Data processing terms

Responsibilities around customer data

The controller and processor commitments that apply when an organisation stores learner, family and staff information in KAIQ.

Effective 24 August 2026

Controller and processor roles

For personal information a customer enters into its KAIQ workspace, the customer is the controller and KAIQ is the processor. Each party will comply with applicable UK data-protection law and maintain appropriate records of its responsibilities.

Processing instructions

KAIQ processes customer data only on documented instructions contained in the agreement, the customer's use of the service and support requests, unless the law requires otherwise. Processing covers hosting, organising, retrieving, displaying, analysing, transmitting, backing up and deleting information needed to provide KAIQ.

  • Subjects: learners, parents or guardians, tutors, staff and authorised contacts.
  • Data: identity, contact, education, attendance, assessment, communications, account and support records.
  • Purpose: tutoring administration, learning delivery, reporting, communication, security and support.
  • Duration: the subscription term plus the documented deletion and legal-retention period.

Confidentiality and security

KAIQ restricts access to authorised personnel and services, uses tenant and role controls, protects data in transit, manages secrets outside client code, maintains backups and monitoring, and reviews access and vulnerabilities proportionate to the risk. Personnel with access are bound by confidentiality obligations.

Subprocessors and transfers

The customer authorises KAIQ to use subprocessors needed to deliver the service. KAIQ remains responsible for their data-protection obligations and will maintain suitable contractual safeguards. Material new subprocessors will be notified through the service or account contact where required.

Requests, incidents and compliance

Taking account of the nature of processing, KAIQ will reasonably assist customers with data-subject requests, security incidents, impact assessments and regulator enquiries. KAIQ will notify affected customers without undue delay after confirming a personal-data breach involving their workspace.

Return, deletion and audit

At the end of the service, customers may export available records. KAIQ will delete or return customer data after the applicable recovery period unless law requires retention. KAIQ will provide information reasonably needed to demonstrate compliance and support proportionate audits, subject to confidentiality, security and reasonable notice.

Questions or requests

For privacy requests email privacy@kaiq.tech. For account support email support@kaiq.tech.