Skip to main content

Trust Center · Policies

Data Classification & Handling Policy

Last updated: 2026-09-03 · Owner: Founder / CTO · Design Excellent Group SL

What kinds of data we hold, how sensitive each is, and the handling rules that follow.

Purpose

Apply protection proportionate to the sensitivity of each kind of data.

Classes

ClassExamplesHandling
PublicMarketing pages, published academy storefronts, this policyNo restrictions.
InternalCourse drafts, analytics aggregates, configuration without secretsAvailable to the owning academy's team and Eduspera staff on a need-to-know basis.
ConfidentialLearner accounts, progress, submissions, grading notes, e-mail addresses, invoicesTenant-isolated by Row Level Security; encrypted in transit and at rest; served through short-lived signed URLs; exported only by the account holder or a tenant admin, with an audit-log entry.
RestrictedSelf-declared accessibility needs (GDPR Art. 9), payment credentials, credentials and API keys, audit logsAccessibility needs are stored only with explicit consent and used to suggest supports, never to decide automatically. Payment card data never touches our systems (Stripe). Secrets live in the encrypted vault. Audit logs are append-only.

Retention

  • Learner and academy data — for the life of the account; exported and erased on request (see the Trust Center's retention and erasure summary).
  • Payments and invoices — 10 years, as required by Spanish tax and commercial law, with personal references anonymised after erasure.
  • Audit logs — per-tenant retention between 1 and 7 years (default 2), then archived to a private bucket and purged by an auditable job.
  • Backups — follow the provider's rolling window; erased data leaves backups as the window rolls over.

Handling rules

  • Data is stored and processed in the EU; transfers outside the EU/EEA are covered by SCCs.
  • No production data is copied to laptops or to non-production environments without anonymisation.
  • Alternative-format exports (PDF, HTML, Markdown) inherit the classification of the source content.
  • Every erasure produces a receipt and an audit-log entry; every export is logged.