Privacy Policy
QLA — Question Level Analysis
Effective date: 14 August 2026 · Version 6.0
This Privacy Policy explains how information may be processed when QLA is used as a standalone web application. QLA is provided as a hosted web service. Schools, tutors and individual teachers access it through their QLA accounts.
1. Who is responsible?
For student and assessment information entered by a school, the school or organisation will normally determine why and how that information is processed. QLA may process information on the school's behalf as a service provider where the school is responsible for the educational purpose of that processing. The parties should document their roles and obligations where required.
2. Information QLA may contain
- Account name, email address and authentication information.
- School, department, class and academic-year information.
- Student names and assessment results entered by authorised users.
- Question topics, maximum marks, achieved marks, predicted percentages and teacher notes.
- Operational information such as timestamps, security logs and technical information required to operate the service.
2A. Student contact and analytics data
Where an authorised teacher, tutor or school chooses to use report delivery, QLA may store a student email address and records of attempted or completed report delivery. QLA can also store Assessment Objective component marks and derive topic/AO performance trends across assessments. These fields are used to provide QLA reporting and learner-outcome features and are not required for every student.
3. How information is used
Information is used to authenticate users, manage access, organise classes and academic years, calculate assessment statistics, generate reports, share question sets, provide support, maintain security and operate the Service.
4. Student data
QLA is designed so that student records and marks are scoped to a class. When an exam is shared, the question set can be made available to another class without automatically sharing the owner's student roster, marks, predictions or teacher notes.
5. Self-hosted installations
Where the school hosts QLA on its own IIS/PHP/SQLite infrastructure, data is stored in the school's environment. The school is responsible for server security, access controls, backups, retention and deletion, unless a separate managed hosting arrangement applies.
6. Hosted installations
For a hosted service, the hosting environment, backups, subprocessors, retention periods and international transfers should be documented in the applicable data-processing arrangements. We will not sell student assessment data.
7. Security
QLA uses measures such as password hashing, authenticated sessions, role-based access checks and database constraints. No internet-connected system can guarantee absolute security. Schools should use strong passwords, restrict administrator access, keep software updated and maintain backups.
8. Retention
Schools determine how long educational records are retained in accordance with their own policies and legal obligations. For hosted services, retention and deletion periods should be specified in the applicable service agreement.
9. Your rights
Depending on the applicable law and the role of the parties, individuals may have rights under applicable data-protection law, which may include the UK GDPR and Data Protection Act 2018, concerning access, correction, deletion, restriction and other forms of control over personal data. Requests concerning student records should normally be directed to the relevant school or organisation.
10. Cookies and sessions
QLA uses session cookies required for authentication and security. The application does not need advertising cookies to perform its core functions.
11. Account access and recovery
QLA may send single-use, time-limited account setup, password reset and passwordless sign-in links to the verified account email address. Tokens are stored as cryptographic hashes, expire automatically and cannot be reused. QLA does not email passwords.
12. Individual rights and data portability
Account holders can use the Privacy Centre to download a structured copy of their account information and submit access, correction, deletion, restriction or objection requests. Requests concerning school-controlled student records may need to be handled by the relevant school as controller.
13. Retention and data minimisation controls
Site administrators can define a security-log retention period and remove expired authentication tokens and old login-attempt records without deleting educational records. Schools remain responsible for defining and applying appropriate retention schedules for student and assessment information.
14. Mobile access
The limited mobile workspace provides access only to selected account, QLA, class and privacy functions. The same authentication, authorisation and session controls apply to mobile access.
15. Changes
We may update this policy when the Service or its processing changes. The effective date and version will be updated when this happens.
16. Contact
Email: kyoung.co.uk@gmail.com
Website: hosti.me
This policy is a product template and is not legal advice. A school should adapt it to its actual deployment, suppliers and data-processing arrangements.