ConceptCare

Legal

Data protection

Our processing commitments for institute, student and guardian data.

01

Roles

The institute is the controller of student, guardian and staff data. ConceptCare acts as processor and processes that data only to provide the platform as instructed.

02

Scope of processing

Processing covers admissions enquiries, student profiles, attendance, assessment results, fee records and communication history connected to a workspace.

03

Minors

Data about students under the age of majority is processed on the institute's instruction and lawful basis. Guardian contact data is used only for the communication the institute configures.

04

Sub-processors

Hosting, database, storage and model inference providers act as sub-processors under written terms no less protective than these. A current list is available on request.

05

Security measures

Tenant isolation with row-level security, encryption in transit and at rest, least-privilege access, audit logging of agent actions and reviewed administrative access.

06

AI and model use

Institute data is used to answer the institute's own requests. It is not used to train shared or third-party foundation models.

07

Data subject requests

We assist controllers in responding to access, correction, deletion, restriction and portability requests within the timelines that apply to them.

08

Retention and deletion

Data is retained for the agreed period and deleted, including from backups on their rotation schedule, after termination or on written instruction.

09

Incidents

Confirmed personal data breaches are reported to affected controllers without undue delay, with the facts known, likely impact and remediation taken.

10

International transfers

Where data crosses borders, transfers rely on an approved mechanism such as standard contractual clauses together with the safeguards above.

This page is illustrative content for ConceptCare and is not legal advice. Enterprise agreements take precedence where they exist.