Data Security & GDPR.
How Aspirational Editech protects personal data, what we promise under the UK GDPR and the Indian DPDP Act, and how to exercise your rights.
Last updated May 2026
Our principles
Personal data — especially that of children — is held with care. We design our systems around three principles:
- Minimise: collect only what we need.
- Protect: defend it in transit and at rest.
- Account: keep records and be ready to answer for what we do with it.
Frameworks we operate under
We comply with the following frameworks, in addition to standard business law:
- UK GDPR and the Data Protection Act 2018, for personal data of UK and EEA residents.
- Digital Personal Data Protection Act, 2023 (India), for personal data of Indian residents.
- UK Keeping Children Safe in Education (KCSiE) and equivalent safeguarding guidance for any data concerning students.
- PCI-DSS, for payment processing — via regulated third-party providers; we do not store card numbers.
We maintain a Record of Processing Activities available to supervisory authorities on request.
Technical safeguards
Our technical measures include, at a minimum:
- TLS 1.3 encryption in transit on all websites, forms and APIs.
- AES-256 encryption at rest for databases and backups.
- Role-based access control with the principle of least privilege.
- Mandatory two-factor authentication for every staff account.
- Audit logs for any access to student records, retained for 12 months.
- Regular vulnerability scanning and an annual penetration test by an independent provider.
- Secure off-site, encrypted backups with documented restoration drills.
- A documented incident response plan with named owners and a 72-hour reporting commitment for notifiable breaches.
Organisational safeguards
- A named Data Protection Lead reachable at dpo@aspiedtech.com.
- All staff complete data-protection and safeguarding training at induction and refresh annually.
- Vetting (DBS / police-clearance) for every staff member who interacts with students.
- Written data-processing agreements with every supplier that touches personal data.
- Quarterly internal audit of access logs, sub-processors and consent records.
International transfers
Personal data may move between India, the United Kingdom and the European Economic Area in the course of running our programmes. Where data is transferred:
- To a country with an adequacy decision (e.g. the UK–EU adequacy arrangement), the decision is relied upon.
- Otherwise, we rely on Standard Contractual Clauses and supplementary safeguards (technical and organisational) to maintain a comparable level of protection.
If there is an incident
If we become aware of a personal-data breach that is likely to result in risk to your rights, we will:
- Contain and assess within hours, led by the Data Protection Lead.
- Notify the supervisory authority within 72 hours.
- Notify affected individuals without undue delay, with clear, plain-language guidance.
- Publish a post-incident review and the corrective steps taken.
Exercising your rights
You can exercise any of your data-subject rights — access, rectification, erasure, restriction, objection, portability, withdrawal of consent — by writing to dpo@aspiedtech.com. We acknowledge within two working days and respond within 30 calendar days at the latest.
Identity verification may be required before we disclose personal data.
Sub-processors
We work with a small number of carefully selected sub-processors:
- Cloud hosting — ISO 27001-certified providers in EU or UK regions.
- Email and document collaboration — enterprise-grade, with audit logging enabled.
- Payment processing — PCI-DSS certified payment gateways.
- Insurance and visa counsel — under written confidentiality and data-processing terms.
A current list, naming each sub-processor and its purpose, is available on request to dpo@aspiedtech.com.
Special protections for students
Where data concerns a student under 18, we apply additional safeguards:
- Parent or guardian consent is required for collection and use.
- Access to student records is logged at the user level and reviewed quarterly.
- Photographs and videos require separate, documented consent and are not retained beyond five years.
- Student data is never used for marketing purposes.
Questions or concerns
Our Data Protection Lead is reachable at dpo@aspiedtech.com. You may also contact the UK Information Commissioner's Office (ico.org.uk) or the Data Protection Board of India.
Questions about this document?Email talk@aspiedtech.com — we respond within two working days.