legal · v0.9.0-draft · Draft
Data Protection Policy
Role-by-purpose controller/processor mapping, Article 28 DPA expectations, rights-request routing, retention link — preferred governance position pending solicitor/DPO review.
- Effective
- 2026-07-25
- Last reviewed
- 2026-07-25
- Next review
- 2027-01-25
- Owner
- StarLiz Academy Product & Compliance (draft)
- Audience
- Public, School Admin, Platform Admin, Staff
Purpose
Set organisational data protection principles and the preferred controller/processor mapping by processing purpose.
Scope
Staff and processors handling personal data for StarLiz Academy UK launch services, including school and direct-to-parent arrangements.
1. Status and principles
Preferred data-governance position pending solicitor and DPO review — not formal legal advice.
Process personal data under UK GDPR principles. Children's data is kept to the minimum necessary.
StarLiz uses a role-by-processing-purpose model. An organisation can be a processor for some activities and a controller for others, depending on who decides the purpose and essential means of processing.
2. Day School records
For school-provisioned Day School activity, the school or academy trust is data controller and StarLiz is data processor.
This covers school enrolment and classroom membership; fixed timetable records; attendance registers; teacher-assigned lessons; school-directed learning records; school reports; classroom and tutor assignments; school-configured safeguarding workflows; and school-authorised exports.
The school determines why these records are processed. StarLiz processes them to provide the contracted service under documented instructions.
School agreements must include an Article 28-compliant Data Processing Agreement covering security, sub-processors, deletion or return, breach notification, staff access, rights assistance, transfers, safeguarding escalation and end-of-contract export/deletion.
3. Direct-to-parent Short Learning
For subscriptions purchased directly by a parent, StarLiz is data controller for parent and student account creation; subscription and billing administration; Short Learning bookings; entitlement checks; booking reliability and no-show controls; direct customer communications; direct-to-parent reports; service improvement necessary to operate Short Learning; complaints and customer support; and fraud, security and audit records for that service.
4. School-funded Short Learning
Where a school purchases Short Learning for pupils, roles are assessed by purpose rather than assumed.
Preferred default: school-directed pupil participation and educational use — school controller, StarLiz processor; StarLiz's independent billing, platform security, fraud prevention and legal compliance processing — StarLiz controller.
This is a split-role arrangement by processing activity, not automatically joint controllership.
5. AI Tutor and analytics
School-directed Day School AI processing used solely to deliver the school's selected lesson and return results under school instructions: school controller, StarLiz processor.
StarLiz-controlled AI safety and platform operation (security, abuse detection, integrity, legal compliance, AI safety incidents, claims defence, operational audit): StarLiz controller.
Do not use the processor role as permission to reuse school pupil data for unrelated model training, advertising or broad product experimentation.
Identifiable school pupil data is not used for StarLiz independent product development unless the school contract expressly permits the specific processing, the role and lawful basis are documented, transparency is provided, and a DPIA supports the use where required.
Irreversibly anonymised analytics may be used for capacity planning, performance, quality monitoring, aggregate educational insight and product improvement. Pseudonymised data remains personal data and must not be described as anonymous.
6. Human tutor support
Day School human-support cases: school controller, StarLiz processor.
Short Learning human-support cases bought directly by parents: StarLiz controller.
Tutor staff and contractors act under the authority of the relevant controller/processor arrangement. They are not independent controllers merely because they view or create session notes.
7. Safeguarding
For routine school-directed safeguarding records, the school normally remains controller and StarLiz acts as processor.
Where StarLiz independently decides that it must record, preserve or disclose information to protect a child, comply with law, manage an incident or cooperate with authorities, StarLiz may act as an independent controller for that specific processing.
8. Platform administration, security and suppliers
StarLiz is controller for staff accounts used to operate StarLiz; authentication and access logs; platform audit logs; cybersecurity monitoring; fraud and misuse prevention; provider management; legal compliance; incident investigation; and service availability monitoring.
Payment providers and infrastructure suppliers are described according to the real contract as processor, independent controller or, exceptionally, joint controller — not automatically all processors.
StarLiz maintains a current sub-processor register, written processor terms, international-transfer safeguards where required, prior authorisation mechanisms for school-controlled data, and equivalent protections in downstream processor contracts.
9. Rights-request routing
Day School / school-controlled request: StarLiz receives the request, logs it, verifies enough information to route safely, promptly refers it to the school, and assists the school under the DPA. StarLiz must not independently decide the school's response unless legally required.
Direct Short Learning / StarLiz-controlled request: StarLiz handles the request directly.
Mixed request: split internally and explain clearly which organisation is handling each part.
10. Retention and breaches
Retention periods follow the Data Retention Policy, including school-instruction priority for school-controlled records.
Suspected breaches must be reported internally immediately for assessment against UK GDPR notification duties and any contractual notice requirements to schools.
11. Reporting
Contact [email protected]. For child welfare concerns use [email protected].
Reporting
Complaints
Related documents
Change history
- v0.9.0-draft · 2026-07-25 — Phase 6 draft aligned to shipped UK launch product behaviour.