Technical and Organisational Measures
Introduction
This document describes the technical and organisational measures Qlix applies to protect personal data, as required by Articles 28(3)(c) and 32 of the UK GDPR. It is provided to schools, tutors and their data protection officers, and forms part of our Data Processing Agreement as Schedule 2.
Every statement in this document must be true on the day it is published. Where a measure is planned rather than in place, it is marked as such. We would rather understate our position than describe controls we have not built.
Qlix Limited · Version 1.0 · 23 July 2026
1. Data location
Application, database, file storage Amazon Web Services, London, United Kingdom AI inference Amazon Bedrock, London, United Kingdom Backups Separate location within the United Kingdom Data stored outside the UK None Qlix Limited is incorporated in Hong Kong SAR. This is the place of incorporation only: no personnel are located there and no access to customer data takes place from Hong Kong SAR.
Qlix personnel are located in the United Kingdom and Thailand. Remote access from Thailand is treated as a restricted transfer and is governed by a UK International Data Transfer Agreement supported by a documented Transfer Risk Assessment.
2. Access control
- Role-based access control on a least-privilege basis
- Multi-factor authentication required for all administrative and production access
- Named-individual accounts; no shared credentials for production systems
- Access reviewed at least annually and revoked within 24 hours of role change or departure
- Separate credential sets for production and non-production environments
- Production access logged, with logs retained for 90 days
3. Encryption
- TLS 1.2 or above enforced for all data in transit
- AES-256 encryption at rest for databases, object storage and backups
- Encryption keys managed through AWS Key Management Service
4. Data segregation
Qlix holds teaching content and student records in structurally separate stores, and only one is shareable:
Record type Contains student personal data Shareable Resources - lesson plans, worksheets, activities No Yes Assignments - resource linked to a class Class membership only No Markbook and assessment records Yes No There is no configuration in which a student record, submission, mark or teacher note can be attached to a shared or published item. A persistent visual warning is displayed whenever content is shared outside the school or made public.
5. Pseudonymisation
- Student names and direct identifiers are replaced with pseudonymous tokens before any content is transmitted for AI inference
- The token mapping is held separately within UK infrastructure and is never transmitted
- No analytics, advertising or behavioural tracking technologies operate on QlixGo, the student-facing surface
6. Application security
- Input validation and parameterised database queries
- Session management with configurable timeout
- Passwords stored using a modern adaptive hashing algorithm
- Passkey authentication supported
- Rate limiting on authentication endpoints
- Cross-site request forgery protection on state-changing operations
7. Infrastructure and network security
- Segregated production environment; production data is never used in development or testing
- Managed firewall and security group configuration on a default-deny basis
- Automated dependency and container vulnerability scanning
- Security patches applied within 14 days for high and critical severity findings
- Change management process for production deployments
8. Resilience, backup and recovery
- Automated daily backups, retained 30 days
- Backups held separately from primary infrastructure, within the United Kingdom
- Documented restore procedure, tested quarterly
- Recovery time objective: 1 hour
- Recovery point objective: 24 hours
9. Organisational measures
- Written confidentiality obligations for all personnel and contractors, surviving termination of engagement
- Data protection training for all personnel with access to customer data, at least annually
- Documented incident response procedure with defined escalation and notification steps
- Personal data breaches notified to the controller within 24 hours of Qlix becoming aware
- Named data protection contact maintained for each customer
10. Sub-processor management
- Written data protection terms in place with every sub-processor
- Sub-processor register maintained and published on our trust and security page
- 30 days' written notice before any sub-processor is added or replaced
- Right for the customer to object on reasonable data protection grounds
11. Data subject rights and deletion
- Self-service export and deletion available in-product at any time
- Requests received directly from data subjects are forwarded to the controller within 3 working days and are not answered substantively by Qlix
- On termination: export available for 30 days; live data deleted within 30 days; backup copies deleted within 90 days
- Written confirmation of deletion provided on request
12. AI processing
- Inference performed in the United Kingdom (Amazon Bedrock, London)
- Content pseudonymised before transmission
- Customer data is never used to train, fine-tune or evaluate any AI model. This is a contractual commitment that survives termination, and our AI sub-processor is contractually prohibited from doing the same
- AI context is controllable by the customer at organisation and individual user level
- All AI output is presented as a draft for review by a member of teaching staff; no significant decisions are made solely by automated means
13. Certifications and registrations
UK GDPR status Qlix Limited has an establishment in the United Kingdom and is subject to the direct supervision of the Information Commissioner's Office ISO 27001 Not held SOC 2 Not held Penetration testing No independent penetration test currently held; automated dependency and container scanning in place We are a small team. We would rather state plainly what we do not hold than imply certifications we have not earned. If your procurement process requires ISO 27001 or SOC 2, please tell us early so neither of us wastes time.
14. Reporting a security issue
Report suspected vulnerabilities to security@qlixapp.com. We acknowledge within two working days and will keep you informed while we investigate. We will not pursue researchers who report in good faith, give us reasonable opportunity to remediate before public disclosure, and do not access or modify data belonging to others.
Qlix Limited · Company number 74458271 · Rooms 1703-1704, 17/F Tung Chiu Commercial Centre, 193 Lockhart Road, Wan Chai, Hong Kong SAR