Trust Center · Policies
Data Classification & Handling Policy
Last updated: 2026-09-03 · Owner: Founder / CTO · Design Excellent Group SL
What kinds of data we hold, how sensitive each is, and the handling rules that follow.
Purpose
Apply protection proportionate to the sensitivity of each kind of data.
Classes
| Class | Examples | Handling |
|---|---|---|
| Public | Marketing pages, published academy storefronts, this policy | No restrictions. |
| Internal | Course drafts, analytics aggregates, configuration without secrets | Available to the owning academy's team and Eduspera staff on a need-to-know basis. |
| Confidential | Learner accounts, progress, submissions, grading notes, e-mail addresses, invoices | Tenant-isolated by Row Level Security; encrypted in transit and at rest; served through short-lived signed URLs; exported only by the account holder or a tenant admin, with an audit-log entry. |
| Restricted | Self-declared accessibility needs (GDPR Art. 9), payment credentials, credentials and API keys, audit logs | Accessibility needs are stored only with explicit consent and used to suggest supports, never to decide automatically. Payment card data never touches our systems (Stripe). Secrets live in the encrypted vault. Audit logs are append-only. |
Retention
- Learner and academy data — for the life of the account; exported and erased on request (see the Trust Center's retention and erasure summary).
- Payments and invoices — 10 years, as required by Spanish tax and commercial law, with personal references anonymised after erasure.
- Audit logs — per-tenant retention between 1 and 7 years (default 2), then archived to a private bucket and purged by an auditable job.
- Backups — follow the provider's rolling window; erased data leaves backups as the window rolls over.
Handling rules
- Data is stored and processed in the EU; transfers outside the EU/EEA are covered by SCCs.
- No production data is copied to laptops or to non-production environments without anonymisation.
- Alternative-format exports (PDF, HTML, Markdown) inherit the classification of the source content.
- Every erasure produces a receipt and an audit-log entry; every export is logged.