Data Protection
1. Data Protection Framework
Nexora implements technical and organizational measures aligned with applicable data protection laws including GDPR-style principles where relevant.
2. Roles and Responsibilities
Institutions are typically data controllers for student and staff records. Radelifame Limited acts as a data processor when handling institution data on Nexora infrastructure.
3. Security Measures
We use encryption in transit, role-based access control, audit logging, Firebase security rules, and monitoring for abuse. Report vulnerabilities responsibly to our security contact.
4. Retention
Retention follows institutional policy and legal requirements. Some records may be retained after account closure where law or legitimate educational interest requires.
5. International Transfers
Data may be processed in cloud regions used by our infrastructure providers. Transfers use appropriate safeguards where required.