Skip to main content

Data Privacy & GDPR

The platform provides tools to help your organization meet GDPR and other data privacy obligations. This page covers what those tools are and how to use them.

Student data rights

Your students have the following rights regarding their personal data:

RightWhat it means
AccessStudents can request a copy of all data held about them
ExportData can be exported as a structured file
Deletion / ErasureStudents can request their account and personal data be deleted

Exporting a student's data

As an admin, you can export all data held about a specific student:

  1. Go to Students, open the student's row action menu
  2. Click Export Data (GDPR)
  3. A ZIP file is generated containing:
    • Profile information (name, email, registration date)
    • Enrollment history
    • Course progress and completion records
    • Quiz attempts and scores
    • Certificates issued
  4. Click Download when ready (generation takes up to 60 seconds for large histories)

Deleting or anonymizing a student account

warning

Account deletion is irreversible. The student's personal data is permanently removed. Aggregate statistics (e.g., total completions per course) are preserved without identifying information.

  1. Go to Students, open the student's row action menu
  2. Click Delete Account (GDPR)
  3. Confirm the deletion

After deletion:

  • The student cannot log in
  • Their name and email are replaced with anonymized placeholders in all records
  • Certificates previously issued remain in the system but are de-linked from the student identity
  • Course completion counts and quiz score aggregates are preserved

Student self-service deletion requests

Students can submit a deletion request themselves without contacting your admin team:

  1. Student goes to Settings → Privacy
  2. Clicks Request Account Deletion
  3. Confirms with their password
  4. The request is queued for admin review

GDPR deletion request queue

Submitted deletion requests appear in your admin panel:

  1. Go to Settings → Privacy
  2. Review pending requests under GDPR Deletion Requests
  3. Click Process — this doesn't delete the account itself; it's a reminder to go complete the deletion from the Students page (see above)

Under GDPR, deletion requests must be actioned within 30 days.

The platform includes a configurable cookie consent banner shown to new visitors.

To configure it:

  1. Go to Settings → Privacy
  2. Toggle Show cookie consent banner on or off
  3. Click Save

This is a single on/off toggle today — there's no per-category (functional/analytics/marketing) consent breakdown yet.

Data Processing Agreement (DPA)

If your organization requires a signed DPA (Data Processing Agreement) with B-Accuracy Infotech as the data processor, contact info@baccuracy.com. A standard DPA is available and can typically be signed within 2–3 business days.

Data residency

Data is currently stored on infrastructure in the EU and US regions. If your organization requires data to be stored in a specific region or on dedicated infrastructure, contact info@baccuracy.com to discuss dedicated tenancy options.