Trust and security
At a glance
- Qlix holds lesson plans, class records and student work. Schools and tutors are entitled to know exactly where that data sits, who can reach it, and what we will and will not do with it. This page answers those questions in one place, and links to the documents your data protection officer will need.
- All data is stored in the United Kingdom - AWS London
- AI processing also takes place in the United Kingdom. Nothing is sent overseas for inference
- Your data is never used to train AI models. This is a contractual commitment, not a policy we can quietly change
- Student names are replaced with anonymous tokens before anything reaches an AI model
- No analytics, advertising or tracking of any kind on the student experience
- Where you use Qlix through a school, the school is the data controller. Private tutors are the controller for their students' information. We are the processor, under a signed agreement
Where your data lives
- Application servers, databases, file storage, authentication and backups all run in Amazon Web Services' London region. Daily backups are held in a separate location within the United Kingdom, so a physical incident at one site does not put your data at risk.
- AI features run on Amazon Bedrock, also in the London region. This matters more than it sounds: many tools will tell you their data is held in the UK and then send your prompts to a model endpoint in another country. Ours do not. No student data leaves the United Kingdom.
- Qlix Limited is registered in Hong Kong SAR. That is our place of incorporation and nothing more - nobody is based there and no data is accessed from Hong Kong. Our team works from the United Kingdom and Thailand. Where a member of our support team in Thailand needs access to investigate a fault, that access is treated as an international transfer and is covered by a UK International Data Transfer Agreement with a published transfer risk assessment behind it. Access is limited to named individuals, requires multi-factor authentication, is time-limited, and is logged. Support staff do not routinely access student data. We would rather tell you this plainly than have you discover it later.
How student data is kept separate
- Qlix holds teaching content and student records in structurally separate places, and only one of them can be shared.
- Resources - lesson plans, worksheets, activities, presentations. Teaching content only. These are what can be shared with colleagues or published.
- Assignments - link a resource to a class. Not shareable.
- Markbook and assessment records - student names, submissions, marks and teacher notes. Never shareable, under any setting.
- Sharing operates only on resources. There is no configuration in which publishing a worksheet exposes a student record, because the student data is held somewhere else entirely. When content is shared outside your school or made public, a persistent warning is displayed so staff always know when something is leaving the school boundary.
AI and your data
- We do not use your data to train AI models. Not lesson content, not student work, not marks, not teacher notes. This is written into our data processing agreement and survives the end of your subscription. Our AI provider is contractually prohibited from doing the same.
- Student names are replaced with anonymous tokens before any content is sent for AI processing. The model can be told that a learner needs dyslexia support without ever being told who that learner is. The mapping between token and name stays inside our UK infrastructure.
- Teachers control what the AI can see. A context panel on every conversation shows exactly which categories of information are included - recent lessons, class notes, support needs - and any category can be switched off.
- Everything the AI produces is a draft for a teacher to review. Qlix makes no decisions about students automatically. We provide no ranking, banding or allocation function, and every mark can be overridden by the teacher.
Security measures
- TLS 1.2 or above for all data in transit
- AES-256 encryption at rest for databases, file storage and backups
- Multi-factor authentication for all administrative and production access
- Role-based access control on a least-privilege basis; no shared credentials
- Production access logged and reviewed
- Segregated production environment - production data is never used in testing
- Automated dependency and vulnerability scanning
- Daily backups with a documented and tested restore procedure
- Passkey support and modern password hashing
- A fuller technical and organisational measures summary is published on this site and forms part of our data processing agreement.
Service providers
- We keep this list current and give schools 30 days' notice before adding or replacing any provider that handles their data.
- Providers that process school and student data
- Amazon Web Services - hosting, database, storage, backup. United Kingdom.
- Amazon Bedrock - AI model inference. United Kingdom. Receives pseudonymised content only.
- Providers that do not process student data
- Stripe - payment and subscription processing. Account holders only; no student data.
- Mailgun - transactional and service email to account holders. EU region.
- Featurebase - in-app support, help centre and feature requests. EEA (Germany).
- Sentry - application error monitoring, so we can detect and fix faults. EU region.
- OneSignal - push notification delivery to the Qlix apps. Data stored in the EU, accessed from the United States under their data processing agreement.
- Mixpanel - product usage analytics. Pseudonymous account identifiers only. EU region.
- Google Analytics - website and application analytics. Pseudonymous account identifiers only. US.
- No analytics or tracking provider operates on QlixGo, the student experience.
Certifications and registrations
- UK GDPR - Qlix Limited has an establishment in the United Kingdom and is subject to the direct supervision of the Information Commissioner's Office
- We do not hold ISO 27001 or SOC 2. We are a small team, and we would rather tell you that directly than imply certifications we have not earned. If your procurement process requires them, please talk to us before you go further so nobody wastes time.
Documents for your data protection officer
- Data Processing Agreement - public standard terms for schools, academy trusts and private tutors; UK GDPR Article 28 compliant; governed by English law
- Data Protection Impact Assessment support pack - pre-filled with everything we can answer, so your DPO only completes the parts that are genuinely yours
- Technical and organisational measures summary - how we protect your data, in detail
- Transfer Risk Assessment - our assessment of the risks arising from support access outside the UK, and the safeguards we apply
- International Data Transfer Agreement - the ICO's standard transfer contract. Entered into as part of your agreement with us; download the generic template from the ICO
- Most suppliers make a school chase these. We would rather your DPO - or a private tutor who needs the same assurances - had them before the first conversation, because it is the fastest route to a decision either way.
Your rights and how to complain
- If you use Qlix through your school, your school is the data controller for student data. Requests to access, correct or delete student information should go to your school first, and we will act on their instruction. If a request reaches us directly, we forward it to the school within three working days.
- If you hold a Qlix account and want to access, correct or delete your own account data, contact us at support@qlixapp.com. You can export your data from within the app at any time.
- Complaints. If you believe we have handled personal data in a way that does not comply with data protection law, tell us at privacy@qlixapp.com. We accept complaints however they reach us and will acknowledge within 30 days, then investigate and tell you the outcome and our reasons. You may also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113 - you do not have to come to us first, though we would like the chance to put things right.
Reporting a security issue
- If you believe you have found a security vulnerability in Qlix, please tell us at security@qlixapp.com. We will acknowledge within two working days and keep you updated while we investigate.
- We ask that you give us a reasonable opportunity to fix an issue before disclosing it publicly, and that you do not access, modify or delete data belonging to anyone else while investigating. We will not pursue researchers who report issues in good faith and follow these principles.
Questions
- We are a small team and we answer these questions ourselves. If something on this page is unclear, or your school needs an answer that is not here, email info@qlixapp.com and we will respond within five working days. We are happy to join a call with your data protection officer at no charge.
- See also our privacy policy, cookie policy and terms and conditions.