MICIS controlled staff pilot privacy notice
Arden University Limited is the controller for the personal information used in the controlled MICIS staff pilot. MICIS supports module review, evidence-led recommendations, improvement decisions and implementation tracking.
The pilot is not a staff-monitoring, performance-management or automated decision-making system. Do not enter student personal data, special-category information, passwords, confidential case material or unnecessary personal information.
Information used
- Your name and Arden University email address.
- Your fixed MICIS role, account status and explicitly assigned modules.
- Sign-in, sign-out, access, refusal and administration timestamps.
- One-way identity, session and security hashes used for audit and protection.
- Role-specific session state: Administrator access remains active until deliberate sign-out, account deactivation or server revocation; other pilot roles use inactivity and absolute expiry limits.
- A shortened one-way fingerprint derived from the connection address for sign-in rate limiting.
Purpose and lawful basis
The information provides secure role-based access, prevents and investigates unauthorised access, records administrative changes and supports evaluation of the pilot. The proposed lawful basis is Arden University's legitimate interests under Article 6(1)(f) UK GDPR. The supporting assessment is MICIS-LIA-001.
Services involved
Authorised MICIS administrators and the services needed to operate the pilot may process the information. These currently include Netlify, Supabase, Postmark and Google Apps Script/Workspace. Live activation requires Arden-approved supplier and transfer arrangements.
Retention
- Approved account and assignment details: retained while the account remains approved and until an authorised Administrator changes or removes it.
- Used or expired magic-link records: deleted within 24 hours.
- Expired or revoked sessions: deleted within 30 days.
- Hashed security and administration audits: deleted after 12 months.
Approved accounts do not expire automatically. Deactivation revokes active sessions immediately, while the account record remains available to authorised Administrators for reactivation or controlled removal.
Your rights and questions
You may ask for access, correction, restriction or deletion where applicable, or object to processing based on legitimate interests. Contact Arden University's Data Protection Officer at dpo@arden.ac.uk.
Further information is available in Arden University's Privacy Policy. You may also complain to the Information Commissioner's Office.