School Approval Pack

Everything your school needs to say yes.

A procurement-ready pack for IT managers, Data Protection Officers, safeguarding leads and school leadership evaluating ATL Portfolio. Covers GDPR, data protection, security, safeguarding and IT requirements in plain language.

Last updated: July 2026

Quick actions for IT & DPO review

Send this pack to your IT manager, request a DPA, or book a call.

Disclaimer: This document supports school due diligence and does not replace the school's own legal, data protection or procurement review.
Executive Summary

ATL Portfolio is a purpose-built digital portfolio platform for IB World Schools (PYP, MYP and DP). It helps students document evidence of their Approaches to Learning (ATL) skills, and supports teachers and coordinators in assessing and tracking skill development over time.

Who it is for: Students aged 5–18 enrolled in IB programmes; teachers and coordinators; school administrators; and IB programme coordinators.

Educational purpose: To support IB ATL skills development through structured reflection, evidence collection, teacher feedback and progress reporting — aligned to the IB framework.

Benefits to schools: A single, secure home for ATL evidence; reduced administrative burden through automated reporting; school-isolated data with role-based access; and accreditation-ready evidence aligned to IB and CIS frameworks.

Quick Facts
ProductATL Portfolio — IB Approaches to Learning portfolio and assessment platform
PlatformWeb-based SaaS (no install required); hosted on the Base44 platform
Intended usersStudents (PYP, MYP, DP), teachers, coordinators, school administrators
AuthenticationEmail-based sign-in with school email domain verification; role-based access
Supported devicesDesktop, laptop, tablet, smartphone (responsive web application)
Browser supportCurrent versions of Chrome, Edge, Safari and Firefox; JavaScript enabled
HostingBase44 platform on AWS-backed infrastructure (Supabase), hosted in the United Kingdom
EncryptionHTTPS / TLS in transit; encryption at rest in cloud storage
GDPR complianceUK GDPR, EU GDPR and Swiss FADP aligned; DPA available on request
Student data ownershipSchools own their data; ATL Portfolio acts as processor
Data retentionActive subscription duration; 30-day deletion window; backups 30 days
Contact informationprivacy@atlportfolio.com
Privacy Highlights
  • Student privacy first — all portfolios are private by default and never publicly visible.
  • Schools own their data — ATL Portfolio acts as a processor on behalf of the school.
  • No advertising — no advertising is displayed to any user.
  • No selling of user data — student and staff data is never sold to third parties.
  • Minimal personal data — only data necessary for educational use is collected.
  • Privacy by design — role-based access and school isolation are enforced at the database layer.
  • No home addresses, phone numbers or national ID numbers.
  • No biometric data, no financial data from students or parents.
  • No marketing tracking cookies or advertising pixels.
  • Student data is not used to train public AI models.
Security Highlights
  • Secure authentication — email-based sign-in with session token expiry.
  • Role-based permissions — students, teachers, coordinators, admins and superusers.
  • Encryption in transit — all traffic is served over HTTPS / TLS.
  • Encryption at rest — data and file uploads are encrypted in cloud storage.
  • Access controls — row-level security (RLS) enforced at the database layer.
  • Principle of least privilege — users see only the data their role requires.
  • School data isolation — every record is tagged with a school identifier; no cross-school access.
  • Domain-based access — only users with a verified school email domain reach school data.
Secure backups and disaster recovery are handled by the underlying hosted platform. Where a specific capability is not yet independently verified, we describe it as a planned enhancement rather than a confirmed feature.
GDPR Compliance

ATL Portfolio is designed to align with the UK GDPR, EU GDPR and the Swiss Federal Act on Data Protection (FADP), recognising that many international schools operate in Switzerland.

UK GDPR

Lawful basis, data subject rights and breach notification (ICO).

EU GDPR

Articles 5–6 principles, Article 15–20 rights, Article 28 DPA.

Swiss FADP

Principles of proportionality, transparency and data subject rights.

International transfers

Data stored in the United Kingdom; appropriate safeguards for any transfers.

  • Data minimisation — only data necessary for ATL assessment is collected.
  • Purpose limitation — data is used only for educational portfolio and assessment purposes.
  • Storage limitation — data is retained for the subscription duration plus a defined grace period.
  • Lawful basis — legitimate educational interest and performance of the school contract.
  • Subject Access Requests — handled within 30 days (GDPR Article 15).
  • Right to erasure — deletion or anonymisation within 30 days of request.
  • Data portability — schools can request export of their data in a portable format.
  • Breach notification — schools notified within 72 hours of any confirmed breach affecting their data.
Safeguarding

ATL Portfolio is designed with safeguarding in mind. The platform provides a teacher-controlled, moderated educational environment:

  • Teacher-controlled environment — teachers manage assessment and feedback for their assigned students.
  • Role-based access — students see only their own data; teachers see only assigned students.
  • No public student profiles — portfolios are private and not indexed or searchable on the internet.
  • No unnecessary sharing — no direct messaging between students and external parties.
  • Age-appropriate design — minimal data collection; no profiling or advertising.
  • Secure authentication — school email domain verification before access is granted.
  • Moderated environment — teacher feedback and assessment within a closed school context.
  • Safeguarding by design — media uploads stored in private, access-controlled storage.
Schools are responsible for obtaining appropriate parental or guardian consent before creating student accounts, in accordance with applicable law (including COPPA, UK GDPR age-appropriate design code, and local requirements).
IT Requirements
  • Supported browsers: Current versions of Chrome, Edge, Safari and Firefox.
  • Supported devices: Any device with a modern web browser — desktop, laptop, tablet, smartphone.
  • Network requirements: Standard internet access; HTTPS on port 443. No special firewall rules or VPN required.
  • Authentication: Email-based sign-in; school email domain used for access control. No on-premise directory integration required.
  • Cookies: Essential session and authentication cookies only. See our Cookie Policy for details.
  • Storage requirements: No local storage required; all data held securely in the cloud. Student evidence file uploads are stored in access-controlled cloud storage.
Email whitelisting (required): School mail filters frequently block or quarantine messages from atlportfolio.com — including password resets, user invitations, notifications and support replies. Your IT department must whitelist the atlportfolio.com domain (sender and SPF/DKIM) so that emails reach staff and student inboxes. Without this, users may not receive password-reset emails and be unable to access the platform or the native app.
Native iOS app & Google sign-in: The native iOS app uses email + password sign-in. Users who first signed in with Google on the web do not yet have a password, so before they can use the native app they must set one via the platform's password-reset flow: open the web login page, choose Forgot password, enter their email, then follow the emailed one-time code (OTP) to set a new password. Google sign-in on the web continues to work alongside the new password.
Single sign-on (SSO) and directory synchronisation are planned future enhancements, not currently available. We will update this pack when they are released.
Procurement Checklist

Use this checklist when reviewing ATL Portfolio for school approval. The page is designed to print cleanly to PDF using your browser's print function.

  • Educational purpose is clearly documented and proportionate
  • Data minimisation: only data needed for ATL assessment is collected
  • Privacy Policy and GDPR information are publicly available
  • Data retention period is stated and documented
  • Data deletion process is available on request
  • Security measures (encryption, access control) are explained
  • School data is isolated from other schools at the database level
  • User roles and access levels are clearly defined
  • Sub-processors are listed and disclosed
  • A Data Processing Agreement (DPA) is available on request
  • Subject Access Request and erasure processes are documented
  • Breach notification commitment (within 72 hours) is stated
  • Contact route for compliance questions is available
  • No advertising, no sale of student data, no profiling

Questions about compliance?

Our data protection team is ready to help IT managers, DPOs and procurement leads review ATL Portfolio for your school.