Transparency & Trust

Policies & Governance

Everything you need to understand how askKira handles your data, our AI ethics commitments, and our compliance with UK regulations.

Governance isn't a document.
It's how we build.

For prospects, customers, partners and regulators. Everything that governs how askKira operates, handles your data and meets its legal obligations โ€” in one place.

๐Ÿ”’
UK Data Residency
All data hosted on AWS London (eu-west-2). Your data never leaves UK jurisdiction. Zero model training on customer data.
๐Ÿ“„
Article 28 DPA
Full UK GDPR Article 28 Data Processing Agreement in place. Every customer relationship is contractually protected.
๐Ÿ›๏ธ
ICO Registered
Registered with the Information Commissioner's Office. ICO Reference ZB622646. Public Sector Analytics Limited, Co. No. 14889377.
๐Ÿ›ก๏ธ
Cyber Essentials
Cyber Essentials certified. Regular penetration testing. ISO 27001 principles. Staff trained in data security. 99.99% uptime SLA.

All policies & compliance documents

Click any document to read a summary and access the full PDF. Can't find what you need? Contact us and we'll respond within 2 working days.

๐Ÿข
ICO Registration & Legal Notices
askKira is operated by Public Sector Analytics Limited, incorporated in England and Wales. Company No. 14889377. Registered with the Information Commissioner's Office, ICO Reference ZB622646. Registered office: England and Wales. Data protection enquiries: [email protected] ยท General enquiries: [email protected]
๐Ÿ”’ Data Protection & Privacy
Privacy PolicyPolicy
โ–พ
๐Ÿ“… Version 2.0โœ… Effective 1 March 2026๐Ÿ”„ Next review 1 March 2027

How we collect, store, use and protect your personal data. Covers identity data, contact data, usage data, audit data and technical data โ€” with the lawful basis for each. All data is stored on UK-based servers and never transferred outside the UK. Third-party AI providers are contractually bound not to use your data to train their models. Your rights under UK GDPR include access, correction, erasure, restriction and portability. Contact [email protected] within 30 days for any data request.

โฌ‡ Download PDF
Data Processing Agreement (Article 28)Agreement
โ–พ
๐Ÿ“… Version 1.0โœ… UK GDPR Article 28 compliant

Our formal Data Processing Agreement governs the relationship between askKira (Data Processor) and your organisation (Data Controller). Covers the nature of processing, categories of data, sub-processors (AWS, OpenAI, Google Gemini, Wonde, Cloudflare, Stripe and others โ€” all UK GDPR bound), data security obligations, breach notification within 72 hours, data retention and deletion (30 days on cancellation, backups purged within 90 days), transfers outside the UK/EEA, and your rights as Controller. askKira is ICO registered (ZB622646) and maintains Article 30 Records of Processing Activities. Signed copies provided within 5 working days on request.

โฌ‡ Download PDF Request Signed Copy
Data Protection Impact Assessment (DPIA)DPIA
โ–พ
๐Ÿ“… Version 1.1โœ… Autumn Term 2025๐Ÿ”„ Reviewed annually

Our full Data Protection Impact Assessment for the askKira platform, covering scope, purpose and lawful basis, nature of processing, risk assessment and mitigation, data protection principles, individual rights, international transfers, sub-processors, cyber security standards and ongoing monitoring. Data subjects are UK school staff (teachers, senior leaders, support staff, 18+). No pupil data is required or encouraged. Risks are assessed as low to medium under current controls. Covers 16 sections including safeguarding, insurance cover (Public Liability ยฃ2m, Professional Indemnity ยฃ2m, Employers' Liability ยฃ10m) and version control.

โฌ‡ Download PDF
Board/Governor Summary DPIADPIA
โ–พ
๐Ÿ“… Autumn Term 2025โœ… Designed for governors & trustees

A plain-English summary of our DPIA written specifically for school governors, trustees and board members. Explains what askKira is, why a DPIA is required, and provides clear assurances on data security (UK-hosted, encrypted, Cyber Essentials certified), legal compliance (UK GDPR, DPA 2018, DfE AI guidance 2025, Ofsted AI expectations), safeguarding (no pupil data required, duty to report), data retention, staff rights and insurance cover. Suitable for inclusion in governor meeting packs.

โฌ‡ Download PDF
Data Protection & Processing Q&AQ&A
โ–พ
๐Ÿ“… Autumn Term 2025โœ… For schools, MATs & procurement teams

Answers to the most common data protection questions from schools, MATs, DPOs and procurement teams. Covers: processor vs controller roles, lawful basis, how personal data is handled and protected, anonymisation, data sharing, international transfers, retention periods, IP ownership, deletion rights, breach handling, safeguarding disclosures, cyber security standards, insurance cover, cookies and accessibility. Also addresses DfE and Ofsted compliance. Designed to be shared with governors, parents and staff.

โฌ‡ Download PDF
Cookie PolicyPolicy
โ–พ

What cookies we use, why we use them and how long we keep them. We use analytics tools (Google Analytics, Hotjar) to improve our services. No advertising cookies are used. Staff and users can opt out or manage cookies through browser settings. We do not sell cookie data.

๐Ÿ“‹ Full policy document coming soon

โš–๏ธ Legal & Terms
Terms of ServicePolicy
โ–พ

The terms governing your use of the askKira platform โ€” including acceptable use, intellectual property, AI-generated content limitations, liability and how disputes are handled. Your data and content remain yours at all times. Governed by the laws of England and Wales.

๐Ÿ“‹ Full policy document coming soon

Acceptable Use PolicyPolicy
โ–พ

The rules governing permitted and prohibited use of the askKira platform. Covers safeguarding obligations, data minimisation, prohibited inputs (pupil names, SEND data, identifiable personal data), and the principle that AI supports โ€” but never replaces โ€” professional judgement. Violation may result in suspension or termination of access.

๐Ÿ“‹ Full policy document coming soon

๐Ÿ›ก๏ธ Security & Infrastructure
Security & Infrastructure StatementStatement
โ–พ
โœ… Cyber Essentials certifiedโœ… ISO 27001 principlesโœ… 99.99% uptime SLA

Our technical and organisational security measures. Primary hosting on AWS London (eu-west-2). Encryption in transit and at rest. Role-based access controls and MFA. Regular penetration testing. ISO 27001 principles. Cyber Essentials certified. Staff trained in data security. Breach notification to Data Controllers within 72 hours. Sub-processors include AWS, Microsoft Azure, OpenAI (API only โ€” no model training), Google Gemini, Wonde (MIS integration), Cloudflare, Stripe (PCI-DSS compliant). SLA includes right to termination for repeated or prolonged downtime.

๐Ÿ“‹ Full statement document coming soon

๐Ÿ›๏ธ Government & Regulatory
UK Government AI Standards Compliance StatementUK Gov
โ–พ
๐Ÿ“… Version 2.0โœ… Effective 1 March 2026

Confirms askKira's alignment to DSIT AI Regulation Principles, CDDO AI Playbook and AI Safety Institute Standards. Covers safety, security and robustness (regular security testing, incident register, documented response); transparency and explainability (all AI outputs include context, users always informed when AI is involved); fairness (bias assessment in AI review cycle, annual equality impact assessment); accountability and governance (board-level AI governance, named DPO, documented framework); and contestability and redress (all outputs can be challenged, human review available, clear complaints process). Public sector compliance enquiries: [email protected]

โฌ‡ Download PDF
DfE AI Guidance ComplianceDfE
โ–พ

askKira aligns to DfE guidance on AI in education (updated August 2025), Ofsted AI study findings, UK GDPR and the Data Protection Act 2018. Human oversight is central to the platform design โ€” AI supports but never replaces professional judgement. All AI outputs are explainable and teacher-controlled. Platform aligned to KCSIE 2025 for safeguarding.

๐Ÿ“‹ Full statement document coming soon

๐Ÿฅ Insurance & Liability
Insurance Cover SummaryInsurance
โ–พ

askKira maintains comprehensive insurance cover to protect clients and users. Public Liability: ยฃ2,000,000. Professional Indemnity & Products Liability: ยฃ2,000,000. Employers' Liability: ยฃ10,000,000. Insurance certificates available on request for procurement and compliance purposes.

Request Certificate
UK GDPR
Compliant by design
0%
Of your data used to train AI
72hrs
Maximum breach notification time
ยฃ10m
Employers' liability insurance cover

Safe AI. Transparent AI.
AI you can actually trust.

Need a signed DPA, security questionnaire response or compliance briefing for your legal team? We'll turn it around within 2 working days.

Get in Touch Back to Governance Hub