legal · v0.9.0-draft · Draft
Security and Incident Response Policy
StarLiz applies access controls, monitoring and incident response for platform security. Personal data incidents are assessed and notified under applicable UK law.
- Effective
- 2026-07-25
- Last reviewed
- 2026-07-25
- Next review
- 2027-01-25
- Owner
- StarLiz Academy Product & Compliance (draft)
- Audience
- Public, Parent, School Admin, Platform Admin
Purpose
Describe StarLiz security expectations and how security incidents are handled.
Scope
Platform security, personal data incidents and user reporting for UK launch.
Purpose and scope
This policy summarises how StarLiz protects accounts and personal data and how security incidents are handled.
It is not a certification claim and remains subject to legal review.
Security controls
Controls include authenticated access, role-based Admin permissions, audit logging of sensitive actions, and encrypted transport for web traffic.
Parents, students and staff must keep login credentials confidential and report suspected account compromise promptly.
Incident response
Suspected security or personal-data incidents are triaged, contained where practical, investigated and recorded.
Where UK GDPR notification duties apply, StarLiz assesses risk and notifies regulators and affected individuals as required by law.
Reporting
Report suspected security issues to [email protected]. For child welfare concerns use [email protected] or emergency services if there is immediate danger.
Reporting
Complaints
Change history
- v0.9.0-draft · 2026-07-25 — Phase 6 draft aligned to shipped UK launch product behaviour.