Before a child pilot, iStéip will complete a DPIA, processor contracts, transfer assessment, retention approval and external legal review.
Who is responsible
iStéip is the controller for direct accounts, product security, support and direct subscriptions. For some school programmes, the school is controller and iStéip acts as its processor. Contact eolas@isteip.com to identify the arrangement that applies to you.
What we collect
We collect only what is needed to provide the feature you use.
- Adult account identity, contact details and sign-in records
- Learner display name, age band, language and linked guardian or school
- Course enrolment, practice activity, assignments and instructor feedback
- Private practice media only when a user chooses to submit it
- Consent, permission, safety and audit records
- Device, security and diagnostic data needed to protect the service
Why we use it
We use data to provide the service and fulfil our agreements, keep accounts and children safe, meet legal duties, respond to requests and improve reliability. Optional features such as marketing, nonessential analytics or AI motion feedback require their own clearly stated basis and control. We do not use child data for advertising, behavioural profiling or model training.
Children and managed learners
Child learner profiles are guardian-managed by default and do not need independent credentials. Instructors receive only class-scoped access. Consent is recorded by purpose, can be withdrawn, and does not replace another lawful basis where consent is not appropriate. Read the child-friendly notice with the learner.
Sharing and international transfers
We share data only with authorised schools, assigned educators, guardians and vetted service providers that help operate iStéip. Access is limited by role and contract. Before international transfers begin, iStéip will publish its subprocessor list and the transfer safeguard used.
Retention and deletion
We keep data only for a documented period. Provisional defaults include 14 days for unanswered guardian invitations, 30 days for raw AI-practice video unless saved, 12 months for pseudonymised security logs, and deletion from active systems within 30 days of an approved request. Encrypted backups expire on their normal cycle, targeted within 90 days. Legal or safeguarding holds are isolated and documented.
Your choices and rights
Depending on where you live, you may ask for access, correction, export, restriction, objection or deletion. You can change language, notification and consent choices inside your account. Requests ordinarily receive a response within one month under EU and UK law.
- Email: eolas@isteip.com
- In-app: Settings → Your data
- For child requests, we consider the child's best interests, capacity and wishes—not only the requester's relationship
