Processor relationship, by design.
CurioPilot is a data processor under GDPR Article 28. Schools and parent tenants are the data controllers. Our DPA defines the relationship and locks in:
- Purpose limitation — we use your data only to provide the service
- Data minimisation — we redact PII before any payload reaches AI
- Storage limitation — TraceLayer 90 days, audit logs 7 years
- Integrity + confidentiality — encryption in transit + at rest
- Accountability — you can audit our processing on demand
Article 15 (right of access): one-click export including TraceLayer. Article 17 (right to erasure): one-click deletion. Active data removed in seconds; backup retention 90 days.