Qlix logo
  • Home
  • Pricing
LoginStart for free

DPIA Support Pack

Introduction

  1. This is Qlix's DPIA Support Pack. A Data Protection Impact Assessment is the Customer's document - it is your school's or trust's legal responsibility under UK GDPR Article 35, not Qlix's. Qlix has pre-filled everything it can answer from its own side of the processing, so that your data protection officer only has to complete the parts that are genuinely yours: your purposes, your context, your pupils, and your judgement calls. Independent private tutors can use this pack too, adapting the sections that assume a school structure.

    Each section below is labelled Pre-filled by Qlix, Customer to complete, or Joint to show who is expected to do the work.

    Not legal advice. This pack is a starting point, not a substitute for your own assessment or, where appropriate, advice from your data protection officer or legal counsel.

  2. Qlix Limited · Version 1.0 · 23 July 2026 · Contact: privacy@qlixapp.com

  3. See also the Data Processing Agreement, the technical and organisational measures document, and our trust and security page.

How to use this pack

    1. Work through Steps 1 to 10 in order. Each step says who is expected to complete it.
    2. Where Qlix has pre-filled a section, check it against your own use of the Services - the pre-filled content describes Qlix's product and infrastructure, not your school's specific configuration or context.
    3. In Step 10 (Sign-off), complete the fields marked for you. Qlix has already filled its own preparation line.
    4. Keep the completed DPIA on file. Qlix does not need a copy, but we are glad to review it or join a call with your DPO at no charge.

Step 1 - Identify the need for a DPIA

  1. Joint - Qlix sets out the relevant facts; the decision on whether a DPIA is required is the Customer's.

  2. The ICO's screening criteria, applied to typical use of the Services:

  3. ICO criterion Applies to Qlix use? Notes
    Use of new or innovative technology Possibly AI-assisted lesson planning, marking support, and messaging features
    Systematic monitoring or profiling Yes Markbook and assessment records involve profiling of pupil attainment (see Step 6)
    Large-scale processing Depends on size Assess against your own pupil and staff numbers
    Data concerning vulnerable individuals Yes Pupils are children; the Services may also hold SEN-related notes if your school chooses to enter them
    Special category or highly personal data Conditional Only if your school enters SEN or health-related notes
    Data matching or combining datasets No Qlix does not combine your data with data from other sources or other customers
    Processing that prevents individuals exercising a right No Pupils and staff retain normal rights; see the Privacy Policy
    Novel use of an existing technology No Standard SaaS architecture
  4. Because at least one criterion (data concerning children, and systematic profiling of attainment) is likely to apply to most schools, the ICO's own guidance suggests a DPIA is good practice even where it is not strictly mandatory. Your DPO should record the decision either way.

Step 2 - Describe the processing

  1. Pre-filled by Qlix.

  2. Data flow. Staff create accounts and enter class, timetable, and pupil information. Teaching content (lesson plans, worksheets, activities) is created and optionally shared or published. Pupil-specific content (submissions via QlixGo, marks, assessment records, teacher notes) is created and stored separately. Where AI features are used, relevant content is pseudonymised and sent to Amazon Bedrock in the UK for inference, and the response is returned to the user. All data is stored on Amazon Web Services infrastructure in London, United Kingdom.

  3. Segregation of pupil data from shareable content:

  4. Record type Contains pupil personal data Shareable or publishable
    Resources - lesson plans, worksheets, activities No Yes
    Assignments - a Resource linked to a class Class membership only No
    Markbook and assessment records Yes No
  5. There is no configuration in which a pupil record, submission, mark, or teacher note can be attached to a shared or published item. A persistent visual warning is displayed whenever content is shared outside the school or made public.

  6. Storage location. All application data, databases, file storage, and backups are held on Amazon Web Services in London, United Kingdom. AI inference is performed on Amazon Bedrock, also in London, United Kingdom. No pupil data is stored or processed outside the UK by default. Qlix is incorporated in Hong Kong SAR, but this is Qlix's place of incorporation only - Qlix has no personnel based there and no pupil data is accessed from Hong Kong SAR. Remote access by Qlix personnel outside the UK is limited to personnel based in Thailand, and is a restricted transfer under a UK IDTA supported by a published Transfer Risk Assessment - see the DPA, Clause 6, and the Transfer Risk Assessment.

  7. Retention. Pupil personal data is retained while the school's account is active, and for 30 days after termination, after which it is deleted (backup copies within 90 days), unless the school instructs earlier deletion. Server and access logs are retained for 90 days. Full detail is in the DPA Clause 4.6 and the Privacy Policy.

Step 3 - Scope

  1. Customer to complete.

  2. Record which parts of the Services your school actually uses, since the risk profile depends on this:

    • QlixGo (pupil-facing surface for completing and submitting work)
    • Markbook and assessment records
    • AI-assisted features (lesson planning, marking support, messaging) - and whether SEN or other special category notes are included in AI context
    • Messaging between staff, and between staff and pupils via QlixGo
    • Public sharing of Resources (QlixSocial or export)
    • Number of pupils and staff whose data is held
    • Whether any pupils have SEN-related or other special category notes recorded

Step 4 - Context

  1. Joint.

  2. Pre-filled by Qlix: Qlix is an education product used by teaching staff to plan, deliver, and assess lessons. Pupils accessing QlixGo do not hold a personal account or credentials of their own; identifiers are set by the teacher (a first name, initial, or code) and no email address, home address, phone number, date of birth, payment information, or device location is collected from pupils. There is no parent or guardian account model as standard.

  3. Customer to complete: describe your specific context, including: the age range of pupils affected; whether any cohort is considered particularly vulnerable (for example pupils with SEN, in care, or subject to safeguarding plans); whether pupils, parents, or staff have raised any concerns about use of the Services; and any relevant school policy (acceptable use, safeguarding, SEN) that governs how staff use the product.

Step 5 - Purposes

  1. Customer to complete.

  2. Describe why your school processes pupil and staff data through Qlix. Typical purposes include: delivering the curriculum; recording and reporting attainment; supporting pastoral and SEN provision; internal school administration; and statutory reporting obligations. Qlix processes Customer Data only for the purposes you instruct via your use of the Services (see the DPA, Clause 3) - it does not independently determine why the data is collected.

Step 6 - Evaluation, scoring, and profiling

  1. Joint.

  2. Pre-filled by Qlix: the markbook and assessment features necessarily involve evaluation and profiling of pupil attainment - marks, grades, and progress against targets. This is standard educational record-keeping, carried out on your instructions.

  3. Meaningful human review (Articles 22A–22D UK GDPR). Where a decision about a pupil is based on data from the Services and could be considered a "setting" decision (for example grouping, streaming, or target-setting) or an "intervention" decision (for example flagging a pupil for additional support or a referral), Qlix's role is limited to presenting data and, where AI features are used, draft suggestions. No such decision is made solely by automated means: every mark, grade, flag, or AI-generated suggestion is a draft that a member of your teaching staff must review, and can edit, override, or discard, before it has any effect on a pupil. This is designed to meet the safeguards required for automated decision-making under UK GDPR - meaningful human involvement, the ability to obtain an explanation, and the ability to contest an outcome.

  4. Customer to complete: confirm in your own policies that a named member of staff reviews any setting or intervention decision before it is acted on, and that pupils or parents can ask for an explanation or challenge a decision through your normal school complaints or appeals process.

Step 7 - Consultation

  1. Customer to complete, with Qlix available to assist.

  2. Consider who should be consulted before or during the assessment: your DPO or privacy lead; senior leadership; teaching staff who will use the Services day to day; and, where proportionate, pupils, parents, or governors - particularly if SEN data or AI features are in scope. Qlix, as processor, is available to join a call with your DPO at no charge (contact privacy@qlixapp.com), and can answer factual questions about the processing but cannot make the necessity or proportionality judgement on your behalf.

Step 8 - Necessity and proportionality

  1. Joint - Qlix provides guidance; the Customer selects and records its own lawful basis.

  2. Lawful basis guidance:

  3. Customer type Likely lawful basis (Article 6) Special category condition (Article 9), if SEN or health notes are entered
    Maintained school or academy trust Public task (Article 6(1)(e)), reflecting statutory education functions Substantial public interest condition, typically supported by your school's Appropriate Policy Document
    Independent school Legitimate interests (Article 6(1)(f)) or contract with parents (Article 6(1)(b)) Substantial public interest condition or explicit consent, as advised by your DPO
    Independent private tutor Contract with the client (Article 6(1)(b)) or legitimate interests Explicit consent is usually the most practical condition for an individual tutor
  4. Your DPO should record the specific basis chosen, not just the category, and confirm it is documented in your privacy notice to parents and pupils.

  5. Necessity and proportionality checklist:

    • Is the data entered into the Services limited to what is needed for teaching, assessment, and pastoral purposes? Qlix does not require SEN or other special category data to operate core features - it is optional and school-controlled.
    • Have you considered whether a less intrusive alternative (for example, keeping SEN notes in a separate, more restricted system) is more proportionate for any particularly sensitive cases?
    • Is access to sensitive notes within the Services limited, at your school, to staff who need it?

Step 9 - Risk register

  1. Pre-filled by Qlix where the measure is Qlix's; Customer to complete likelihood, impact, and residual risk based on your own context.

  2. ID Risk Qlix measure Customer measure Likelihood / impact / residual risk
    R1 Unauthorised external access to pupil records TLS in transit, AES-256 at rest, MFA on admin access, least-privilege access control Strong staff passwords/passkeys; report suspected compromise promptly Customer to complete
    R2 Internal misuse - staff accessing pupil data beyond their need Role-based access control; access logging Assign roles appropriately; review staff access periodically Customer to complete
    R3 Loss or corruption of data Daily backups retained 30 days, held separately within the UK; documented restore procedure Periodically confirm exports work for your records Customer to complete
    R4 Personal data breach not identified or notified in time Documented incident response procedure; breach notified to Customer within 24 hours of Qlix becoming aware Maintain an up-to-date DPO contact with Qlix; have your own breach procedure ready to receive Qlix's notification Customer to complete
    R5 Pupil data mistakenly included in a shared or published Resource Structural separation between shareable Resources and non-shareable pupil records; persistent warning banner on shared/public content Staff guidance not to paste pupil names into shareable Resource text; spot-check published content Customer to complete
    R6 Identifiable pupil data exposed to the AI model, or used to train a model Pseudonymisation before AI transmission; contractual no-training commitment (see DPA Clause 3.4) surviving termination Instruct staff not to type pupil names into free-text AI prompts even though tokens are used Customer to complete
    R7 Excessive retention of leaver data Automatic deletion 30/90 day workflow on termination or account closure Instruct Qlix promptly when a pupil or member of staff leaves, if earlier deletion is wanted Customer to complete
    R8 Over-collection of special category (SEN) data SEN fields are optional, not required for core use Enter only what is necessary; agree internal guidance on what belongs in free-text notes Customer to complete
    R9 International transfer / overseas personnel access UK hosting for all storage and AI inference; remote access limited to personnel in Thailand (Qlix has no personnel in, and no data is accessed from, Hong Kong SAR, which is incorporation only); governed by UK IDTA, MFA, logging, and need-to-know limits None required beyond standard due diligence; the published Transfer Risk Assessment and the ICO IDTA template cover this Customer to complete
    R10 Sub-processor failure or breach Written data protection terms with every sub-processor; Qlix remains liable for sub-processor performance; 30 days' notice of change Review the sub-processor list at /trust periodically; raise objections within the notice period if needed Customer to complete
    R11 Automated decision-making without adequate human review No solely automated significant decisions; all markbook/AI output is a draft for staff review (see Step 6) Confirm in school policy that staff review setting/intervention decisions before acting on them Customer to complete
    R12 Inaccurate data leading to an incorrect intervention or missed support need Self-service correction tools in-product; export/audit trail Periodic data quality checks; encourage staff to correct records promptly Customer to complete
    R13 Safeguarding disclosure mishandled within the product Messaging and notes features log content for accountability; access controls limit visibility Follow your safeguarding policy for anything disclosed via the Services; do not rely on the Services as a safeguarding reporting system in place of statutory routes Customer to complete
    R14 Loss of service availability UK infrastructure with backup and restore procedures; recovery time objective 1 hour, recovery point objective 24 hours Maintain a fallback process for critical periods (for example exam periods) in case of an outage Customer to complete
    R15 Data subject rights request mishandled Requests received directly by Qlix forwarded to the Customer within 3 working days; self-service export/deletion in-product Have a documented process for handling access, correction, and deletion requests from pupils, parents, and staff Customer to complete

Step 10 - Sign-off

  1. Customer to complete.

  2. Field Detail
    DPIA prepared by Qlix Limited
    Reviewed by (DPO or equivalent) [Customer to complete]
    Outcome [Customer to complete]
    Outstanding actions [Customer to complete]
    Review date [Customer to complete]

Appendix A - Frequently asked questions

  1. Question Answer
    Where is our data stored? London, United Kingdom, on Amazon Web Services. AI inference also runs in London, on Amazon Bedrock.
    Is Qlix Limited a UK company? No. Qlix Limited is incorporated in Hong Kong SAR (company number 74458271) but has an establishment in the United Kingdom for UK GDPR purposes and is subject to ICO supervision. See the DPA, Clause 13.
    Does Qlix train AI models on our pupils' data? No. This is a contractual commitment that survives termination - see the DPA, Clause 3.4.
    Can Qlix staff outside the UK access our data? Only staff based in Thailand, under controlled, logged, time-limited access governed by a UK International Data Transfer Agreement and a published Transfer Risk Assessment - see the DPA, Clause 6. Qlix has no staff based in, and no data is accessed from, Hong Kong SAR, which is Qlix's place of incorporation only.
    Does Qlix hold ISO 27001 or SOC 2? No. Qlix is a small team and would rather state this plainly than imply certifications it has not earned. Ask us directly if your procurement process requires a specific certification.
    Has Qlix had a penetration test? No independent penetration test currently held; automated dependency and container scanning in place. Ask privacy@qlixapp.com if you need further detail for procurement.
    Is there a parent or guardian portal? Not as standard. Parent or guardian data only appears in the Services if a member of school staff chooses to enter it.
    What happens to our data if we leave? You can export data at any time before termination. Live data is deleted within 30 days of termination, and backup copies within 90 days.
    Does Qlix send push notifications to pupils? No. OneSignal is not used to send push notifications to students.
    Does error monitoring (Sentry) run on the pupil-facing product? Yes. Sentry runs on QlixGo for application error monitoring, but no user personal data is sent in those error events.
    Who do we contact about a data protection question? privacy@qlixapp.com.

Appendix B - Related duties

  1. Complaints duty. Qlix will forward any complaint or data subject request it receives directly, relating to Customer Data, to the Customer within 3 working days (see the DPA, Clause 4.3). Your school remains responsible for handling and responding to complaints about your own processing, and pupils, parents, and staff retain the right to complain to the ICO at any time.

  2. Children's Code (Age Appropriate Design Code). The ICO's Children's Code is aimed primarily at online services offered directly to children, such as consumer apps and social media. QlixGo is provided to pupils by their school, for teaching and assessment purposes, and pupils do not hold a personal account, so the Code's direct-to-consumer design obligations are unlikely to apply in the way they would to a standalone children's app. Qlix nonetheless designs QlixGo consistently with the Code's underlying principles: no accounts or credentials for pupils, no advertising, no behavioural tracking or profiling beyond attainment, no analytics of any kind on the pupil-facing surface, and privacy-protective settings by default. Schools should still consider the Code in their own DPIA where they operate any parent- or child-facing communication alongside the Services.

  3. Business continuity. Data is backed up daily and retained for 30 days, held separately from primary infrastructure within the United Kingdom. Qlix's documented restore procedure is tested quarterly. Recovery time objective is 1 hour; recovery point objective is 24 hours. Schools relying on the Services during high-stakes periods (for example exam windows) should maintain a manual fallback for critical records.

  4. Qlix Limited · Company number 74458271 · Rooms 1703-1704, 17/F Tung Chiu Commercial Centre, 193 Lockhart Road, Wan Chai, Hong Kong SAR · privacy@qlixapp.com

  5. This DPIA Support Pack is provided as general guidance for schools, trusts, and tutors completing their own Data Protection Impact Assessment. It is not legal advice and does not replace your own assessment or advice from your data protection officer or legal counsel.

Qlix logo

Qlix is the teaching workspace built by teachers: timetable, lessons and resources in one place, plus an AI assistant that already knows your classes. Plan anywhere. Teach with confidence.

Links
  • About us
  • FAQs
  • Trust and security
  • Contact us
Legal
  • Terms and conditions
  • Privacy policy
  • Cookie policy
Follow us
  • Facebook
  • X (Twitter)
  • LinkedIn

© 2026 Qlix. Qlix Limited is a registered company in Hong Kong SAR company number 74458271. Icon Pond icons and country flags made by Freepik are from flaticon.com and are licensed by CC 3.0 BY. Illustrations by pch.vector, Storyset, and studiogstock on Freepik.