The short version
Personal details are protected in three separate ways, and each covers a different risk:
- On the way to and from your device, everything travels over an encrypted connection. Nobody sitting between you and Practicks — on a school network, a café Wi-Fi, or anywhere along the way — can read it.
- While it is stored, the databases, backups and file storage Practicks uses are encrypted. On top of that, institutions can ask for individual personal details to be separately encrypted, so that even a copy of the database does not contain readable names, addresses or photos.
- In who can see it, access follows the job. Teachers see their own learners; a parent sees their own child; nobody browses the platform’s users at large.
What can be individually encrypted
Your institution chooses, field by field, which personal details Practicks holds encrypted rather than as typed. There are four, and they are separate choices because they carry different risks:
- Name— given and family name, wherever they are stored.
- Email address— the address used to sign in and to receive mail.
- Phone number— contact numbers on a person’s record.
- Proctoring photo— the webcam images captured during a supervised assessment, and the face signature worked out from them. These are collected only when proctoring is switched on for that assessment, and only after the person taking it has been told and has agreed.
When a field is encrypted, what is stored is not a scrambled version of the original that could be unscrambled by studying it. It is unreadable without a separate key, and that key is not kept where the data is.
Who can see personal details in full
Two people, and only two:
- You, about yourself.Your own details are yours to read. You never need anyone’s permission to see your own record.
- A Practicks platform administrator, when there is a reason — answering a request about your own data, or investigating a security incident. Every time this happens it is recorded: who looked, whose record, and when.
Everyone else works with the details they need for the task in front of them. Your teacher sees your name on their class list because that is what teaching requires. Your school’s administrators see shortened forms — enough to find the right person, not enough to collect contact details in bulk.
Practicks staff cannot browse learner data casually. There is no screen anywhere in the product that lists people’s personal details across institutions.
The keys
Encryption is only as good as the care taken with the key, so:
- Keys are themselves stored protected, under a separate secret that is not kept in the database. A stolen copy of the database, on its own, decrypts nothing.
- Keys can be replaced. When a new key takes over, the previous one is retired rather than destroyed — it is still what reads the records made while it was in use, and destroying it would destroy those records.
- Every change of key is recorded with the date and the person who made it, so there is always an answer to which key protected which records and when.
- Only a Practicks platform administrator can make these changes. They are logged.
Backups and deletion
Backups carry the same protection as the live system — a backup of encrypted data is encrypted. When you ask for your data to be deleted, your personal details are removed or made permanently anonymous; see our data retention policy for how long different kinds of records are kept and why.
What this page does not tell you
You will not find the specific algorithms, parameters, key locations or internal procedures here. That is deliberate. Those details are of no practical use when you are deciding whether to trust us with a school roll, and publishing them helps only somebody trying to get past the protection. Institutions carrying out a formal security review can request the detail under a confidentiality agreement — write to privacy@practicks.com.
We describe protections that are actually in place. Practicks makes no claim to hold a formal security certification, and this page should not be read as one.
What to do if something looks wrong
If you think someone has seen data they should not have, or you spot something that looks like a weakness, tell us at security@practicks.com. Reports made in good faith are welcome and we will not pursue anyone for making one.
For what data is collected in the first place, and your rights over it, see the privacy policy.