Legal information

Document Upload and Retention Notice

This notice explains protected uploads, staff access and configurable retention controls for student files.

01

Accepted uploads

Authorized case checklists accept one PDF, JPG or PNG within the configured limit. Profile photos accept validated JPEG or PNG images. Unrelated records must not be uploaded.

02

Validation and quarantine

The server checks extension, declared type and signature. Images are inspected and profile photos normalized. If the configured malware-scanning add-on is enabled, files remain quarantined until confirmed.

03

Private delivery

Authenticated Cloudinary delivery and opaque identifiers are used. A short-lived signed link is created only after ownership or permitted staff scope is confirmed.

04

Review and replacement

Documents may be under review, accepted, rejected or replaced. Rejected and superseded files follow the approved retention rule.

05

Retention controls

Values are centralized and disabled until approved. Active-case files are not automatically destroyed. Narrow dry-run-first jobs and reviewed deletion requests handle eligible assets.

06

Deployment-specific details

Cloudinary region, backup or version recovery, document-retention periods, legal holds and closed-case evidence requirements are not published until they are approved in production configuration.