Acrux Education
Security

How we protect your school's data.

Security is fundamental to everything we build. Student data and assessment submissions are protected with industry-standard encryption, both in transit and at rest.

Encrypted at rest & in transit

Industry-standard protocols

Data stays in your region

GCP regional isolation — AU, UK, SG

ST4S assessment in progress

Submission planned Q2 2026

Regular pen testing

Independent security assessments

Frequently asked

Security & Data Protection

How long is data retained?

Teacher and staff data is retained for the duration of the account plus 12 months. Identifiable student data is retained for the duration of a student's enrolment, or as directed by the school. Anonymised analytics data is retained indefinitely for research and system improvement and cannot be linked back to any individual.

Who is the Data Protection Officer?

Dr Leanne Russell — [email protected]

Is Acrux being assessed under ST4S or equivalent frameworks?

Acrux Education is currently completing the ST4S (Safer Technologies for Schools) data sovereignty assessment, with submission planned for May 2026.

How do we submit a formal data deletion or Subject Access Request?

Contact [email protected]. We will verify your identity and authority, confirm the scope of the request, and respond within 30 days.

Can we export our data?

Yes. School platform administrators can request a full export of all student records, assessment results, and class data directly from the platform. Exports require authenticated access and are available for download for 48 hours before the file is permanently deleted.

What happens to data when we delete it?

Deletion cascades automatically — student records, assessment submissions, marking results, and uploaded PDF files are all permanently removed. Files are securely erased to DoD 5220.22-M standard (3-pass overwrite). A GDPR Article 17 compliance certificate is generated on completion.

Can we delete our data?

Yes. School administrators can delete individual student records, classes, and assessments directly from the platform. A full school account deletion can also be requested, with a 30-day grace period before permanent deletion is processed.

Do students interact with the platform directly?

No. Students do not create accounts or submit data directly. All student data is provided and managed by authorised school staff.

What privacy laws does Acrux comply with?

Our Data Protection Policy covers compliance with the Privacy Act 1988 (Australia), UK GDPR, and Singapore's Personal Data Protection Act 2012 (PDPA). The latest version of our Data Protection Policy is available at acrux.education/legal.

Does Acrux sell or share student data?

No. We do not sell, monetise, or use student data for advertising or profiling. Infrastructure providers such as Google Cloud Platform act as subprocessors under Data Processing Agreements and may only process data as directed by Acrux. A full list of subprocessors is available in our Trust Centre.

Who owns the data?

Schools are the data controller. Acrux Education acts as a data processor, handling data only on the school's behalf and in accordance with their instructions.

Does Acrux undergo security testing?

Yes. We conduct regular vulnerability assessments and independent penetration testing as part of our ongoing security programme.

What encryption does Acrux use?

All data is encrypted at rest and in transit using industry-standard protocols. Uploaded assessment files are stored in Google Cloud Storage with encryption applied at the file level.

Where is data hosted?

Acrux Education runs on Google Cloud Platform (GCP). Data is stored in regional instances and may be hosted in Australia, the UK, Europe, Canada or Singapore depending on your school's location.

Do you keep the student data?

No personal information on students is kept by our program.

Questions about data security?

Contact our Data Protection Officer directly — [email protected]