Qlix logo
  • Home
  • Pricing
LoginStart for free

Transfer Risk Assessment

Introduction

  1. This is Qlix's public Transfer Risk Assessment ("TRA"). It supports the UK International Data Transfer Agreement ("IDTA") referred to in the Data Processing Agreement, Clause 6, and explains why Qlix's arrangements for remote personnel access outside the United Kingdom present a low residual risk to Customer Data.

    Status: Public standard assessment. Not legal advice. This is a generic assessment published for transparency; a school, academy trust, or private tutor relying on it commercially should have its own solicitor review it, and the completed IDTA, before signing, if that is important to them.

  2. Qlix Limited · Version 1.0 · 23 July 2026

Transfer Risk Assessment

  1. Exporter the Customer (United Kingdom Controller) - the school, academy trust, or independent private tutor using the Services
    Importer Qlix Limited, Processor, incorporated in Hong Kong SAR, company number 74458271
    Transfer tool UK International Data Transfer Agreement (IDTA)
    Transfer at issue Remote access to Customer Data by Qlix personnel located outside the United Kingdom, for support, operations, and development purposes
    Confirmed position Qlix has no personnel based in, and no Customer Data is accessed from, Hong Kong SAR. Hong Kong SAR is Qlix Limited's place of incorporation only. Remote access outside the UK, where it occurs, is from Thailand
    Governing DPA clause Data Processing Agreement, Clause 6 and Schedule 4

1. Details of the transfer

  1. 1.1 What is transferred. Customer Data is not routinely copied, moved, or stored outside the United Kingdom. The transfer assessed here is remote access - a Qlix team member outside the UK viewing or interacting with Customer Data that remains hosted in the UK, typically to answer a support query, investigate a fault, or carry out engineering work.

  2. 1.2 Where the data is at rest. All Customer Data is stored and processed on Amazon Web Services infrastructure in London, United Kingdom. AI inference runs on Amazon Bedrock, also in London, United Kingdom. Backups are held in a separate location within the United Kingdom. No Customer Data is stored outside the UK.

  3. 1.3 Who may access remotely. Qlix Limited is incorporated in Hong Kong SAR but has no personnel based there. Personnel who may need remote access to Customer Data are based in the United Kingdom or Thailand. Access from Thailand is the only overseas personnel access in scope of this assessment.

  4. 1.4 Frequency and nature of access. Remote access is occasional and purpose-limited - it is not continuous or bulk access. It is used for named-individual, need-to-know support and engineering tasks, not for independent processing of Customer Data for Qlix's own purposes.

  5. 1.5 Legal basis for the transfer. The Customer is Controller and Qlix is Processor of Customer Data under the Data Processing Agreement. This TRA, together with the IDTA, is the transfer mechanism under Article 46 UK GDPR that permits remote access from outside the United Kingdom.

2. Data being transferred

  1. 2.1 Categories of data subjects. Pupils or students, and staff, of the Customer, as described in Schedule 1 to the Data Processing Agreement.

  2. 2.2 Categories of personal data. Potentially any Customer Data visible within the Services during a support or engineering task - for example account and profile information, class and timetable structures, markbook and assessment entries, messages, and content of lesson plans or notes. Special category data (in particular special educational needs or health-related notes, where the Customer has chosen to enter it) may be visible if it is present in the record being investigated.

  3. 2.3 Volume and duration. Access is limited to what is necessary to resolve the specific support ticket, incident, or engineering task in hand - not a general export or bulk transfer of records. Access is time-limited and does not result in a copy of Customer Data being retained outside the United Kingdom.

  4. 2.4 Sensitivity. Because Customer Data concerns children and may include special category data, Qlix treats this as a higher-sensitivity transfer and applies the supplementary measures in Section 6 accordingly, rather than relying on the transfer tool alone.

3. Enforceability of the IDTA

  1. 3.1 Importer's presence. Qlix Limited has an establishment in the United Kingdom for UK GDPR purposes and is subject to the direct supervision of the Information Commissioner's Office. The Customer's DPA and this TRA are governed by the laws of England and Wales.

  2. 3.2 Contractual enforceability. The IDTA is the ICO's own prescribed transfer tool. It gives the Customer, as exporter, directly enforceable rights against Qlix, as importer, including the ability to bring proceedings in the courts of England and Wales and to seek an injunction, specific performance, or damages for breach.

  3. 3.3 Practical enforceability. Qlix is a UK-establishment business with a UK bank account, UK contracting entity relationships, and ongoing commercial reasons to comply - it is not a shell entity without a practical connection to the jurisdiction. Qlix has not been the subject of any regulatory or judicial order in Hong Kong SAR, Thailand, or elsewhere requiring disclosure of Customer Data, and has no reason to expect one given the nature of the Services.

  4. 3.4 No conflicting local law identified. Qlix is not aware of any law in Hong Kong SAR or Thailand that would prevent Qlix, or a Qlix employee or contractor located there, from complying with the IDTA's terms, including its obligations on confidentiality, security, and cooperation with the exporter and the ICO.

  5. 3.5 Conclusion on enforceability. The IDTA is capable of being enforced in practice, and there is no identified legal or practical obstacle to Qlix honouring it.

4. Laws and practices of the destination countries

  1. 4.1 Hong Kong SAR - incorporation only, not a destination for this transfer. Hong Kong SAR is Qlix Limited's place of incorporation. No Qlix personnel are based in Hong Kong SAR, and no remote access to Customer Data occurs from Hong Kong SAR. A company's place of incorporation does not, of itself, create a transfer of personal data. This section addresses Hong Kong SAR only for completeness and transparency, given Qlix's corporate domicile; it is not assessed as a destination of access because no access occurs there.

  2. 4.2 Thailand - the relevant destination. Thailand is where Qlix personnel may remotely access Customer Data. Thailand has its own comprehensive data protection law, the Personal Data Protection Act 2019 ("PDPA"), enforced by the Personal Data Protection Committee, and is a signatory to relevant international human rights instruments. Thailand's PDPA imposes obligations on data handlers broadly consistent in aim with UK GDPR principles, including purpose limitation, security, and data subject rights, although it is not the subject of a UK adequacy decision.

  3. 4.3 Government access considerations (Thailand). Thai law permits government authorities to compel disclosure of data in defined circumstances (for example under criminal investigation or national security powers), subject to legal process. Qlix has not received, and has no reason to expect, any such request in connection with Customer Data, given that the Services are an education product with no content of the kind typically targeted by national security powers. Qlix has not enabled, and will not enable, any government or law enforcement authority with direct, unmediated access to its systems.

  4. 4.4 Oversight and redress. Thailand's PDPA provides a route for individuals to complain to the Personal Data Protection Committee. In addition, and independently of Thai law, the Customer's Data Subjects retain their normal rights against the Customer as Controller, and against Qlix as Processor under the Data Processing Agreement and this TRA, enforceable in the courts of England and Wales.

  5. 4.5 Overall assessment. Neither destination country's laws or practices are assessed as likely, in the context of an education SaaS product with no content of intelligence or national-security interest, to undermine the protection given by the IDTA and the supplementary measures below.

5. Residual risk assessment

  1. 5.1 Taking Sections 1 to 4 together:

    • the transfer is narrow in scope - remote access to data that remains hosted in the UK, not bulk transfer or overseas storage;
    • the importer (Qlix) is enforceable against, has a UK establishment, and has no history of, or exposure to, compelled disclosure of this kind of data;
    • the destination country genuinely engaged by this transfer (Thailand) has its own data protection law and no elevated profile for the kind of government access that would defeat the IDTA's protections in this context;
    • Hong Kong SAR is not itself a destination of access and does not add to the risk;
    • substantial technical and organisational supplementary measures, set out in Section 6, further reduce risk independently of the legal analysis above.
  2. 5.2 Conclusion: the residual risk to Data Subjects from this transfer is low.

6. Supplementary measures

  1. In addition to the IDTA itself, Qlix applies the following supplementary measures to remote access from outside the United Kingdom:

    • Data minimisation by design. Customer Data remains hosted and stored solely in the United Kingdom; remote access is to data in place, not a copy exported overseas.
    • Least privilege and named individuals. Access is limited to specific, named individuals who require it for the task at hand, not standing access for an entire team.
    • Multi-factor authentication. Required for all access to production systems, regardless of location.
    • Logging and time limits. Access is logged and time-limited, so that it can be reviewed and does not persist beyond the task requiring it.
    • Reduced exposure for support staff. Support personnel do not routinely access Customer Data containing pupil records as part of day-to-day work.
    • Pseudonymisation for AI. Where AI features are used, student names and direct identifiers are pseudonymised before any content is transmitted for inference; the mapping is held only in UK infrastructure. See the Data Processing Agreement, Clause 4.7.
    • Confidentiality obligations. All personnel with potential access, wherever located, are bound by confidentiality obligations that survive the end of their engagement.
    • No independent processing. Personnel accessing Customer Data remotely act only on Qlix's instructions as Processor; they do not process Customer Data for any independent purpose.
    • Contractual no-training commitment. Customer Data is never used to train, fine-tune, or evaluate any AI model, wherever the personnel involved are located. See the Data Processing Agreement, Clause 3.4.
  2. These measures are also described in full in Qlix's technical and organisational measures document.

7. Conclusion

  1. 7.1 Having assessed the transfer, the data involved, the enforceability of the IDTA, and the laws and practices of the destination countries genuinely engaged by this transfer, Qlix concludes that the IDTA, together with the supplementary measures in Section 6, provides Data Subjects with a standard of protection that is not undermined by the transfer, and that the residual risk is low.

  2. 7.2 This conclusion depends on the confirmed position at the top of this document remaining accurate - namely, that Qlix has no personnel based in Hong Kong SAR and that no Customer Data is accessed from Hong Kong SAR. Qlix will notify Customers under Clause 5.3 of the Data Processing Agreement if that position changes in a way that affects this assessment, and will update this TRA accordingly.

  3. 7.3 Assessment record:

  4. Field Detail
    Assessment completed by Qlix Limited
    Next review date Annually, or on any change to where Qlix personnel are based
    Access and support logs retained for 90 days

Completing the IDTA for your school

  1. This TRA is designed to sit behind a completed IDTA between the Customer and Qlix. Some practical notes for a school, academy trust, or tutor completing that paperwork:

    • The IDTA is the ICO's own prescribed form. It is not a Qlix-drafted document - it is the standard transfer tool published by the Information Commissioner's Office, so your governors, trustees, or procurement team should recognise it as a standard instrument rather than a bespoke Qlix contract. Download the generic template: International Data Transfer Agreement (PDF). Guidance on completing it is on the ICO IDTA page.
    • Qlix's fields are pre-filled. Because Qlix is the same importer for every Customer, most of the IDTA can be completed as a click-through: the importer's details, the security measures, and the transfer description are the same for every school and can be pre-filled by Qlix. Your data protection lead only needs to complete the exporter (school) details and confirm the tables are accurate for your use of the Services.
    • Table 3 (Extra Protection Clauses). Table 3 should record that the transfer in scope is remote access only - Qlix personnel viewing data that remains hosted in the UK - and that no Customer Data is stored outside the United Kingdom at any point. This is the accurate description of what Qlix does, and keeping Table 3 worded this way avoids overstating the transfer.
    • Optional note for your solicitor. Some solicitors ask whether Article 3(2) UK GDPR (which can extend the UK GDPR's direct application to an overseas processor in some circumstances) affects whether a full IDTA is strictly required here. Qlix completes the IDTA regardless, on the basis that it is the clearer and more conservative approach for schools; your solicitor may still wish to consider this point as part of their own review.
  2. Qlix Limited · Company number 74458271 · Rooms 1703-1704, 17/F Tung Chiu Commercial Centre, 193 Lockhart Road, Wan Chai, Hong Kong SAR · privacy@qlixapp.com

Qlix logo

Qlix is the teaching workspace built by teachers: timetable, lessons and resources in one place, plus an AI assistant that already knows your classes. Plan anywhere. Teach with confidence.

Links
  • About us
  • FAQs
  • Trust and security
  • Contact us
Legal
  • Terms and conditions
  • Privacy policy
  • Cookie policy
Follow us
  • Facebook
  • X (Twitter)
  • LinkedIn

© 2026 Qlix. Qlix Limited is a registered company in Hong Kong SAR company number 74458271. Icon Pond icons and country flags made by Freepik are from flaticon.com and are licensed by CC 3.0 BY. Illustrations by pch.vector, Storyset, and studiogstock on Freepik.