Internal · For TBS Education Ltd Oy staff and contractors

Internal Data Policies

Operational policies for handling personal data · Version 1.0, September 2026. Effective 28 April 2026
Organisation registration

TBS Education Ltd Oy · Business ID 3614159-3 · Lahti, Finland
UK ICO Registration: ZC133810

1. Scope

This document describes the internal operational policies of TBS Education Ltd Oy with respect to personal data. It applies to all staff, founders, and engaged contractors. It supplements (and is consistent with) the public-facing Privacy Policy and the Data Processing Agreement signed with each customer school.

2. Roles and Responsibilities

RoleResponsibility
Data Protection LeadSakari Laajoki (Founder & Director), first point of contact for all data-protection enquiries, breach response, and regulator correspondence.
Engineering PartnerAppifest, Sydney, Australia (Muhammad Feroz), operates the production codebase under written confidentiality terms; access to production database is logged and audited.
Sub-processorsNetlify (frontend), Neon (database), OpenAI (AI inference). Each operates under their own DPA and Standard Contractual Clauses.

3. Access Control

4. Data Minimisation

5. Encryption

6. Logging and Monitoring

7. Breach Response

If a personal data breach is suspected or confirmed, the following process applies:

  1. Hour 0-2: Containment, the Data Protection Lead and Engineering Partner isolate affected systems; access tokens are rotated
  2. Hour 2-24: Assessment, scope, data categories, number of data subjects, and risk to rights and freedoms are documented
  3. Hour 24-72: Notification, affected schools (Controllers) are notified within 72 hours of awareness, with all information required under UK GDPR Art. 33. The UK ICO and the Finnish Data Protection Ombudsman are notified directly where required
  4. Day 7: Post-incident review, root cause, remediation, and policy updates are documented

The Data Protection Lead is Sakari Laajoki, support@thebusiness.school.

8. Sub-processor Engagement

9. Training and Awareness

10. Data Subject Rights, Internal Workflow

When a data-subject request is received (typically via the school as Controller):

  1. Acknowledge within 5 working days
  2. Verify identity (or rely on Controller verification)
  3. Locate relevant records; redact third-party personal data
  4. Respond within 30 days of receipt; in complex cases, extend to 60 days with written explanation
  5. Log the request and response in the internal register

11. Retention and Deletion

Data typeRetentionTrigger to delete
Free-tier session data≤ 24 hoursSession end + 24h auto-delete
Paid-tier saved sessionsTeacher-controlledTeacher delete action
Teacher account dataSubscription durationSubscription termination + 30 days
Server logs (incl. IP)30 daysAuto-purge
Backups30 days rollingAuto-rotation

12. Review

This document is reviewed at least annually by the Data Protection Lead, and immediately after any material change to processing, sub-processors, or applicable law.