Summary: SOLASTIAN acts as a Data Processor on behalf of your school (the Data Controller). All data is stored within the EEA, never sold or shared with third parties, and protected in accordance with GDPR (Regulation EU 2016/679).
1. Roles and Responsibilities
Under the General Data Protection Regulation (GDPR), the following roles apply:
Your school — Data Controller
Your school determines the purposes and means of processing personal data (staff, student, and parent records) within the SOLASTIAN platform.
SOLASTIAN — Data Processor
SOLASTIAN processes personal data solely on your instructions and for the purpose of providing the Services. We do not use your data for any other purpose.
2. What Data We Process
The categories of personal data processed through the SOLASTIAN platform may include:
- Staff and employee records (name, email address, role, photo)
- Student records (name, year group, photo, card identifier)
- Parent contact information (name, email, for conference booking)
- Authentication data (hashed passwords, MFA credentials)
- Usage data (login timestamps, booking records, ticket history)
- Third-party integration credentials (encrypted, e.g. Google Workspace service account keys)
The scope and volume of personal data is determined entirely by what your school chooses to input into the platform.
3. Legal Basis for Processing
SOLASTIAN processes personal data on the basis of:
- Contractual necessity — processing required to deliver the Services under your subscription agreement
- Legitimate interests — platform security, fraud prevention, and service improvement
- Legal obligation — where required by applicable law
Your school, as Data Controller, is responsible for ensuring it has a valid legal basis for collecting and entering personal data into the platform.
4. Data Storage and Location
All personal data processed by SOLASTIAN is stored exclusively within the European Economic Area (EEA), on Netcup infrastructure in Nuremberg, Germany. No data is transferred outside the EEA without explicit agreement and appropriate safeguards.
5. Sub-processors
SOLASTIAN uses the following sub-processors to deliver the Services:
- Netcup GmbH — application infrastructure, database hosting and backup storage in Nuremberg, Germany (EEA)
- Google Analytics — anonymous website analytics (public marketing pages only, subject to consent)
- LinkedIn Insight Tag — marketing analytics (public pages only, subject to consent)
We will notify you of any changes to this list with reasonable advance notice.
6. Data Retention
Personal data is retained for as long as your subscription is active. Upon termination:
- You may request a full export of your data within 30 days of termination
- All personal data will be permanently deleted within 60 days of termination
- Backup snapshots containing your data will be purged according to our backup retention schedule (max 90 days)
7. Security Measures
We implement appropriate technical and organisational measures to protect personal data, including:
- Schema-level data isolation — each school's data is structurally separated at the database level
- TLS encryption in transit and encrypted storage for sensitive credentials
- Multi-Factor Authentication (MFA) enforced for all admin accounts
- Role-based access controls limiting data access to authorised users
- Automated encrypted backups with defined retention policies
Full details are available on our Security page.
8. Your Rights as Data Subject
Under GDPR, individuals whose data is processed have the following rights:
- Right of access — request a copy of personal data held about you
- Right to rectification — request correction of inaccurate data
- Right to erasure — request deletion of your personal data
- Right to restriction — request that processing be limited
- Right to portability — receive your data in a machine-readable format
- Right to object — object to processing based on legitimate interests
Requests from data subjects should be directed to your school's Data Controller (the school itself). Schools may contact us at privacy@solastian.com to fulfil erasure or portability requests.
9. Data Breaches
In the event of a personal data breach, SOLASTIAN will notify the affected Customer without undue delay and no later than 72 hours after becoming aware of the breach, in accordance with Article 33 of the GDPR. Notifications will include the nature of the breach, the categories and approximate number of data subjects affected, and the measures taken or proposed.
10. Data Processing Agreement
A formal Data Processing Agreement (DPA) is available to all SOLASTIAN customers. The DPA sets out the specific obligations of both parties under Article 28 of the GDPR. To request a signed DPA, contact us at privacy@solastian.com.
11. Contact
For all data protection enquiries, contact our data protection team at privacy@solastian.com.