Built for schools that take data protection seriously
Saved Student Support Files are encrypted on the teacher's device, and privacy checks are built into every AI request. Explore the safeguards, architecture, and documentation your DPO needs.
How we protect student data
Client-Side Encryption
Saved Student Support Files are encrypted on the teacher's device using AES-256-GCM before reaching our servers, which hold ciphertext and wrapped keys only. During normal operation we have no technical means to decrypt stored files: decryption depends on teacher-held credentials such as the data password or recovery key. Details and exceptions are described in our Privacy Whitepaper.
Privacy Built into AI
SENScribe checks and redacts personal details in the teacher's browser before AI processing.
EU-first hosting
The customer database is hosted in an Azure EU region (West Europe), and supported AI processing uses the EU data zone. A small number of operational providers may process limited data outside the EEA; these exceptions are documented in our Providers & Sub-processors register.
Split-Key Secure Sharing
Secure review links split each decryption key between the application and a separate, database-free email service, so neither service alone can decrypt the shared file. As with any link-based sharing, a recipient who forwards both the email and its link grants access to others, so invitations should be sent only to intended reviewers.
Compliance Documents
Everything your school's Data Protection Officer needs to evaluate SENScribe. Download, share with your principal, or forward to your board of management.
Privacy Policy
GDPR Art. 13/14How SENScribe handles data, processing, retention, and individual rights.
Privacy Whitepaper
For PrincipalsTechnical explainer for Principals and DPOs. Covers client-side encryption and split-key sharing in plain English with data flow diagrams.
School Information Pack
For SchoolsLeadership-ready overview covering school accounts, pricing, onboarding, and practical FAQs for evaluating SENScribe.
Data Processing Agreement
GDPR Art. 28School-facing DPA template ready for your DPO to review. Covers processor obligations, sub-processors, and breach notification.
Data Protection Impact Assessment
GDPR Art. 35Pre-completed DPIA for SENScribe's encrypted sync service. Covers risks, mitigations, and residual risk assessment.
Terms of Service
LegalService terms, acceptable use, liability, and subscription conditions for SENScribe.
Cookie Policy
ePrivacyDetails on strictly necessary cookies (authentication) and optional analytics cookies with consent management.
Accessibility Statement
WCAG 2.2Our commitment to WCAG 2.2 Level AA accessibility and inclusive design for all teachers.
Providers & Sub-processors
Provider registerSchool-service sub-processors and controller-side operational providers, with their purposes and safeguards.
Service Level Agreement
99.5% targetUptime targets, support response times, backup and recovery commitments, and service credit terms.
Sustainability
GPP readyEnvironmental commitments, cloud hosting sustainability, and Green Public Procurement readiness.
Security Measures
Technical safeguards protecting your data at every layer.
These measures correspond to the Technical and Organisational Measures described in Annex 2 of our Data Processing Agreement, so each item above can be traced to a contractual commitment. The current Providers & Sub-processors register is the authoritative list of providers behind these safeguards.
Document control
This Trust Center is a maintained compliance document. We record its ownership, review status, and change history so schools and Data Protection Officers can rely on the version they read.
| Document owner | Data Protection Lead, SENScribe Limited |
| Last reviewed | 24 August 2026 |
| Version | v1.5 |
| Status | Published |
| Next scheduled review | Within 12 months of the last review |
Review log
| Version | Date | Summary of changes |
|---|---|---|
| 1.5 | 24 August 2026 | Governance block introduced; encryption, hosting, and split-key wording made more precise; Article 30 processing summary and EU AI Act readiness position added. |
| Pre-1.5 | Before August 2026 | Earlier revisions were published without an on-page review log. |
Record of processing (GDPR Article 30 summary)
This summary shows how SENScribe acts for each category of data, so your school can complete its own record of processing activities. Full detail is in our Privacy Policy and DPA (Annex 1). We recommend recording SENScribe in your school's register; our whitepaper covers this.
| Data category | SENScribe role | Purpose | Lawful basis | Retention (in general terms) |
|---|---|---|---|---|
| Encrypted Student Support Files | Processor for the school | Secure storage, sync, and sharing of student support records | Determined by the school as controller | Until deleted by the school or handled per offboarding instructions (DPA Clause 12) |
| Browser-redacted AI prompts | Processor for the school | Generating draft support-plan text from teacher input | Determined by the school as controller | Not stored by SENScribe (in-memory processing); flagged prompts may be retained by Microsoft under Azure abuse-monitoring terms |
| Account and service email | Controller (Microsoft primary; Resend fallback) | Delivering password reset and account service emails | Contract (Art. 6(1)(b)) | Kept only as long as needed to deliver and troubleshoot email |
| School-related email (secure review invitations) | Processor for the school (Microsoft primary; Resend fallback outside split-key flows) | Delivering secure review invitations on school instructions | Determined by the school as controller | Deleted or returned under Clause 12 of the DPA; invitation key split so neither service holds both halves |
| Teacher account data | Controller | Account creation, authentication, fair-use limits | Contract (Art. 6(1)(b)) | Personal accounts deleted after 12 months of inactivity; school-controlled records excluded |
| School licence enquiries | Controller | Managing prospective school relationships | Legitimate interests / steps toward a contract | Kept while needed to manage the enquiry, then reviewed or deleted |
| Subscription payments | Controller (billing via Revolut under its own terms) | Processing subscription payments | Contract (Art. 6(1)(b)) | Retained for the life of the subscription and as needed for billing records |
| Product updates & service email | Controller | Account service email; product updates to existing customers (soft opt-in) or with affirmative consent | Contract / legitimate interests (Art. 6(1)(b)/(f)); consent where given; ePrivacy soft opt-in for existing customers | Marketing held while consent stands or the soft-opt-in conditions are met; service records kept as needed for service |
| Website and app analytics | Controller | Understanding and improving the service (consent-gated) | Consent (Art. 6(1)(a) / ePrivacy) | Pseudonymous analytics data retained per cookie settings |
EU AI Act readiness
The EU AI Act applies in stages, with most obligations taking effect from 2 August 2026 and further provisions following later. Our current position:
- Assistive drafting only. The service helps teachers draft documents from their own input. Teachers review, edit, and decide on everything before it is saved or shared. There is no profiling and no automated decision-making about students.
- Not used for student evaluation. SENScribe is not designed or intended for admitting, assessing, grading, or proctoring students, nor for monitoring behaviour during tests.
- Deployer posture.We deploy Microsoft's Azure OpenAI models within an EU data zone under Microsoft's commercial terms. We do not train foundation models.
- Transparency. Our documentation explains where AI is involved and how browser-side redaction works. We disclose AI-assisted drafting in the product interface, consistent with the transparency duties under Article 50 of the EU AI Act that apply from 2 August 2026, and we keep our labelling under review as guidance develops.
- A position, not a certification. This page states our good-faith readiness position and will be updated as guidance and applicable obligations evolve.
Responsible disclosure
We take security seriously and welcome responsible reports from the security community. If you believe you have found a vulnerability in SENScribe, please let us know so we can address it.
How to report
Email security@senscribe.ie with the subject line "Security report".
What to include
- A description of the vulnerability
- Steps to reproduce
- Potential impact
What to expect
- Acknowledgement within 5 business days
- Updates as we investigate and resolve the issue
- Credit in our acknowledgements if you wish (optional)
Scope and rules
- No denial-of-service testing
- No social engineering of staff or users
- Never access real student data
- Test only against your own account
Safe harbour
We will not pursue legal action against good-faith security researchers who follow this policy. We consider responsible disclosure activities conducted in accordance with this policy to be authorised.
Our security contact details are also published at /.well-known/security.txt per RFC 9116.
Questions about compliance?
We're happy to speak with your DPO, Principal, or Board of Management about how SENScribe meets your school's data protection requirements.