Data security statement

Data security statement

This page explains how Studee protects the personal data that schools and their students place in the University Application Workspace (the "Workspace").

It describes what is in place today. The commitments we make to a school are in the school's agreement with us and in our Privacy notice and Terms and conditions. Where this page and those documents differ, those documents prevail.

Where your data is stored

Amazon Web Services (AWS) stores the Workspace data we hold, including the database, uploaded documents and backups, at rest in its London region (eu-west-2), in the United Kingdom. We do not replicate Workspace data to any other region. The suppliers that process data on our behalf, and where they are located, are listed in our Privacy notice.

Who is responsible for it

In the Workspace, your school is the data controller for the student, parent or guardian and staff data that it and its users put in. Studee is your school's processor for that data, under a written data processing agreement, and acts on the school's documented instructions. We do not use Workspace data for advertising or marketing. Our Privacy notice sets out the limited processing for which Studee is an independent controller.

How we protect it

Encryption. Connections between your browser and the Workspace use HTTPS. The production database and its backups, uploaded documents, caches and application secrets are encrypted at rest with encryption keys that Studee manages in AWS.

A private network. Application servers and the database run on private subnets with no inbound route from the internet. The database is not reachable from the internet.

Sign-in without passwords. Users do not have passwords. They sign in with a one-time code sent to their email address, or with Google sign-in. Codes expire after ten minutes. Sessions last 60 minutes and are renewed while you are active. Unless you choose Stay signed in, the Workspace signs you out after 60 minutes without activity.

Separation between schools. The server checks the signed-in user's school and role before returning school data. One school's users cannot see another school's data.

Documents. Every uploaded file is scanned for malware, and cannot be downloaded until the scan is clean. Downloads are streamed by our API after a permission check. Studee does not create public or shareable links to uploaded files.

Engineer access to data. Engineers reach the production database only through a private connection inside AWS, with multi-factor authentication and a recorded reason for each session. Each session is recorded and alerted to the engineering leads.

Changes. Code changes are tested automatically before they are merged, and deployments of the Workspace to production require approval from a named group.

Monitoring and audit trail

Sign-ins and other significant actions in the Workspace are written to an audit trail with the date and time, the acting account and the IP address. Application and platform logs are collected centrally, and the engineering team is alerted to failures and to use of elevated access to production.

Backups and recovery

The production database is backed up automatically and continuously. Backups are kept for 35 days in the same UK region, and are then deleted. When a file is deleted, it is deleted. We do not keep earlier versions of uploaded files.

Our suppliers

A small number of suppliers process Workspace data on our behalf, each under a written data processing agreement. They are listed, with their locations and the safeguards we rely on for any transfer outside the United Kingdom, in the "Who we share your data with" and "International transfers" sections of our Privacy notice. Under our agreement with each school, we give 30 days' notice before adding a supplier.

If something goes wrong

If a personal data breach affects data your school controls, we tell your school without undue delay and, under our agreement with the school, within 48 hours of becoming aware of it. The school then decides what it must report and to whom, and we support that with the facts we hold. Security concerns can be reported to [email protected]; data protection questions go to [email protected].

Certifications and audit

Studee does not currently hold any external security certification. We are working towards Cyber Essentials and Cyber Essentials Plus, the UK government-backed certification schemes run by the National Cyber Security Centre. In the meantime, the controls described on this page are in place today. Each school's agreement with us includes the right to audit our compliance. If you would like further information, please contact us at [email protected].

Security white paper

Our security white paper describes each of the controls above in more depth, including the categories of data we process, our sub-processors, retention and deletion, and how we approach AI features. It is available on request to any school considering or using the Workspace. Email [email protected] or your Studee contact and we will send it to you.

Who we are

Studee Ltd is registered in England and Wales, company number 06842641, with its registered office at 15 The Woolmarket, Cirencester, Gloucestershire, GL7 2PR. We are registered with the Information Commissioner's Office under registration number Z2110366. Our Data Protection Officer is Ellie Robertson, [email protected].