legal · v0.9.0-draft · Draft

Security and Incident Response Policy

StarLiz applies access controls, monitoring and incident response for platform security. Personal data incidents are assessed and notified under applicable UK law.

Draft for legal review — this document describes current product behaviour and is not formal legal advice.
Effective
2026-07-25
Last reviewed
2026-07-25
Next review
2027-01-25
Owner
StarLiz Academy Product & Compliance (draft)
Audience
Public, Parent, School Admin, Platform Admin

Purpose

Describe StarLiz security expectations and how security incidents are handled.

Scope

Platform security, personal data incidents and user reporting for UK launch.

Purpose and scope

This policy summarises how StarLiz protects accounts and personal data and how security incidents are handled.

It is not a certification claim and remains subject to legal review.

Security controls

Controls include authenticated access, role-based Admin permissions, audit logging of sensitive actions, and encrypted transport for web traffic.

Parents, students and staff must keep login credentials confidential and report suspected account compromise promptly.

Incident response

Suspected security or personal-data incidents are triaged, contained where practical, investigated and recorded.

Where UK GDPR notification duties apply, StarLiz assesses risk and notifies regulators and affected individuals as required by law.

Reporting

Report suspected security issues to [email protected]. For child welfare concerns use [email protected] or emergency services if there is immediate danger.

Reporting

[email protected]

Complaints

[email protected]

Change history

  • v0.9.0-draft · 2026-07-25Phase 6 draft aligned to shipped UK launch product behaviour.

Back to Policies · Knowledge Centre