Hosting approach and client support model

Many Eduquery products are regionally hosted. Access from outside the hosting location may be necessary for client support, product maintenance purposes and additional functionalities. Our client support is generally provided by the regional teams during regular business hours. To provide full 24/7 follow-the-sun support, Client Support’s global team of staff may access environments containing client data from any of our support locations (e.g., US, Colombia, India, the Netherlands, Australia). Additionally, the product teams in our global locations may have access to environments containing client data where required to maintain the products (e.g., reviewing performance issues) and to provide specialist expertise for client support cases. Additionally, our vendors (third-party subprocessors) may require access to client data for them to provide the contracted services. Any access only takes place on a need-to-know-basis.

Some products (e.g., SafeAssign), some product-specific Eduquery capabilities (e.g., microservices supporting our products, content delivery networks) as well as many of our vendor-supported product functionalities (e.g., authentication, messaging, generative AI capabilities) may be provided from data centers outside of our clients’ usual hosting location. Such processing of personal information outside the usual hosting location only takes place in accordance with applicable data privacy laws & regulations and our contractual permissions and commitments.

Protecting your transferred data

To ensure that client/student data receives a high level of protection when it is accessed from and processed outside the hosting locations, we use the EU Commission 2021 Processor-to-Processor Standard Contractual Clauses (P2P SCCs) that are incorporated within Eduquery’s group of companies through intra-group data transfer agreements.

Further measures to protect transferred personal information:

  • When data is transferred via the internet, it is encrypted in transit
  • Encryption at rest is available for all key products
  • Employees only have access to the personal information they need for the performance of their role (least-privilege principle)
  • Employees must use multi-factor authentication for remote access to the IT infrastructure
  • Detailed contractual commitments regarding the level of security controls
  • Contractual protection for personal data of our clients in the case of any requests by foreign authorities