Data Protection Policy

Policy

Data Protection Policy

Version 1.0 Last updated: 12 July 2026

1. Purpose

This Data Protection Policy describes how AppliedMode handles personal data across the Platform in a manner consistent with applicable data protection legislation, including principles relevant to international higher-education environments.

2. Roles and Responsibilities

Institutions typically act as data controllers for student, staff, and academic records processed within their workspace. AppliedMode generally acts as a data processor, processing personal data on documented instructions from institutions to deliver the Platform.

AppliedMode acts as a controller for certain data, such as account administration for institutional buyers, website analytics, and direct communications with platform contacts.

3. Categories of Personal Data

Depending on institutional configuration, the Platform may process identification data, contact details, authentication logs, enrolment records, assessment outcomes, communications, support tickets, and technical telemetry necessary for security and performance.

4. Processing Principles

We process personal data lawfully, fairly, and transparently; collect data for specified purposes; limit processing to what is necessary; maintain accuracy where practicable; retain data only as long as needed; and protect data with appropriate security measures.

5. Storage and Location

Personal data is stored in secure cloud infrastructure operated by vetted providers. Storage locations and subprocessors are disclosed to institutional customers as part of contractual and security documentation.

6. Retention

Retention schedules are influenced by institutional requirements, applicable law, and operational necessity. Institutions may configure retention or export processes within permitted Platform capabilities. Backup copies may persist for a limited period consistent with disaster recovery practices.

7. Security Measures

AppliedMode applies layered security controls including access management, encryption in transit, monitoring, vulnerability management, and incident response procedures. Details are summarised in our Security Statement.

8. Processors and Subprocessors

We engage subprocessors for infrastructure, communications, analytics, and specialised services. Subprocessors are subject to contractual obligations requiring appropriate data protection and security standards. Institutional customers may request subprocessor information through their account representative.

9. Institutional Responsibilities

Institutions are responsible for providing lawful bases and notices to learners and staff, configuring roles and permissions appropriately, responding to data subject requests relating to academic records where they are controller, and ensuring that uploaded content complies with applicable law.

10. Individual Rights

Individuals may have rights of access, rectification, erasure, restriction, objection, and portability, subject to applicable law and the controller's obligations. Requests concerning academic records should generally be submitted to the relevant institution. AppliedMode will assist institutions in fulfilling processor obligations where required.

11. Data Subject and Institutional Contact Process

Privacy and data protection enquiries may be sent to privacy@appliedmode.com. Institutions should include sufficient detail to verify identity and identify the relevant workspace or records. We aim to acknowledge enquiries promptly and respond within timeframes required by applicable law.

12. Breach Notification

AppliedMode maintains procedures to assess and respond to personal data incidents. Where we act as processor, we will notify affected institutions without undue delay when required by contract or law, so institutions can meet their own regulatory obligations.

13. Policy Review

This policy is reviewed periodically and updated to reflect changes in law, platform capabilities, and institutional practice.