Legal information
Document Upload and Retention Notice
This notice explains protected uploads, staff access and configurable retention controls for student files.
Accepted uploads
Authorized case checklists accept one PDF, JPG or PNG within the configured limit. Profile photos accept validated JPEG or PNG images. Unrelated records must not be uploaded.
Validation and quarantine
The server checks extension, declared type and signature. Images are inspected and profile photos normalized. If the configured malware-scanning add-on is enabled, files remain quarantined until confirmed.
Private delivery
Authenticated Cloudinary delivery and opaque identifiers are used. A short-lived signed link is created only after ownership or permitted staff scope is confirmed.
Review and replacement
Documents may be under review, accepted, rejected or replaced. Rejected and superseded files follow the approved retention rule.
Retention controls
Values are centralized and disabled until approved. Active-case files are not automatically destroyed. Narrow dry-run-first jobs and reviewed deletion requests handle eligible assets.
Deployment-specific details
Cloudinary region, backup or version recovery, document-retention periods, legal holds and closed-case evidence requirements are not published until they are approved in production configuration.