Skip to content

School supplier pack

Supplier due-diligence answers for schools

Straight answers to the Department for Education's "Procuring EdTech" checklist and its cyber security questions for suppliers, with the exit plan, a safeguarding summary and the items still open.

Supplier due-diligence answers for schools

Draft – to be reviewed by a qualified adviser before use.

Version 2026-09-30 draft 2 · Last updated 30 September 2026

Wilgenry Software Limited (trading as Squono), a company registered in England and Wales, company number 17392061, registered office 42a Church Street, Hatfield, England, AL9 5AW. Email hello@squono.com.

About this document

This answers, in advance, the questions a school's DPO, DSL and IT lead usually ask. Each answer points to the document in this pack (squono.com/schools/trust) with the detail. Where something isn't done yet, it says so.

DfE "Procuring EdTech" checklist

#Checklist pointSquono's answerMore detail
1DPIA before buyingA DPIA template pre-filled for Squono is ready for the school to adopt and sign off.squono.com/schools/trust/dpia
2Minimal dataNo pupil accounts. No dates of birth (year group only). No medical details by default. Lesson-leave lists never include medical or SEND information. Public results never name pupils.squono.com/schools/trust/dpa
3Documented lawful basisThe school's decision. The DPIA sets out the bases schools commonly use for each purpose.squono.com/schools/trust/dpia
4Controller and processor roles in the contractThe DPA makes the school the controller and Squono the processor for school data, and states openly what Squono is controller for (each person's own account, security logs, service emails and its own billing).squono.com/schools/trust/dpa
5List of sub-processorsPublished, with 30 days' notice of changes and a right to object.squono.com/schools/trust/sub-processors
6Storage location and international transfersHosting, database, file storage and email in London (AWS eu-west-2). Push notifications (only if turned on) and the mobile app's font download involve servers outside the UK.squono.com/schools/trust/sub-processors
7Retention and deletion, including backupsAutomatic deletion by type of data; backups roll off within 35 days.squono.com/schools/trust/retention
8Export, portability and exit planCSV exports at any time; deletion within 30 days of termination; written confirmation on request. See "Exit plan" below.squono.com/schools/trust/due-diligence
9Encryption, MFA for staff and audit logsHTTPS with HSTS. Two-factor authentication mandatory for every school staff account. Audit log of administrative, sharing, publishing and deletion actions. Encryption at rest: see the security overview for exactly where things stand.squono.com/schools/trust/security
10AI tools: no training on pupil dataSchools mode has no AI features, no face recognition and no automatic tagging. School data is never used to train AI. Machine translation is off by default and not used for schools.squono.com/schools/trust/dpa
11Children's code standardsSquono's own assessment is that the ICO Children's code is likely to apply to its service (parents create their own accounts), so it treats it as applying. In Schools mode pupils have no accounts, there is no profiling, no advertising, no prompts to buy anything, and school teams have no public pages.squono.com/schools/trust/dpia
12Safeguarding, with the DSL involvedNo pupil accounts; chat off by default; no direct messages to pupils; concerns go to the school's DSL first. See "Safeguarding and online safety" below.squono.com/schools/trust/due-diligence
13Support for data subject rightsStaff can correct, delete and export in the app. Squono helps within 5 working days of a request.squono.com/schools/trust/dpa
14Breach notification timesWithout undue delay – target 24 hours, never later than 48 hours after Squono becomes aware.squono.com/schools/trust/dpa
15Ongoing reviewEvery document is versioned and dated. Squono answers a yearly supplier questionnaire free of charge. A new DPA version must be accepted again.squono.com/schools/trust
16Contract clausesThe DPA covers every Article 28(3)(a)–(h) duty, plus Articles 28(2) and 28(4).squono.com/schools/trust/dpa
17Consult the DPO, DSL and ITThis pack is written for all three. Questions to hello@squono.com.squono.com/schools/trust

DfE cyber security questions for suppliers

QuestionSquono's answer
Cyber Essentials, Cyber Essentials Plus or ISO 27001?Not yet. Squono is not yet Cyber Essentials certified and has no ISO 27001 certification.
How is data processed, stored and deleted?On Squono's servers in London, with automatic deletion as in the retention schedule (squono.com/schools/trust/retention).
Is data encrypted in transit and at rest?In transit: yes, HTTPS everywhere. At rest: the data is on AWS in London, but Squono doesn't yet add its own encryption to the database server's disk or on-server backups, and object storage encryption is to be confirmed in the hosting configuration. Details in squono.com/schools/trust/security.
Does the data stay in the UK?Hosting, database, files and email: yes, London. Exceptions: push notifications (only if turned on) and the mobile app's font download from Google.
MFA for all accounts, and least-privilege access?MFA is mandatory for all school staff accounts and optional for parents. Roles limit what each person sees. Squono staff can only access a school's data through a time-limited grant the school approves.
Ransomware and outage recovery?Daily database backups kept 14 days on the server plus hosting snapshots, and a written restore procedure. Encrypted off-site backups are planned. No contractual uptime guarantee.
Breach notification timescales in the contract?Yes: DPA section 13 – target 24 hours, never later than 48 hours.
Critical and high-risk patches within 14 days?Dependencies are updated regularly and Squono aims to meet the 14-day standard. It doesn't claim a fixed deadline.
Annual supplier review?Squono answers a yearly questionnaire free of charge and publishes dated versions of this pack.
Penetration testing?Not yet done. It is planned.

Exit plan

  • The school can export its data at any time as CSV: fixtures, results, attendance and consent slips.
  • To leave, the school tells Squono at hello@squono.com. Squono makes the export available and then deletes the school's data within 30 days of termination.
  • Backups roll off within 35 days.
  • On request, Squono confirms the deletion in writing.
  • Parents keep their own Squono accounts, without any link to the school.

Safeguarding and online safety

  • Pupils have no accounts, so there is no contact between adults and pupils through Squono.
  • Chat is off by default in Schools mode, and there are no direct messages to pupils.
  • Concerns about a child go to the school's designated safeguarding lead first. Squono is not a safeguarding record system and must not be used to record concerns.
  • No face recognition, no automatic tagging and no AI features.
  • Photos follow the school's consent records, with "do not photograph" warnings for staff and location data removed.
  • A school setting records whether staff may upload photos from personal phones. The default is no: school devices only.
  • Pupils with a safeguarding restriction are never named to anyone outside staff and their own family.
  • Online Safety Act: Squono's risk assessments under the Act are not yet completed. A summary will be added to this pack when they are.

Items still open

For transparency, these are the things Squono has not finished yet:

  • Legal review: every document in this pack is a draft until a qualified adviser has reviewed it.
  • ICO registration: to be confirmed.
  • Cyber Essentials: not yet certified.
  • Penetration test: planned, not yet done.
  • Encryption at rest: Squono's own encryption of the database server disk and backups is not in place yet; encrypted off-site backups are planned.
  • Online Safety Act risk assessments: not yet completed.
  • Accessibility: no full WCAG 2.2 AA audit yet.

Other documents in the pack