Clear Responsibility
The subscribing school decides which authorised staff, teachers and parents may use its records. ISMS provides the platform and processes those records to deliver the contracted school service.
Every onboarding agreement must identify the school contact responsible for privacy and safeguarding, the permitted uses of the platform, and the escalation contacts on both sides.
Access Around Each Learner
School administrators manage accounts and permissions. Teachers receive work-related access, while parents see only the children linked to their account. Sensitive medical, safeguarding and finance records must be limited to roles that need them.
ISMS records sensitive administrative actions in audit logs so the school and platform team can investigate changes and support concerns.
A Safer Start
Before a school goes live, ISMS and the school review data quality, staff permissions, parent-account links, backup arrangements, payment settings and the agreed support route.
Schools should not upload informal safeguarding notes or medical details until the correct restricted-access roles have been assigned and tested.
Security and Service Continuity
Production access uses HTTPS, authenticated sessions, server-enforced permissions, rate limits and audit records. Platform credentials are managed by ISMS and are never presented as a school configuration burden.
ISMS maintains backup procedures and service monitoring. Backup restoration and incident-response evidence is reviewed as part of the release process and can be discussed during procurement.
Data Requests and Incidents
Parents and staff should first contact their school about correction, access or account concerns. The school may then raise a platform request with ISMS.
Privacy, security and safeguarding concerns can be reported to support@isms.school. Include the school name and enough detail to route the request, but do not place medical or safeguarding evidence in an ordinary email.