Data Protection
OneScull is committed to protecting the personal data of all users, especially students and minors. We comply with GDPR, COPPA, FERPA, and other applicable data protection regulations.
Data Protection Principles
We adhere to the following principles when processing personal data:
- Lawfulness, fairness, and transparency in data processing
- Purpose limitation - data collected for specific purposes only
- Data minimization - only collecting necessary information
- Accuracy - maintaining up-to-date records
- Storage limitation - retaining data only as long as necessary
- Integrity and confidentiality - ensuring data security
Student Data Protection
We take extra precautions when handling student data. We never sell or share student information with third parties for marketing purposes. Access to student records is strictly controlled and limited to authorized educational personnel. Parents and guardians have the right to review, correct, or request deletion of their child's information.
GDPR Compliance
For users in the European Economic Area (EEA), we comply with the General Data Protection Regulation (GDPR). This includes:
- Obtaining explicit consent before processing personal data
- Providing clear information about data usage
- Ensuring the right to access, rectify, and erase data
- Data portability rights
- The right to object to processing
- Protection against automated decision-making
Data Breach Response
In the event of a data breach, we will:
- Notify affected users within 72 hours of discovery
- Report the breach to relevant supervisory authorities
- Take immediate steps to contain and remediate the breach
- Provide guidance on protective measures users can take
- Conduct a thorough investigation and implement preventive measures
International Data Transfers
If we transfer data internationally, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission or adequacy decisions confirming adequate data protection levels.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations. After this period, data will be securely deleted or anonymized.