Appropriate Policy Document
Supplier assurance for special-category and criminal-offence data processing controls.
- Version
- 1.1
- Reviewed
Procurement & due diligence
Start with one versioned pack, then trace any question to the individual policy, certificate or review template behind it.
Every entry shows its status, version and review date. The MSA and DPA are procurement review templates, not signature copies or executed agreements.
They contain no customer-specific names, selections, instructions or order details.
Share the same versioned set of supplier evidence with every reviewer, alongside a checksum manifest.
Open the exact policy, certificate or template behind a question without searching through a generic document list.
Keep supplier-wide evidence separate from school-specific decisions, selections and executed agreements.
Complete review pack
Version 2026.08.1, reviewed . The ZIP contains the same 16 source documents listed below and a manifest with file versions and SHA-256 checksums. It contains no customer-specific order details.
Use the pack for supplier review. School-specific selections, instructions, order details and signed terms belong in your school’s own approval and contracting process.
Individual source documents
Review by subject, open a browser-friendly PDF, or download the source document. Status, version and review date remain visible so a reviewer can tell exactly what they are looking at.
Browser PDF previews are convenience copies. Where a source DOCX is supplied, that downloaded source remains the controlling document.
07 documents
Controller and processor responsibilities, privacy, retention and sub-processor transparency.
Supplier assurance for special-category and criminal-offence data processing controls.
Current use of cookies, browser storage and cookie-free performance telemetry.
Shareable controller-processor review terms; a clean execution copy is prepared after review.
Supplier facts and a controller-owned template for completing a school or trust DPIA.
Current retention, export, deletion and backup-handling schedule by data class.
How Student Radar handles personal data across its website and services.
Current supplier register for public and school-enabled processing.
04 documents
Security controls, incident response, continuity and certification.
Buyer-facing continuity, backup, recovery and resilience arrangements.
Current Cyber Essentials certificate for security due diligence.
Buyer-facing incident handling, escalation and notification arrangements.
Buyer-facing overview of organisational and technical security controls.
02 documents
Shareable contract-review templates and standards for authorised platform users.
Expected use standards for authorised platform users and administrators.
Shareable service-terms review template; customer-specific terms belong in an Order Form.
02 documents
Accessibility position and safeguarding responsibilities for schools.
Current accessibility position, known limitations and contact route.
Supplier assurance and school responsibilities for safeguarding workflows.
01 document
Technical transparency for public tools and school-enabled AI processing.
Verified public-tool processing, anonymous Sensory inputs and signed PDF boundaries.
School-specific review
Request access to the Demo School, or bring your data protection, security, service-boundary and package questions to a 30-minute walkthrough.