QLAQLA

Privacy Policy

QLA — Question Level Analysis
Effective date: 14 August 2026 · Version 6.0

This Privacy Policy explains how information may be processed when QLA is used as a standalone web application. QLA is provided as a hosted web service. Schools, tutors and individual teachers access it through their QLA accounts.

1. Who is responsible?

For student and assessment information entered by a school, the school or organisation will normally determine why and how that information is processed. QLA may process information on the school's behalf as a service provider where the school is responsible for the educational purpose of that processing. The parties should document their roles and obligations where required.

2. Information QLA may contain

2A. Student contact and analytics data

Where an authorised teacher, tutor or school chooses to use report delivery, QLA may store a student email address and records of attempted or completed report delivery. QLA can also store Assessment Objective component marks and derive topic/AO performance trends across assessments. These fields are used to provide QLA reporting and learner-outcome features and are not required for every student.

3. How information is used

Information is used to authenticate users, manage access, organise classes and academic years, calculate assessment statistics, generate reports, share question sets, provide support, maintain security and operate the Service.

4. Student data

QLA is designed so that student records and marks are scoped to a class. When an exam is shared, the question set can be made available to another class without automatically sharing the owner's student roster, marks, predictions or teacher notes.

5. Self-hosted installations

Where the school hosts QLA on its own IIS/PHP/SQLite infrastructure, data is stored in the school's environment. The school is responsible for server security, access controls, backups, retention and deletion, unless a separate managed hosting arrangement applies.

6. Hosted installations

For a hosted service, the hosting environment, backups, subprocessors, retention periods and international transfers should be documented in the applicable data-processing arrangements. We will not sell student assessment data.

7. Security

QLA uses measures such as password hashing, authenticated sessions, role-based access checks and database constraints. No internet-connected system can guarantee absolute security. Schools should use strong passwords, restrict administrator access, keep software updated and maintain backups.

8. Retention

Schools determine how long educational records are retained in accordance with their own policies and legal obligations. For hosted services, retention and deletion periods should be specified in the applicable service agreement.

9. Your rights

Depending on the applicable law and the role of the parties, individuals may have rights under applicable data-protection law, which may include the UK GDPR and Data Protection Act 2018, concerning access, correction, deletion, restriction and other forms of control over personal data. Requests concerning student records should normally be directed to the relevant school or organisation.

10. Cookies and sessions

QLA uses session cookies required for authentication and security. The application does not need advertising cookies to perform its core functions.

11. Account access and recovery

QLA may send single-use, time-limited account setup, password reset and passwordless sign-in links to the verified account email address. Tokens are stored as cryptographic hashes, expire automatically and cannot be reused. QLA does not email passwords.

12. Individual rights and data portability

Account holders can use the Privacy Centre to download a structured copy of their account information and submit access, correction, deletion, restriction or objection requests. Requests concerning school-controlled student records may need to be handled by the relevant school as controller.

13. Retention and data minimisation controls

Site administrators can define a security-log retention period and remove expired authentication tokens and old login-attempt records without deleting educational records. Schools remain responsible for defining and applying appropriate retention schedules for student and assessment information.

14. Mobile access

The limited mobile workspace provides access only to selected account, QLA, class and privacy functions. The same authentication, authorisation and session controls apply to mobile access.

15. Changes

We may update this policy when the Service or its processing changes. The effective date and version will be updated when this happens.

16. Contact

Email: kyoung.co.uk@gmail.com
Website: hosti.me

This policy is a product template and is not legal advice. A school should adapt it to its actual deployment, suppliers and data-processing arrangements.