BodyAnswers

Trust centre

Everything a university needs to assess this platform before putting it in front of students. Where a document is in draft or does not exist yet, this page says so rather than leaving you to find out.

Where your data lives

Application hosting
Vercel, London (lhr1) region
Database and authentication
Supabase, EU/UK region
Data residency commitment
United Kingdom and European Economic Area
Encryption in transit
TLS 1.2 or above, HSTS enforced
Encryption at rest
AES-256, managed by the database provider

No student personal data is transferred outside the United Kingdom or the European Economic Area for storage. Where a subprocessor’s own operations touch data in the United States — request logs, for example — the transfer relies on Standard Contractual Clauses and the UK Addendum, and is listed individually on the subprocessor page.

Before we approach a university

Absent, these end the conversation in the first meeting.

  • What personal data the platform holds, why, for how long, and the rights a student has over it. Written against what the application actually does.

    Reviewed by
    Data protection officer, students
  • Terms of use

    Available

    The terms a student agrees to. Separate from the institutional contract, which governs the university.

    Reviewed by
    Legal, students
  • Conformance against WCAG 2.2 AA, stated honestly: what has been tested, what has not, and the known exceptions. Universities have Equality Act 2010 obligations, so this is checked, not skimmed.

    Reviewed by
    Accessibility and digital inclusion team
  • Every third party that processes personal data on our behalf, what they do, where they hold it, and the transfer safeguard where one applies.

    Reviewed by
    Data protection officer, IT
  • Authentication, authorisation, tenant isolation, encryption, logging, backups and dependency management, described at the level an IT reviewer can assess.

    Reviewed by
    IT security
  • Data flow and hosting

    Available

    Where data is stored and processed, which regions, and how it moves between the application, the database and each subprocessor.

    Reviewed by
    Data protection officer, IT

To negotiate the first contract

Asked for during procurement and legal review, not before.

  • The Article 28 terms under which we process student data on the university's instructions: scope, purposes, retention, deletion, subprocessors, security and breach notification.

    Reviewed by
    Legal, data protection officer
    Outstanding
    Solicitor review before it is offered to a customer.
  • Data retention schedule

    Available

    How long each category of data is kept, what triggers deletion, and what happens to student records when a contract ends.

    Reviewed by
    Data protection officer
  • Incident response procedure

    Available

    How a suspected breach is detected, contained, assessed and reported — including the 72-hour notification path to the university as controller.

    Reviewed by
    IT security, data protection officer
  • Business continuity and disaster recovery

    In draft

    Recovery objectives, backup regime, and what a student sees during an outage. Honest about what is achievable at our current size.

    Reviewed by
    IT, procurement
    Outstanding
    A restore has to be rehearsed and the result recorded before this is credible.
  • Cyber Essentials certification

    Not yet started

    The UK government-backed baseline. Frequently a hard requirement in public-sector procurement and cheap to obtain relative to what it unlocks.

    Reviewed by
    Procurement, IT security
    Outstanding
    Self-assessment and certification. The single highest-leverage credential at this stage.
  • Insurance certificates

    Not yet started

    Professional indemnity and cyber liability cover, at the levels a university contract requires.

    Reviewed by
    Procurement
    Outstanding
    Cover to be arranged. Contract templates commonly specify a minimum; check before quoting.
  • Support and service levels

    In draft

    Response targets, support hours, escalation route and the availability commitment.

    Reviewed by
    Procurement, IT
    Outstanding
    Commit only to targets that can be met by the people who actually exist.

As we scale

Expected by larger buyers and by any public-sector framework.

  • Penetration test summary

    Not yet started

    An independent test of the platform, with the remediation record.

    Reviewed by
    IT security
    Outstanding
    Not yet commissioned. Expect to be asked for this by any university buying for a whole cohort; budget for it before the second contract.
  • ISO/IEC 27001

    Not yet started

    A full information security management system, independently audited.

    Reviewed by
    Procurement, IT security
    Outstanding
    Deliberately not a Phase 1 goal. Meaningful only with the headcount to operate the management system it certifies.

Ask us directly

If a security questionnaire, DPIA or accessibility audit needs something not listed here, ask. A specific question gets a specific answer, including where the answer is “not yet”.

Contact us