Trust & Compliance

Built for schools that take data protection seriously

Saved Student Support Files are encrypted on the teacher's device, and privacy checks are built into every AI request. Explore the safeguards, architecture, and documentation your DPO needs.

How we protect student data

Client-Side Encryption

Saved Student Support Files are encrypted on the teacher's device using AES-256-GCM before reaching our servers, which hold ciphertext and wrapped keys only. During normal operation we have no technical means to decrypt stored files: decryption depends on teacher-held credentials such as the data password or recovery key. Details and exceptions are described in our Privacy Whitepaper.

Privacy Built into AI

SENScribe checks and redacts personal details in the teacher's browser before AI processing.

EU-first hosting

The customer database is hosted in an Azure EU region (West Europe), and supported AI processing uses the EU data zone. A small number of operational providers may process limited data outside the EEA; these exceptions are documented in our Providers & Sub-processors register.

Split-Key Secure Sharing

Secure review links split each decryption key between the application and a separate, database-free email service, so neither service alone can decrypt the shared file. As with any link-based sharing, a recipient who forwards both the email and its link grants access to others, so invitations should be sent only to intended reviewers.

Compliance Documents

Everything your school's Data Protection Officer needs to evaluate SENScribe. Download, share with your principal, or forward to your board of management.

Privacy Policy

GDPR Art. 13/14

How SENScribe handles data, processing, retention, and individual rights.

Privacy Whitepaper

For Principals

Technical explainer for Principals and DPOs. Covers client-side encryption and split-key sharing in plain English with data flow diagrams.

School Information Pack

For Schools

Leadership-ready overview covering school accounts, pricing, onboarding, and practical FAQs for evaluating SENScribe.

Data Processing Agreement

GDPR Art. 28

School-facing DPA template ready for your DPO to review. Covers processor obligations, sub-processors, and breach notification.

Data Protection Impact Assessment

GDPR Art. 35

Pre-completed DPIA for SENScribe's encrypted sync service. Covers risks, mitigations, and residual risk assessment.

Terms of Service

Legal

Service terms, acceptable use, liability, and subscription conditions for SENScribe.

Cookie Policy

ePrivacy

Details on strictly necessary cookies (authentication) and optional analytics cookies with consent management.

Accessibility Statement

WCAG 2.2

Our commitment to WCAG 2.2 Level AA accessibility and inclusive design for all teachers.

Providers & Sub-processors

Provider register

School-service sub-processors and controller-side operational providers, with their purposes and safeguards.

Service Level Agreement

99.5% target

Uptime targets, support response times, backup and recovery commitments, and service credit terms.

Sustainability

GPP ready

Environmental commitments, cloud hosting sustainability, and Green Public Procurement readiness.

Security Measures

Technical safeguards protecting your data at every layer.

AES-256-GCM encryption at rest (teacher-side)
TLS 1.2+ encryption in transit
Passwords hashed with scrypt
Azure Cosmos DB with server-side encryption
AI privacy-validation errors omit request content
Sessions expire after 7 days of inactivity (secure cookies)
Rate limiting on all endpoints
Automated dependency vulnerability scanning

These measures correspond to the Technical and Organisational Measures described in Annex 2 of our Data Processing Agreement, so each item above can be traced to a contractual commitment. The current Providers & Sub-processors register is the authoritative list of providers behind these safeguards.

Document control

This Trust Center is a maintained compliance document. We record its ownership, review status, and change history so schools and Data Protection Officers can rely on the version they read.

Document ownerData Protection Lead, SENScribe Limited
Last reviewed24 August 2026
Versionv1.5
StatusPublished
Next scheduled reviewWithin 12 months of the last review

Review log

VersionDateSummary of changes
1.524 August 2026Governance block introduced; encryption, hosting, and split-key wording made more precise; Article 30 processing summary and EU AI Act readiness position added.
Pre-1.5Before August 2026Earlier revisions were published without an on-page review log.

Record of processing (GDPR Article 30 summary)

This summary shows how SENScribe acts for each category of data, so your school can complete its own record of processing activities. Full detail is in our Privacy Policy and DPA (Annex 1). We recommend recording SENScribe in your school's register; our whitepaper covers this.

Data categorySENScribe rolePurposeLawful basisRetention (in general terms)
Encrypted Student Support FilesProcessor for the schoolSecure storage, sync, and sharing of student support recordsDetermined by the school as controllerUntil deleted by the school or handled per offboarding instructions (DPA Clause 12)
Browser-redacted AI promptsProcessor for the schoolGenerating draft support-plan text from teacher inputDetermined by the school as controllerNot stored by SENScribe (in-memory processing); flagged prompts may be retained by Microsoft under Azure abuse-monitoring terms
Account and service emailController (Microsoft primary; Resend fallback)Delivering password reset and account service emailsContract (Art. 6(1)(b))Kept only as long as needed to deliver and troubleshoot email
School-related email (secure review invitations)Processor for the school (Microsoft primary; Resend fallback outside split-key flows)Delivering secure review invitations on school instructionsDetermined by the school as controllerDeleted or returned under Clause 12 of the DPA; invitation key split so neither service holds both halves
Teacher account dataControllerAccount creation, authentication, fair-use limitsContract (Art. 6(1)(b))Personal accounts deleted after 12 months of inactivity; school-controlled records excluded
School licence enquiriesControllerManaging prospective school relationshipsLegitimate interests / steps toward a contractKept while needed to manage the enquiry, then reviewed or deleted
Subscription paymentsController (billing via Revolut under its own terms)Processing subscription paymentsContract (Art. 6(1)(b))Retained for the life of the subscription and as needed for billing records
Product updates & service emailControllerAccount service email; product updates to existing customers (soft opt-in) or with affirmative consentContract / legitimate interests (Art. 6(1)(b)/(f)); consent where given; ePrivacy soft opt-in for existing customersMarketing held while consent stands or the soft-opt-in conditions are met; service records kept as needed for service
Website and app analyticsControllerUnderstanding and improving the service (consent-gated)Consent (Art. 6(1)(a) / ePrivacy)Pseudonymous analytics data retained per cookie settings

EU AI Act readiness

The EU AI Act applies in stages, with most obligations taking effect from 2 August 2026 and further provisions following later. Our current position:

  • Assistive drafting only. The service helps teachers draft documents from their own input. Teachers review, edit, and decide on everything before it is saved or shared. There is no profiling and no automated decision-making about students.
  • Not used for student evaluation. SENScribe is not designed or intended for admitting, assessing, grading, or proctoring students, nor for monitoring behaviour during tests.
  • Deployer posture.We deploy Microsoft's Azure OpenAI models within an EU data zone under Microsoft's commercial terms. We do not train foundation models.
  • Transparency. Our documentation explains where AI is involved and how browser-side redaction works. We disclose AI-assisted drafting in the product interface, consistent with the transparency duties under Article 50 of the EU AI Act that apply from 2 August 2026, and we keep our labelling under review as guidance develops.
  • A position, not a certification. This page states our good-faith readiness position and will be updated as guidance and applicable obligations evolve.

Responsible disclosure

We take security seriously and welcome responsible reports from the security community. If you believe you have found a vulnerability in SENScribe, please let us know so we can address it.

How to report

Email security@senscribe.ie with the subject line "Security report".

What to include

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact

What to expect

  • Acknowledgement within 5 business days
  • Updates as we investigate and resolve the issue
  • Credit in our acknowledgements if you wish (optional)

Scope and rules

  • No denial-of-service testing
  • No social engineering of staff or users
  • Never access real student data
  • Test only against your own account

Safe harbour

We will not pursue legal action against good-faith security researchers who follow this policy. We consider responsible disclosure activities conducted in accordance with this policy to be authorised.

Our security contact details are also published at /.well-known/security.txt per RFC 9116.

Questions about compliance?

We're happy to speak with your DPO, Principal, or Board of Management about how SENScribe meets your school's data protection requirements.

Tutorials