01
Roles
The institute is the controller of student, guardian and staff data. ConceptCare acts as processor and processes that data only to provide the platform as instructed.
Legal
Our processing commitments for institute, student and guardian data.
01
The institute is the controller of student, guardian and staff data. ConceptCare acts as processor and processes that data only to provide the platform as instructed.
02
Processing covers admissions enquiries, student profiles, attendance, assessment results, fee records and communication history connected to a workspace.
03
Data about students under the age of majority is processed on the institute's instruction and lawful basis. Guardian contact data is used only for the communication the institute configures.
04
Hosting, database, storage and model inference providers act as sub-processors under written terms no less protective than these. A current list is available on request.
05
Tenant isolation with row-level security, encryption in transit and at rest, least-privilege access, audit logging of agent actions and reviewed administrative access.
06
Institute data is used to answer the institute's own requests. It is not used to train shared or third-party foundation models.
07
We assist controllers in responding to access, correction, deletion, restriction and portability requests within the timelines that apply to them.
08
Data is retained for the agreed period and deleted, including from backups on their rotation schedule, after termination or on written instruction.
09
Confirmed personal data breaches are reported to affected controllers without undue delay, with the facts known, likely impact and remediation taken.
10
Where data crosses borders, transfers rely on an approved mechanism such as standard contractual clauses together with the safeguards above.
This page is illustrative content for ConceptCare and is not legal advice. Enterprise agreements take precedence where they exist.