Security & Compliance
Protecting your data and maintaining the highest standards of compliance.
Data Security & GDPR Compliance Summary
Overview for Schools and Educational Partners
We provide an AI-powered marking service designed with a Privacy-by-Design architecture. Our relationship with Google Cloud, combined with our strict data residency protocols, ensures that student PII is handled with the highest standards of care.
1. Data Residency & Sovereignty
- Primary Storage: All student records and exam papers are stored in a UK-region locked Google Cloud SQL database. This data never leaves the UK jurisdiction at rest.
- Processing: Application logic runs on Google Cloud Run servers, also locked to the UK region.
- AI Inference: Transient data passed to Google Vertex AI is processed under the protections of the Google Cloud Data Processing Addendum (CDPA).
2. Legal Safeguards
We operate under a robust contractual framework that includes:
- UK GDPR Compliance: Our terms incorporate the UK Standard Contractual Clauses (SCCs) and the International Data Transfer Addendum (IDTA).
- Article 46 Protections: These clauses provide "appropriate safeguards" for data processing, ensuring student rights are enforceable regardless of where the technical processing occurs.
3. Security Provisions
- Encryption: Data is encrypted at rest using AES-256 and in transit via TLS 1.2+.
- No Model Training: Under our Enterprise agreement, Google is contractually prohibited from using your data to train its AI models.
- Instruction-Based Processing: Google acts strictly as a Data Processor, handling data only as directed by our service to fulfill the marking request.
4. Our Commitment
We act as a Processor on behalf of the School (the Controller). We commit to:
- Never using student data for marketing or profiling.
- Maintaining a minimal data footprint (Data Minimisation).
- Deleting data in accordance with school-defined retention policies.