PROCUREMENT & GOVERNANCE

Give every reviewer what they need to make a responsible decision.

Clear public information, current controlled documents and an honest record of what is implemented, awaiting approval or still requires independent evidence.
CONTROLLED DOCUMENT REQUEST

Tell us who is reviewing ODISSYS.

We use these details only to respond to this review, supply the correct document version and maintain the distribution record.

Do not include learner or case information. Request details are retained as procurement correspondence and handled under the ODISSYS privacy framework.
See the approval path

PUBLIC INFORMATION

Useful before you contact us.

Start your review immediately. These pages explain the operating model and the boundaries that should shape any implementation.

CONTROLLED DOCUMENTS

Current copies for your review team.

CONTROLLED DOCUMENT REQUEST

Tell us who is reviewing ODISSYS.

We use these details only to respond to this review, supply the correct document version and maintain the distribution record.

Do not include learner or case information. Request details are retained as procurement correspondence and handled under the ODISSYS privacy framework.
Prepared for independent review

DPIA support pack

Processing context, data flow, technical controls, residual dependencies and controller decisions.

Current controlled copy

Security and access overview

Authentication, MFA, session security, role-scoped access, auditing and production configuration controls.

Legal and DPO review draft

Data Processing Agreement and schedules

Processing instructions, security, rights assistance, suppliers, return, deletion and controller responsibilities.

Evidence assembled; review open

Subprocessor and supplier schedule

Current hosting and transactional-email processing boundaries, locations and transfer safeguards.

Implemented; human exercises pending

Incident and data-rights procedures

Governed response, assessment, decision, export and evidence workflows.

Draft; activation blocked

Retention and exit position

Review triggers, holds, return, deletion and guarded anonymisation boundaries.

We ask which organisation is reviewing the pack so controlled copies can be versioned, contextualised and replaced when material facts change.

ASSURANCE STATUS

Evidence without false confidence.

“Implemented” describes a working control. It does not mean that an external reviewer has approved the entire service.
Implemented

Mandatory MFA, privacy locking, role and relationship-scoped access, sensitive-record boundaries and metadata-only audit.

Implemented

Encrypted incident register, data-rights workflow, safeguarding notification and escalation, and quarterly access review.

Awaiting sign-off

DPIA, child-rights assessment, privacy wording, retention decisions and controller–processor terms.

Evidence required

Independent penetration test, restore and deletion exercises, human rehearsals and independent accessibility audit.

What is in the DPIA support pack?Open DPO checklist
PROCESSING

Purpose, scope and data flow

  • Controller and processor operating model
  • Data subjects and information categories
  • Purpose limitation and human decision boundaries
  • Current data-flow and role matrix
TECHNICAL EVIDENCE

Security and access

  • Mandatory MFA and five-minute privacy lock
  • Role, organisation, school, DSL and caseload boundaries
  • Sensitive-record and metadata-only audit controls
  • Production configuration and access-review evidence
SUPPLIERS

Hosting and transactional email

  • CloudSpace/CT1 hosting evidence and open questions
  • Brevo transactional-email processing boundary
  • Subprocessor, location and transfer review status
  • Backup, restore and exit evidence status
CONTROLLER DECISIONS

Items your organisation must determine

  • Lawful basis and Article 9 condition by purpose
  • Necessity, proportionality and child-rights considerations
  • Retention instructions and safeguarding holds
  • Authorised roles, escalation routes and residual risk

The pack distinguishes working technical controls from independent approval. It does not claim AWS, Azure, Postmark, AES-256, TLS 1.3 or a 24-hour incident SLA without applicable evidence and agreement.

MULTI-SCHOOL PROCUREMENT

Procuring for a MAT or local authority?

Start with the governance structure—not a one-school template stretched across several settings.

Contracting and data roles

Confirm whether the trust, authority, individual schools or a combination determine each processing purpose. The appropriate controller, joint-controller and processor arrangements follow those facts.

Central oversight with school boundaries

Design central reporting, administration and access review without giving every central user unrestricted learner or safeguarding access across every school.

Safeguarding and escalation

Document school-level DSL ownership, central escalation routes, absence cover and the circumstances in which trust or authority staff require access.

Implementation and commercial scope

Agree the onboarding sequence, school additions and removals, user lifecycle, support model and volume pricing against the actual number and type of settings.

Discuss a multi-school implementation

DPO and governance

Processing purposes, lawful basis, special-category conditions, data subjects, rights, retention, suppliers and residual risk.

Safeguarding leadership

Human responsibility, access boundaries, notification, acknowledgement, escalation and urgent-concern procedures.

IT and security

Authentication, permissions, session handling, hosting, suppliers, incident response, recovery and independent testing status.

Procurement and finance

Scope, implementation, responsibilities, commercial terms and the evidence required by your own purchasing rules.

THE APPROVAL PATH

From interest to a governed implementation.

  1. 01

    Define the implementation

    Confirm organisations, schools, user roles, processing purposes and the workflows required.

  2. 02

    Review governance

    Share the controlled pack with your DPO, information-governance lead, safeguarding owner and IT/security reviewer.

  3. 03

    Agree responsibilities

    Complete controller decisions, contractual schedules, authorised contacts, retention instructions and escalation routes.

  4. 04

    Configure and verify

    Set up scoped access, onboarding, training and agreed readiness checks before live learner records are introduced.

READY TO START THE REVIEW?

Tell us who needs to assess ODISSYS.

We will provide the current controlled pack and identify any decisions or evidence that remain open.

CONTROLLED DOCUMENT REQUEST

Tell us who is reviewing ODISSYS.

We use these details only to respond to this review, supply the correct document version and maintain the distribution record.

Do not include learner or case information. Request details are retained as procurement correspondence and handled under the ODISSYS privacy framework.