Security & Compliance

Protecting your data and maintaining the highest standards of compliance.

Data Security & GDPR Compliance Summary

Overview for Schools and Educational Partners

We provide an AI-powered marking service designed with a Privacy-by-Design architecture. Our relationship with Google Cloud, combined with our strict data residency protocols, ensures that student PII is handled with the highest standards of care.

1. Data Residency & Sovereignty

  • Primary Storage: All student records and exam papers are stored in a UK-region locked Google Cloud SQL database. This data never leaves the UK jurisdiction at rest.
  • Processing: Application logic runs on Google Cloud Run servers, also locked to the UK region.
  • AI Inference: Transient data passed to Google Vertex AI is processed under the protections of the Google Cloud Data Processing Addendum (CDPA).

2. Legal Safeguards

We operate under a robust contractual framework that includes:

  • UK GDPR Compliance: Our terms incorporate the UK Standard Contractual Clauses (SCCs) and the International Data Transfer Addendum (IDTA).
  • Article 46 Protections: These clauses provide "appropriate safeguards" for data processing, ensuring student rights are enforceable regardless of where the technical processing occurs.

3. Security Provisions

  • Encryption: Data is encrypted at rest using AES-256 and in transit via TLS 1.2+.
  • No Model Training: Under our Enterprise agreement, Google is contractually prohibited from using your data to train its AI models.
  • Instruction-Based Processing: Google acts strictly as a Data Processor, handling data only as directed by our service to fulfill the marking request.

4. Our Commitment

We act as a Processor on behalf of the School (the Controller). We commit to:

  • Never using student data for marketing or profiling.
  • Maintaining a minimal data footprint (Data Minimisation).
  • Deleting data in accordance with school-defined retention policies.