writing within 14 days with your reasons and pay the undisputed part on time.

12.3 We may charge interest on overdue undisputed amounts at a reasonable rate permitted by law and may suspend the Services after written notice of non-payment (see 19.3).

12.4 Fees are non-refundable except where these Terms or an Order say otherwise or the law requires.

12.5 Unless an Order says otherwise, subscriptions renew for successive terms equal to the initial term. We may change our fees for a renewal term by giving at least 30 days’ notice before the term ends, and either party may decline renewal by notice before then.

12.6 For Products, we may require a deposit or payment in advance and may hold delivery until it is received. Unless the Order says otherwise, shipping, insurance in transit, import duties and installation are charged separately.

13. Availability, support and maintenance

13.1 We will use reasonable efforts to keep the Services available and to carry out maintenance with minimal disruption, including by scheduling planned maintenance outside normal working hours and giving notice where practicable.

13.2 The Services depend on networks, power and third-party infrastructure outside our control. We do not guarantee uninterrupted or error-free operation unless a written service level agreement says so. Any service credits or remedies are set out only in that agreement.

13.3 Support is provided through the contact details in section 26, during normal business hours in Kenya (East Africa Time) unless an Order states otherwise. We will respond to reported issues in order of severity.

14. Third-party services

The Services may link to or interoperate with third-party products, websites or services, such as payment providers, messaging providers or identity services. These are governed by their own terms. We are not responsible for them, and your use of them is at your own risk. Where a third party acts as our sub-processor, section 6.5 applies.

15. Confidentiality

15.1 Each party will keep the other’s non-public business, technical and financial information that is marked confidential or would reasonably be understood to be confidential, and will use it only for the purposes of the agreement and disclose it only to personnel and advisers who need to know and are bound by confidentiality.

15.2 This does not apply to information that is public through no fault of the recipient, was already lawfully known to it, is independently developed, or is lawfully received from a third party. A party may disclose confidential information where required by law or a competent authority, after giving the other party notice where permitted.

15.3 These obligations continue for three years after the agreement ends, and for as long as the information remains a trade secret or, for personal data, as long as we hold it.

16. Warranties and disclaimers

16.1 Each party warrants that it has the authority to enter into these Terms. We warrant that we will provide the Services with reasonable skill and care and in line with applicable law. Warranties for Products are set out in section 23.

16.2 Except as expressly stated in these Terms, and to the fullest extent permitted by law, the Services are provided “as is” and “as available”, and we disclaim all other warranties, express or implied, including those of merchantability, fitness for a particular purpose, non-infringement and uninterrupted or error-free operation.

16.3 Nothing in these Terms limits any rights you have under consumer protection law that cannot lawfully be excluded.

17. Limitation of liability

17.1 Nothing in these Terms excludes or limits liability that cannot be excluded or limited by law, including liability for fraud, death or personal injury caused by negligence, or wilful misconduct.

17.2 Subject to 17.1, neither party is liable to the other for any indirect or consequential loss, or for loss of profit, revenue, goodwill or anticipated savings, whether in contract, tort (including negligence) or otherwise, even if advised of the possibility.

17.3 Subject to 17.1, each party’s total aggregate liability arising out of or in connection with the Services in any 12-month period is limited to the fees paid or payable by the Customer to us for the Services in that period.

17.4 The limits in this section do not apply to the Customer’s obligation to pay fees, or to either party’s liability under section 18 for third-party claims.

18. Indemnity

18.1 You will defend and indemnify us against third-party claims, and resulting losses, damages and reasonable costs, arising from Customer Data, from your breach of section 6.4 or section 8, or from your use of the Services in breach of these Terms.

18.2 We will defend and indemnify you against third-party claims alleging that the Services, as we provide them and used as permitted, infringe that third party’s intellectual property rights, provided that you notify us promptly, let us control the defence and settlement, and cooperate reasonably. We may modify the Services, procure a right to continue, or end the affected Service and refund prepaid fees for the unused period. This section states our entire liability for infringement claims.

19. Term, suspension and termination

19.1 These Terms apply from when you first access the Services and continue for the term of your Order, or for as long as you use the Services if there is no Order.

19.2 Either party may terminate by written notice if the other materially breaches these Terms and does not remedy the breach within 30 days of written notice, or immediately if the other becomes insolvent.

19.3 We may suspend access, in whole or in part, immediately if necessary to protect the security or integrity of the Services, to comply with the law, or where you breach section 8; and after 14 days’ written notice if you fail to pay undisputed fees. We will limit suspension to what is needed and restore access when the cause is resolved.

19.4 Exit and data return. For 30 days after termination or expiry, the Customer may ask us to make Customer Data available for export in a common format, such as CSV or JSON. After that period, and subject to section 6.3 and to any retention required by law, we will delete Customer Data from our live systems, and from backups as they cycle out.

19.5 Sections that by their nature should survive, including those on intellectual property, confidentiality, warranty, safety, liability, indemnity and governing law, will survive.

19.6 On termination the Customer must return any loaned, leased, trial or pilot Products in good condition, fair wear and tear excepted. Products not yet paid for in full remain ours under 23.3 and must be returned on request.

20. Changes to these Terms

We may update these Terms from time to time. We will publish the updated version on this page with a new version number and “effective” date and, for material changes affecting Customers, give at least 30 days’ notice by email or in the Service. A change does not alter the terms of an Order during its current term unless you agree. Continued use of the Services after a change takes effect means you accept the updated Terms. If you do not agree, you must stop using the Services.

21. Governing law and dispute resolution

21.1 These Terms and any dispute arising out of or in connection with them are governed by the laws of Kenya.

21.2 Escalation. The parties will first try in good faith to resolve any dispute through discussion between senior representatives for at least 30 days after written notice of the dispute.

21.3 Mediation and arbitration. If the dispute is not resolved, the parties will try mediation. If that fails within a further 30 days, either party may refer the dispute to arbitration under the Arbitration Act, 1995, before a single arbitrator seated in Nairobi, in English. The award is final and binding.

21.4 Either party may at any time seek urgent injunctive relief from the courts of Kenya to protect its confidential information, personal data or intellectual property, and the courts of Kenya have jurisdiction to support the arbitration.

22. General provisions

  • Entire agreement. These Terms, together with any Order, are the entire agreement between us about the Services and replace earlier discussions and understandings.
  • Severability. If a provision is found unenforceable, the rest of these Terms remains in effect.
  • No waiver. A failure or delay in exercising a right is not a waiver of it.
  • Assignment. You may not assign or transfer your rights under these Terms without our written consent. We may assign ours in connection with a merger, reorganisation or sale of our business, or to an affiliate, if we give you notice and the assignee is bound by these Terms.
  • Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, including power or network failures, natural disasters, acts of government, strikes or failures of third-party infrastructure. This does not excuse payment obligations.
  • Trade compliance. The Customer will comply with applicable export, import, customs and sanctions laws for Products and related technology, and will not export, re-export or transfer them in breach of those laws.
  • Anti-bribery. Each party will comply with applicable anti-corruption law, including the Bribery Act, 2016, and will not offer or accept improper payments in connection with the Services.
  • Independent parties. The parties are independent contractors. Nothing creates a partnership, agency or employment relationship.
  • Third parties. Only the parties to these Terms may enforce them.
  • Publicity. We may name the Customer as a customer in a list of clients unless the Customer objects in writing. We will not use its name in any other marketing without its consent.
  • Notices. Notices must be in writing. We may give notice by email to the contact on your account, in the Service or by posting on our website. You must send notices to us at the address in section 26.
  • Language. These Terms are in English, which prevails over any translation.

23. Hardware, devices and vehicles

23.1 This section applies to Products. It is in addition to the rest of these Terms.

23.2 Specifications. We supply Products as described in the Order and our product documentation. Images, ranges, speeds, capacities and other figures on our website or in marketing are illustrative and depend on conditions of use. Prototype, pilot and test units may differ from production units, are provided for evaluation, and we may recall or replace them.

23.3 Delivery, risk and title. Delivery dates are estimates. Risk in a Product passes to the Customer on delivery. Title passes only when we have received payment in full, unless the Order says otherwise. Until then the Customer must keep the Product insured, identifiable and in good condition, and must not sell, pledge or otherwise encumber it.

23.4 Inspection. The Customer must inspect Products on delivery and tell us in writing of visible damage, shortages or non-conformity within 7 days. Otherwise the Products are treated as accepted, without affecting the warranty below.

23.5 Installation and training. Unless we agree otherwise in writing, we or our authorised persons install and commission Products. The Customer will provide a suitable and safe site, power, connectivity, access and any permits needed, and will make sure that operators attend the training we provide.

23.6 Product warranty. For the warranty period in the Order or, if none is stated, 12 months from delivery, we warrant that a Product will materially conform to its documentation and be free from defects in materials and workmanship under normal use. If a Product does not, we will, at our option, repair it, replace it or refund the price paid for it. This is the Customer’s sole remedy for breach of this warranty, to the extent the law permits. The warranty does not cover: misuse or use outside the documentation; unauthorised repair or modification; accident, impact or exposure to conditions the documentation prohibits; failure to carry out required maintenance or install required updates; third-party parts or software we did not supply; or consumable and wear parts such as batteries, propellers, tyres and filters, except for defects present on delivery.

23.7 Returns and repairs. Products must not be returned without our return authorisation. We may ask the Customer to send the Product to us or to allow us to inspect it on site. Data on a returned Product may be erased, so the Customer should export what it needs first.

23.8 Maintenance, updates and safety notices. The Customer must maintain Products as the documentation requires, and must install firmware and software updates that we identify as safety-critical or security-critical within a reasonable time. If we issue a safety notice or recall, the Customer must follow it promptly. Some features depend on updates or on a connection to our systems.

23.9 Batteries and hazardous items. Products may contain lithium batteries or other items that are dangerous if misused. The Customer must charge, store, transport and dispose of them in line with the documentation and applicable law, including environmental and waste rules.

23.10 Support and end of life. We will give reasonable notice before we stop supplying a Product or its updates, and will make spare parts and support available for a reasonable period after supply, as stated in the Order or documentation.

24. Safety and regulated use

24.1 Responsibility. The Customer is responsible for operating Products safely and lawfully, including using only trained operators, supervising them, keeping operating and maintenance records, and following the documentation.

24.2 Licences and approvals. The Customer must obtain and keep all licences, registrations, permits, permissions and approvals needed to operate a Product where and how it is used, such as those required by the Kenya Civil Aviation Authority for unmanned aircraft, the National Transport and Safety Authority or traffic law for road vehicles, county authorities, and landowners or site operators. We will give the technical information reasonably needed to support applications, but we do not give legal advice and are not responsible for obtaining approvals unless the Order says so.

24.3 Human oversight. Products with assisted, automated or autonomous features are tools. A trained person must supervise them, be able to take control or stop them, and remain responsible for their operation, unless a signed Order expressly authorises unattended operation in a defined environment and sets any added conditions.

24.4 Limits on use. The Customer must not operate a Product beyond its rated limits or in conditions the documentation prohibits. Unless the Order expressly approves it, Products must not be used to carry people, for medical, emergency-response, life-support or other safety-critical purposes, to carry hazardous goods, or for military or weapons purposes.

24.5 Incidents. The Customer must tell us at the address in section 26, as soon as possible and in any event within 24 hours for a serious incident, of any accident, injury, near miss, property damage or serious malfunction involving a Product. The Customer must preserve the Product and its data, cooperate with any investigation by us or a regulator, and not destroy evidence.

24.6 Suspension for safety. Where a Product is connected, we may limit, ground or disable it remotely, or ask the Customer to stop using it, if we reasonably believe this is needed for safety or to comply with the law. We will tell the Customer where practicable and restore operation when the cause is resolved.

24.7 Trials and pilots. Experimental Products are used at the Customer’s risk, within the scope, location and conditions set in the Order, and may have extra safety rules.

24.8 Insurance. Each party will maintain insurance appropriate to its activities under these Terms. The Customer’s cover must include third-party liability for operating the Products where the law or reasonable practice requires it, and the Customer will give us evidence on reasonable request.

25. Device, sensor and location data

25.1 Connected Products may generate Device Data. Which data is collected depends on the Product and its settings, and is described in the documentation or the Order.

25.2 Where Device Data identifies a person, such as the location of a driver or operator, or footage showing people, it is personal data. Section 6 applies: the Customer is the controller and we are the processor. To the extent the law allows, we may use diagnostic and safety data as a controller for safety, security, fault investigation, product improvement and legal compliance.

25.3 Cameras and sensors. The Customer is responsible for using cameras, microphones and other sensors lawfully, including giving the notices and signage the law requires, avoiding capture of people or places without a lawful basis, and taking particular care around children. The Customer must not use a Product to identify individuals by biometric means unless the Order expressly provides for it and the law allows.

25.4 Our use of Device Data. We may use Device Data that does not identify any person or Customer, and is aggregated or anonymised, to operate, secure, test and improve our Products, including safety and performance models. We will not sell identifiable Device Data or use it for advertising, and will not use it to train models for other customers unless the Customer agrees.

25.5 Retention and incidents. We keep Device Data for the period in the Order or, if none, for as long as needed to provide the Services. We may keep data relevant to an incident, a claim or a regulator’s request for as long as needed for that purpose.

26. Contact us

For questions about these Terms, to give notice, to report a security issue, or to exercise rights relating to your data, contact us at info@vertexlabs.co.ke.

Vertex Labs · Kenya · vertexlabs.co.ke

Schedule A: Product notes

These notes apply in addition to the main Terms when you use the named product. They describe how the product is intended to be used; the Customer decides what data to enter.

ProductWhat it doesCustomer responsibilities
ExeatManages student exeat (leave) requests, approvals and records.Make sure that approval workflows reflect the school’s own policy and that guardians are informed as the school’s policy requires. Staff remain responsible for student welfare decisions.
StaffSyncStaff management, such as records, schedules and administration.Give staff the privacy notice required by law, restrict access to HR information to those who need it, and follow employment law.
Meal TrackerTracks meal and utensil accountability, such as collection and distribution, at group level.Decide whether any individual-level data is needed and, if so, ensure the lawful basis and notices for it. Do not use the data to humiliate or discriminate against any student.
E-PortfolioLets students and teachers keep and share a record of learning and work.Obtain any consent needed to publish student work or images, and moderate content shared in the portfolio.
SkyMobilityMobility and transportation products and related software, devices and services.Hold the licences, permits and insurance needed to operate, use trained operators, and follow sections 23 to 25. Products are used only as the Order and documentation allow.
RoboticsRobots, automation equipment and related control software.Prepare and keep the work site safe, restrict access to the working area, use trained operators, and keep human supervision in place unless the Order authorises otherwise.
Other productsNew products and services we launch.Until a product is listed here, the Order and product documentation set its specific terms.

Schedule B: Data processing details

Subject matterProvision of the Services to the Customer.
DurationThe term of the agreement, plus the export and deletion period in section 19.4.
Nature and purposeHosting, storing, retrieving, displaying, transmitting and backing up Customer Data, collecting and processing Device Data from connected Products, and supporting and securing the Services.
Types of personal dataDepends on the products used. May include names, contact details, class or role, student identifiers, leave and attendance records, staff records, meal accountability records, work submitted by students, and, for connected Products, device identifiers, location, route and mission logs, and sensor, image or video data. The Customer controls what is entered and which sensors are used.
Data subjectsThe Customer’s students, parents or guardians, teachers, staff, operators, drivers and administrators, and members of the public who may be captured by a Product’s sensors.
Special categoriesWe do not ask for sensitive personal data, such as health data. If the Customer chooses to enter any, it must be lawful and the Customer must tell us beforehand so that suitable safeguards can be agreed.
Sub-processorsHosting and infrastructure providers used to run the Services. A current list is available on request.