Clear. Compliant. Transparent.

Your Data. Your School. Fully Protected.

Starlight is built on a simple principle: professional reflection must be safe, lawful, and transparent.

We operate in full compliance with UK GDPR and the Data Protection Act 2018. Schools remain the Data Controller at all times. STAR21 acts as Data Processor under documented instructions.

Starlight is not a surveillance system and not a safeguarding monitoring tool. It is a teacher-first professional development platform designed for reflective practice.

We understand that safeguarding and data protection are often the first questions school leaders ask. Below, you'll find a clear summary of our approach, infrastructure, legal framework, and responsibilities.

Watch: Starlight and GDPR

If you prefer a short overview, this three-minute explainer outlines exactly how Starlight handles data, roles, retention, and safeguarding responsibilities.

Data Roles and Legal Framework

School or MAT

Data Controller

Determines the purpose and lawful basis for recording and uploading audio.

STAR21 Limited

Data Processor

Processes personal data strictly under the school's documented instructions.

Anonymised Data

Independent Controller

Where data cannot identify any individual or school, STAR21 acts as an independent Data Controller solely for service improvement, analytics, and research. No re-identification attempts are ever made.

This structure is defined in our Data Processing Agreement (Schedule 3 of the SaaS Customer Agreement).


Secure Hosting & Infrastructure

European Hosting by Default

Secure European Data Centres

Germany & Finland

Encryption

In transit and at rest

HTTPS Secure Transport

All data transmitted securely

Access Controls

Role-based access with customer data segregation

All subprocessors are contractually bound by data protection terms no less protective than those in our SaaS Agreement. International transfers are safeguarded via Standard Contractual Clauses or the UK International Data Transfer Addendum.


Data Minimisation and Retention

User Control at All Times

  • Teachers can delete recordings, transcripts and reports at any time.
  • Deletions are permanent (hard delete).
  • Upon contract termination, all Customer Personal Data is deleted or returned within 90 days, unless legally required otherwise.
  • Anonymised, non-identifiable aggregate data may be retained for research and service improvement.

No sensitive or special category data should be uploaded. Clear guidance is provided at the point of recording.


Safeguarding: Clear Boundaries

Starlight Is Not a Safeguarding Tool

Safeguarding responsibility remains entirely with the school, in line with Keeping Children Safe in Education (KCSIE 2025).

If an allegation arises:

  • The school must secure the recording.
  • The Headteacher or Chair of Governors must consult the LADO.
  • STAR21 can place a legal hold on the file to prevent deletion.
  • Recordings are not reviewed or disclosed without lawful authority.

STAR21 maintains:

  • Encrypted storage
  • Access logs for evidential integrity
  • Legal hold functionality
  • Neutral technical support only

Teachers are instructed:

  • Not to delete recordings linked to safeguarding concerns.
  • To report any issues directly to their DSL.

Data Subject Rights

Starlight supports full UK GDPR rights:

Access

Rectification

Erasure

Restriction

Portability

Objection

Complaint to the ICO

Requests are handled in cooperation with the school as Data Controller.

Contact: info@starlightmentor.com


Independent Review and Oversight

Our DPIA and data practices have been reviewed in consultation with:

  • Participating school leadership teams and DPOs
  • Our appointed Data Protection Officer partner, One West (Bath)
  • Internal safeguarding and technical leads

The DPIA is reviewed annually or sooner if material changes occur.

Residual risk is assessed as low and proportionate to educational purpose.

What This Means for Schools

You remain in control as Data Controller.

Teachers retain deletion rights.

Recordings are encrypted and access-controlled.

Legal hold protects evidence if required.

No surveillance or performance management functionality.

Fully aligned with UK GDPR and Data Protection Act 2018.

Transparent contractual framework.

Have questions about GDPR or safeguarding?

We are happy to speak directly with your DPO or Trust compliance lead.