01Roles and instructions
The school acts as Controller and NexioraAI as Processor for school personal data. Processing is limited to documented instructions needed to authenticate users, operate the selected modules, provide support, protect the service, and meet agreed legal obligations.
02People and data
Data subjects may include students, guardians, teachers, administrators, and staff. Data may include identity, membership, academic records, assessment content and results, learning materials, activity, support, audit, and limited device or network data.
03Security commitments
Controls include role-aware access, tenant separation, configured encryption, audit evidence, secure-development gates, backup and recovery procedures, incident response, personnel confidentiality, and vendor review proportionate to risk.
04Requests, incidents, and deletion
NexioraAI assists with lawful access, correction, export, restriction, and deletion requests. Suspected personal-data breaches are reported without undue delay within the executed contractual window. On termination, data is returned or deleted under the agreed schedule, legal holds, and backup expiry.
05Subprocessors and transfers
The executed schedule names cloud, database, identity, AI, email, and monitoring providers actually used, including purpose, region, safeguards, and change notice. Cross-border transfers require an approved mechanism.
06Evidence and execution
Schools can request security evidence under confidentiality. Legal entity, hosting region, retention, subprocessors, governing law, liability, and notification window must be completed before signature.