Privacy statement
How Student Cyber Portal uses information
This statement explains the personal information used by Student Cyber Portal when schools, colleges, teachers, students, and administrators use the service.
Last updated: 9 September 20261. Who is responsible for the information
The school, college, or organisation that provides access to the portal is normally responsible for deciding why student and staff information is used. They may act as the data controller for their users.
The portal provider may act as a processor or service provider where it hosts, supports, backs up, or maintains the portal on behalf of the organisation. Your organisation’s own privacy notice should explain the local controller, data protection officer, and contact details.
2. Information the portal may hold
The portal may hold account information such as name, email address, role, organisation, student ID or candidate number, account status, verification status, Microsoft Entra tenant and account identifiers, and sign-in security information.
It may also hold student portfolio work, uploaded evidence, screenshots, teacher comments, assessment decisions, section reviews, practice exam responses, marks, progress records, group membership, archive status, and download/export records.
For security and audit purposes, the portal may record technical information such as sign-in time, last activity, failed sign-in events, account lockout status, session activity, IP address, browser user agent, and administrator actions.
3. Why the information is used
The information is used to provide accounts, authenticate users, support multi-factor authentication, enable Microsoft Entra sign-in, store student evidence, support teaching and assessment, show progress, send progress updates where enabled, create downloads, maintain backups, investigate issues, and protect the portal from misuse.
The portal does not use Microsoft sign-in to read mailboxes, calendars, OneDrive files, SharePoint sites, or directory-wide information.
4. Lawful basis
The lawful basis depends on how each school, college, or organisation uses the portal. Common bases may include public task, legal obligation, contract, legitimate interests, or consent where appropriate.
Your organisation is responsible for identifying and explaining the correct lawful basis in its own privacy information. Where special category data is added by users, the organisation should identify any additional condition required under data protection law.
5. Who can see information
Students can see their own account area, work, feedback, and assessment information. Teachers can see students and learning records for their organisation. Ultimate User administrators can manage organisations, users, configuration, backups, audit logs, and support functions.
Support access should only be used where needed to operate, secure, troubleshoot, or support the service.
6. Sharing information
Information may be shared with the school, college, training provider, teachers, assessors, internal quality assurance staff, awarding body or qualification staff where required, and trusted service providers used to host, secure, email, back up, or support the portal.
Information is not sold. The portal should not be used for advertising profiles or unrelated marketing to students.
7. Microsoft Entra sign-in
Where Microsoft sign-in is enabled, the portal uses Microsoft Entra ID to verify the user’s identity. The portal asks only for sign-in details needed to match the Microsoft account to an existing portal account, such as the user’s email address, basic profile, tenant ID, and Microsoft account identifier.
School administrators may be asked to approve the app for their organisation using a Microsoft admin consent link.
8. Retention
Information is kept for as long as it is needed for education, assessment, safeguarding, legal, audit, backup, security, or service administration purposes. Retention periods may vary by organisation and by type of record.
Archived student accounts may be scheduled for deletion after a retention period. Backup copies and audit logs may remain for a limited period after live records are changed or deleted.
9. Security
The portal includes security controls such as password rules, multi-factor authentication, account lockout, role-based access, organisation separation, CSRF protection in production, activity logging, backups, and secure configuration options.
No online system can be guaranteed to be free from risk. Users should report suspected security issues promptly to their organisation administrator or portal support contact.
10. Your rights
Depending on the lawful basis and circumstances, individuals may have rights to be informed, access their information, request correction, request deletion, restrict processing, object, request data portability, and raise a complaint with a supervisory authority.
Students, parents or carers, staff, and administrators should normally contact their school, college, or organisation first. In the UK, individuals can also contact the Information Commissioner’s Office if they are unhappy with how personal data has been handled.
11. Questions
If you have a question about your information, contact your teacher, school or college administrator, or the data protection contact named in your organisation’s own privacy notice. School administrators can then contact the portal provider or support contact used for their service agreement.