Controller decisions. Processor discipline. Human safeguarding judgement.
ODISSYS supports accountable work without taking ownership of decisions that belong to schools, organisations and authorised professionals.
- Customer organisations normally act as Data Controllers
- Odis Systems Ltd acts as Data Processor on documented instructions
- Access is scoped through role and organisational relationships
- Safeguarding decisions remain with authorised professionals
1. Scope and identity
This framework applies to Odis Systems Ltd, company number 14748152, registered at 82 Black Oak Road, Cardiff, in relation to the ODISSYS platform and associated public services. It describes the usual operating model and does not replace a customer’s Data Processing Agreement, processing schedule, privacy notice or documented instructions.
2. Controller and processor roles
The school, children’s service, intervention provider or other contracting organisation normally determines the purpose and means of processing and acts as Data Controller for the records it places in ODISSYS. Odis Systems Ltd operates the service as Data Processor on the controller’s documented instructions.
Where organisations share responsibility or determine purposes jointly, those organisations must document the appropriate arrangement. ODISSYS does not decide a customer’s lawful basis.
3. Categories of information
Configured implementations may process learner identifiers, contact and school information, referral details, consent records, expected and recorded delivery, attendance, professional notes, questionnaires and outcome measures, reports, user accounts, role assignments, audit events and safeguarding records.
Wellbeing, disability, health and safeguarding information may include special-category personal data. Controllers must determine necessity, proportionality, lawful basis and any Article 9 condition before processing.
4. Purpose limitation and data minimisation
Access and collection should be limited to information required for referral, consent, coordinated delivery, safeguarding, review, reporting and accountable administration. Customers should not upload information merely because a field exists. Routine emails and broad notifications should not reproduce sensitive case narrative.
5. Access architecture
- Authenticated accounts are assigned defined roles.
- Organisation, school, service, team, caseload and funding relationships can restrict the available view.
- Practitioners should receive only the learners and functions required for their work.
- Funder reporting should use appropriately aggregated, privacy-protected information rather than unrestricted case access.
- Super-administrator activity should be limited, purposeful and auditable.
6. Accuracy, matching and human review
Automated name-confidence indicators can support consent matching, but they do not remove the need for appropriate review where identity, school or context is uncertain. The system must not make autonomous decisions about eligibility, safeguarding or a child’s needs.
7. Retention and deletion
The controller determines retention requirements in line with its statutory, safeguarding and organisational obligations. Odis Systems Ltd applies configured or contracted retention instructions and supports authorised deletion where appropriate. Deletion of safeguarding or other material records must be permission-controlled and should preserve sufficient audit metadata to evidence the accountable action without retaining deleted narrative unnecessarily.
8. Individual rights
Requests for access, rectification, restriction, erasure, objection or portability should normally be directed to the relevant Data Controller. Odis Systems Ltd will provide reasonable assistance to the controller within the contractual process and must not disclose controller-held records directly without authority.
9. Security and accountability
ODISSYS uses authenticated, role-scoped access and relationship-based permissions. Material administrative actions and sensitive access may be recorded to support accountability. Current technical controls, hosting arrangements, supplier information and incident contacts are provided through controlled due-diligence documents so procurement teams receive the current position rather than a stale public claim.
10. Suppliers and international transfers
Subprocessor and hosting information is maintained in the current processing schedule. Customers may request the applicable supplier list, locations and transfer safeguards. ODISSYS will not imply UK-only processing unless confirmed by the current contractual and technical arrangement.
11. Incident response
Suspected confidentiality, integrity or availability incidents are assessed, contained, documented and escalated through the incident process. Where a personal-data breach affects controller data, Odis Systems Ltd will notify the controller without undue delay in accordance with the agreement and provide information reasonably required for the controller’s assessment.
12. Safeguarding boundary
ODISSYS supports recording, routing, acknowledgement and audit. It is not an emergency service and must never be the sole route for an immediate risk of harm. Users must follow their organisation’s safeguarding procedure and contact emergency or statutory services where required.
Contact, ownership and review
Data-protection enquiries: dod@odissys.com. Document owner: Odis Systems Ltd. General response target: one working day. Last reviewed September 2026; next scheduled review September 2027, or sooner following material legal, supplier or processing change.