# Education Alliance Finland (EAF)
Source: https://docs.squid.gg/education
## **Curriculum Quality Accreditation**
### **Overview**
Education Alliance Finland (EAF) is an independent Finnish quality assurance organization that evaluates educational programs, digital learning solutions, and curricula against internationally recognized standards for effective teaching and learning.
EAF was established by Finnish education experts and researchers to help educational providers demonstrate that their programs are built on proven pedagogical principles rather than engagement alone.
For Squid Academy, EAF accreditation provides independent verification that program design, learning experiences, and educational methodologies support meaningful learning outcomes.
# **What EAF Accredits**
Unlike institutional accreditation bodies that assess an organization as a whole, EAF evaluates the quality of the educational product itself.
The accreditation focuses on:
* Curriculum Design
* Learning Methodology
* Educational Effectiveness
* Learner Engagement
* Accessibility
* Pedagogical Quality
* Assessment Design
* Learning Outcome Alignment
EAF does not assess business operations, financial performance, or institutional governance. Its focus is solely on educational quality and learner impact.
# **Why EAF Matters**
Many esports and digital learning programs are developed primarily around participation and engagement.
EAF accreditation provides assurance that a program has been evaluated against recognized educational standards and learning science principles.
The accreditation demonstrates that:
* Learning objectives are clearly defined.
* Activities support intended outcomes.
* Assessments align with learning goals.
* Content is age-appropriate.
* Educational experiences are learner-centered.
* Program design supports knowledge retention and skill development.
# **Benefits for Students**
Students benefit from programs that have been independently reviewed for educational effectiveness.
This means learners receive:
* Structured learning pathways
* Clear progression routes
* Meaningful assessment opportunities
* Evidence-based educational experiences
* Improved engagement and retention
Students can be confident that the program has been designed to support genuine learning and skill development.
# **Benefits for Schools and Partners**
For schools, colleges, and training providers, EAF accreditation provides an additional layer of educational assurance.
Benefits include:
* Independent curriculum validation
* Increased stakeholder confidence
* Enhanced quality assurance credentials
* Support for educational audits and inspections
* Evidence of commitment to educational excellence
The accreditation demonstrates that the program has been assessed against internationally recognized educational quality standards.
# **EAF and the Squid Academy Quality Framework**
Within the Squid Academy Accreditation Framework, Education Alliance Finland represents the first layer of quality assurance.
### **Layer 1 – The Curriculum**
**Key Question:** Is the program educationally sound?
**Accreditation:** Education Alliance Finland (EAF)
**Focus:** Curriculum quality, pedagogy, and learning effectiveness.
This layer ensures that students are engaging with learning experiences that have been independently evaluated against recognized educational standards.
# **Accreditation Status**
**Accreditation Body:** Education Alliance Finland (EAF)
**Country of Origin:** Finland
**Accreditation Type:** Curriculum and Pedagogical Quality Certification
**Scope:** Educational Products, Programs, and Learning Methodologies
**Squid Academy Status:** Accredited
# **Summary**
Education Alliance Finland accreditation confirms that Squid Academy programs are built on recognized educational principles and have undergone independent evaluation for pedagogical quality.
The accreditation provides confidence to students, parents, schools, and educational partners that learning experiences are designed not only to engage learners but also to deliver meaningful educational outcomes.
\\
# FAQs
Source: https://docs.squid.gg/faqs
Quick answers about getting started, accounts, user roles, tournaments, and policies.
> Can’t find it here? Use the search bar above or email **[support@squid.gg](mailto:support@squid.gg)**.
## General
Squid Academy is a role-based learning and competition platform for schools, teams, and partners.
Start on the Welcome page for a quick overview and video.
Admins: Org Admins. Teachers: Teachers.
Students: Students. Tournaments:
Team Captains,
Players,
Tournament Admins.
Use the **Contact Us** button in the header or email **[support@squid.gg](mailto:support@squid.gg)**.
For school-specific issues, contact your organization’s admin first.
***
## Accounts & Access
Org Admins are created by a Partner or Reseller.
Teachers/Students are created by the Org Admin (your school).
Use Forgot Password on the sign-in page. If you don’t receive an email, ask your Org Admin to reset it.
You may not be assigned yet. Ask your Org Admin to add you to the correct org/class; then log out and back in.
Ask your Org Admin (or your Partner/Reseller if you’re an org admin). They can update user details in their console.
***
## LMS (Classes, Courses, Progress)
Org Admins: go to Classes → Add Class, assign a teacher, pick modules/courses, then add students.
See Org Admins.
If enabled by your school, teachers can add students from the class Edit page. Otherwise, ask the Org Admin.
Enable/disable chapters in the class Edit page (teachers or admins, depending on your school’s settings).
Have them reopen the lesson and click Finish/Complete, then refresh. Teachers/Admins can verify progress on the class page.
You can choose which modules/chapters are active for each class. Course material itself is managed centrally.
***
## Tournaments
Team Captains: open the tournament area, Create Team, set the name/logo, and invite players.
See Team Captains.
Open the event page and click Register Team. Ensure your roster meets event requirements.
Captains report scores on the match page and attach proof if requested. Tournament Admins verify and resolve disputes.
Contact a Tournament Admin immediately with evidence (screenshots, VOD). They will adjust results per the rules.
***
## Privacy, Security & Legal
Use the Privacy Request Form. We’ll verify your identity and respond within the required legal timeframe.
***
## Partners & Resellers
Use the Partner console to create organizations and (optionally) appoint Resellers.
See Partners.
Yes. Your Partner can convert an existing org to a Reseller or create a separate Reseller account and keep the original org for teaching.
See Partners.
# About Squid Academy
Source: https://docs.squid.gg/introduction/about
What Squid Academy is, who it’s for, and how the platform works.
Squid Academy is a **role-based learning and competition platform** for schools, teams, and partners. We combine an LMS for day-to-day teaching and learning with a tournaments system for events and leagues—all under one account.
Our docs are organized by **role** (Org Admins, Teachers, Students, Partners/Resellers, Team Captains, Players, Tournament Admins) so each person can get exactly what they need.
If you’re new here, jump to Get Started or browse the User Guides.
## Platform at a glance
| Area | What it includes | Typical users |
| --------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ----------------------------------------- |
| **LMS (Learning Platform)** | Classes, lessons/modules, assignments, assessments, progress tracking, and basic analytics. | Org Admins, Teachers, Students |
| **Tournaments Platform** | Teams/rosters, registrations, brackets & schedules, match reporting, results & standings, and dispute resolution tools. | Tournament Admins, Team Captains, Players |
| **Admin Console** | Organization setup, user & role management, quotas/limits, branding, and policy settings. | Partners/Resellers, Org Admins |
| **Trust & Safety** | Privacy controls, consent workflows, incident response, data processing terms, and compliance documentation. | All roles / leadership |
## Who it’s for
* **Partners / Resellers** – create and manage organizations; assign quotas; help schools get set up.\
See Partners and Resellers.
* **Org Admins** – run the LMS for a school; add teachers & students; manage classes and access.\
See Org Admins.
* **Teachers** – deliver lessons, unlock content, grade submissions, and monitor progress.\
See Teachers.
* **Students** – take lessons and quizzes, submit work, and track scores.\
See Students.
* **Tournament Admins** – configure events, publish schedules, verify results, and resolve disputes.\
See Tournament Admins.
* **Team Captains & Players** – create or join teams, register for events, and report match scores.\
See Team Captains and Players.
## How the platform fits together
* Schools run classes inside the LMS.
* Teachers assign lessons/modules and grade work.
* Students complete activities and see feedback/scores.
* Admins track progress and manage accounts centrally.
* Events are configured with rules, eligibility, and formats.
* Teams register; schedules and brackets are published.
* Captains/players report scores; admins verify results.
* Standings are updated automatically; disputes are resolved with evidence.
## What makes Squid Academy different
* **Role-based experience** – interfaces and docs are tailored to each role, keeping things simple.
* **One platform** – learning + competition in one place, with a single account.
* **Built-in safeguards** – privacy settings, consent workflows, and incident response are first-class.
* **Clear documentation** – policies and user guides live together so schools can deploy with confidence.
## Trust, Safety & Privacy
We take privacy and security seriously. Key references:
* **Privacy Policy:** /platform/privacy-policy
* **Terms & Conditions:** /platform/terms-and-conditions
* **Security & Incident Response:** /platform/security-incident-response
* **Data Processing Addendum (DPA):** /platform/data-processing-addendum
* **International Data Transfers:** /platform/intl-data-transfers
* **Sub-processor List:** /platform/sub-processor-list
* **Data Retention & Deletion:** /platform/data-retention-deletion
* **Parental Content Guide:** /platform/parental-content-guide
* **Your Privacy Rights (how to make a request):** /platform/your-privacy-rights
* **Submit a Privacy Request:** /platform/privacy-request-form
Security concern? Email [security@squid.gg](mailto:security@squid.gg).\
Privacy question or request? Email [privacy@squid.gg](mailto:privacy@squid.gg) or use the Privacy Request Form.
## Get started
Start with the guide for your role under User Guides.
Partners/Resellers create organizations and assign quotas. Org Admins add teachers & students and create classes. Teachers open a class and assign a lesson.
Teachers assign a lesson and collect submissions. Tournament Admins configure an event, then publish schedules.
## Need help?
* General support: [support@squid.gg](mailto:support@squid.gg)
* Community: Discord
# Get Started
Source: https://docs.squid.gg/introduction/get-started
A fast, role-based setup guide for Squid Academy. Pick your role and follow the first steps.
Welcome! This page gets your school, team, or event moving in **minutes**. Squid Academy is role-based, so choose your role below and follow the checklist.
New here? Also see About Squid Academy for a high-level overview.
## What you’ll need
* A **Squid Academy account** (created by your Partner/Reseller or Org Admin).
* The email you’ll use to log in.
* If you’re a parent/guardian in a jurisdiction requiring consent, see Parental Content Guide.
***
## Quick start by role
Create organizations, assign quotas, enable modules, and monitor usage.
Onboard schools under a Partner, add org admins, and help run setup.
Add teachers & students, create classes, and manage access.
Assign lessons/modules, grade submissions, and track progress.
Join your class, complete lessons, submit work, and see scores.
Configure events, publish schedules, verify results, and resolve disputes.
Create/manage teams, register for events, and report match scores.
Join your team, follow schedules, play matches, and submit results.
***
## 5-minute setup (everyone)
Use the email provided by your organization. If you can’t sign in, contact your Org Admin or Reseller.
Your dashboard shows features for your role (Teacher, Student, Admin, etc.). If it looks wrong, ask an Org Admin to adjust your role.
• LMS users: open the **Classes** area.\
• Tournament users: open the **Competitions** area (Teams, Events, Schedules).\
• Admins: open the **Admin Console** for setup and user management.
***
## Org Admin launch checklist (≈15–20 minutes)
* [ ] **Add Teachers** — create teacher accounts.
* [ ] **Add Students** — import or create students (optionally grouped by class).
* [ ] **Create Classes** — name, assign teacher(s), and select modules/chapters to unlock.
* [ ] **Review Policies/Settings** — branding, quotas, and privacy options in your Admin Console.
* [ ] **Share Access Details** — send login info and the links to the Teacher and Student guides.
Helpful references:
* Org Admins guide
* Terms & Conditions · Privacy Policy
* Your Privacy Rights · Privacy Request Form
***
## Teacher first steps (≈10 minutes)
* [ ] **Open your Class** → **Add Lesson/Module** → assign to students.
* [ ] **Collect Submissions** and (if needed) **Grade**.
* [ ] **Check Progress** in the class dashboard.
* [ ] **Unlock/Lock Chapters** to pace content.
See the full Teachers guide.
***
## Student first steps (≈5 minutes)
* [ ] **Sign in** → open **My Classes**.
* [ ] **Start your next Lesson** and complete all steps.
* [ ] **Submit** your work and confirm status shows **Finished/Complete**.
* [ ] **Check Scores/Feedback** once reviewed.
See the full Students guide.
***
## Tournaments quick start
**Tournament Admins**
* [ ] Create an **Event** → set rules, eligibility, and format.
* [ ] Open **Registration** and publish **Schedules/Brackets**.
* [ ] **Verify Results** and resolve disputes with evidence when needed.\
See Tournament Admins.
**Team Captains / Players**
* [ ] **Create/Join** a team.
* [ ] **Register** for an event and review match times.
* [ ] After playing, **report scores** (attach proof if requested).\
See Team Captains and Players.
***
## Roles & where they work
| Role | Who creates the account | Where they spend time |
| -------------------- | ------------------------------ | -------------------------------------------- |
| **Partner** | Squid / Enterprise agreement | Admin Console (organizations, quotas) |
| **Reseller** | Partner | Admin Console (onboarding, user setup) |
| **Org Admin** | Partner/Reseller | Admin Console (users, classes, settings) |
| **Teacher** | Org Admin | LMS (classes, lessons, grading) |
| **Student** | Org Admin | LMS (lessons, assignments, results) |
| **Tournament Admin** | Org Admin/Partner | Tournaments area (events, results, disputes) |
| **Team Captain** | Tournament Admin or self-serve | Tournaments area (teams, registrations) |
| **Player** | Captain/Admin | Tournaments area (roster, matches) |
***
## Privacy, safety, and requests
* Privacy Policy · Terms & Conditions
* Security & Incident Response
* Data Processing Addendum (DPA) · International Data Transfers
* Your Privacy Rights → submit a request via the Privacy Request Form.
Security concern? Email [security@squid.gg](mailto:security@squid.gg).\
Privacy question or request? Email [privacy@squid.gg](mailto:privacy@squid.gg).
***
## Troubleshooting
Check you’re using the right email and workspace. If still stuck, contact your Org Admin or Reseller.
Your role might be set incorrectly. Ask an Org Admin to update your role (Teacher, Student, Admin, etc.).
Reopen the lesson and ensure you clicked **Finish/Complete**, then refresh. Teachers/Admins can verify progress.
See Your Privacy Rights and use the Privacy Request Form.
***
# Support
Source: https://docs.squid.gg/introduction/support
How to get help, report a problem, or contact the right team.
We’re here to help! Use the options below to reach the right team quickly.
Questions about accounts, classes, tournaments, or anything else.
Read your rights and submit a request via the Privacy Request Form.
Report a potential security or data-protection issue.
New to the platform? Start with Get Started or the User Guides.
***
## How to report a problem (best practice)
Please include:
1. **Page or Area** – URL or feature name (e.g., Classes → Assignments).
2. **What happened** – the error, unexpected behavior, or missing option.
3. **What you expected** – what you tried to do.
4. **Steps to reproduce** – numbered steps help a ton.
5. **Screenshots or short video** – if possible.
Send to **[support@squid.gg](mailto:support@squid.gg)**.
***
## Common requests
If your school manages accounts, contact your **Org Admin** first. Otherwise email [support@squid.gg](mailto:support@squid.gg).
Teachers and Org Admins control class setup and lesson pacing. Start with the relevant guide:
Squid Academy is a role-based learning and competition platform for schools, teams, and partners. Use the quick links below to jump into guides, policies, and FAQs.
## Start here
Add teachers & students, create classes, assign courses.
Manage classes, unlock content, track progress, and grade.
Find your classes, complete lessons, and check your scores.
Set rules, brackets, schedules; verify results & resolve disputes.
## Policies & help
What we collect, why, and your choices.
The rules for using our platform.
Our security practices and incident response.
Submit an access, deletion, correction, or export request.
# Language and Accessibility Standards
Source: https://docs.squid.gg/language
## **Purpose**
Squid Academy is committed to ensuring that all program materials are accessible, inclusive, and appropriate for their intended audience. To support consistent delivery across international markets and mixed-ability learning environments, all program content is developed according to defined Common European Framework of Reference for Languages (CEFR) standards.
These standards ensure that learners, educators, coaches, assessors, and partner institutions can engage with program content confidently, regardless of prior experience in esports, gaming, education, or well-being.
# **Mind Your Game (MYG)**
## **Student-Facing Materials**
The following resources are written at **CEFR A2–B1**:
* eCourse Materials
* Student Reflection Worksheets
* Lesson Handouts
* Student Glossaries
* In-Class Learning Resources
This language level supports:
* Mixed-ability classrooms
* English language learners
* Students new to gaming and well-being education
* Accessible understanding of key concepts
Materials are designed to introduce topics such as dopamine, flow, tilt, neuroplasticity, emotional regulation, resilience, and well-being using clear, age-appropriate language while maintaining academic accuracy.
## **Teacher-Facing Materials**
The following resources are written at **CEFR B1**:
* Class Slides and Delivery Scripts
* Teacher Workshop Guides
* Module Overviews
* Teacher Glossaries
* Delivery Notes
These resources are designed to support educators who may have no prior background in gaming, esports, or psychology. Sessions are structured to be delivered confidently using step-by-step guidance and read-aloud teaching materials.
These standards apply across all thirteen modules within the Mind Your Game framework.
# **Play The Game (PTG)**
## **Player-Facing Materials**
The following resources are written at **CEFR A1–A2**:
* eCourse Materials
* Student Learning Guides
* In-Class Resources
* Practice Activities
This language level ensures accessibility for:
* Younger learners
* Mixed-ability training groups
* English language learners
* Players new to structured esports coaching
The program includes built-in age adaptation, allowing coaches to deliver identical concepts using simplified language for younger players and more competitive framing for older participants.
## **Coach-Facing Materials**
The following resources are written at **CEFR B1**:
* Coach Navigation Index
* Session Structures
* Coaching Notes
* Delivery Guides
* Review Frameworks
These materials support certified coaches delivering adaptive training sessions, VOD reviews, performance analysis, and scrimmage debriefs across mixed-skill groups.
These standards apply across all game modules and program themes within the Play The Game framework, including Valorant, League of Legends, and Counter-Strike 2.
# **Esports Educator Certification program (EECP)**
## **Educator-Facing Materials**
The following resources are written at **CEFR B1–B2**:
* Module Handbooks
* Scenario Assessments
* Practical Task Briefs
* Assessment Rubrics
* Style Guide Documentation
This language level supports educators who may not have prior experience in professional teaching, instructional design, or esports education.
Materials introduce concepts such as:
* Backward Design
* Gradual Release of Responsibility
* Psychological Safety
* Transferable Skills
* Facilitator-Led Learning
All content is structured using clear language and practical implementation guidance.
## **Assessor and Certification Materials**
The following resources are written at **CEFR B2**:
* Assessment Answer Keys
* Facilitator Notes
* Educator Code of Conduct
* Safeguarding Guidance
* Program Overview Documentation
* Certification Administration Materials
These resources provide the precision and clarity required for assessment, moderation, quality assurance, and certification activities while remaining accessible to professionals from diverse backgrounds.
These standards apply across all fourteen modules within the Esports Educator Certification Program and are maintained through the program's quarterly review and update cycle.
# **Quality Assurance**
All program materials undergo review against established language and accessibility standards during development and revision.
This process ensures the following:
* Consistent learner accessibility
* Clear instructional design
* International usability
* Appropriate reading levels
* Inclusive educational delivery
* Alignment with program learning outcomes
Language standards are reviewed as part of the program quality assurance process and are maintained across all future content updates and program revisions.
\\
# Academic Integrity & Plagiarism Policy
Source: https://docs.squid.gg/platform/academic-integrity-plagiarism-policy
# **1. Purpose**
Squid Academy is committed to maintaining high standards of academic integrity, honesty, and ethical conduct across all educational programs, assessments, projects, coursework, and certification activities.
Learners are expected to submit work that represents their own knowledge, understanding, and effort.
This policy outlines Squid Academy's expectations regarding plagiarism, academic misconduct, artificial intelligence (AI) tools, cheating, collusion, and other forms of dishonest academic behavior.
# **2. Scope**
This policy applies to:
* Students
* Learners
* Apprentices
* Candidates
* Participants in accredited program organizations
* Participants in non-accredited programs
The policy applies to:
* Written assignments
* Coursework
* Assessments
* Projects
* Presentations
* Practical activities
* Portfolio submissions
* Online assessments
* Certification activities
# **3. Academic Integrity Principles**
All learners are expected to:
* Submit their own work.
* Acknowledge the work of others appropriately.
* Use sources honestly.
* Follow assessment instructions.
* Complete assessments independently unless collaboration is explicitly permitted.
* Maintain honesty throughout the learning process.
Academic integrity supports fairness, credibility, and the value of qualifications and certifications awarded by Squid Academy.
# **4. What Is Plagiarism?**
Plagiarism occurs when a learner presents another person's work, ideas, words, research, or intellectual property as their own without appropriate acknowledgement.
Plagiarism may be intentional or unintentional.
Both forms may result in academic penalties.
# **5. Examples of Plagiarism**
Examples include:
### **Direct Copying**
Copying text from:
* Websites
* Books
* Articles
* Reports
* Other learners
without an appropriate citation.
### **Paraphrasing Without Attribution**
Rewriting someone else's work while presenting it as original.
### **Copying Assignments**
Submitting all or part of another learner's work.
### **Reusing Previous Work**
Submitting previously assessed work without permission.
### **Unauthorised Translation**
Translating another person's work and presenting it as original.
### **Using Purchased Work**
Submitting work created by another individual or service.
# **6. Artificial Intelligence (AI) Use**
Squid Academy recognizes that AI tools may be used responsibly as learning aids.
Examples include:
* Research assistance
* Brainstorming ideas
* Grammar checking
* Structure suggestions
* Study support
However, learners must not submit AI-generated content as entirely their own work unless explicitly permitted by the assessment instructions.
Where AI use is permitted, learners may be required to:
* Declare the AI tool used.
* Explain how the tool was used.
* Demonstrate personal understanding of the submitted work.
The Academy reserves the right to investigate submissions suspected of excessive or inappropriate AI-generated content.
# **7. Collusion**
Collusion occurs when learners work together inappropriately on an assessment intended to be completed individually.
Examples include:
* Sharing answers.
* Jointly producing individual assignments.
* Allowing another learner to copy work.
Collusion is considered academic misconduct.
# **8. Cheating**
Cheating includes any dishonest action designed to gain an unfair academic advantage.
Examples include:
* Using unauthorized materials.
* Accessing prohibited resources during assessments.
* Receiving unauthorized assistance.
* Impersonation.
* Falsifying assessment evidence.
# **9. Contract Cheating**
Contract cheating occurs when a learner arranges for another person or organisation to complete work on their behalf.
Examples include:
* Purchasing assignments.
* Hiring writers.
* Using essay-writing services.
* Paying third parties to complete assessments.
Contract cheating is considered a serious breach of academic integrity.
# **10. Referencing and Citations**
Learners should:
* Acknowledge all sources used.
* Use appropriate citations where required.
* Clearly identify quotations.
* Follow assessment guidance on referencing standards.
Staff may provide guidance on acceptable referencing methods.
# **11. Detection Methods**
Squid Academy may use various methods to identify potential misconduct, including:
* Plagiarism detection software.
* Similarity reports.
* Assessment reviews.
* Oral questioning.
* Practical demonstrations.
* Staff observations.
* AI-detection indicators.
* Verification interviews.
The Academy reserves the right to investigate any work that appears inconsistent with a learner's demonstrated ability or previous performance.
# **12. Investigation Procedure**
Where academic misconduct is suspected:
1. The concern will be documented.
2. Evidence will be reviewed.
3. The learner may be invited to provide an explanation.
4. A fair and impartial decision will be made.
5. The outcome will be recorded.
The Academy will ensure investigations are conducted consistently and proportionately.
# **13. Academic Misconduct Outcomes**
Depending on severity, outcomes may include the following:
### **Minor Breach**
Examples:
* Incorrect referencing
* First-time citation errors
Possible outcomes:
* Feedback and guidance
* Resubmission opportunity
### **Moderate Breach**
Examples:
* Significant unattributed content
* Copying sections of work
Possible outcomes:
* Assessment penalty
* Resubmission requirement
* Formal warning
### **Serious Breach**
Examples:
* Contract cheating
* Deliberate plagiarism
* Assessment fraud
* Impersonation
Possible outcomes:
* Assessment failure
* Programme removal
* Disqualification from certification
* Notification to awarding organisations, where applicable
# **14. Appeals**
Learners may appeal academic misconduct decisions through the Academy's Appeals Procedure.
Appeals must:
* Be submitted within the specified timeframe.
* Provide supporting evidence.
* Clearly state the grounds for appeal.
Appeals will be reviewed by an appropriate independent reviewer where possible.
# **15. Responsibilities**
### **Learners**
Responsible for:
* Producing original work.
* Following assessment rules.
* Acknowledging sources appropriately.
* Maintaining academic honesty.
### **Staff**
Responsible for:
* Explaining academic integrity expectations.
* Monitoring assessments fairly.
* Investigating concerns appropriately.
* Applying this policy consistently.
### **Squid Academy**
Responsible for:
* Promoting academic integrity.
* Providing guidance and support.
* Maintaining fair assessment processes.
* Protecting the value of its qualifications and certifications.
# **16. Review**
This policy will be reviewed annually or whenever academic, technological, legal, or awarding organization requirements change.
If you have any questions, comments, or concerns, please feel free to reach out to us at [support@squid.academy](mailto:support@squid.academy)
\\
# Data Processing Addendum (DPA)
Source: https://docs.squid.gg/platform/data-processing-addendum
Our contract terms for processing customer data, roles/responsibilities, and GDPR safeguards.
**...to the Squid Academy Terms & Conditions**
*(Version: August 14, 2025)*
This Data Processing Addendum (“DPA”) forms part of the Squid Academy [Terms & Conditions](https://docs.google.com/document/u/6/d/1naMWUBeGi99rmMptIY-oXLlr9BmTGDXIoFk2qQ-_p4A/edit) (the “Agreement”) between:
* Squid Academy Ltd, incorporated in England & Wales, company no. 14264598, registered office 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ (“Processor” or “Squid”), and
* The Organization identified in the Order/Sign‑Up or other agreement that governs use of the Services (“Controller”, “Customer”, or “Organization”).
Capitalized terms not defined here have the meanings in the Agreement. If there is a conflict between this DPA and the Agreement regarding processing of personal data on behalf of the Organization, this DPA controls.
## **1. Scope & Roles**
1.1 **Roles.** For personal data that the Organization provides or makes available to Squid for the Services, the Organization is Controller (or equivalent under applicable law) and Squid is Processor (or service provider/processor under non‑EU laws).
This DPA applies to all regions where Squid Academy operates, subject to applicable local privacy laws, as further detailed in the Region-Specific Addenda in [Annex VI](https://docs.squid.gg/platform/data-processing-addendum#annex-iv-%E2%80%94-cross%E2%80%91border-transfers).
1.2 **Public Users.** For personal data of Public Users who contract directly with Squid, Squid acts as an independent controller; this DPA does not apply to that processing. Processing of Public User data is governed by Squid’s [Privacy Policy](https://docs.squid.gg/platform/privacy-policy), not this DPA.
1.3 **Duration.** This DPA applies for the term of the Agreement and until deletion of personal data in accordance with [Section 10](https://docs.squid.gg/platform/data-processing-addendum#10-retention).
## **2. Controller Instructions**
2.1 Squid will process personal data only on documented instructions from the Organization, including those set forth in this DPA, the Agreement, and the [Annex I](https://docs.squid.gg/platform/data-processing-addendum#annex-i-%E2%80%94-description-of-processing) (Description of Processing).
2.2 The Organization is solely responsible for ensuring that it has obtained all necessary rights, consents, and authorizations… especially in relation to minors, in accordance with the requirements set out in the Region-Specific Addenda ([Annex VI](https://docs.squid.gg/platform/data-processing-addendum#annex-iv-%E2%80%94-cross%E2%80%91border-transfers)).
**2.3 No Model Training.** Squid will not use Controller Personal Data (including pseudonymized data) to train, retrain, or fine‑tune generalized AI/ML models or datasets for product development unrelated to the Services, except on the Organization’s documented instructions.
## **3. Processor Obligations**
3.1 **Confidentiality.** Squid will ensure personnel who access personal data are bound by confidentiality obligations.
3.2 **Security.** Squid will implement and maintain appropriate technical and organizational measures (TOMs) described in [Annex II](https://docs.squid.gg/platform/data-processing-addendum#annex-ii-%E2%80%94-technical-%26-organizational-measures-toms).
3.3 **Sub‑processors.** a) The Organization authorizes Squid to engage sub‑processors for the Services subject to this Section. b) Squid will impose written obligations on sub‑processors that are no less protective than this DPA and remain responsible for sub‑processor performance. c) **Sub‑processor list & notice.** Squid will maintain a current [Sub‑processor List](/platform/sub-processor-list) and provide at least 30 days’ advance notice of any new or replacement sub‑processor by (i) emailing the Organization’s admin contact(s) and (ii) updating the Sub‑processor List. Where an emergency replacement is required to maintain availability, security, or support, Squid may appoint the sub‑processor and will provide notice without undue delay, after which the Organization may raise a reasonable objection; if unresolved in good faith within a reasonable period, either party may terminate only the affected Service for a pro‑rated refund.
3.4 **Data Subject Requests.** Squid will assist the Organization, without undue delay, in responding to data‑subject requests (access, deletion, etc.) under applicable law (see [Section 7](https://docs.google.com/document/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit?tab=t.0#heading=h.86n0owwa9jie)).
3.5 **Assistance.** Taking into account the nature of processing, Squid will assist the Organization with data‑protection impact assessments, consultations with supervisory authorities, and security obligations (Articles 32–36 GDPR or equivalents).
3.6 **Records.** Squid will maintain records of processing activities as required by law.
3.7 **Government Requests.** If a public authority requests access to personal data, Squid will (i) notify the Organization promptly unless legally prohibited, (ii) limit disclosure to what is legally required, and (iii) challenge unlawful or overbroad requests where reasonable.
## **4. Children & Student Data (Schools/Organizations)**
4.1 **Under‑13 Public Users.** Public sign‑up for under‑13s is not allowed.
4.2 **Organization‑Invited Minors.** Organization must verify age, obtain and retain verifiable parental/guardian consent where required (e.g., COPPA; India DPDP for under‑18; Thailand PDPA for certain minors), and ensure compatible lawful bases under applicable law (e.g., UK/EU GDPR).
4.3 **No Targeted Ads / Sale.** Squid will not sell personal data, nor process it for cross‑context behavioral advertising, profiling of minors, or other restricted purposes under applicable US state privacy laws when acting as Processor.
4.4 **Combination Limits.** Squid will not combine personal data received from the Organization with other data except as permitted to provide and secure the Services, or as required by law.
## **5. Security Incidents**
5.1 \*\*Notifications. \*\*Squid will notify the Organization without undue delay after becoming aware of a Security Incident (meaning any confirmed unauthorized access to, or accidental loss, alteration, or disclosure of, personal data processed for the Organization). Where GDPR applies, Squid shall notify the Organization without undue delay and, where feasible, not later than 72 hours after becoming aware of a Security Incident. The initial notice will include known details per [Annex V](https://docs.google.com/document/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit?tab=t.0#heading=h.s4z5afjkizxc) and be followed by updates as information becomes available. Notices will be sent to the Organization’s admin/DP contact and [privacy@squid.gg](mailto:privacy@squid.gg).
5.2 Squid will promptly take reasonable steps to contain, investigate, and remediate the incident and will cooperate with the Organization’s reasonable requests, including regulatory notifications the Organization must make.
## **6. International Transfers**
6.1 **Mechanisms.** Where personal data are transferred across borders, Squid will use appropriate safeguards, including:
* **EU Standard Contractual Clauses (SCCs 2021/914)**: Module 2 (Controller→Processor) and/or Module 3 (Processor→Processor), as applicable ([Annex IV](https://docs.google.com/document/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit?tab=t.0#heading=h.g6ld9xp3nybu)),
* **UK Addendum/IDTA** to the SCCs for UK transfers, and
* other approved mechanisms (e.g., contractual, adequacy, or local law equivalents) for Malaysia, Thailand, India, or other regions.
Squid will support the Organization’s transfer impact assessments and implement supplementary measures (technical, organizational, and contractual) reasonably required to address cross‑border data transfer risks identified by the Organization.
6.2 Conflicts. To the extent of conflict, the SCCs/UK Addendum and required local addenda prevail solely for cross‑border transfers.
For a plain-language overview, see our [International Data Transfers](/platform/intl-data-transfers) page.
***
## **7. Data Subject Rights & Cooperation**
Taking into account the nature of processing, Squid will assist the Organization by appropriate technical and organizational measures to fulfill data‑subject requests (access, rectification, erasure, portability, restriction, objection). The Organization is responsible for authenticating requesters and providing Squid with the necessary information to identify relevant records. Where requests are excessive, manifestly unfounded, or duplicative, Squid may charge reasonable costs for assistance.
For more information on how data subjects can exercise these rights, see our [Your Privacy Rights](/platform/your-privacy-rights) page and [Submit a Privacy Request form](/platform/privacy-request-form).
***
## **8. Audits & Certifications**
8.1 **Reports.** On request (no more than once per 12‑month period, unless there is a reasonable suspicion of non‑compliance or after a Security Incident), Squid will provide available audit reports or certifications relevant to the Services (e.g., independent penetration tests, security summaries, or any ISO/SOC reports if available).
8.2 **On‑site Review.** If such reports are insufficient, the Organization may conduct a reasonable audit of Squid’s applicable controls, subject to: (i) 30 days’ notice, (ii) confidentiality, (iii) conduct during business hours without disrupting operations, and (iv) allocation of Organization’s own costs.
Prior to any on‑site review, the parties will first exhaust remote audit options (e.g., security questionnaires, third‑party reports, and control walkthroughs). The Organization may appoint an independent, qualified auditor bound by confidentiality to perform the audit on its behalf.
8.3 **Sub‑processor audits** are satisfied by reliance on Squid’s due diligence and third‑party reports where available.
***
## **9. Return & Deletion**
9.1 **During Term.** The Organization may export data via available tools or request reasonable assistance.
9.2 **Termination.** Upon termination/expiry of the Services, upon the Organization’s written instruction, Squid will delete or return personal data and delete existing copies within 35 days, unless retention is required by law or for backup/archival integrity (in which case data will be isolated and securely deleted on the next standard cycle).
Upon completion of deletion, Squid will provide a written deletion confirmation. Returned data will be provided in a commonly used, machine‑readable format (e.g., CSV/JSON), unless otherwise agreed.
For details of our standard retention periods by category of data, see our [Data Retention & Deletion Schedule](/platform/data-retention-deletion).
***
## **10. Liability & Indemnity (DPA)**
10.1 **Allocation.** The parties’ liability limitations in the Agreement apply to this DPA to the maximum extent permitted by law.
10.2 **Controller Indemnity.** Organization will indemnify Squid for claims arising from the Organization’s failure to provide required notices/consents (including parental consent), unlawful instructions, or misuse of the Services.
10.3 **Processor Indemnity.** Squid will indemnify the Organization for third‑party claims to the extent arising from Squid’s material breach of this DPA or willful misconduct in its role as Processor.
***
## **11. Service Provider / Processor (Non‑EU Laws)**
For US state privacy laws (including but not limited to CCPA/CPRA, VCDPA, CPA, UCPA, CTDPA, TDPSA), Squid acts as a service provider/processor: it shall (a) process only for the limited and specified purposes in the Agreement, (b) not sell or share personal data, (c) not retain, use, or disclose data outside the business purpose, (d) implement security measures, and (e) flow down the same obligations to sub‑processors.
***
## **12. Order of Precedence; Updates**
12.1 If there is a conflict between this DPA and the Agreement regarding data processing, this DPA prevails.
12.2 Squid may update Annexes to reflect sub‑processor changes, security improvements, or legal changes with prior notice where material; material adverse changes require mutual agreement unless required by law.
***
## **13. Term & Termination**
This DPA enters into force on the date the Organization accepts/executes the Agreement or this DPA (whichever earlier) and remains in effect until Squid’s deletion/return of personal data under [Section 9](https://docs.google.com/document/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit?tab=t.0#heading=h.so045ia3ic86).
***
## **14. Governing Law & Venue**
14.1 Between the parties, this DPA follows the governing law and venue set in the Agreement (England & Wales), except that the SCCs/UK Addendum are governed by their own clauses as specified in [Annex IV](https://docs.google.com/document/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit?tab=t.0#heading=h.g6ld9xp3nybu).
14.2 Nothing in this DPA limits mandatory protections under applicable law.
***
### **SIGNATURES**
This DPA may be accepted by click‑wrap or executed in counterparts (electronic signatures permitted).
**Controller / Organization** By: \_**\_ (Name)Title: \_**\_ Date: \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_
**Processor / Squid Academy Ltd** By: \_**\_ (Name)Title: \_**\_ Date: \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_
## **ANNEX I — Description of Processing**
**A. Subject Matter & Purpose.** Squid processes personal data to provide the LMS + Tournament Services (user provisioning, authentication, classroom & team management, course delivery, progress tracking, tournament operations, support, security, and service improvement). Squid may analyze aggregated and de-identified usage metrics to maintain and improve the Services. Squid will not attempt to re‑identify de‑identified data.
**B. Duration.** For the term of the Agreement plus deletion period in [Section 9](https://docs.google.com/document/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit?tab=t.0#heading=h.so045ia3ic86).
**C. Nature of Processing.** Collection, storage, retrieval, transmission, display, structuring, analysis of usage for security/operations, deletion.
**D. Types of Personal Data.**
* \*\*Identification: \*\*name, email, organization affiliation/role, user IDs.
* **Educational use data:** enrollments, progress/completions, classroom/team membership, submissions, match results, timestamps, limited telemetry (e.g., login logs).
* **Support meta:** ticket content, error logs (which may incidentally contain personal data).
* \*\*Payments: \*\*Squid does not process payment card data for the Services. Payments are handled by third‑party payment processors, except where explicitly stated in the Order.
**E. Special Categories.** Not intended. Organization must not transmit special‑category data (health, biometrics, etc.) or children’s data beyond what is necessary for educational use.
**F. Data Subjects.** Students, teachers/coaches, Organization staff, tournament participants invited by the Organization.
**G. Controller Instructions.** Process strictly to deliver the Services per the Agreement; apply age/consent restrictions; support export and deletion upon request.
***
## **ANNEX II — Technical & Organizational Measures (TOMs)**
**1. Governance & Access**
* Role‑based access control (RBAC), least privilege; MFA for admin access.
* Background‑checked staff under confidentiality commitments.
* Joiner‑mover‑leaver processes; periodic access reviews.
**2. Encryption**
* **In transit:** TLS 1.2+ for all external connections.
* **At rest:** Industry‑standard encryption (e.g., AES‑256 or cloud‑provider equivalent) for databases and backups where supported.
**3. Secure Development & Change Management**
* Source control, code review, dependency scanning.
* Vulnerability management (CVSS‑based triage), remediation SLAs for critical/high findings.
* Staging/testing before production; change logs and approvals.
**4. Network & Infrastructure Security**
* Segmented cloud environments; hardened images; security groups/firewalls; WAF/anti‑DDoS where applicable.
* Continuous monitoring/alerting; audit logging for security‑relevant events.
**5. Data Minimization & Retention**
* Collect only necessary fields (name, email, org, progress).
* Time‑bound log retention; backups encrypted and time‑limited.
**6. Business Continuity & Disaster Recovery**
* Regular backups; documented recovery procedures; periodic restore testing.
**7. Third‑Party Risk**
* Due diligence for sub‑processors; contractual flow‑down of data‑protection obligations; ongoing monitoring.
**8. Incident Response**
* Defined escalation paths; detection, containment, eradication, recovery; post‑incident review; customer notification “without undue delay.”
For a plain‑language overview, see our [Security & Incident Response](/platform/security-incident-response) page.
## **ANNEX III — Sub‑Processors**
**Current categories** (non‑exhaustive):
* Cloud infrastructure/IaaS (compute, storage, networking)
* Email delivery & notifications
* Error monitoring & crash analytics
* Customer support tooling / ticketing
* Log management & security monitoring
**Disclosure & updates.** Squid will maintain a [Sub‑processor List](/platform/sub-processor-list) identifying each sub‑processor’s name, purpose, processing location, and transfer mechanism (if outside the UK/EU) and will keep it up to date. Squid will provide at least 30 days’ advance notice of new or replacement sub‑processors as set out in 3.3(c), and the Organization’s objection/termination rights in 3.3(c) apply.
**Upon request,** Squid will provide the then‑current named list if the Organization cannot access the Sub‑processor List.
## **ANNEX IV — Cross‑Border Transfers**
**EU SCCs (2021/914)**
* **Module 2 (Controller→Processor)** applies to Organization→Squid transfers.
* **Module 3 (Processor→Processor)** applies to Squid→sub‑processor transfers.
* **Docking clause** enabled.
* **Governing law/forum for SCCs:** Ireland; Irish Data Protection Commission as supervisory authority; Irish courts have jurisdiction.
* **Annex I(A–C)**: Parties, Description of Transfer → use [Annex I](https://docs.squid.gg/platform/data-processing-addendum#annex-i-%E2%80%94-description-of-processing) of this DPA.
* **Annex II**: TOMs → as per [Annex II](https://docs.squid.gg/platform/data-processing-addendum#annex-ii-%E2%80%94-technical-%26-organizational-measures-toms) of this DPA.
* **Annex III**: Sub‑processors → as per [Annex III](https://docs.google.com/document/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit?tab=t.0#heading=h.80o7pwvxdwsq) of this DPA.
**UK Addendum (IDTA/Addendum to EU SCCs)**
* Incorporated for UK transfers; the Issuing Clauses are as per the UK ICO template. Complete required tables by reference to this DPA’s Annexes.
* UK Addendum (Addendum to EU SCCs). The parties incorporate the UK ICO Addendum. Table 1 (Parties), Table 2 (Selected SCCs), and Table 3 (Technical and Organizational Measures and Sub‑processors) are completed by reference to this DPA’s[Annex I](https://docs.squid.gg/platform/data-processing-addendum#annex-i-%E2%80%94-description-of-processing) (Parties/Description of Processing), [Annex II](https://docs.squid.gg/platform/data-processing-addendum#annex-ii-%E2%80%94-technical-%26-organizational-measures-toms) (TOMs), and [Annex III](https://docs.google.com/document/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit?tab=t.0#heading=h.80o7pwvxdwsq) (Sub‑processors), and Table 4 (Ending the UK Addendum when the Approved Addendum Changes) is set to the template default.
**Other Regions**
* Use contractual safeguards permitted under local law (e.g., Malaysia PDPA cross‑border rules; Thailand PDPA adequacy/safeguards; India DPDP contractual protections pending rules).
## **ANNEX V — Security Incident Playbook (Summary)**
This Annex summarizes Squid’s internal playbook and complements [Section 5](https://docs.google.com/document/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit?tab=t.0#heading=h.vr9byi9v4dh1); where GDPR applies, Squid targets initial notification within 72 hours of awareness.
**Trigger:** Potential or confirmed compromise affecting personal data.
**Notification:** To Controller without undue delay after confirmation; initial notice aims to include: nature of incident, categories/volume of data affected, likely consequences, and measures taken/proposed.
**Containment & Recovery:** Isolate affected systems; rotate keys/secrets; restore from clean backups as needed.
**Investigation:** Root cause analysis; timeline reconstruction; corrective actions.
**Post‑Incident:** Report and preventive improvements shared with Controller.
For a plain‑language overview, see our [Security & Incident Response](/platform/security-incident-response) page.
## **ANNEX VI — Region‑Specific Addenda (Processor Commitments)**
**United States (incl. Texas) & Puerto Rico**
* Act as service provider/processor (no “sale” or “sharing”; no cross‑context behavioral ads; children’s data protections).
* For COPPA contexts: process children’s personal information only on documented instructions from the Controller; rely on verifiable parental consent obtained and retained by the Controller; provide deletion assistance.
* FERPA (where applicable): act as a “school official” under Controller’s direct control, using data only for educational purposes.
* Support state privacy obligations (access, deletion, correction) through Controller workflows.
**Malaysia (PDPA 2010)**
* Process only for stated purposes; assist Controller with PDPA access/correction rights; use approved cross‑border safeguards.
**Thailand (PDPA 2019)**
* Respect consent requirements for minors per PDPA; assist with data‑subject rights; implement appropriate safeguards for cross‑border transfers.
**India (DPDP Act 2023)**
* Treat **children (\<18)** as protected data principals: no tracking/targeted advertising directed at children; process only on Controller’s instructions with parental consent confirmed by Controller; assist with data‑principal requests; apply transfer safeguards consistent with DPDP.
# Data Retention & Deletion Schedule
Source: https://docs.squid.gg/platform/data-retention-deletion
What data we keep, for how long, and when/how it’s securely deleted.
*Last updated: June, 22, 2026*
Squid Academy retains personal data only for as long as it is needed for the purposes described in our [Privacy Policy](https://docs.google.com/document/u/6/d/1pJDPGOXueYFzt81Wzzv25-04_nuPi3seArJJkqm_d_4/edit) and to meet legal, contractual, and operational requirements.
This page summarizes the main retention periods and deletion procedures referenced in Section 12 of our [Privacy Policy](https://docs.google.com/document/u/6/d/1pJDPGOXueYFzt81Wzzv25-04_nuPi3seArJJkqm_d_4/edit) and Section 8 of our [Data Processing Addendum](https://docs.google.com/document/u/6/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit).
## **1. Key Principles**
* **Purpose limitation** – We keep personal data only for as long as necessary for the specific purpose it was collected.
* **Legal obligations** – Some data must be retained for statutory reasons (e.g., tax, accounting, or child protection laws).
* **Customer instructions** – For organization-provisioned accounts, we follow the controller’s instructions for retention and deletion under our DPA.
* **Secure deletion** – When data is no longer needed, it is securely deleted or anonymized.
## **2. Standard Retention Periods**
| **Data Category** | **Examples** | **Standard Retention** | **Deletion / Anonymization Method** |
| :---------------------------------- | :----------------------------------------- | :------------------------------------------------------------------------ | :----------------------------------------------------------------- |
| **Account Data (Public Users)** | Name, email, profile info | Kept until account deletion request or 24 months of inactivity | Secure database deletion; backups overwritten within 35 days |
| **Account Data (Org-Provisioned)** | Name, username, org affiliation | Retained until controller instructs deletion or contract ends | Deleted per controller request; backups overwritten within 35 days |
| **Course & Activity Data** | Assignments, grades, attendance | Retained while account is active; deleted within 12 months after deletion | Secure deletion from LMS & storage systems |
| **Tournament Data** | Player IDs, match stats, leaderboards | Kept for active season + 12 months | Purged from tournament platform; anonymized for analytics |
| **Payment & Billing Data** | Billing name, address, transaction history | 7 years (tax & accounting compliance) | Secure deletion from billing system |
| **Support & Communication Records** | Emails, chat transcripts, support tickets | 24 months after case closure | Secure deletion from ticketing platform |
| **Security Logs** | Login history, IP addresses, device info | 12 months (security & fraud prevention) | Automatic purge from log management system |
| **Marketing Data** | Newsletter sign-ups, marketing preferences | Until withdrawal of consent or inactivity for 24 months | Removed from CRM/email platform |
## **3. Backup Data**
* Deleted data may remain in backups until the backup cycle expires. Backups are encrypted, and access is restricted.
* Data is deleted once the agreement ends.
## **4. Deletion Process**
1. **Trigger** – Retention period expires or a valid deletion request is received.
2. **Verification** – Confirm identity of requester (public users) or confirm request with controller (org-provisioned).
3. **Deletion** – Remove data from active systems.
4. **Backup purge** – Data naturally removed as backup cycles expire.
5. **Confirmation** – For DSR requests, confirmation sent to requester or controller.
## **5. Exceptions**
Some data may be retained beyond standard periods:
* To comply with legal obligations.
* To resolve disputes or enforce agreements.
* For ongoing investigations into misuse or violations.
## **6. Contact**
For questions about data retention or deletion: email [privacy@squid.gg](mailto:privacy@squid.gg) or [Submit a Privacy Request](https://drive.google.com/open?id=1IwxaKEtOAeDeaGgC6E3I_nLwY4zKsBp2XVnW1S_0gew)
# Grievance Redressal Procedure (India-Focused)
Source: https://docs.squid.gg/platform/grievance-redressal-procedure-india-focused
# **1. Purpose**
Squid Academy is committed to providing high-quality educational services and maintaining a fair, transparent, and responsive process for handling complaints, concerns, and grievances.
This Grievance Redressal Procedure establishes a formal mechanism through which learners, parents, guardians, educational partners, employees, and other stakeholders may raise concerns and seek resolution.
Squid Academy aims to resolve grievances promptly, fairly, and consistently.
# **2. Scope**
This procedure applies to grievances relating to:
* Educational services
* Teaching and learning activities
* Assessments
* Student conduct
* Staff conduct
* Customer service
* Data protection and privacy
* Safeguarding concerns
* Platform access and technical issues
* School partnership activities
* Administrative matters
This procedure does not replace emergency safeguarding or legal reporting requirements.
# **3. Principles**
All grievances will be handled in accordance with the following principles:
### **Fairness**
All parties will be treated respectfully and impartially.
### **Transparency**
Processes and decisions will be clearly communicated.
### **Confidentiality**
Information will be shared only with those who require access to investigate or resolve the matter.
### **Timeliness**
The Academy will seek to resolve grievances without unnecessary delay.
### **Accessibility**
The procedure will be available to learners, parents, staff, and partners.
# **4. Who May Submit a Grievance**
Grievances may be submitted by:
* Learners
* Students
* Parents or guardians
* Schools
* Educational institutions
* Employees
* Contractors
* Tutors and lecturers
* Business partners
* Members of the public affected by Academy services
# **5. Types of Grievances**
Examples include:
### **Academic Concerns**
* Assessment disputes
* Feedback concerns
* Learning delivery issues
### **Operational Concerns**
* Platform access issues
* Service quality concerns
* Communication problems
### **Staff Conduct Concerns**
* Professional behaviour
* Harassment
* Discrimination
### **Data Protection Concerns**
* Personal data handling
* Privacy requests
* Information security matters
### **Safeguarding Concerns**
* Child protection concerns
* Online safety issues
Safeguarding concerns may require immediate escalation outside the standard grievance process.
# **6. Informal Resolution**
Where appropriate, individuals are encouraged to seek an informal resolution first.
This may involve:
* Discussing concerns with the relevant tutor or lecturer.
* Contacting the support team.
* Clarifying misunderstandings.
* Seeking administrative assistance.
Many issues can be resolved quickly without requiring a formal investigation.
# **7. Formal Grievance Submission**
If informal resolution is unsuccessful or inappropriate, a formal grievance may be submitted.
A grievance should include:
* Full name
* Contact details
* Description of the concern
* Relevant dates
* Individuals involved
* Supporting evidence (if available)
* Desired outcome
# **8. Acknowledgement of Receipt**
The Academy will:
* Acknowledge receipt of a grievance within five (5) business days.
* Provide a reference number where appropriate.
* Confirm the next steps in the process.
# **9. Investigation Process**
The Academy will:
1. Review the grievance.
2. Assess the information provided.
3. Gather relevant evidence.
4. Interview relevant individuals where necessary.
5. Review applicable policies and procedures.
6. Determine an appropriate outcome.
Investigations will be conducted objectively and proportionately.
# **10. Resolution Timeframes**
The Academy aims to:
### **Acknowledge**
Within 5 business days.
### **Investigate**
Within 20 business days where reasonably practicable.
### **Respond**
Within 30 business days of receiving the grievance.
Complex matters may require additional time.
Where delays occur, the complainant will be informed.
# **11. Possible Outcomes**
Outcomes may include:
* Clarification of facts.
* Corrective action.
* Policy improvements.
* Staff guidance or training.
* Service improvements.
* Formal apology where appropriate.
* Referral to another procedure.
Not all grievances will result in the outcome requested by the complainant.
# **12. Appeals**
If the complainant is dissatisfied with the outcome, they may request a review.
Appeals must:
* Be submitted within fourteen (14) days of receiving the decision.
* Explain why the outcome is being challenged.
* Include any new supporting information.
Appeals will be reviewed by an individual not directly involved in the original decision, where reasonably practicable.
# **13. Data Protection and Privacy Complaints**
Individuals may submit concerns relating to:
* Collection of personal data
* Use of personal data
* Data security
* Data subject rights
* International data transfers
Privacy-related complaints will be managed in accordance with Squid Academy's privacy policy and data protection procedures.
# **14. Safeguarding Concerns**
Safeguarding concerns involving children or vulnerable individuals will be prioritized and handled in accordance with the Academy's Safeguarding Policy.
Where necessary, concerns may be referred to:
* Schools
* Parents or guardians
* Law enforcement
* Child protection authorities
Immediate safeguarding concerns may bypass the standard grievance process.
# **15. Record Keeping**
The Academy will maintain records of:
* Grievances received
* Investigation activities
* Outcomes
* Appeals
* Corrective actions
Records will be retained in accordance with the Data Retention Schedule.
# **16. Protection Against Retaliation**
Individuals raising concerns in good faith will not be subjected to retaliation, discrimination, harassment, or adverse treatment for doing so.
Malicious, knowingly false, or vexatious complaints may be subject to separate review.
# **17. Continuous Improvement**
Grievance data may be analyzed periodically to identify:
* Recurring issues
* Service improvements
* Training needs
* Policy enhancements
The Academy is committed to continuous improvement based on stakeholder feedback.
# **18. Review**
This procedure will be reviewed annually or when legal, operational, or regulatory changes occur.
# India Compliance Addendum
Source: https://docs.squid.gg/platform/india-compliance-addendum
**Applicable Jurisdiction:** India
**Related Documents:**
* Privacy Policy
* Information Security Policy
* Grievance Redressal Procedure
* Data Processing Addendum
* Terms & Conditions
# **1. Purpose**
This India Compliance Addendum explains how Squid Academy processes personal data and delivers educational services in accordance with applicable Indian legal requirements.
# **2. Applicable Legislation**
Squid Academy seeks to comply with:
* Digital Personal Data Protection Act, 2023 (DPDP Act)
* Information Technology Act, 2000 (where applicable)
* Applicable consumer protection legislation
* Relevant educational regulations
# **3. Processing of Personal Data**
Squid Academy may process personal data for:
* Educational services
* Assessment and certification
* Student administration
* Safeguarding
* Customer support
* Legal compliance
Personal data processing will be limited to legitimate educational and operational purposes.
# **4. Children's Data**
Where learners are minors:
* Additional safeguards will be applied.
* Parent or guardian consent may be required.
* Data will be processed only for authorised educational purposes.
* Safeguarding procedures will be followed.
# **5. Rights of Individuals**
Individuals may submit requests relating to:
* Access to personal information
* Correction of information
* Withdrawal of consent where applicable
* Data processing concerns
# **6. Grievance Redressal**
Individuals may raise complaints through Squid Academy's Grievance Redressal Procedure.
Squid Academy will:
* Acknowledge complaints promptly.
* Investigate concerns fairly.
* Provide timely responses.
* Maintain records of complaints and resolutions.
# **7. Cross-Border Data Processing**
Squid Academy may use international cloud service providers and educational technology platforms.
Appropriate safeguards will be implemented to protect personal data during international processing activities.
# **8. Security Measures**
Squid Academy maintains administrative, technical, and organisational measures designed to protect personal data from:
* Unauthorised access
* Disclosure
* Alteration
* Loss
* Misuse
These measures are further described in the Information Security Policy.
If you have any questions, comments, or concerns, please feel free to reach out to us at [support@squid.academy](mailto:support@squid.academy)
# Internal Quality Assurance (IQA) Policy
Source: https://docs.squid.gg/platform/internal-quality-assurance-policy
# **1. Purpose**
Squid Academy is committed to maintaining high standards of assessment, teaching, learning, and learner achievement.
The purpose of this Internal Quality Assurance (IQA) Policy is to ensure that assessment decisions are:
* Fair
* Valid
* Reliable
* Consistent
* Transparent
* Evidence-based
This policy establishes the processes used to monitor and improve the quality of assessment activities delivered by Squid Academy.
# **2. Scope**
This policy applies to:
* Accredited programmes
* Non-accredited programmes
* Internal assessments
* Coursework assessments
* Practical assessments
* Portfolio assessments
* Tutors
* Assessors
* Internal Quality Assurers (IQAs)
* Academic staff
# **3. Objectives**
The objectives of Internal Quality Assurance are to:
* Ensure consistency in assessment decisions.
* Support assessors in making accurate judgements.
* Maintain learner confidence.
* Meet awarding organisation requirements.
* Identify areas for continuous improvement.
* Promote best practice across all programmes.
* Ensure assessment standards are applied fairly.
# **4. Principles of Internal Quality Assurance**
All quality assurance activities will be:
### **Fair**
All learners will be assessed against the same standards.
### **Valid**
Assessment decisions will measure the intended learning outcomes.
### **Reliable**
Different assessors should reach similar decisions when reviewing the same evidence.
### **Consistent**
Assessment criteria will be applied uniformly.
### **Transparent**
Processes and decisions will be documented and auditable.
### **Supportive**
Quality assurance activities will encourage staff development and continuous improvement.
# **5. Roles and Responsibilities**
## **Academic Management**
Responsible for:
* Oversight of quality assurance activities.
* Ensuring adequate resources are available.
* Reviewing quality assurance outcomes.
* Supporting continuous improvement.
## **Internal Quality Assurer (IQA)**
Responsible for:
* Sampling assessment decisions.
* Monitoring assessment quality.
* Providing feedback to assessors.
* Supporting assessor development.
* Maintaining IQA records.
* Identifying trends and risks.
* Ensuring compliance with awarding organisation requirements.
## **Assessors and Tutors**
Responsible for:
* Assessing learners fairly.
* Maintaining accurate assessment records.
* Applying assessment criteria consistently.
* Participating in standardisation activities.
* Acting on IQA feedback.
## **Learners**
Responsible for:
* Providing authentic evidence.
* Participating honestly in assessments.
* Following the assessment requirements.
# **6. Sampling Strategy**
The Academy will operate a risk-based sampling strategy.
Sampling may consider:
* New assessors
* Experienced assessors
* High-risk qualifications
* New programmes
* Learner complaints
* Previous quality concerns
* Assessment complexity
Sampling will review:
* Assessment decisions
* Learner evidence
* Feedback quality
* Record keeping
* Compliance with assessment requirements
# **7. Standardisation Activities**
Standardisation helps ensure consistency across assessors.
Activities may include:
* Assessor meetings
* Evidence reviews
* Assessment discussions
* Benchmarking exercises
* Moderation activities
* Training sessions
Standardisation meetings should be documented and retained for quality assurance purposes.
# **8. Observation of Assessment Practice**
Where appropriate, IQAs may observe:
* Teaching sessions
* Assessment activities
* Practical demonstrations
* Professional discussions
* Online assessments
Observations help ensure assessment processes are applied consistently and professionally.
# **9. Feedback to Assessors**
Following quality assurance activities, assessors may receive feedback regarding:
* Assessment decisions
* Documentation quality
* Evidence requirements
* Learner support
* Compliance matters
Feedback should:
* Be constructive.
* Be evidence-based.
* Support professional development.
# **10. Assessment Records**
The Academy will maintain accurate records of:
* Assessment decisions
* IQA sampling activities
* Standardisation meetings
* Assessor feedback
* Corrective actions
* Quality improvement activities
Records will be retained in accordance with the Data Retention Policy.
# **11. Managing Inconsistent Assessment Decisions**
Where inconsistencies are identified:
The Academy may:
* Review assessment decisions.
* Conduct additional sampling.
* Require reassessment.
* Provide additional assessor training.
* Increase monitoring activities.
Corrective actions will be documented and reviewed.
# **12. Continuous Improvement**
Quality assurance activities will be used to identify:
* Areas of good practice.
* Training requirements.
* Assessment improvements.
* Learner experience improvements.
* Process enhancements.
The Academy is committed to continual improvement across all educational provision.
# **13. Learner Appeals**
Learners who disagree with assessment decisions may use the Academy's Assessment Appeals Procedure.
IQA activities may be used to support appeal reviews where appropriate.
# **14. Malpractice and Maladministration**
Any suspected malpractice or maladministration identified during quality assurance activities will be managed in accordance with the Academy's Malpractice and Maladministration Policy.
Examples include:
* Plagiarism
* Assessment fraud
* Falsification of records
* Unauthorised assistance
* Procedural failures
# **15. Annual Quality Review**
The Academy will conduct an annual review of quality assurance activities.
The review may consider:
* Assessment outcomes
* Learner achievement rates
* Appeals data
* Complaints data
* Assessor performance
* Awarding organisation feedback
* Continuous improvement actions
Findings will be used to update quality assurance processes where required.
# **16. Review**
This policy will be reviewed annually or whenever
* Regulatory requirements change.
* Awarding organization requirements change.
* Significant quality issues arise.
* Organizational changes occur.
If you have any questions, comments, or concerns, please feel free to reach out to us at [support@squid.academy](mailto:support@squid.academy)
# International Data Transfers
Source: https://docs.squid.gg/platform/intl-data-transfers
How we transfer data across borders, the legal mechanisms (e.g., Standard Contractual Clauses), and protections.
*Last updated: \[August 27, 2025]*
Squid Academy operates internationally. This means that your personal data may be transferred to and processed in countries outside of your own — including countries that may not have the same level of data protection as your home country.
This page summarizes how we handle cross-border transfers as described in Section 14 of our [Privacy Policy](https://docs.google.com/document/u/6/d/1pJDPGOXueYFzt81Wzzv25-04_nuPi3seArJJkqm_d_4/edit) and Section 10 of our [Data Processing Addendum](https://docs.google.com/document/u/6/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit).
## **1. Where Your Data May Go**
* **Primary processing locations** – We store and process data in the regions where we (and our sub-processors) operate, which may include the United States, the United Kingdom, the European Union, and Asia-Pacific regions.
* **Third-party sub-processors** – Our [Sub-processor List](https://docs.google.com/document/u/6/d/1hSsHISPyzidVjqRFjI2EwKUCX3lrMDW5LtjxLhJ1zVs/edit) includes details of vendors that may process personal data internationally.
## **2. How We Protect Your Data During Transfers**
When personal data is transferred across borders, we implement safeguards that meet applicable legal requirements, such as:
### **Adequacy Decisions**
* Transfers from the EU/EEA, UK, or Switzerland to countries recognized by the European Commission (or UK Government) as having adequate protection.
### **Standard Contractual Clauses (SCCs)**
* For transfers to countries without an adequacy decision, we use the European Commission’s SCCs or the UK International Data Transfer Addendum as appropriate.
### **Supplementary Measures**
* Technical measures such as encryption in transit and at rest.
* Access controls ensuring only authorized personnel can access the data.
* Organizational measures such as staff training and vendor due diligence.
### **Transfer Impact Assessments (TIAs)**
* We assess the legal and practical risks of each transfer, and document these assessments.
## **3. Transfers Initiated by Your Organization**
If your organization (school, university, or esports center) uses our services from outside the EU/EEA/UK, it is responsible for ensuring that its own data transfers to us comply with applicable laws.
## **4. Your Rights**
You can request:
* A copy of the SCCs or other applicable transfer mechanism.
* Details of the countries where your personal data has been processed.
Contact [privacy@squid.gg](mailto:privacy@squid.gg) or [Submit a Privacy Request](https://drive.google.com/open?id=1IwxaKEtOAeDeaGgC6E3I_nLwY4zKsBp2XVnW1S_0gew) to make this request.
## **5. Updates**
We may update this page to reflect changes in our transfer practices or legal requirements. Updates will be posted here with a revised “Last updated” date.
# Lecturer, Tutor & Coach Protection Policy
Source: https://docs.squid.gg/platform/lecturer-tutor-and-coach-protection-policy
**Document Owner:** Squid Academy Ltd\
**Version:** 1.0\
**Review Date:** Annually
# **1. Purpose**
Squid Academy is committed to providing a safe, respectful, and professional working environment for all lecturers, tutors, coaches, assessors, mentors, moderators, and guest speakers.
While safeguarding learners remains a priority, Squid also recognizes its responsibility to protect staff from the following:
* Harassment
* Abuse
* Intimidation
* Discrimination
* Threatening behaviour
* False allegations
* Online misconduct
* Unreasonable student or parent behaviour
This policy establishes the standards and protections available to all educational staff engaged by Squid Academy.
# **2. Scope**
This policy applies to:
* Lecturers
* Tutors
* Coaches
* Assessors
* Moderators
* Mentors
* Guest Speakers
* Volunteers
* Contractors
* Employees
The policy applies across the following:
* Virtual classrooms
* Learning Management Systems
* Discord communities
* Coaching sessions
* Assessments
* Competitions
* Workshops
* Parent communications
# **3. Professional Respect**
All students, parents, guardians, staff, and community members must treat educational staff with professionalism and respect.
The Academy will not tolerate behavior that undermines the safety, well-being, or professional reputation of its educators.
# **4. Unacceptable Behaviour Towards Staff**
The following behavior is prohibited:
### **Verbal Abuse**
Including:
* Insults
* Personal attacks
* Aggressive language
* Mocking or humiliation
* Offensive remarks
### **Harassment**
Including:
* Repeated unwanted contact
* Intimidation
* Targeted hostility
* Persistent disruption
### **Discrimination**
Including discrimination based on:
* Age
* Race
* Ethnicity
* Gender
* Disability
* Religion
* Sexual orientation
* Nationality
### **Threatening Behaviour**
Including:
* Threats of harm
* Threats to employment
* Threats to reputation
* Threats of legal action made maliciously
### **Online Abuse**
Including:
* Cyberbullying
* Social media attacks
* Harassing messages
* Public shaming
* Sharing personal information
# **5. Protection from False Allegations**
Squid Academy recognises that false, misleading, or malicious allegations can have serious consequences for staff.
Where concerns are raised:
* All allegations will be investigated fairly.
* Staff will be treated with dignity and professionalism.
* No assumptions of guilt will be made.
* Evidence will be gathered objectively.
* Confidentiality will be maintained where possible.
Malicious or knowingly false allegations may result in disciplinary action against the individual making the allegation.
This provision does not prevent legitimate complaints or safeguarding concerns from being investigated.
# **6. Professional Boundaries**
To protect both learners and staff:
Staff must:
* Use approved communication platforms.
* Maintain professional language.
* Keep interactions educational in nature.
* Follow safeguarding procedures.
* Document concerns when required.
Staff must not
* Share personal contact information.
* Use private social media for student communication.
* Engage in inappropriate discussions.
* Meet students outside approved educational activities.
Maintaining clear boundaries protects all parties.
# **7. Recording and Session Protection**
Where legally permitted and operationally appropriate:
* Lessons may be recorded.
* Assessment sessions may be recorded.
* Coaching sessions may be recorded.
Recordings may be used to:
* Resolve disputes.
* Investigate complaints.
* Verify assessment decisions.
* Protect both learners and staff.
Recordings will be handled in accordance with the Privacy Policy and Data Retention Schedule.
# **8. Student Conduct Towards Staff**
Students are expected to:
* Follow instructions.
* Communicate respectfully.
* Participate appropriately.
* Refrain from disruptive behavior.
* Respect professional decisions.
Repeated misconduct towards staff may result in:
* Warnings
* Removal from sessions
* Suspension
* Permanent removal from programmes
# **9. Parent and Guardian Conduct**
Parents and guardians must:
* Communicate respectfully.
* Raise concerns through official channels.
* Allow investigations to be completed before public comment.
The Academy reserves the right to restrict communication where behavior becomes abusive, threatening, or unreasonable.
# **10. Social Media Protection**
Students, parents, and community members must not:
* Harass staff online.
* Publish defamatory statements.
* Share personal information.
* Encourage harassment campaigns.
* Misrepresent staff communications.
Squid Academy may investigate online behavior that impacts staff well-being or professional reputation.
# **11. Wellbeing and Mental Health**
Squid Academy recognizes that educational roles can be demanding.
The Academy will seek to:
* Promote reasonable workloads.
* Encourage well-being practices.
* Provide support following incidents.
* Maintain respectful workplace culture.
* Address concerns promptly.
# **12. Incident Reporting**
Staff should report:
* Abuse
* Harassment
* Threats
* Safeguarding concerns
* Inappropriate communications
* False allegations
* Online misconduct
Reports should be submitted as soon as reasonably possible through designated reporting channels.
# **13. Investigation Procedures**
Reported incidents will be:
* Logged appropriately.
* Investigated fairly.
* Reviewed objectively.
* Handled confidentially where possible.
The Academy may collect:
* Screenshots
* Chat logs
* Email correspondence
* Session recordings
* Witness statements
as part of an investigation.
# **14. Disciplinary Action**
Where misconduct towards staff is confirmed, Squid Academy may take action, including
### **Learners**
* Verbal warning
* Written warning
* Temporary suspension
* Permanent removal
### **Community Members**
* Removal of access
* Community bans
* Restriction of services
### **Parents or Guardians**
* Communication restrictions
* Escalation through partner institutions
* Termination of programme participation where necessary
# **15. Responsibilities**
### **Squid Academy**
Responsible for:
* Maintaining safe working conditions.
* Investigating incidents fairly.
* Supporting affected staff.
* Enforcing this policy.
### **Staff**
Responsible for:
* Maintaining professional conduct.
* Following safeguarding procedures.
* Reporting incidents promptly.
### **Students and Community Members**
Responsible for:
* Treating staff respectfully.
* Following Academy policies.
* Maintaining professional behavior.
# **16. Review**
This policy will be reviewed annually or following any significant incident, regulatory change, or organizational requirement.
# Parental Consent Guide
Source: https://docs.squid.gg/platform/parental-content-guide
How schools and parents provide consent for minors’ accounts, plus how to manage or revoke it.
*Last updated: \[August 27, 2025]*
This guide explains how Squid Academy obtains, verifies, and manages parental or guardian consent when processing the personal data of children under applicable laws (such as COPPA in the United States, UK children’s privacy rules, and GDPR-K in the EU).
## **1. When We Require Parental Consent**
We require verifiable parental consent before collecting, using, or sharing personal data of:
* Children under 13 in the United States (COPPA).
* Children under the age of digital consent in other jurisdictions (varies by country, usually 13–16).
* Where required by a customer organization’s local laws or school policies.
## **2. Who is Responsible**
* **For public accounts**: Squid Academy collects and verifies parental consent directly.
* **For organization-provisioned accounts**: The school, university, or esports center acts as the data controller and is responsible for obtaining parental consent. Squid Academy assists by providing consent tools, templates, and guidance.
## **3. How We Obtain Consent**
Depending on the law and context, we may use:
* **Digital signature forms** (sent via secure link).
* **Credit card/online payment verification** (with nominal refundable charge).
* **Government-issued ID check** (parent uploads ID to secure channel).
* **Signed paper consent forms** (returned via scan or post).
* **School-mediated consent** (controller provides documented proof to Squid Academy).
## **4. Verification Process**
* We verify that the person providing consent is the child’s parent or legal guardian.
* We record the date, method, and proof of consent in our compliance log.
* Consent records are retained as long as the child’s account is active, plus 12 months after closure.
## **5. Revoking Consent**
Parents/guardians can revoke consent at any time by:
* Using our [Privacy Request Form](https://drive.google.com/open?id=1IwxaKEtOAeDeaGgC6E3I_nLwY4zKsBp2XVnW1S_0gew).
* Emailing [privacy@squid.gg](mailto:privacy@squid.gg) with the child’s name, username, and school/organization (if applicable). When consent is revoked, the child’s account is suspended or deleted, depending on the request.
## **6. Tips for Parents & Guardians**
* Review our [Privacy Policy](https://docs.google.com/document/u/6/d/1pJDPGOXueYFzt81Wzzv25-04_nuPi3seArJJkqm_d_4/edit) before granting consent.
* Ask your child’s school or esports center how they use Squid Academy.
* Encourage your child to use privacy settings and be mindful about sharing personal information.
## **7. Questions**
Contact our Privacy Team: Email [privacy@squid.gg](mailto:privacy@squid.gg) or [Submit a Privacy Request](https://drive.google.com/open?id=1IwxaKEtOAeDeaGgC6E3I_nLwY4zKsBp2XVnW1S_0gew)
# Privacy Policy
Source: https://docs.squid.gg/platform/privacy-policy
What we collect, why we collect it, how we use it, and your choices.
*(Effective date: August 15, 2025)*
## **1. Who We Are & Scope**
This Privacy Policy explains how Squid Academy Ltd (“Squid”, “we”, “us”) collects, uses, shares, and protects personal information across our websites, web apps, and services (collectively, the “Services”). It works together with our [Terms & Conditions](https://docs.google.com/document/u/6/d/1naMWUBeGi99rmMptIY-oXLlr9BmTGDXIoFk2qQ-_p4A/edit) and our [Data Processing Addendum](https://docs.google.com/document/u/6/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit) (DPA) for Organization customers.
**Contact:** [privacy@squid.gg](mailto:privacy@squid.gg).
## **2. How This Policy Relates To Our T\&Cs & DPA**
* For Public Users (people who create an account directly with us): Squid is the controller for your core account data; this Privacy Policy applies.
* For Organization‑provisioned users (students, teachers, staff invited by a school, university, esports center, etc.): the Organization is the controller and Squid is the processor/service provider under the DPA; this Privacy Policy should be read together with the DPA and your Organization’s privacy notices.
If the T\&Cs and this Privacy Policy ever conflict on Organization data processing, the DPA prevails as to processing on the Organization’s behalf.
## **3. Who May Use The Services** (children and students)
* **Public accounts:** Under‑13 sign‑ups are not permitted. Public Users must be 13+.
* **Organization‑provisioned minors:** Organizations must verify age and obtain/retain verifiable parental/guardian consent where required (e.g., COPPA; India DPDP under 18; Thailand PDPA).
Guidance for obtaining and verifying parental consent is available in our [Parental Consent Guide](https://docs.google.com/document/u/6/d/16g2ikC0mSpiT5Lhsh_yCTMe8tVgxJUPPmHqvQdloq8Y/edit).
* We do not sell personal data, profile minors for advertising, or use Organization‑provisioned minors’ data for cross‑context behavioral ads.
## **4. What We Collect**
### **4.1 Information you provide**
* Account and profile data (e.g., name, email, role/organization), classroom/team participation, coursework and tournament participation, and support requests.
### **4.2 Data we collect automatically**
* Technical telemetry (e.g., login logs, timestamps) and security/operations data necessary to run the Services.
### **4.3 Information from others**
* If you sign in via a third‑party identity provider (e.g., Google/Apple) or you are invited by an Organization, we may receive limited account/roster information consistent with your settings and the Organization’s instructions.
### **4.4 Special categories and payment data**
* We do not intend to collect special‑category data (e.g., health, biometrics). Please do not submit it unless necessary for educational use and permitted by law.
* We do not process payment card data for the Services; payments are handled by third‑party payment processors unless expressly stated in an Order.
## **5. Why We Use Your Information** (purposes)
We use personal information to:
* Provide the Services (user authentication, class/team management, course delivery, progress/tournament operations, support, and security).
* Maintain and improve the Services using aggregated/de-identified usage metrics; we do not attempt to re‑identify de‑identified data.
* Comply with law and enforce our T\&Cs; respond to lawful requests (with safeguards).
### **AI/ML model training**
We do not use Controller Personal Data (Organization‑provided data) to train, retrain, or fine‑tune generalized AI/ML models for unrelated product development, unless on the Organization’s documented instructions.
## **6. Cookies & Similar Tech**
Right now we use only essential session cookies for authentication and core functions. If we later add analytics or non‑essential cookies, we’ll implement a compliant consent mechanism.
## **7. Sharing Your Information**
We share personal information with:
* Sub‑processors/service providers that help us host, support, secure, and deliver the Services; we maintain a [Sub‑processor List](https://docs.google.com/document/u/6/d/1hSsHISPyzidVjqRFjI2EwKUCX3lrMDW5LtjxLhJ1zVs/edit) and give 30 days’ advance notice of changes, with an emergency replacement carve‑out and objection/termination rights as set out in the DPA.
* Authorities when legally required (we notify and limit disclosure where possible).
* **Business transfers.** If we are involved in a reorganization (e.g., merger, acquisition, or sale of assets), personal information may transfer as part of the transaction; we will continue to protect it and will provide notice of any material changes to this Policy.
**No sale/sharing for ads:** When acting as a processor/service provider, we do not sell or share personal information or use it for cross‑context behavioral advertising; our US state privacy commitments are spelled out in the DPA and T\&Cs.
## **8. International Data Transfers**
We use approved safeguards for cross‑border transfers, including the EU Standard Contractual Clauses (SCCs) (Module 2/3 as applicable) and the UK Addendum/IDTA; we also support transfer impact assessments and supplementary measures where needed. See [DPA](https://docs.google.com/document/u/6/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit) Section 6 and Annex IV.
For details, see our [International Data Transfers](https://docs.google.com/document/u/6/d/1CyjvkQlK117ZzibQoIzbA9fgCzVihPBzt1vNClSkgiw/edit) page.
## **9. Security**
We maintain [appropriate technical and organizational measures](https://docs.google.com/document/u/6/d/1vyd27JAHAeSYlxSRP0gG9LyMicI6uBO7YjfjQfHYU6k/edit) (access controls, encryption in transit/at rest, secure development and change management, monitoring, backups/DR, incident response). A summary of our TOMs is in Annex II of the [DPA](https://docs.google.com/document/u/6/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit).
If we become aware of a confirmed [Security Incident](https://docs.google.com/document/u/6/d/1vyd27JAHAeSYlxSRP0gG9LyMicI6uBO7YjfjQfHYU6k/edit) affecting Organization data, we will notify the impacted customer without undue delay (and where GDPR applies, where feasible within 72 hours, EEA 1 month; US states 45 days + permissible extension), and cooperate on remediation.
## **10. Retention**
We keep personal information only as long as needed for the purposes above or as required by law. Upon termination/expiry, we’ll delete or return Organization personal data on written instruction and delete existing copies within 35 days; we can provide written deletion confirmation.
For details, see our [Data Retention & Deletion Schedule](https://docs.google.com/document/u/6/d/1vFMrCnA-rl3LgBMuAifFAh2rFAmHFjWgtJzmT-4q4TA/edit).
## **11. Your Privacy Rights & How To Exercise Them**
### **11.1 If you are a Public User**
You may request access, correction, deletion, portability, and to object/restrict certain processing, subject to applicable law. Contact: [privacy@squid.gg](mailto:privacy@squid.gg) or submit a [Privacy Request Form](https://drive.google.com/open?id=1IwxaKEtOAeDeaGgC6E3I_nLwY4zKsBp2XVnW1S_0gew)
### **11.2 If you are an Organization‑provisioned user**
Your Organization is the controller and is responsible for authenticating requests and routing them to us; we will assist without undue delay via controller workflows. Where requests are excessive, manifestly unfounded, or duplicative, we may charge reasonable costs for assistance (as set out in the DPA).
### **11.3 Appeals & complaints**
If we decline your request, you may appeal by replying to our decision email. You can also complain to a supervisory authority (e.g., the UK ICO) where applicable.
### **11.4 Global Privacy Control (GPC) & Non‑discrimination**
Where required by law, we treat Global Privacy Control (GPC) signals (or equivalent) as an opt‑out request related to sale/sharing or targeted advertising. We will not discriminate against you for exercising [Your Privacy Rights](https://docs.google.com/document/u/6/d/1WoUT4idzD_znkFrF8fiE5eFaBj34cg_7VsYdBtwyl-0/edit) (e.g., no denial of services, different prices, or reduced quality).
## **12. Third‑Party Services & Links**
If you enable third‑party sign‑in or integrations, those providers’ terms and privacy practices apply to their handling of your data. We’re not responsible for third‑party sites or services outside our control.
## **13. Marketing**
We may send service and account notices. You can opt out of non‑essential marketing emails via the unsubscribe link in each message.
## **14. Automated Decision‑making**
We do not engage in automated decision‑making that produces legal or similarly significant effects on individuals.
## **15. Changes To This Privacy Policy**
We may update this Policy. We’ll post the new version with an updated effective date and, for material changes, provide reasonable notice. Continued use after the effective date constitutes acceptance.
## **16. How To Contact Us**
**Email:** [privacy@squid.gg](mailto:privacy@squid.gg)
**Address:** 71‑75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
## \*\*Regional Disclosures \*\*(supplemental)
### **A) European Economic Area (EEA) & United Kingdom (UK)**
* **Controller:** For Public Users, Squid Academy Ltd. For Organization users, your Organization is controller and Squid is processor under the DPA.
* **Legal bases:** contract performance (providing the Services), legitimate interests (security, service improvement using de‑identified data), consent (where we rely on it, e.g., non‑essential cookies), and legal obligations.
* **Transfers:** SCCs + UK Addendum; supplementary measures as needed.
* **Your rights:** access, rectification, erasure, restriction, portability, objection; complain to your local DPA.
### **B) United States (including state laws such as CA/VA/CO/UT/CT/TX)**
* When acting as a processor/service provider for Organizations, we **do not sell or share** personal information and do not use it for cross‑context behavioral advertising; we process only for limited, specified purposes and flow down obligations to sub‑processors.
* You may request access, deletion, correction (where applicable), and information about our disclosures; we verify requests and respond as required by law.
* Texas and other state‑specific student/minor protections apply through controller (Organization) workflows.
#### **US State Privacy Notice (CA/VA/CO/UT/CT/TX and similar)**
* **Categories collected (last 12 months):** identifiers (name, email, account IDs); internet/network activity (basic logs, timestamps); education information (enrollments, progress, team/tournament participation). Not collected: precise geolocation; payment card numbers; biometrics; inferences.
* **Sensitive Personal Information (SPI):** **Not used** for inferring characteristics or additional purposes.
* **Sources:** you; your Organization; identity providers (e.g., Google/Apple); device/browser telemetry.
* **Purposes:** as described in [Section 5](https://docs.google.com/document/d/1pJDPGOXueYFzt81Wzzv25-04_nuPi3seArJJkqm_d_4/edit?tab=t.0#heading=h.4iy3caqpmnjf) (provide, secure, support, and improve Services using aggregated/de‑identified metrics).
* **Disclosures:** service providers/sub‑processors; authorities where required; **business transfers** per [Section 7](https://docs.google.com/document/d/1pJDPGOXueYFzt81Wzzv25-04_nuPi3seArJJkqm_d_4/edit?tab=t.0#heading=h.9m1qdw5zav3b). Sale/Share/Targeted advertising: No when we act as processor/service provider.
* **Retention:** per [Section 10](https://docs.google.com/document/d/1pJDPGOXueYFzt81Wzzv25-04_nuPi3seArJJkqm_d_4/edit?tab=t.0#heading=h.y10b5gunx5x3).
* **Requests & appeals:** see [Section 11](https://docs.google.com/document/d/1pJDPGOXueYFzt81Wzzv25-04_nuPi3seArJJkqm_d_4/edit?tab=t.0#heading=h.ywxi7dq2plqt) (we verify identity and allow authorized agents where required).
### **C) Malaysia (PDPA 2010)**
* We assist controllers with access/correction rights and use approved cross‑border safeguards where data leaves Malaysia.
### **D) Thailand (PDPA 2019)**
* Parental consent is required for certain minors under PDPA; we assist controllers with data‑subject rights and appropriate transfer safeguards.
Guidance for obtaining and verifying parental consent is available in our [Parental Consent Guide](https://docs.google.com/document/u/6/d/16g2ikC0mSpiT5Lhsh_yCTMe8tVgxJUPPmHqvQdloq8Y/edit) .
### **E) India (DPDP Act 2023)**
* Children (\<18) are treated as a protected class under DPDP; controllers must obtain verified parental consent before processing children’s data. We assist with data‑principal requests and apply transfer safeguards consistent with DPDP.
Guidance for obtaining and verifying parental consent is available in our [Parental Consent Guide](https://docs.google.com/document/u/6/d/16g2ikC0mSpiT5Lhsh_yCTMe8tVgxJUPPmHqvQdloq8Y/edit) .
***
## **Appendix — Key definitions** (plain English)
* **Public User**: Someone who creates a personal account directly with Squid (13+).
* **Organization**: A school, university, club, or esports center that invites users to the Services.
* **Controller / Processor**: The Organization decides “why/how” data is processed (controller); Squid processes **on their instructions** (processor).
# Privacy Request Form
Source: https://docs.squid.gg/platform/privacy-request-form
Submit a privacy rights request (access, deletion, correction, or export)—we’ll verify your identity and respond within the legally required timeframe.
# Safeguarding & Child Protection Policy
Source: https://docs.squid.gg/platform/safeguarding-and-child-protection-policy
*Protecting children and young people across our programmes, platforms, and partner institutions*
| **Document title** | Safeguarding and Child Protection Policy |
| :------------------------------------- | :----------------------------------------------------------------------------------------------------------- |
| **Organisation** | Squid Academy Ltd (registered in the United Kingdom) |
| **Version** | 2.0 |
| **Designated Safeguarding Lead (DSL)** | **Anusuya Mukherjee** \| **[anusuya@squid.academy](mailto:anusuya@squid.academy)** \| +44 7455 230639 |
| **Deputy Safeguarding Lead** | **Jeffrey Cray** \| **[jeffrey@squid.academy](mailto:jeffrey@squid.academy)** \| +44 7455 230639 |
| **Approved by** | **Steyn Van Hövell, CEO** |
| **Date of approval/commencement** | **21.6.2026** |
| **Next review date** | **21.6.2027** |
| **Review frequency** | Annually, or sooner if circumstances require |
# **1. Purpose and Aim**
Squid Academy Ltd (“Squid Academy”, “we”, “us”) is committed to safeguarding and promoting the welfare, safety, and wellbeing of all children and young people who engage with our educational programmes, esports activities, online learning platforms, workshops, coaching sessions, assessments, and community events. As an organisation registered with the AQA Unit Award Scheme, we recognise that the recognition of learning we provide carries with it a duty of care towards every learner who works towards it.
We believe that:
* Every child has the right to learn and take part in a safe environment.
* Safeguarding is everyone’s responsibility.
* The welfare of the child is paramount.
* All concerns about the welfare of a child must be taken seriously and acted upon.
* Appropriate action must be taken whenever a child may be at risk of harm.
This policy sets out the principles, responsibilities, and procedures through which Squid Academy meets its safeguarding commitment and the steps that all individuals acting for or on behalf of Squid Academy must take to keep children safe.
# **2. Scope**
This policy applies to all individuals who act for or on behalf of Squid Academy, including:
* Employees and directors
* Contractors and associates
* Coaches, tutors, and mentors
* Volunteers and guest speakers
* Any external partner delivering services on behalf of Squid Academy
It applies across all of the learning environments we provide or operate, including virtual classrooms, live online coaching, esports competitions and tournaments, educational workshops, community events, our learning management system, and any Discord or community platforms operated by Squid Academy.
Squid Academy delivers the majority of its programmes **through partner institutions**, including schools, colleges, universities, and esports centres, which retain their own statutory and local safeguarding duties. This policy governs the conduct of Squid Academy and its personnel and operates alongside the safeguarding policy and designated leads of each partner institution. Where a concern arises about a learner, Squid Academy will work with, and refer to, the partner institution’s designated safeguarding lead and the relevant local authorities.
# **3. Our Commitment**
Squid Academy is committed to creating and maintaining an environment in which children and young people are safe, respected, listened to, and able to flourish. We will put the welfare of children first, respond promptly to concerns, work with parents, schools, and authorities where appropriate, and maintain confidentiality while protecting children’s welfare.
**Equality.** We give equal priority to keeping all children and young people safe regardless of age, disability, gender reassignment, race, religion or belief, sex, sexual orientation, nationality, or socioeconomic background.
**Additional vulnerability.** We recognise that some children are additionally vulnerable because of the impact of discrimination, previous experiences, disability, communication needs, special educational needs, or their level of dependency, and that online environments can introduce specific risks. We take additional care to ensure these children are heard and protected.
# **4. Legal and Regulatory Framework**
As a company registered in the United Kingdom that operates internationally, Squid Academy has regard to recognised safeguarding standards across every jurisdiction in which it works. In particular:
* **United Kingdom guidance.** We have regard to the principles of “Keeping Children Safe in Education”, “Working Together to Safeguard Children”, and the Department for Education code of practice “Keeping children safe in out-of-school settings”.
* **Local law in countries of operation.** We comply with the child protection and safeguarding laws and expectations of each country in which we deliver, currently including Malaysia, Thailand, India, and the United States, and any further territories we enter.
* **International standards.** We uphold Article 19 of the United Nations Convention on the Rights of the Child, which requires that all appropriate measures be taken to protect children from violence, abuse, neglect, and exploitation.
* **Partner frameworks.** Where we deliver through a partner institution, that institution’s local statutory framework and designated leads operate alongside this policy, and we refer and escalate accordingly.
# **5. Definitions**
**Child.** A person under the age of 18.
**Safeguarding.** Protecting children from abuse, neglect, exploitation, and harm, while promoting their welfare and development.
**Child protection.** The actions taken when there is a reasonable concern that a child may be suffering, or may be at risk of suffering, significant harm.
# **6. Recognising Abuse**
All personnel must be aware of the main categories of abuse and the signs that may indicate a child is at risk. The examples below are indicators, not an exhaustive list.
**Physical abuse:** deliberate physical harm or injury, for example, hitting, shaking, burning, or assault.
**Emotional abuse:** persistent emotional mistreatment, for example, humiliation, intimidation, bullying, or threats.
**Sexual abuse:** any sexual activity involving a child, including grooming, exploitation, sexual communication, and the sharing of inappropriate content.
**Neglect:** a failure to meet a child’s basic physical or emotional needs, for example, a lack of supervision, care, or safe conditions.
**Online abuse:** abuse facilitated through technology, including cyberbullying, grooming, exploitation, harassment, and the sharing of harmful content.
# **7. Roles and Responsibilities**
## **Senior Management Team**
Responsible for policy oversight, allocating resources for safeguarding, and monitoring compliance across the organisation.
## **Designated Safeguarding Lead (DSL)**
The DSL is the first point of contact for any safeguarding concern. The DSL receives concerns, decides on and makes referrals, liaises with authorities and partner institutions, maintains records, and provides guidance to staff.
**DSL:** **Anusuya Mukherjee** Email: **[anusuya@squid.academy](mailto:anusuya@squid.academy)** Phone: **+44 7455 230639**
## **Deputy Safeguarding Lead**
Acts with the full authority of the DSL in the DSL’s absence, or where a concern relates to the DSL.
**Deputy: Jeffrey Cray** Email: **[jeffrey@squid.academy](mailto:jeffrey@squid.academy)** Phone: **+44 7455 230639**
## **Staff, Associates, and Volunteers**
Responsible for following this policy, maintaining professional conduct, and reporting any concern without delay.
## **Partner Institutions**
Retain their own statutory safeguarding duties and designated leads. Squid Academy works with partner leads and shares relevant concerns so that they can be acted upon locally and promptly.
# **8. Safer Recruitment and Locally Appropriate Checks**
Squid Academy applies safer recruitment principles to all personnel who may have contact with children, and carries out checks that are appropriate to the role and lawful in the jurisdiction in which the individual is engaged. These may include:
* Verifying identity
* Obtaining and following up references
* Verifying relevant qualifications
* Confirming the right to work
* Criminal background checks, such as a DBS check in the United Kingdom or the local equivalent, where legally permitted and required for the role
* Prohibition or barred-list checks where these exist in the relevant jurisdiction
No individual may work unsupervised with children until the checks appropriate to their role and location have been completed and recorded. Where Squid Academy delivers through a partner institution that employs the supervising staff, Squid Academy will seek assurance that the partner has completed locally appropriate checks on those staff. Records of checks are retained securely.
# **9. Code of Conduct**
All staff, associates, and volunteers must:
* Treat learners with respect and maintain professional boundaries at all times
* Use only approved communication channels
* Promote a safe and inclusive environment
* Report any safeguarding concern immediately
They must not:
* Engage in inappropriate conversations or use inappropriate language
* Share personal contact information with learners
* Communicate privately with learners through personal social media or personal accounts
* Request personal photographs from learners
* Arrange unsupervised meetings with learners
* Form relationships with learners outside the professional educational setting
# **10. Online Safety and Digital Safeguarding**
As a provider whose programmes are delivered substantially online, Squid Academy places particular importance on digital safeguarding. We will:
* Use moderated learning platforms and apply age-appropriate controls
* Monitor community spaces, including any Discord or community platforms we operate, where appropriate
* Restrict and remove inappropriate content
* Provide clear reporting mechanisms for learners
* Promote safe online behaviour and educate learners in digital citizenship
Learners are expected to treat others respectfully, report inappropriate behaviour, avoid sharing personal information publicly, and follow platform rules and community guidelines.
# **11. One-to-One Communication with Learners**
To reduce safeguarding risk:
* One-to-one communication with a child should be avoided wherever possible
* Communication should take place through approved platforms only
* Parents, carers, or the partner institution may be copied into communications where appropriate
* Sessions should be recorded where permitted and practical
* Professional language must be maintained at all times
# **12. Recognising and Reporting Concerns**
Any individual who observes concerning behaviour, receives a disclosure, suspects abuse, becomes aware of online exploitation or grooming, or is otherwise worried about a child’s wellbeing, must report the concern to the Designated Safeguarding Lead or Deputy without delay.
A report should include:
* The date and time
* The individuals involved
* The facts observed
* The exact words used, where possible
* Any immediate risk identified
Those raising a concern must not promise confidentiality, attempt to investigate the matter themselves, confront an alleged perpetrator, or delay reporting. Concerns are raised using
**Reporting route: [support@squid.academy](mailto:support@squid.academy) → [anusuya@squid.academy](mailto:anusuya@squid.academy) → [jeffrey@squid.academy](mailto:jeffrey@squid.academy)**
# **13. Responding to a Disclosure**
If a child discloses abuse, staff should stay calm, listen carefully, take the child seriously, reassure them that they have done the right thing by speaking up, record the information accurately, and report it immediately.
Staff should not ask leading questions, make promises, express shock or disbelief, or conduct their own investigation.
# **14. Managing Allegations Against Staff, Associates, or Volunteers**
Squid Academy takes seriously any concern or allegation that a member of staff, an associate, a volunteer, or any adult acting on its behalf may have:
* Behaved in a way that has harmed, or may have harmed, a child
* Possibly committed a criminal offence against, or related to, a child
* Behaved towards a child in a way that indicates they may pose a risk of harm
* Behaved, or may have behaved, in a way that indicates they may not be suitable to work with children, including conduct in their personal life that may present a transferable risk
Where such a concern arises, the following process applies:
* **Report immediately** to the DSL. If the concern is about the DSL, it must instead be reported to **Jeffrey Cray** | [jeffrey@squid.academy](mailto:jeffrey@squid.academy) | +44 7455 230639
* The DSL, or the alternative lead where the concern relates to the DSL, takes charge, ensures the child’s immediate safety, and does not attempt an informal investigation or alert the subject in a way that could prejudice an inquiry.
* Squid Academy refers the matter to the relevant statutory or local authority, for example local children’s services or the police, and in England the Local Authority Designated Officer or equivalent, in line with the law of the jurisdiction concerned, and cooperates fully.
* Where the individual is supervised by, or engaged through, a partner institution, Squid Academy informs and works with that institution’s designated safeguarding lead.
* Appropriate employment or contractual action, including precautionary suspension or removal of access to learners and platforms, is considered to protect children while any inquiry proceeds.
* Confidential records of the allegation, decisions, and actions are kept securely.
* Allegations found to be malicious or unfounded are handled fairly, and support is offered to those affected.
# **15. Concerns About Another Child or Young Person**
Concerns about the behaviour of one child towards another, including bullying and peer-on-peer abuse, are taken seriously, reported to the DSL, recorded, and escalated where necessary. Support is offered to all children involved, and the matter is shared with the relevant partner institution and authorities where appropriate.
# **16. Escalation and Risk Levels**
**Low-level concern** (for example inappropriate language or minor bullying): record the incident, monitor behaviour, and inform the relevant supervisor.
**Safeguarding concern** (for example grooming indicators, self-harm concerns, or significant emotional distress): escalate immediately, notify the DSL, and consider notifying the parent, carer, or partner institution.
**Immediate risk** (for example a threat of serious harm, sexual exploitation, or expressed intent to take one’s own life): contact local emergency services or the relevant authorities immediately, notify the DSL, and preserve any evidence.
# **17. Confidentiality and Information Sharing**
Information is shared only when necessary to protect a child, with relevant authorities, and with schools, partner institutions, parents, or carers where appropriate, and always in accordance with applicable data protection law. The welfare of the child is paramount and takes precedence over confidentiality. A concern about a child must always be shared with the DSL, even if the child asks that it not be.
# **18. Record Keeping and Data Protection**
Safeguarding records are stored securely, access-controlled, available only to authorised personnel, and retained in accordance with Squid Academy’s data retention schedule and applicable data protection law, including the UK General Data Protection Regulation where relevant.
# **19. Training and Awareness**
All personnel who work with learners receive safeguarding awareness training covering child protection principles, online safety, recognising abuse, reporting procedures, and professional boundaries. The Designated Safeguarding Lead and Deputy receive enhanced training appropriate to their role. Training is refreshed at least every two years, and completion of this policy forms part of induction.
# **20. Whistleblowing and Complaints**
Any individual who believes a safeguarding concern has not been handled appropriately, or that a child is being placed at risk by the conduct of others or by organisational failure, can and must raise it. Concerns may be raised with the DSL, the Senior Management Team, or, where internal routes are exhausted or inappropriate, with the relevant external authority. No one who raises a genuine concern in good faith will suffer any detriment for doing so.
# **21. Monitoring and Review**
This policy is reviewed by the Designated Safeguarding Lead and the Senior Management Team at least annually, or sooner if legislation changes, new safeguarding risks emerge, a significant incident occurs, or regulatory guidance is updated.
# **22. Contact Details**
**Designated Safeguarding Lead: Anusuya Mukherjee** | **[anusuya@squid.academy](mailto:anusuya@squid.academy)** | +44 7455 230639
**Deputy Safeguarding Lead: Jeffrey Cray** | **[jeffrey@squid.academy](mailto:jeffrey@squid.academy)** | +44 7455 230639
**Internal reporting channel: [support@squid.acadey](mailto:support@squid.acadey) → [anusuya@squid.academy](mailto:anusuya@squid.academy) → [jeffrey@squid.academy](mailto:jeffrey@squid.academy)**
In an emergency, staff must contact the local emergency services number for the country in which the learner is located. Widely used examples include 999 in the United Kingdom and 911 in the United States. The relevant local emergency and child protection contacts for each country of delivery are maintained by the partner institution.
Additional support and reporting:
* **NSPCC Helpline (adults concerned about a child):** 0808 800 5000
* **Childline (for children and young people):** 0800 1111
* **AQA safeguarding team (for concerns relating to AQA UAS):** [safeguarding@aqa.org.uk](mailto:safeguarding@aqa.org.uk)
# **Appendix A: AQA UAS Safeguarding Assurance Mapping**
AQA UAS asks that a registering organisation’s safeguarding policy addresses five points. The table below shows where each is met in this policy.
| **AQA UAS assurance point** | **How this policy provides assurance** | **Where** |
| :------------------------------------------------------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------- | :--------------------- |
| 1. Clear contact details of the designated person for safeguarding matters | Named Designated Safeguarding Lead and Deputy, with direct email and phone contact | Sections 7 and 22 |
| 2. A process to respond to any safeguarding concern raised | Defined procedures for recognising, reporting, responding to disclosures, and escalating concerns | Sections 12, 13 and 16 |
| 3. A process in line with local legislation or guidance | Legal and regulatory framework covering UK statutory guidance, the law of each country of operation, and the UN Convention on the Rights of the Child | Section 4 |
| 4. Locally appropriate checks on staff employed | Safer recruitment standards with vetting appropriate to the role and lawful in each jurisdiction | Section 8 |
| 5. A process to respond to concerns raised about staff members | Dedicated procedure for managing allegations against staff, associates, and volunteers, including referral to the relevant authority | Section 14 |
# \\
**Appendix B: Safeguarding Reporting Flow**
A quick reference for any member of staff, associate, or volunteer with a concern about a child.
1. Ensure the child is safe. If a child is in immediate danger, contact local emergency services first.
2. Record what you have seen or been told, using the child’s own words where possible. Do not investigate or confront anyone.
3. Report to the Designated Safeguarding Lead, or the Deputy, without delay. Do not promise confidentiality.
4. The DSL assesses the concern, decides on referral, and contacts the relevant authorities and, where applicable, the partner institution’s safeguarding lead and the child’s parents or carers.
5. All actions, decisions, and information shared are recorded securely.
# Security & Incident Response
Source: https://docs.squid.gg/platform/security-incident-response
Our security practices, monitoring, and how incidents are detected, reported, and handled.
*Last updated: \[August 27, 2025]*
Squid Academy is committed to maintaining strong technical and organizational measures (TOMs) to protect the personal data we process, and to responding promptly and effectively to any security incidents.
This page summarizes the measures outlined in Annex II and Annex V of our [Data Processing Addendum](https://docs.google.com/document/u/6/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit) in plain language.
## **1. Technical & Organizational Measures** (TOMs)
We use a layered security approach designed to protect data confidentiality, integrity, and availability.
### **Governance & Access Control**
* Role-based access control (RBAC) and least-privilege principles.
* Multi-factor authentication (MFA) required for all admin and privileged accounts.
* Unique credentials for each authorized user; password complexity enforced.
* Regular access reviews and removal of dormant accounts.
### **Encryption**
* TLS 1.2+ for all data in transit.
* AES-256 or equivalent for all data at rest.
* Encryption key management and regular rotation.
### **Application Security**
* Secure software development lifecycle (SSDLC) with code reviews and automated scanning.
* Regular penetration tests and vulnerability assessments.
* Change management with staging, testing, and rollback procedures.
### **Network & Infrastructure**
* Segmented networks for production, staging, and development environments.
* Web application firewall (WAF) and intrusion detection/prevention systems (IDS/IPS).
* DDoS mitigation in place.
### **Monitoring & Logging**
* Centralized logging with anomaly detection alerts.
* Audit logs for administrative actions and exports.
* Retention of logs for security investigations.
### **Business Continuity & Disaster Recovery**
* Daily encrypted backups with offsite storage.
* Disaster recovery plans tested at least annually.
* Recovery point objective (RPO) and recovery time objective (RTO) defined.
### **Third-party Risk Management**
* Due diligence on vendors and [sub-processors](https://docs.google.com/document/u/6/d/1hSsHISPyzidVjqRFjI2EwKUCX3lrMDW5LtjxLhJ1zVs/edit).
* Binding contractual obligations for data protection and security.
## **2. Incident Response**
We have a defined process for detecting, reporting, and responding to security incidents.
### **Incident Triggers**
* Detection of unauthorized access, disclosure, loss, alteration, or destruction of personal data.
* Alerts from security monitoring systems.
* Reports from employees, customers, or third parties.
### **Initial Response**
* Immediate containment and isolation of affected systems.
* Rotation of credentials and revocation of compromised access.
* Preservation of evidence for investigation.
### **Notification to Controllers**
* We will notify the affected customer (data controller) without undue delay after becoming aware of a personal data breach.
* Where GDPR applies, our target is to notify within 72 hours.
* Initial notice includes:
* Nature of the incident.
* Categories and approximate number of data subjects affected.
* Categories and approximate number of records affected.
* Likely consequences.
* Measures taken or proposed to address the incident.
### **Investigation & Remediation**
* Root cause analysis (RCA).
* Corrective actions to prevent recurrence.
* Security posture review and update.
### **Post-incident Review**
* Lessons learned session with relevant teams.
* Update to security controls and policies.
* Customer communication with the final report where applicable.
## **3. Contact**
If you believe your data has been impacted by a security incident involving Squid Academy, contact: [security@squid.gg](mailto:security@squid.gg)
# Sub-processor List
Source: https://docs.squid.gg/platform/sub-processor-list
The third-party vendors we use to deliver the service and what data they process.
*Last updated: \[July 13, 2026]*
## **1. Introduction**
Squid Academy uses carefully selected third-party service providers (“Sub-processors”) to support the delivery of our LMS, tournament platform, and related services. These Sub-processors may process personal data on our behalf when providing their services. (For details on our cross-border data protection safeguards, see our [International Data Transfers](https://docs.google.com/document/u/6/d/1CyjvkQlK117ZzibQoIzbA9fgCzVihPBzt1vNClSkgiw/edit) page.)
We conduct due diligence before engaging any Sub-processor and require all Sub-processors to enter into written agreements that impose data protection obligations consistent with our [Data Processing Addendum](https://docs.google.com/document/u/6/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit).
## **2. How We Update This List**
* **Advance Notice:** We will update this page at least **30 days before** engaging a new Sub-processor, except where urgent replacement is required (see below).
* **Emergency Replacement:** In urgent cases (e.g., to maintain security, availability, or continuity of service), we may engage a Sub-processor without prior notice. In these cases, we will update this list as soon as reasonably practicable and provide notice promptly.
* **How to Object:** If you are a customer with a current agreement incorporating our [DPA](https://docs.google.com/document/u/6/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit), you may object to a new Sub-processor by emailing [privacy@squid.gg](mailto:privacy@squid.gg) within 30 days of notice. Objections must be based on reasonable, documented grounds relating to data protection risks.
## **3. Current Sub-processors**
| Name of Sub-processor | Purpose of Processing | Location of Processing | Data Categories Processed | Transfer Mechanism (if outside EEA/UK) | Link to Privacy Policy |
| :-------------------- | :--------------------------------------------------- | :------------------------------------------------- | :------------------------------------------------ | :----------------------------------------------- | :------------------------------------------------------------------------------- |
| Mailgun | Email delivery (transactional + notification emails) | USA | Account email addresses, notification preferences | SCCs 2021/914, Module 2 + supplementary measures | [Resend Privacy Policy](https://resend.com/legal/privacy-policy) |
| **DigitalOcean** | Cloud hosting & storage | USA / Netherlands (depending on deployment region) | User account data, content uploads, activity logs | SCCs 2021/914, Module 2 + supplementary measures | [DigitalOcean Privacy Policy](https://www.digitalocean.com/legal/privacy-policy) |
| MongoDB | Data Management | Singapore | | | |
## **4. Change Log**
| **Date** | **Change** | **Notes** |
| :--------- | :------------------------------------ | :----------------------------------- |
| 2025-08-27 | Added [Resend.com](http://Resend.com) | New Sub-processor for email delivery |
| 2025-08-27 | Added DigitalOcean | New Sub-processor for cloud hosting |
| 2025-08-27 | Removed Payment Vendor | Payment processing not applicable |
## **5. Contact**
Questions about this list or your rights under the DPA can be directed to: [privacy@squid.gg](mailto:privacy@squid.gg)
# Terms & Conditions
Source: https://docs.squid.gg/platform/terms-and-conditions
The rules for using our platform—your rights, responsibilities, and our service commitments.
*(Last updated: August 14, 2025)*
## **1. Introduction**
These Terms & Conditions (“Terms”) govern access to and use of Squid Academy’s online learning management system and tournament environment, including web apps, content, modules, code, and related services (the “Services”).
Squid Academy Ltd is incorporated in England & Wales (company no. 14264598), registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ (“Squid”, “we”, “our”, “us”). By creating an account, accepting these Terms at sign‑up, or using the Services, you agree to be bound by these Terms.
Click‑wrap acceptance. Public Users must accept these Terms during sign-up. Organization Administrators must accept these Terms when creating or activating an Organization Account and are responsible for ensuring all users they onboard comply with them.
## **2. Definitions**
* **Public User**: An individual user creating a personal account (13+ only).
* **Organization**: A school, college/university, esports center, club, or other entity using the Services.
* **Organization Administrator / “Org Admin”**: An adult individual (18+) authorized by an Organization to manage its Organization Account, classrooms, teams, and users.
* **Student User**: A user onboarded by an Organization (may be under 13 subject to local‑law consent).
* **Programs / Licenses**: Educational programs and related entitlements purchased for access in the Services.
* **LMS + Tournament Platform**: Squid’s SaaS platform enabling classroom/course access and esports tournament features.
* **Organization Data:** Any data, content, or records submitted to or generated within the Services by or for an Organization (including class rosters, enrollments, progress records, tournament entries/results, and related metadata), excluding Squid materials and anonymized/aggregated data.
## **3. Eligibility & Accounts**
**3.1 Public Users.** You must be 13 years or older to create a Public User account. Public account creation by users under 13 is not permitted.
**3.2 Organization Accounts.** Org Admins must be 18+ and duly authorized by their Organization. Org Admins may invite Student Users (including under‑13) only if they (the Organization) have obtained and recorded verifiable parental/guardian consent and otherwise comply with applicable law (see [Section 8](https://squidacademy.mintlify.app/platform/terms-and-conditions#8-privacy%2C-data-collection-%26-cookies) and [Regional Annexes](https://squidacademy.mintlify.app/platform/terms-and-conditions#regional-annexes-incorporated-by-reference)).
**3.3 Account Security.** You’re responsible for your credentials and all activity under your account. Notify us immediately of any suspected unauthorized access.
**3.4 Prohibition on Transfer.** Accounts are personal to the registered user/Organization and may not be sold, transferred, or shared except as expressly permitted in the Services.
## **4. Global Compliance Statement**
We operate internationally and comply with applicable local laws, including: (a) UK & EU GDPR / UK GDPR (data protection, user rights, and cross‑border transfers); (b) United States laws relevant to education and minors, including COPPA and, where applicable, FERPA, and US state privacy laws where we act as a service provider/processor; (c) Malaysia PDPA 2010 (lawful processing, notices, access/correction, cross‑border restrictions); (d) Thailand PDPA 2019 (consent—including for minors—and data‑subject rights); and (e) India DPDP Act 2023 (including protections for individuals under 18). Nothing in these Terms overrides mandatory statutory rights. Where local law imposes stricter requirements, those apply in addition to these Terms.
## **5. Children & Student Data (Schools/Organizations)**
**5.1 Public Users under 13.** Not permitted. If we learn a Public User is under 13, we will suspend or delete the account.
**5.2 Organization‑Invited Under‑13 Users.** Org Admins must:\
(a) verify age; (b) obtain and retain verifiable parental/guardian consent as required by local law; (c) provide consent evidence to Squid upon request; and (d) ensure the scope of data shared with Squid is limited to what is necessary for educational use.
**5.3 Roles under privacy laws.** For Organization‑provisioned users, the Organization is typically the controller (or equivalent) and Squid acts as a processor/service provider. For Public Users, Squid acts as a controller for core account data. A Data Processing Addendum (DPA) is incorporated by reference for Organization use (see [Section 14.7](https://docs.google.com/document/d/1naMWUBeGi99rmMptIY-oXLlr9BmTGDXIoFk2qQ-_p4A/edit?tab=t.0#bookmark=id.2gcyw0brhgqj)).
**5.4 QR/Invite Journeys.** Where QR or invite links are used to join a class/team, Org Admins must ensure the invited user meets age eligibility and consent requirements before use.
**5.5 Protection of Minors.** Public users under 13 are not permitted to create accounts. For Organization‑provisioned users who are minors, Org Admins are solely responsible for verifying age, obtaining and retaining verifiable parental/guardian consent where required by local law, and ensuring lawful onboarding and use. You must not use the Services to profile, target, or deliver advertising to minors, and you must not collect more personal data than necessary for educational purposes. Where applicable, you must follow local age‑appropriate design standards.
## **6. Acceptable Use**
\*\*You (and anyone using the Services under your account) must not: \*\*(a) violate laws or third‑party rights; (b) upload infringing, harmful, or abusive content; (c) harass or endanger others; (d) attempt to bypass security; (e) interfere with tournaments (e.g., cheating, botting, match‑fixing); (f) scrape, data‑mine, or reverse engineer except as permitted by law; (g) share credentials; or (h) use the Services to build a competing product.
We may suspend or terminate access immediately to protect users or the platform (see [Section 17](https://docs.google.com/document/d/1naMWUBeGi99rmMptIY-oXLlr9BmTGDXIoFk2qQ-_p4A/edit?tab=t.0#heading=h.wkadln68ubd7)).
## **7. Service Description; Changes; Beta**
**7.1 Description.** The Services include access to Squid’s LMS modules, tournaments, and related features, which may vary by plan, license, or Organization settings.
**7.2 Changes.** We may improve, modify, or discontinue features with notice where practicable. If a change materially reduces core functionality of a paid plan during a committed term, your sole remedy is a pro‑rated refund of prepaid, unused fees for the affected period.
**7.3 Beta/Preview.** Beta or experimental features are provided “AS IS”, may change or end at any time, and are excluded from any uptime or support commitments.
**7.4 Service Levels.** Unless you have a separate, signed service level agreement (SLA) with Squid, the Services are provided without any uptime, support response, or other service level commitments.
## **8. Privacy, Data Collection & Cookies**
**8.1 Minimal data.** We collect what’s needed to operate the Services: name, email, associated Organization, course/tournament participation, progress logs, and technical telemetry necessary to secure and maintain the Services. We do not collect phone numbers or physical addresses unless strictly necessary for security or support.
**8.2 Sensitive data.** You must not input health, financial, or other special‑category data unless we expressly agree in writing.
**8.3 Cookies.** We currently use only essential session cookies for authentication and core functions. If we introduce analytics/non‑essential cookies later, we will implement a compliant consent mechanism per applicable law.
**8.4 Privacy Policy & DPA.** Our [Privacy Policy](https://docs.google.com/document/u/6/d/1pJDPGOXueYFzt81Wzzv25-04_nuPi3seArJJkqm_d_4/edit) (linked in‑product) explains purposes, legal bases, retention, international transfers, and user rights. For Organizations, the [DPA](https://docs.google.com/document/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit?usp=sharing) governs processing on their behalf, including sub‑processors and cross‑border transfer mechanisms (e.g., SCCs/UK addendum or other approved safeguards).
**8.5 Student & child transparency.** Organizations must provide appropriate notices to parents/guardians and students as required by local law (e.g., COPPA notices, FERPA directory‑information disclosures).
**8.6 No Sale/Sharing of Personal Data.** When acting as a processor/service provider for Organizations, Squid does not “sell” or “share” personal information as those terms are defined under applicable US state privacy laws, nor does Squid use such data for cross‑context behavioral advertising.
**8.7 Privacy Contact.** Questions about privacy, data subject rights, or this policy may be directed to [privacy@squid.gg](mailto:privacy@squid.gg) (you can also submit a request via our [Privacy Request Form](https://drive.google.com/open?id=1IwxaKEtOAeDeaGgC6E3I_nLwY4zKsBp2XVnW1S_0gew)).
Details on how long we keep different types of information are provided in our [Data Retention & Deletion Schedule](https://docs.google.com/document/u/6/d/1vFMrCnA-rl3LgBMuAifFAh2rFAmHFjWgtJzmT-4q4TA/edit).
## **9. Security & Incident Response**
We maintain administrative, technical, and physical [safeguards](https://docs.google.com/document/u/6/d/1vyd27JAHAeSYlxSRP0gG9LyMicI6uBO7YjfjQfHYU6k/edit) appropriate to the nature of the data. You must secure your devices and credentials.
If we become aware of a security incident affecting your data, we’ll notify the impacted customer/Organization without undue delay and cooperate as required by law and the DPA.
## **10. Content** **& IP**
**10.1 Our IP.** The Services (software, content, visuals, trademarks) are owned by Squid and its licensors and licensed, not sold, to you. No rights are granted except as expressly stated.
**10.2 Your Content.** You retain rights to content you upload. You grant Squid a non‑exclusive, royalty‑free license to host, display, and process such content solely to operate and improve the Services. You represent you have all rights needed and your content complies with law and these Terms.
**10.3 Feedback.** You grant Squid a perpetual, worldwide, royalty‑free license to use feedback/suggestions to improve the Services without obligation to you.
## **11. Third‑Party Services & Sign‑In**
You may enable third‑party sign‑in (e.g., Google, Apple) or integrations. Use of third‑party services is subject to their terms and privacy practices. We’re not responsible for third‑party services or data they process beyond our control.
## **12. Copyright Complaints (DMCA‑Style)**
If you believe content infringes your copyright, send a notice to our DMCA agent:
**DMCA Agent:** Squid Academy Ltd
**Address:** 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
**Email:** [dmca@squid.gg](mailto:dmca@squid.gg)
Your notice must include: (a) identification of the copyrighted work claimed to have been infringed; (b) identification of the material claimed to be infringing (URL if available); (c) your contact information; (d) your good‑faith statement that the use is not authorized; (e) a statement under penalty of perjury that the information is accurate and that you are the copyright owner or authorized to act; and (f) your physical or electronic signature. We may remove content and/or terminate repeat infringers where legally required.
## **13. Fees, Taxes & Promotions**
**13.1 Fees.** Fees for licenses/subscriptions are set out in your order, invoice, or Organization agreement. Promotional terms (e.g., complimentary access periods) are time‑limited and subject to the applicable commercial document.
**13.2 Taxes.** Fees are exclusive of all applicable taxes (e.g., VAT, GST, sales/use/IVU, digital services taxes). The seller of record must collect and remit taxes as required by local law. Jurisdiction‑specific rules in the [Regional Annexes](https://docs.google.com/document/d/1naMWUBeGi99rmMptIY-oXLlr9BmTGDXIoFk2qQ-_p4A/edit?tab=t.0#heading=h.4fr6g3pq19cp) (e.g., United States incl. Texas, Puerto Rico, Malaysia, Thailand, India) form part of these Terms and may require registration, invoicing, or exemption documentation by the invoicing party.
**13.3 Nonpayment.** We may suspend or terminate Services for nonpayment after reasonable notice.
## **14. Data Governance (Organizations)**
**14.1 Controller/Processor.** As between the parties, the Organization is controller of personal data it supplies; Squid is processor/service provider.
**14.2 DPA Incorporated.** The Squid[Data Processing Addendum](https://docs.google.com/document/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit?usp=sharing) (current version posted in‑product) is incorporated by reference and governs processing, sub‑processors, security measures, assistance with data‑subject requests, audits, and incident handling.
**14.3 International Transfers.** We use approved transfer mechanisms (e.g., SCCs, UK IDTA/Addendum, or equivalent) for cross‑border transfers.
**14.4 Retention & Deletion.** Upon termination or request, we delete or return Organization personal data per the DPA unless law requires retention.
**14.5 Parental Consent Records.** Organizations must maintain parental/guardian consent records for under‑13 users (or local equivalents) and supply proof upon request.
**14.6 Student Rights Requests.** Organizations are responsible for authenticating and routing access/deletion requests from students/parents; we will assist per the DPA.
\*\*14.7 Policies Hierarchy. \*\*If there is any conflict between these Terms and the DPA with respect to processing of personal data on behalf of an Organization, the DPA prevails. If there is a conflict between these Terms and any other incorporated policy or annex (e.g., Privacy Policy, Regional Annexes), the document that more specifically addresses the subject matter controls, unless these Terms or that document expressly state otherwise.
## **15. Warranties & Disclaimers**
The Services are provided “AS IS” and “AS AVAILABLE”. To the maximum extent permitted by law, we disclaim all warranties, express, implied, or statutory, including merchantability, fitness for a particular purpose, and non‑infringement. We do not warrant the Services will be error‑free, uninterrupted, or meet your specific requirements.
## **16. Indemnification**
**16.1 By Organization.** The Organization will defend, indemnify, and hold harmless Squid and its affiliates against claims, losses, damages, and expenses (including reasonable legal fees) arising from: (a) Organization’s or Org Admin’s breach of these Terms or the DPA; (b) failure to obtain/retain verifiable parental consent or comply with child/student privacy laws; (c) content provided by the Organization; or (d) use of the Services in violation of law.
**16.2 By Public User.** Public Users will indemnify Squid for claims arising from their breach of these Terms or violation of law.
**16.3 IP Indemnity by Squid (Organizations only).** We will defend Organization against third‑party claims alleging the Services infringe a patent, copyright, or trademark, and pay resulting damages finally awarded, provided Organization: (a) promptly notifies us; (b) gives us sole control of defense/settlement; and (c) cooperates. We may modify or replace the Services to avoid infringement or terminate access with a pro‑rated refund. This does not apply to claims based on Organization content, combinations, or non‑current versions.
## **17. Suspension & Termination**
We may suspend or terminate accounts or access (in whole or part) if: (a) you materially breach these Terms; (b) nonpayment persists; (c) your use poses security, legal, or safety risks; or (d) required by law. We will notify you of a suspension and the reason, unless prohibited by law, and will reinstate access promptly after the issue is resolved.
You may stop using the Services at any time. Upon termination, your right to access the Services ceases, and [Sections 10](https://docs.google.com/document/d/1naMWUBeGi99rmMptIY-oXLlr9BmTGDXIoFk2qQ-_p4A/edit?tab=t.0#heading=h.yxf75bmyfqh4)–[21](https://docs.google.com/document/d/1naMWUBeGi99rmMptIY-oXLlr9BmTGDXIoFk2qQ-_p4A/edit?tab=t.0#heading=h.sy3fu43y1za0) survive. For Organizations, data handling upon termination is governed by the DPA.
**Post‑Termination Data Handling.** Upon termination or expiration, you (or your Organization) may request an export of Organization Data and personal data within 30 days of termination. Squid will delete or anonymize remaining personal data within 60 days thereafter, except where retention is required by law or for limited back‑up integrity (in which case data will be isolated and deleted on the next standard cycle). Extended storage or migration assistance must be agreed in writing and may incur fees.
## **18. Limitation of Liability**
To the maximum extent permitted by law:
**18.1 No Indirect Damages.** Neither party is liable for indirect, incidental, consequential, special, exemplary, or punitive damages, or for loss of profits, revenue, goodwill, or data, even if advised of the possibility of such damages.
**18.2 Aggregate Cap.** Each party’s total aggregate liability under these Terms (whether in contract, tort—including negligence—strict liability, or otherwise) is limited to the total amounts paid or payable to Squid in the twelve (12) months immediately preceding the event giving rise to liability. For Public Users, the cap is the lower of that amount or £10,000 (or USD equivalent); for free plans, £100.
**18.3 Carve‑Outs.** The above limitations do not apply to: (a) a party’s fraud or willful misconduct; (b) your payment obligations; (c) your indemnification obligations; or (d) liability that cannot be excluded under applicable law (including death or personal injury caused by negligence).
**18.4 DPA & Data Protection.** For Organization‑processed personal data, the DPA governs data‑protection liabilities and remedies; this §18 applies except to the extent the DPA expressly provides otherwise.
## **19. Export, Sanctions & Government Use**
You must comply with export control and sanctions laws applicable to you. You may not use the Services if you are subject to sanctions or in prohibited territories. Government users: the Services are provided as “commercial computer software” and related documentation subject to restricted rights.
## **20. Changes to Terms**
We may update these Terms from time to time. We’ll post the new version with an updated “Last updated” date and, for material changes, provide reasonable advance notice. Continued use after the effective date constitutes acceptance.
## **21. General**
**21.1 Governing Law & Venue.** These Terms are governed by the laws of England & Wales, and disputes will be resolved exclusively in the courts of England & Wales, except that mandatory local laws may also apply and nothing herein limits non‑waivable statutory rights.\
**21.2 Order of Precedence.** If there is a conflict between these Terms and a signed order/agreement with Squid, the signed document prevails; for Organization data, the DPA prevails over these Terms to the extent of conflict.\
**21.3 Force Majeure.** Neither party is liable for delays/failures caused by events beyond reasonable control.\
**21.4 Assignment.** You may not assign these Terms without our prior written consent; we may assign to an affiliate or in connection with reorganization, merger, or sale.\
**21.5 Notices.** Legal notices to Squid: [legal@squid.gg](mailto:legal@squid.gg) and 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. Notices to you: the email on your account or in‑app notifications.\
**21.6 Severability; Waiver.** If any provision is unenforceable, the remainder remains in effect. Failure to enforce is not a waiver.\
**21.7 Entire Agreement.** These Terms (including the Privacy Policy, DPA, and Regional Annexes) form the entire agreement for your use of the Services.
## **Regional Annexes (Incorporated by Reference)**
### **Annex A — United States (including Texas) & Puerto Rico**
1. **Children’s privacy**: Compliance with COPPA is mandatory. Public users under 13 are not permitted. Org Admins must obtain verifiable parental consent before inviting under‑13 users; maintain records for as long as the account is active.
2. **FERPA (where applicable)**: For US educational institutions, you acknowledge your responsibilities under FERPA. Squid acts as a “school official” under your control for authorized educational purposes when processing student data.
3. **Texas**: Comply with Texas privacy laws applicable to minors and students. Where an Organization operates in Texas, Org Admins must ensure COPPA‑grade guardian consent and age gating; retain consent records and provide them upon request.
4. **Puerto Rico**: Comply with Puerto Rico data‑protection requirements; ensure guardian consent for under‑13 users; maintain documentation (including SURI evidence for tax‑related exemptions if relevant to invoicing outside these Terms).
### **Annex B — Malaysia (PDPA 2010)**
1. Provide PDPA‑compliant notices to data subjects (or guardians) describing purposes, rights of access/correction, and how to contact your PDPA officer.
2. Do not transfer personal data outside Malaysia except in accordance with PDPA cross‑border rules or where a controller‑approved transfer mechanism is in place (covered by our DPA safeguards).
### **Annex C — Thailand (PDPA 2019)**
1. Obtain explicit consent from a parent/guardian for under‑ten users; for older minors, obtain consent where required by PDPA and applicable regulations.
2. Respect PDPA rights (access, correction, deletion); route requests via the Organization for Organization‑provisioned users; Squid will assist per the DPA.
### **Annex D — India (DPDP Act 2023)**
1. Treat children (under 18) as a protected class: obtain verifiable parental consent before processing their personal data; do not undertake tracking/behavioral monitoring or targeted advertising directed at children.
2. Comply with notice, consent, and data‑principal rights requirements; use our DPA safeguards for cross‑border transfers until further rules specify otherwise.
# Thailand Compliance Addendum
Source: https://docs.squid.gg/platform/thailand-compliance-addendum
**Applicable Jurisdiction:** Thailand
**Related Documents:**
* Privacy Policy
* Data Processing Addendum
* Information Security Policy
* Terms & Conditions
# **1. Purpose**
This Addendum explains how Squid Academy manages educational services and personal data relating to individuals located in Thailand.
# **2. Applicable Legislation**
Squid Academy seeks to comply with the following:
* Thailand Personal Data Protection Act (PDPA)
* Applicable consumer protection laws
* Relevant educational requirements
# **3. Lawful Processing of Personal Data**
Personal data may be processed for:
* Educational delivery
* Student administration
* Assessment activities
* Safeguarding
* Customer support
* Legal compliance
Processing will be limited to legitimate and necessary purposes.
# **4. Data Subject Rights**
Individuals may request:
* Access to personal data
* Correction of inaccurate information
* Deletion where legally appropriate
* Withdrawal of consent where applicable
# **5. Recording of Sessions**
Where educational sessions are recorded for safeguarding, quality assurance, or operational purposes:
* Learners will be informed.
* Recordings will be protected.
* Access will be restricted to authorised personnel.
* Retention periods will follow Academy policies.
# **6. Children's Data**
Where services involve minors:
* Additional safeguards will apply.
* Parental involvement may be required.
* Safeguarding procedures will be followed.
# **7. International Transfers**
Data may be stored or processed outside Thailand.
The Academy will implement reasonable safeguards to protect personal data during international transfers.
If you have any questions, comments, or concerns, please feel free to reach out to us at [support@squid.academy](mailto:support@squid.academy)
\\
# Discord Community & Online Communication Policy
Source: https://docs.squid.gg/platform/untitled-page
**Document Owner:** Squid Academy Ltd\
**Version:** 1.0\
**Review Date:** Annually
# **1. Purpose**
Squid Academy provides Discord servers and online community spaces to support learning, collaboration, esports participation, and student engagement.
The purpose of this policy is to ensure that all community members interact safely, respectfully, and professionally while participating in Squid Academy online environments.
This policy forms part of the wider Safeguarding, Child Protection, Code of Conduct, and Online Safety framework.
# **2. Scope**
This policy applies to:
* Students
* Parents and guardians
* Staff
* Coaches
* Tutors
* Moderators
* Volunteers
* Guest speakers
* Community members
The policy applies to all official Squid Academy Discord servers and related communication platforms.
# **3. Community Principles**
All members are expected to:
* Treat others with respect.
* Communicate professionally.
* Support an inclusive learning environment.
* Demonstrate good sportsmanship.
* Follow moderator instructions.
* Contribute positively to the community.
Squid Academy operates a zero-tolerance approach to bullying, harassment, discrimination, or harmful behaviour.
# **4. Respectful Communication**
Members must:
* Use respectful language.
* Remain courteous during discussions.
* Accept differing opinions respectfully.
* Avoid disruptive behaviour.
* Communicate constructively during esports activities.
Members must not:
* Use offensive language.
* Insult, threaten, or intimidate others.
* Engage in personal attacks.
* Deliberately provoke arguments.
* Encourage harmful behaviour.
# **5. Anti-Bullying and Harassment**
The following behaviour is prohibited:
* Bullying
* Harassment
* Discrimination
* Hate speech
* Targeted abuse
* Sexual harassment
* Doxxing
* Public shaming
This applies regardless of:
* Age
* Gender
* Nationality
* Ethnicity
* Religion
* Disability
* Sexual orientation
* Gaming ability
Any reported incident will be investigated and may result in disciplinary action.
# **6. Child Safety Requirements**
Protecting young people is a priority.
Members must not:
* Request personal contact details from minors.
* Request photographs or videos from minors.
* Attempt to arrange private meetings.
* Engage in inappropriate conversations.
* Discuss sexual content.
* Share harmful material.
* Encourage secrecy between students and adults.
Any suspected grooming behaviour will result in immediate escalation under the Safeguarding Policy.
# **7. Direct Messaging (DM) Rules**
To maintain a safe environment:
### **Students**
Students should:
* Use public channels whenever possible.
* Report inappropriate messages immediately.
* Block users if instructed by moderators.
### **Staff and Coaches**
Staff must:
* Use approved communication channels.
* Avoid unnecessary one-to-one conversations.
* Maintain professional language.
* Follow safeguarding procedures.
Private communications involving minors should only occur where operationally necessary and in accordance with safeguarding procedures.
# **8. Voice Channel Expectations**
During voice communications:
Members must:
* Speak respectfully.
* Allow others to participate.
* Follow moderator instructions.
* Use appropriate language.
Members must not:
* Shout at other users.
* Use discriminatory language.
* Play offensive audio.
* Disrupt lessons or activities.
Moderators may mute or remove disruptive participants.
# **9. Usernames, Avatars, and Profiles**
All usernames, avatars, banners, and profile content must be appropriate.
The following are prohibited:
* Offensive usernames
* Explicit content
* Hate symbols
* Violent imagery
* Drug-related content
* Gambling promotion
* Impersonation of staff or students
Moderators may require profile changes.
# **10. Sharing Content**
Members may not post:
* Pornographic content
* Graphic violence
* Illegal content
* Pirated software
* Malware
* Scam links
* Harmful challenges
* Content that violates copyright
Educational and esports-related discussions should remain appropriate for the age group of participants.
# **11. Privacy and Personal Information**
Members must not share:
* Home addresses
* Phone numbers
* School details
* Financial information
* Personal identification documents
* Passwords
Users should avoid posting personal information publicly.
# **12. Recording and Streaming**
Members may not record, stream, or redistribute:
* Classes
* Coaching sessions
* Voice chats
* Community events
without prior permission from Squid Academy.
Unauthorized recording may result in disciplinary action.
# **13. Reporting Concerns**
Members are encouraged to report:
* Bullying
* Harassment
* Safeguarding concerns
* Inappropriate content
* Security concerns
* Rule violations
Reports may be submitted through:
* Moderators
* Community Managers
* Designated Safeguarding Lead
* Official reporting forms
All reports will be treated seriously and reviewed promptly.
# **14. Moderator Authority**
Moderators may:
* Remove messages
* Mute users
* Restrict permissions
* Remove inappropriate content
* Issue warnings
* Suspend users
* Remove users from the community
Moderation decisions are made to protect community safety and well-being.
# **15. Disciplinary Actions**
Violations may result in:
### **Level 1**
* Verbal reminder
* Informal warning
### **Level 2**
* Formal warning
* Temporary restrictions
### **Level 3**
* Temporary suspension
### **Level 4**
* Permanent removal from the Discord community
### **Immediate Removal**
Serious incidents, including:
* Grooming
* Sexual misconduct
* Threats of violence
* Hate speech
* Sharing illegal material
may result in immediate permanent removal and referral to appropriate authorities.
# **16. Parent and School Involvement**
Where appropriate, Squid Academy may notify:
* Parents or guardians
* Partner schools
* Relevant educational organisations
When serious incidents involve students.
# **17. Policy Review**
This policy will be reviewed annually and updated whenever safeguarding, legal, or operational requirements change.
# Information Security Policy
Source: https://docs.squid.gg/platform/untitled-page-3
# **1. Purpose**
Squid Academy is committed to protecting the confidentiality, integrity, and availability of its information, systems, services, and data.
The purpose of this information security policy is to establish the principles, responsibilities, and controls necessary to safeguard information assets against unauthorized access, disclosure, alteration, loss, or destruction.
This policy supports the Academy's obligations relating to:
* Data protection and privacy
* Safeguarding responsibilities
* Educational delivery
* Business continuity
* Regulatory compliance
* Customer trust
# **2. Scope**
This policy applies to:
* Employees
* Directors
* Contractors
* Consultants
* Tutors
* Coaches
* Assessors
* Volunteers
* Third-party service providers with authorised access
The policy applies to:
* Information assets
* Student records
* Assessment data
* Learning platforms
* Internal systems
* Cloud services
* Company devices
* Communication platforms
* Physical and digital records
# **3. Information Security Objectives**
Squid Academy aims to
* Protect sensitive information from unauthorized access.
* Ensure information remains accurate and reliable.
* Maintain availability of critical services.
* Reduce security risks.
* Comply with legal and contractual obligations.
* Promote security awareness throughout the organization.
* Support safe and secure learning environments.
# **4. Security Principles**
The Squid Academy's information security program is based on the following principles:
## **Confidentiality**
Information shall only be accessible to authorized individuals with a legitimate business need.
## **Integrity**
Information shall be protected from unauthorized modification, corruption, or destruction.
## **Availability**
Information and systems shall remain available to authorized users when required.
## **Accountability**
Individuals are responsible for protecting information entrusted to them.
## **Least Privilege**
Access rights shall be limited to the minimum level necessary for a user's role.
# **5. Roles and Responsibilities**
## **Senior Management**
Responsible for:
* Security oversight.
* Resource allocation.
* Risk management.
* Policy approval.
## **Information Security Lead**
Responsible for:
* Security governance.
* Policy maintenance.
* Incident coordination.
* Risk monitoring.
* Security improvement initiatives.
## **Staff and Contractors**
Responsible for:
* Following security policies.
* Protecting information assets.
* Reporting security incidents.
* Maintaining secure working practices.
## **Third-Party Suppliers**
Responsible for:
* Protecting Academy information under contractual obligations.
* Maintaining appropriate security controls.
* Reporting security incidents affecting Academy data.
# **6. Information Classification**
Information shall be classified according to sensitivity.
## **Public**
Information approved for public release.
Examples:
* Marketing materials
* Public website content
## **Internal**
Information intended for internal use.
Examples:
* Internal procedures
* Operational documents
## **Confidential**
Information requiring protection from unauthorized disclosure.
Examples:
* Business plans
* Commercial agreements
* Staff records
## **Restricted**
Highly sensitive information requiring enhanced protection.
Examples:
* Student records
* Safeguarding reports
* Assessment data
* Personal data
* Security credentials
# **7. Access Control**
Access to systems and information shall be as follows:
* Authorized.
* Role-based.
* Reviewed periodically.
* Removed promptly when no longer required.
The Academy will apply the principle of least privilege whenever access is granted.
Users shall only access information necessary to perform their duties.
# **8. Authentication and Password Security**
Users must:
* Maintain strong passwords.
* Keep credentials confidential.
* Use multi-factor authentication where available.
* Avoid password sharing.
* Report suspected credential compromise immediately.
Shared accounts should be avoided unless operationally required and formally approved.
# **9. Acceptable Use of Systems**
Company systems must be used:
* Lawfully.
* Responsibly.
* Professionally.
Users must not:
* Circumvent security controls.
* Install unauthorized software.
* Access prohibited content.
* Use systems for illegal activities.
* Share sensitive information without authorization.
# **10. Remote Working and Cloud Services**
When accessing Academy systems remotely, users must:
* Use approved devices where possible.
* Maintain device security.
* Protect login credentials.
* Avoid accessing sensitive information on unsecured public networks.
Approved cloud platforms may be used only in accordance with Academy policies.
# **11. Data Protection**
Personal data shall be processed in accordance with the following:
* Applicable data protection legislation.
* The Academy Privacy Policy.
* Data Processing Agreements.
* Data Retention Schedules.
Access to personal data shall be limited to authorized personnel.
# **12. Safeguarding Information**
Safeguarding records requires authorized enhanced protection.
Such information shall:
* Be restricted to authorised personnel.
* Be stored securely.
* Be shared only when necessary.
* Be handled confidentially.
Safeguarding concerns shall always be prioritized appropriately.
# **13. Security Monitoring**
The Academy may monitor systems, networks, and services to:
* Detect security threats.
* Investigate incidents.
* Protect information assets.
* Maintain service integrity.
Monitoring activities shall be conducted lawfully and proportionately.
# **14. Incident Management**
All actual or suspected security incidents must be reported immediately.
Examples include:
* Data breaches
* Unauthorised access
* Malware infections
* Credential compromise
* Loss of devices
* System misuse
Incidents shall be managed in accordance with the Security & Incident Response Policy.
# **15. Business Continuity**
Squid Academy will maintain appropriate measures to support service continuity and recovery following the:
* Cyber incidents
* System failures
* Service outages
* Infrastructure disruptions
Business continuity and disaster recovery arrangements shall be reviewed periodically.
# **16. Security Awareness**
Personnel shall receive appropriate security awareness training covering:
* Information security responsibilities
* Data protection
* Password security
* Phishing awareness
* Safeguarding considerations
* Incident reporting
Training may be refreshed periodically.
# **17. Third-Party Management**
Where third parties process or access Academy information:
* Appropriate due diligence shall be performed.
* Security expectations shall be documented.
* Contractual protections shall be implemented where required.
* Risks shall be reviewed periodically.
# **18. Compliance**
Failure to comply with this policy may result in:
* Removal of access privileges
* Disciplinary action
* Contractual remedies
* Legal action where appropriate
The Academy reserves the right to investigate potential violations.
# **19. Policy Review**
This policy shall be reviewed annually or whenever
* Significant security changes occur.
* Legal requirements change.
* New technologies are introduced.
* Material incidents occur.
# Malaysia Compliance Addendum
Source: https://docs.squid.gg/platform/untitled-page-4
**Applicable Jurisdiction:** Malaysia
**Related Documents:**
* Privacy Policy
* Data Processing Addendum
* Information Security Policy
* Data Retention Schedule
* Terms & Conditions
# **1. Purpose**
This Malaysia Compliance Addendum supplements Squid Academy's global policies and explains how Squid Academy manages personal data and educational services in accordance with applicable Malaysian legal requirements.
# **2. Applicable Legislation**
Squid Academy seeks to comply with the following:
* Personal Data Protection Act 2010 (PDPA)
* Applicable consumer protection legislation
* Relevant educational regulations where applicable
# **3. Personal Data Collection**
Squid Academy may collect personal data, including:
* Student information
* Parent or guardian information
* Contact details
* Educational records
* Assessment records
* Technical platform data
Personal data will only be collected for legitimate educational, operational, safeguarding, or legal purposes.
# **4. Consent**
Where required, consent will be obtained from:
* Learners
* Parents or guardians
* Schools or educational partners
Consent may be obtained through enrolment forms, platform registration, parental consent forms, or contractual agreements.
# **5. Data Access and Correction**
Individuals may request:
* Access to personal data
* Correction of inaccurate information
* Clarification regarding data processing activities
# **6. International Data Transfers**
Squid Academy may use cloud-based systems and international service providers.
Appropriate safeguards will be implemented to protect personal data when transferred internationally.
# **7. Student Safeguarding**
Where services are provided to minors, the Academy will apply its Safeguarding Policy, Parental Consent Procedures, and Online Safety Framework.
# **8. Complaints**
Individuals may raise concerns through the Academy's Grievance Redressal Procedure and Privacy Request mechanisms.
If you have any questions, comments, or concerns, please feel free to reach out to us at [support@squid.academy](mailto:support@squid.academy)
# Your Privacy Rights
Source: https://docs.squid.gg/platform/your-privacy-rights
…you can submit a request here or email [privacy@squid.gg](mailto:privacy@squid.gg). Description of your new file.
This page explains how you (or your organization) can exercise your rights over the personal data processed by Squid Academy.
It reflects the rights described in Section 11 of our [Privacy Policy](https://docs.google.com/document/u/6/d/1pJDPGOXueYFzt81Wzzv25-04_nuPi3seArJJkqm_d_4/edit) and Section 7 of our [Data Processing Addendum](https://docs.google.com/document/u/6/d/1IXgzc8vsrTkkPtnwghZ2pHGoR_ZyCeKdo2db0m7dNsw/edit).
## **1. Who Should Submit a Request?**
### **Public Users**
If you created your own Squid Academy account directly with us (not through a school, university, or esports center), you may submit a request to us directly.
### **Organization-Provisioned Users**
If your account was created for you by an organization (such as a school, university, or esports center):
* Your organization is the data controller for your personal data.
* We process that data on their behalf.
* You should submit your request directly to your organization.\
We will assist your organization in responding, in accordance with our DPA.
## **2. Rights You May Have**
Depending on your location, applicable privacy laws may give you the right to:
* **Access** – Ask for a copy of the personal data we hold about you.
* **Correction** – Ask us to correct inaccurate or incomplete data.
* **Deletion** – Ask us to delete your personal data.
* **Portability** – Ask for a copy of your data in a machine-readable format.
* **Restriction** – Ask us to limit how your data is processed.
* **Objection** – Object to certain types of processing (e.g., marketing, profiling).
* **Appeal** – If we decline your request, you may appeal our decision.
We will not discriminate against you for exercising your rights.
## **3. How to Submit a Request**
### **Online Form (Recommended)**
You can submit a request through our online form: [Submit a Privacy Request](https://forms.gle/aB3DRg55ojrYoKBL7)
### **Email**
Alternatively, email [privacy@squid.gg](mailto:privacy@squid.gg) with:
* Your full name and contact details.
* Whether you are a public user or organization-provisioned user.
* Details of your request.
* Any supporting documents to verify your identity.
## **4. Verifying Your Identity**
We must verify your identity before fulfilling certain requests to protect your privacy and security.
We may:
* Ask for additional information to confirm your identity.
* Contact your organization (if applicable) to confirm your status.
## **5. Fees**
We do not charge a fee for processing your request, unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act.
## **6. How Long It Takes**
We aim to respond:
* Within 30 days under GDPR/UK GDPR.
* EEA 1 month; US states 45 days + permissible extension
* Within the timelines set by applicable law in your region.
* If we need more time, we’ll let you know and explain why.
## **7. Appeals**
If we decline your request:
* You can appeal by replying to our decision email and stating the reasons you believe the decision was incorrect.
* We will review your appeal and respond within the time required by law.
## **8. Contact**
For questions about this process, contact: [privacy@squid.gg](mailto:privacy@squid.gg)
*PS - If you are a parent or guardian seeking to give or revoke consent for your child’s use of Squid Academy, please see our *[*Parental Consent Guide*](https://docs.google.com/document/u/6/d/16g2ikC0mSpiT5Lhsh_yCTMe8tVgxJUPPmHqvQdloq8Y/edit)* for instructions.*
# Squid Academy Accreditation Framework
Source: https://docs.squid.gg/squid-academy-accreditation-framework
## **A Multi-Layered Quality Assurance Model**
### **Overview**
Squid Academy has adopted a multi-layered accreditation and quality assurance framework designed to validate three critical areas of educational delivery:
1. The Quality of the Curriculum
2. The Achievement of the Learner
3. The Quality of the Institution
Rather than relying on a single accreditation or certification, Squid Academy's framework combines internationally recognized organizations that evaluate different aspects of educational provision.
This approach provides students, parents, schools, colleges, and educational partners with confidence that quality exists throughout the entire learning experience.
# **The Three-Layer Framework**
## **Layer 1 – Curriculum Quality**
### **Education Alliance Finland (EAF)**
**Key Question:** Is the curriculum educationally effective?
Education Alliance Finland independently evaluates educational programs against recognized learning science and pedagogical standards.
This layer focuses on:
* Learning Design
* Educational Effectiveness
* Learner Engagement
* Curriculum Structure
* Assessment Alignment
* Pedagogical Quality
The purpose of this layer is to ensure that programs are built on sound educational principles and support meaningful learning outcomes.
### **Outcome**
Independent validation that the curriculum is designed to teach effectively, not simply to engage learners.
## **Layer 2 – Learner Achievement**
### **AQA Unit Award Scheme (UAS)**
**Key Question:** What does the learner achieve?
The AQA Unit Award Scheme provides formal recognition for the successful completion of defined learning outcomes.
This layer focuses on:
* Skills Development
* Knowledge Acquisition
* Achievement Recognition
* Learner Progression
* Portfolio Building
* Continuous Certification
Students receive formal certification for completed units, allowing achievement to be recognized throughout their educational journey.
### **Outcome**
Learners build a portfolio of recognized achievements that evidence their skills and learning.
## **Layer 3 – Institutional Quality**
### **Cognia Accreditation**
**Key Question:** Is the organization delivering education credible and quality assured?
Cognia evaluates the institution as a whole, reviewing leadership, governance, quality assurance systems, learner support, and continuous improvement processes.
This layer focuses on:
* Organisational Effectiveness
* Governance
* Leadership
* Safeguarding
* Quality Assurance
* Continuous Improvement
Institutional accreditation provides assurance that educational quality is embedded throughout the organization.
### **Outcome**
Independent validation that the institution operates according to internationally recognized educational standards.
# **Why a Multi-Layered Approach Matters**
Many educational providers operate with only one form of accreditation.
For example:
* Some institutions hold institutional accreditation but do not certify learner achievement.
* Some programs offer certificates but have no independent curriculum review.
* Some curricula have been evaluated academically but are delivered through organizations with no external quality assurance.
The Squid Academy framework addresses all three areas simultaneously.
Each accreditation performs a different function, and together they create a comprehensive quality assurance model.
# **How the Framework Supports Students**
Students benefit from:
* High-quality learning experiences
* Clearly structured educational pathways
* Recognition of achievement
* Internationally credible certification
* Strong learner support systems
* Continuous programme improvement
The framework ensures that students receive value not only from what they learn but also from how that learning is delivered and recognized.
# **How the Framework Supports Schools and Partners**
Educational partners benefit from:
* Independent curriculum validation
* Recognised learner certification
* Organisational quality assurance
* Increased stakeholder confidence
* Stronger quality and compliance frameworks
* Reduced implementation risk
The framework allows schools and colleges to offer innovative esports and digital education programs within a structure that aligns with recognized educational standards.
# **Quality Assurance Philosophy**
Squid Academy believes that educational quality cannot be measured through a single accreditation alone.
True quality requires the following:
* Effective Curriculum Design
* Meaningful Learner Outcomes
* Strong Organisational Governance
The Accreditation Framework has therefore been designed to provide assurance across all three dimensions.
This approach supports transparency, accountability, continuous improvement, and long-term educational impact.
# **Framework Summary**
| **Layer** | **Focus** | **Accreditation Body** | **Purpose** |
| :-------- | :-------------------- | :------------------------------- | :----------------------------------------------------------- |
| Layer 1 | Curriculum Quality | Education Alliance Finland (EAF) | Validates educational design and pedagogy |
| Layer 2 | Learner Achievement | AQA Unit Award Scheme (UAS) | Recognises student achievement and skills |
| Layer 3 | Institutional Quality | Cognia | Validates organisational effectiveness and quality assurance |
Together, these layers provide a complete educational quality framework that supports learners, educators, partner institutions, and stakeholders across the Squid Academy ecosystem.
# **Accreditation Status**
| **Accreditation** | **Focus Area** | **Status** |
| :------------------------------- | :-------------------- | :---------- |
| Education Alliance Finland (EAF) | Curriculum Quality | Accredited |
| AQA Unit Award Scheme (UAS) | Learner Achievement | In Progress |
| Cognia | Institutional Quality | In Progress |
# **Conclusion**
The Squid Academy Accreditation Framework provides a comprehensive approach to educational quality assurance by independently validating the curriculum, recognizing learner achievement, and strengthening institutional credibility.
By combining internationally recognized quality standards across multiple dimensions, Squid Academy ensures that learners, educators, and partners can participate with confidence in programs that are designed, delivered, and recognized according to established educational best practices.
# English Language Support Framework
Source: https://docs.squid.gg/untitled-page
# **High School Programmes (CEFR A2–B1)**
### **Document Purpose**
This document outlines the English language support requirements and expectations for learners enrolled in Squid Academy High School programs.
The program has been designed to be accessible to students whose English language proficiency falls between **CEFR A2 (Elementary)** and **CEFR B1 (Intermediate)** levels. Learning materials, teaching methods, and assessments have been developed to support learners within this range while allowing them to develop both subject knowledge and English communication skills throughout their studies.
# **1. Common European Framework of Reference for Languages (CEFR)**
The Common European Framework of Reference for Languages (CEFR) is an internationally recognized standard used to assess language proficiency.
| **CEFR Level** | **Description** |
| :------------- | :----------------- |
| A1 | Beginner |
| A2 | Elementary |
| B1 | Intermediate |
| B2 | Upper Intermediate |
| C1 | Advanced |
| C2 | Proficient |
Squid Academy High School programs are designed for learners operating between **A2 and B1 proficiency levels**.
**2. Entry Requirements**
### **Minimum Recommended Entry Level**
**CEFR A2**
Students should be able to:
* Understand basic spoken and written English.
* Follow simple classroom instructions.
* Read short educational texts.
* Participate in structured classroom activities.
* Communicate simple ideas and responses.
### **Ideal Entry Level**
**CEFR B1**
Students at this level can generally:
* Understand the main points of lessons delivered in English.
* Participate actively in group discussions.
* Complete written assignments independently.
* Engage confidently with program materials and assessments.
# **3. Learner Language Expectations**
## **A2 Learners**
Learners at A2 level are expected to:
* Understand common expressions and vocabulary related to everyday situations.
* Follow structured lesson delivery with teacher support.
* Read and interpret short texts.
* Complete guided worksheets and activities.
* Contribute to discussions using simple language.
## **B1 Learners**
Learners at the B1 level are expected to:
* Understand clear explanations and classroom instruction.
* Engage in collaborative learning activities.
* Read program materials independently.
* Produce short written responses and reflections.
* Present opinions and ideas using appropriate vocabulary.
# **4. English Language Support Measures**
To ensure accessibility and learner success, the program incorporates a range of language support strategies.
### **Simplified Learning Materials**
* Clear and concise written content.
* Age-appropriate vocabulary.
* Structured lesson materials.
* Key terminology is explained throughout the learning resources.
### **Visual Learning Support**
* Diagrams and infographics.
* Screenshots and visual examples.
* Practical demonstrations and guided activities.
* Context-based learning through esports and business scenarios.
### **Instructor Support**
* Clarification of unfamiliar terminology.
* Guided classroom discussions.
* Additional explanations were required.
* Structured questioning and learner support.
### **Practical Learning Approach**
* Activity-based learning.
* Collaborative group tasks.
* Real-world esports and business applications.
* Interactive classroom participation.
# **5. Assessment Approach**
Assessment methods are designed to measure learner understanding and achievement of learning outcomes rather than advanced English language proficiency.
Assessment activities may include:
* Classroom participation.
* Group activities.
* Presentations.
* Worksheets and written tasks.
* Reflective learning activities.
* Project-based assignments.
Reasonable language support may be provided where appropriate, provided it does not compromise the integrity of the assessment.
# **6. Accessibility and Inclusion**
Squid Academy is committed to providing an inclusive learning environment for students from diverse linguistic and cultural backgrounds.
Program delivery is designed to:
* Support English language learners.
* Encourage confidence in communication.
* Promote participation regardless of native language.
* Develop both academic and employability skills.
* Provide progression opportunities into higher-level study.
Students below CEFR A2 may require additional English language support prior to enrollment or alongside program participation.
# **Program Language Profile**
**Programme Type:** High School Programs\
**Delivery Language:** English\
**English Support Level:** CEFR A2–B1\
**Target Age Group:** 14–18 Years\
**Learning Approach:** Guided, Practical, and Accessible\
**Progression Goal:** Development of subject knowledge, employability skills, and English communication confidence.
**Approved By:** Squid Academy Academic Team\
**Document Version:** 1.0\
**Review Cycle:** Annual
\\
# Org Admins
Source: https://docs.squid.gg/user-guides/org-admins
How Org Admins run the LMS—add teachers/students, create classes, assign modules/courses, and manage access.
## Overview
**Org Admins** run the LMS for a single **Organization** (e.g., a school, university, or LAN center). You create **Classes**, add **Teachers** and **Students**, assign **modules/courses**, and handle account access (including password resets). You also keep an eye on basic progress across classes.
**Organization** = your school or institution within Squid Academy.\
If you need additional orgs or quotas, contact your **Reseller** or **Partner**.
## Getting started
* Your account is assigned to your **Organization**.
* Log in to the **Admin Console** to manage users, classes, and settings.
## What you can do
* Add and manage **Teachers** and **Students**.
* Create and manage **Classes**.
* Assign **modules/courses** to each class (and unlock chapters as needed).
* Reset passwords and keep accounts up to date.
* Monitor basic progress across classes.
## How-to steps
### Add a Teacher
1. Go to **Account → Users → Create User**.
2. Enter details and set **Role = Teacher**.
3. (Optional) Add them to the appropriate **Classroom(s)**.
4. **Save** — they’ll receive an invite email (if enabled).
### Add a Student
1. Go to **Account → Users → Create User**.
2. Enter details and set **Role = Student**.
3. (Later) enroll them in the right **Classroom(s)**.
4. **Save** — they’ll receive an invite email (if enabled).
### Create a Class
1. Go to **Classes → Add Class**.
2. Name the class (e.g., “Esports 101 – G9”).
3. Assign **Teacher(s)**.
4. Select **modules/courses** and (optionally) unlock chapters.
5. Add **Students**.
6. **Save**.
### Edit a Class
1. Go to **Classes**, find the class → **Edit**.
2. Update teacher(s), modules/courses/chapters, or the student roster.
3. **Save**.
### Reset a password
1. Go to **Account → Users** (or **Teachers/Students**, depending on your view).
2. Open the user’s **Edit** screen and set a new password.
3. Confirm and share sign-in instructions with the user.
## FAQs
* **No classes shown.**\
Create your first class, then assign teachers and students.
* **Can I change course content?**\
You can toggle **modules/chapters** for a class, but you can’t edit lesson content itself.
* **A student left the organization.**\
Prefer **Deactivate** (if available) to preserve history instead of deleting.
* **Deleted a class by accident.**\
Contact your **Reseller/Partner** immediately. You can recreate the class; restoration of history may require admin support.
# Partners
Source: https://docs.squid.gg/user-guides/partners
How Partners oversee regions—create Resellers and Organizations, assign Org Admins, enable modules/courses, and monitor usage.
## Overview
**Partners** manage a region or portfolio of **organizations** and may appoint **Resellers** to manage a subset of those orgs. As a Partner you can create and manage **Organizations** (schools, universities, LAN centers), assign **Org Admins**, set quotas (max students/teachers/classes), enable **modules/courses**, and monitor usage. You can also create users (Org Admins, Teachers, Students) on an organization’s behalf when needed.
**Organization** = a school, university, LAN center, or similar entity under your management.\
**Reseller** = a partner you authorize to manage a subset of your organizations.
## Getting started
* Your **Partner** account is created for you (or your existing user is upgraded to Partner after approval).
* Log in to access the **Admin Console**, which typically includes:
* **Dashboard** — high-level stats across your region.
* **Partner Console** — manage **Resellers** and **Organizations**; view **Classes**, **Teachers**, **Students**.
* **Account → Users** — create users and assign roles (Reseller, Org Admin, Teacher, Student).
## What you can do
* Create and manage **Resellers**.
* Create and manage **Organizations** (schools, universities, LAN centers, etc.).
* Assign **Org Admins** to organizations.
* Control which **modules/courses** each organization can use.
* (Optional) Create users for an org (**Org Admins**, **Teachers**, **Students**).
* Monitor usage across resellers and organizations.
## How-to steps
### Create a Reseller
1. Go to **Account → Users → Create User**.
2. Enter details and set **Role = Reseller**.
3. Save — the Reseller receives login details by email.
### Create an Organization
1. Go to **Organizations → Create Organization**.
2. Enter the organization’s **Name** and upload a logo (optional).
3. Set license limits: **Max Students**, **Max Teachers** (and classes if applicable).
4. Assign one or more **Org Admins** (create the user first if needed).
5. Select the **modules/courses** the org can access.
6. Click **Submit**.
### Assign or add an Org Admin (later)
1. Go to **Organizations**, find the org → **Edit**.
2. In **Admins**, add the user (or create them under **Account → Users** with **Role = Org Admin**).
3. Save.
### Edit an Organization
1. Go to **Organizations**, find the org → **Edit**.
2. Update quotas, Org Admins, and available modules/courses (and chapters if applicable).
3. Click **Save**.
### (Optional) Create Teachers/Students for an org
1. Go to **Account → Users → Create User**.
2. Enter details, set **Role = Teacher** or **Student**, and assign the correct **Organization**.
3. (If Teacher) add them to the appropriate **Classroom(s)**.
4. Save and share credentials with the org as needed.
## Quick checks
* Use the **Dashboard** for totals (orgs/classes/teachers/students).\
Click any card (e.g., **Total Classes**) to jump to the detailed list.
## FAQs
* **Can I create another Partner?**\
No. Only platform owners can create Partner accounts.
* **An Org Admin can’t see their organization.**\
Open **Organizations → Edit** and ensure they’re assigned. Have them sign out and back in.
* **Where do I change modules/courses for an organization?**\
In **Organizations → Edit** under the modules/courses section for that org.
* **Delete vs. deactivate?**\
Prefer **Deactivate** (if available) to preserve history. **Delete** removes access and may archive data.
# Resellers
Source: https://docs.squid.gg/user-guides/resellers
How Resellers onboard and support organizations—create orgs, assign Org Admins, and help set up classes and users.
## Overview
Resellers manage a subset of **organizations** under a **Partner**. Your core jobs are to create **Organizations**, assign **Org Admins**, optionally help add **Teachers/Students** to get them started, and support day-to-day operations.
**Organization** = a school, university, LAN center, or similar entity you manage under a Partner.
## Getting started
* Your **Reseller** account is created by a **Partner**.
* Log in to the **Admin Console** — you’ll only see the organizations assigned to you.
## What you can do
* Create and manage **Organizations**.
* Create users and assign roles (e.g., **Org Admin**, **Teacher**, **Student**).
* (If needed) Help a new org by creating Teachers/Students and assigning them to classes to jump-start usage.
* Review usage across your organizations.
## How-to steps
### Create an Organization (school, university, LAN center, etc.)
1. Go to **Organizations → Create Organization**.
2. Enter the organization’s name and upload a logo (optional).
3. Set license limits: **Max Students** and **Max Teachers**.
4. Assign one or more **Org Admins** (create the user first if needed).
5. Select the **modules/courses** the org can access.
6. Click **Submit**.
### Create an Org Admin
1. Go to **Account → Users → Create User**.
2. Enter details and set **Role = Org Admin**.
3. Assign them to the correct **Organization**.
4. (Optional) If they will also teach, add them to a **Classroom**.
5. Save and share credentials with the org.
### Assist an Organization (add Teachers/Students)
1. Go to **Account → Users → Create User**.
2. Enter details, set **Role = Teacher** or **Student**, and assign to the correct **Organization**.
3. (If Teacher) Add them to the appropriate **Classroom(s)**.
4. Save (share credentials if needed).
## FAQs
* **I can’t create other Resellers.**\
Correct — only **Partners** can create or manage Resellers.
* **An Org Admin can’t see their organization.**\
In **Organizations → Edit**, make sure they’re assigned to that org. Have them sign out and back in.
* **Can we bulk-import rosters?**\
If bulk import isn’t available in your workspace, add users individually or ask your **Partner** to enable/import on your behalf.
# Students
Source: https://docs.squid.gg/user-guides/students
How Students use the LMS—find classes, complete lessons and assessments, and check scores.
## Overview
**Students** sign in to access their **Classes**, work through **modules/courses** and **chapters**, complete **assessments**, and view **scores/feedback**.
If you don’t see your class after signing in, ask your **Teacher** or **Org Admin** to enroll you in the correct class.
## Getting started
* Your account is created by your **school/organization**.
* After login, open **Classes** (or **My Classes**) to see the classes you’re enrolled in.
## What you can do
* Open your **Class** and work through **modules/courses** and their **chapters**.
* Watch videos, read materials, and complete activities/assessments.
* See **scores** and **teacher feedback** once graded.
* Ask your **Teacher** for help if something doesn’t load or you’re missing a class.
## How-to steps
### Join your class
1. Sign in and open **Classes** (or **My Classes**).
2. Click a **Class** to view its modules/courses and chapters.
3. If you don’t see your class, contact your **Teacher** or **Org Admin**.
### Complete a lesson
1. Open the next **chapter/lesson** in your class.
2. Follow all steps (watch/read/answer).
3. Click **Finish/Complete** at the end so your progress is recorded.
### Submit an assessment
1. Open the **assessment** in your class.
2. Follow the instructions (type answers, upload files, or answer MCQs).
3. Click **Submit**. If manual grading is required, wait for your teacher’s feedback.
### Check your score & feedback
1. Return to the **lesson/assessment** to see your result,\
**or** open your **Account/Progress** page for an overview.
2. If something looks wrong, ask your **Teacher** to review.
### Password help
* If you forget your password, use **Forgot Password** on the sign-in screen,\
or ask your **Teacher**/**Org Admin** to reset it for you.
## FAQs
* **I don’t see my class.**\
Ask your **Teacher** or **Org Admin** to enroll you in the correct class.
* **My progress didn’t save.**\
Re-open the lesson and make sure you clicked **Finish/Complete**, then refresh the page.
* **I submitted the wrong file.**\
Tell your **Teacher**; they can allow a re-submission if your school’s policy permits it.
* **I can’t log in.**\
Check your email/username and try **Forgot Password**. If it still fails, contact your **Teacher** or **Org Admin**.
# Teachers
Source: https://docs.squid.gg/user-guides/teachers
How Teachers manage classes—deliver lessons, unlock content, track progress, and grade assessments.
## Overview
**Teachers** run day-to-day learning inside their assigned **Classes**. You deliver lessons, pace content (unlock/lock chapters if allowed), monitor progress, and grade submissions. Depending on your school’s policy, you may also add students to your class.
Roster editing and chapter controls can be limited by your **Organization**. If you don’t see an option, ask your **Org Admin**.
## Getting started
* Your **Teacher** account is created by an **Org Admin**.
* After login, open **Classes** to see the classes you’ve been assigned.
## What you can do
* View your assigned **Classes** and class rosters.
* (If allowed) **Add students** to your class.
* **Unlock/lock chapters** to pace learning.
* **Review progress** and **grade** submissions requiring manual grading.
* Help students with sign-in and access questions.
## How-to steps
### Review your class
1. Go to **Classes** → open a class.
2. Review **Teacher(s)**, **Students**, and attached **modules/courses** (and chapters).
### Add a student to your class (if allowed)
1. **Classes** → open your class → **Edit**.
2. In **Students**, add the student.
* If the student isn’t listed, ask your **Org Admin** to create them (or confirm they aren’t already assigned to another class).
3. **Save**.
### Unlock / lock chapters (if enabled)
1. **Classes** → open your class → **Edit**.
2. Toggle chapter availability to control pacing.
3. **Save**.
### Grade assessments
1. Open **Grade Assessments** (from your menu or inside the class).
2. Select a submission → review work → enter score/feedback.
3. **Save/Submit** the grade and repeat as needed.
### Check progress
1. **Classes** → open a class → **Progress** (or **Roster/Progress** view).
2. Filter by student or chapter to see status and scores.
3. Follow up with students who are behind.
## FAQs
* **I don’t see my classes.**\
Ask your **Org Admin** to assign you to the correct classes.
* **I can’t edit rosters or chapters.**\
Your school may restrict these actions. Request changes from your **Org Admin**.
* **A student says a lesson didn’t “complete.”**\
Have them re-open the lesson and click **Finish/Complete**, then refresh. Confirm they’re using the correct account/email.
# User Manual
Source: https://docs.squid.gg/user-guides/tournament/untitled-page
Role-based tournament workflows, permissions, and lifecycle overview for Squid Tournament.
## Overview
Squid Tournament is a **web-based tournament management platform** designed to support both **public** and **organization-specific** competitions.
It enables administrators, organizers, teachers, and players to create, manage, and participate in tournaments using structured brackets, role-based access, and controlled match progression.
The platform prioritizes:
* Competitive integrity
* Clear role separation
* Scalable tournament workflows
It supports both **open public events** and **controlled institutional tournaments**.
***
## User Roles & Access Control
This section explains each role along with its **end-to-end operational flow**.
***
### Super Admin
**Scope:** System-wide authority across all public and organizational tournaments.
#### Capabilities
* Create **Public** and **Organizational** tournaments
* View and manage **all tournaments and teams**
* Full access to brackets, scoring, media, and announcements
#### Flow
1. Switch to **Super Admin**
2. Navigate to **Tournament**
3. View:
* All Tournaments (Public + Organizational)
* My Tournaments
4. Click **Create New Tournament**
5. Select:
* Tournament type (Public or Organizational)
* Game
6. Complete creation flow:
* Basics → Details → Settings → Bracket
7. Save as **Draft** or **Publish**
8. Manage tournament via:
* Overview
* Participants
* Bracket & scoring
* Media & Announcements
* Standings
#### Team Management
* Navigate to **Team**
* View all teams
* Create Public or Organizational teams
#### Visibility Rules
* Draft tournaments are visible **only to the creator**
* Published tournaments follow **role-based visibility**
***
### Organizer (Organization-Specific)
**Scope:** Tournaments and teams within a single organization.
#### Capabilities
* Create **Organization-only tournaments**
* Create and manage **Organization teams**
* Invite organization teams
* Manage brackets, match results, media, and announcements
#### Restrictions
* Cannot create Public tournaments
* Cannot interact with users or teams outside their organization
#### Flow
1. Switch to **Organizer**
2. Navigate to **Tournament**
3. View organization-specific tournaments only
4. Click **Create New Tournament**
* Organization auto-selected
* Public option disabled
5. Complete creation flow
6. Save as Draft or Publish
7. After publishing:
* Invite organization teams
* Manage matches and scores (if permitted)
***
### Teacher
**Scope:** Same functional flow as Organizer, with stricter ownership rules.
#### Flow
1. Switch to **Teacher**
2. Navigate to **Tournament**
3. Create an organization-specific tournament
4. Complete the full creation flow
5. Save as Draft or Publish
6. Manage tournament lifecycle and matches
#### Ownership Rules
* Tournaments created by a Teacher:
* Can be edited **only by the same Teacher**
* Organization Admins / Organizers:
* **Cannot edit** Teacher-created tournaments
* Draft tournaments created by a Teacher:
* Visible **only to that Teacher**
***
### Player
**Scope:** Participation-only access.
#### Capabilities
* View tournaments they are participating in
* Access:
* Overview
* Bracket (read-only)
* Standings
* Media
* Announcements
* Chat
#### Restrictions
* Cannot create or edit tournaments
* Cannot accept tournament invitations
* Cannot manage teams
#### Flow
1. Switch to **Player**
2. Navigate to **Tournament**
3. View tournaments where the player is a participant
4. Open tournament detail page
5. Interact via available sections and chat
***
### Team Captain
Each team has **one designated Captain**.
#### Responsibilities
* Receives tournament invitations
* Accepts or declines invitations on behalf of the team
* Selects team members when joining a tournament
#### Flow
1. Receive invitation notification
2. Open invitation
3. Accept or decline
4. Select participating team members
5. Confirm team participation
***
### Public Player
**Scope:** Public tournaments only.
#### Capabilities
* View all **Published Public Tournaments**
* Participate through a Public Team
* View:
* Overview
* Bracket
* Standings
* Media
* Announcements
* Chat
* Create **one Public Team** (if not already part of a team)
#### Restrictions
* Cannot access Organizational tournaments
* Cannot view Organizational teams
* Cannot accept invitations directly
* Cannot create multiple teams
#### Flow
1. Login as **Public Player**
2. Navigate to **Tournament**
3. View published Public Tournaments
4. If not part of a team:
* Navigate to **Team**
* Create a Public Team
* Select Public Players only
* Assign a Team Captain
5. Organizer invites the Public Team
6. Team Captain accepts the invitation
7. Player receives join confirmation
8. Access tournament details and chat
***
### Partner Role (FYI)
> The Partner role operates at the **same permission level as Super Admin**.
* Full system-wide access
* No functional differences in tournament or team workflows
* Exists for **hierarchy, ownership, and management purposes only**
***
## Tournament Types
### Public Tournament
* Created by Super Admin
* Visible to Public Players **after publishing**
* Draft state:
* Visible only to the creator
### Organizational Tournament
* Created by Super Admin, Organizer, or Teacher
* Visible only within the selected organization
* Draft state:
* Visible only to the creator
***
## Tournament Creation Flow
Tournament creation follows a **multi-step wizard**.
### Game Selection
* Select one available game
***
### Basics
* Tournament Name *(required)*
* Start Date & Time *(future dates only)*
* Description
***
### Details
* Contact method *(required)*
* Platform selection
* Contact details
* Critical rules
* General rules
* Prizes
* Schedule
***
### Settings
* Number of teams
* Players per team
* Check-in requirement
* Check-in start time
* Match score reporting:
* Organizer or Player
* Screenshot requirement (Yes / No)
***
### Bracket Configuration
Supported formats:
* Single Elimination
* Double Elimination
**Best-of options:** 1, 3, 5, 7, 11
**Odd team count:**\
If the number of teams is odd, one team receives a bye and advances automatically.
***
## Tournament Lifecycle
States:
* Draft
* Published
* Started
**Rules**
* Draft tournaments cannot send invitations
* Brackets are locked once the tournament starts
***
## Tournament Detail Sections
Each tournament includes:
* Overview
* Participants
* Bracket
* Standings
* Media
* Announcements
* Chat
* Invite *(state-restricted)*
* Edit *(state-restricted)*
***
## Team Management
### Public Teams
* Created by Super Admin
* Public Players only
### Organizational Teams
* Created by Super Admin, Organizer, or Teacher
* Linked to a single organization
* Organization Players only
**Team creation requires:**
* Team name
* Team image
* Team Captain (mandatory)
***
## Invitations & Notifications
* Tournament invitations are sent **only to Team Captains**
* Players receive confirmation once the Captain accepts
* Invitations are disabled for Draft tournaments
***
## Match Scoring & Progression
* Best-of rules enforced
* No tie states allowed
* Automatic match progression
* Bye logic applied when team count is odd
***
## Data Integrity & Validation Rules
* Minimum **4 teams** required
* Past dates are blocked across create/edit flows
* Role-based access enforced across all modules
* Brackets are immutable once the tournament starts
***
## Summary
Squid Tournament provides a **robust, role-driven tournament ecosystem** suitable for both public competitions and controlled organizational events. Its structured workflows, strict permission handling, and flexible bracket configurations ensure fairness, scalability, and operational clarity.