A coastline at dusk seen from a wooded ridge.
Trust & data

Leaving is a feature,
not a support ticket.

Children’s records deserve a straight answer to four questions: where the data lives, who can read it, what happens the day you leave, and what we have not finished. All four are below, including the last one.

In practice

Six answers you can check yourself

Someone working at a laptop outdoors.
Documents

A child’s passport scan stays in private storage

Every authorised open mints a signed link that expires in ten minutes. Authorised removal deletes the record and stored bytes.

Two colleagues looking at a laptop together.
Permissions

Per tenant, role and guarded operation

Ariadne requires authenticated organisation membership; tool actions still pass their own permission, scope and approval checks.

Someone taking notes beside a laptop.
The log

Append-only, enforced by a trigger

Guarded writes and designated sensitive reads append receipts. Update and delete are blocked by database triggers.

A student working under a tree.
Consent

Granular, timestamped, withdrawable

One live consent per combination. Withdrawal is a timestamp, never a deletion, and guardianship is recorded before consent is asked for.

Someone on the phone by the water.
Break-glass

Emergency access costs a sentence

It exists, expires in an hour, and asks for your reason — which goes into the log with your name on it.

Someone working on a bench in the sun.
Leaving

Portable tables, readable without us

At any time, on any plan, in any billing state. Every table must be present, uncapped and readable before closure can be scheduled.

ResidencyConfirm the contract
DocumentsPrivate, signed access
PermissionsPer field, per role
The logAppend-only
ConsentWithdrawable, never deleted
LeavingPortable tables, readable without us
ResidencyConfirm the contract
DocumentsPrivate, signed access
PermissionsPer field, per role
The logAppend-only
ConsentWithdrawable, never deleted
LeavingPortable tables, readable without us
The logAppend-only
ConsentWithdrawable, never deleted
LeavingPortable tables, readable without us
ResidencyConfirm the contract
DocumentsPrivate, signed access
PermissionsPer field, per role
The logAppend-only
ConsentWithdrawable, never deleted
LeavingPortable tables, readable without us
ResidencyConfirm the contract
DocumentsPrivate, signed access
PermissionsPer field, per role
Hills above the coast in evening light.
The four answers

A private store and short-lived access.

Read paths to a document
4
And you can count them
Signed link lifetime
10 min
Every open mints a new one
Authorised removal
2
Record and stored bytes
Residency

Confirmed before it becomes a promise

TermWhat must be agreedStatus
Processing regionApproved location and data categories Confirm in contract
MigrationScope, interruption and retention Assessed per request
Sub-processorsApproved list and change terms Confirm in contract

The product does not promise self-service region selection, an annual migration interval or a universal notice period. Audecius must confirm the approved terms for the organisation before signing.

A child’s passport scan stays in private storage

The document bucket is private. Authorised access is resolved against the current student and organisation relationship rather than a permanently public object address.

Every open mints a signed link that expires in ten minutes. Four policy paths cover the student, staff of the owning organisation, the coordinator on the student’s placement and the designated partner path.

Authorised staff can remove a document. The guarded operation deletes the record first and then its stored bytes; a cleanup worker handles a leftover private object if the second step is interrupted.

The first segment of every object name is the subject of the file — the only part of a filename a policy can trust, since the rest is chosen by whoever uploaded it.

Document · passport · Lena V.
Who may read this
The student herself
Staff of the owning organisation
Her coordinator, on her own placement
Everyone else — named in no policy
…/lena-vermeulen/passport-2026.pdf?sig=… expires 14:58
Removal is guarded. Authorised staff remove the record and stored bytes together.
Who can read it

Per tenant, role and guarded operation

Permissions are per field

Medical and allergy detail, contact details, academic records and incident reports can have different readers. Authorised administrators adjust visibility; server-side policies still govern sensitive operations.

Ariadne has explicit boundaries

Chat requires authenticated organisation membership. Tool actions separately enforce tenant scope, permission, consequence class and approval before they can write.

Emergency access costs a sentence

Break-glass exists, expires in an hour, and asks for your reason — which goes into the log with your name on it.

Someone taking notes beside a laptop.
“A log you can edit is a log nobody should have trusted.”

Guarded changes and designated sensitive reads leave a receipt.

The log

Append-only, enforced by a trigger rather than a role

Actor, action, entity and timestamp are recorded for guarded writes and designated sensitive reads. Audit rows are append-only: update and delete are blocked by database triggers. The page does not claim that every read or every denial is captured until that coverage is evidenced.

Consent

Granular, timestamped, withdrawable

Granted for a subject, by a grantor, for a kind, in a jurisdiction — with its evidence, and one live consent per combination at a time.

Withdrawal is a timestamp, never a deletion. The history of what was agreed and when survives the withdrawal.

Guardianship is recorded before consent is asked for, not inferred from it afterwards. Why can this adult read this child’s file must always have an answer.

The jurisdiction decides the age threshold, not us. A student below it cannot finish signing up alone; the account is created and held, and nothing personal is stored while it is held.

Two-factor cannot be switched off for any role that can open a minor’s record.

Someone smiling on the phone by the water.
“The organisation loses access. The student does not.”

What no lock-in has to mean to be worth saying.

The day you leave

Portable data tables, readable without us

1

Ask for it

At any time, on any plan, in any billing state — including thirty days past due.

2

Get the operational tables

People, placements, the document register, incidents, support history, broadcasts and the family ledger as CSV files, plus a machine-readable manifest. Document bytes are not copied into this browser archive and must be retrieved separately.

3

Close, if you want

A fresh receipt for every offered table is required first; capped or refused files do not count. Active students, placements, safety cases, support work, connected apps and billing all block closure.

4

Change your mind

Closure is scheduled, not deletion. There are thirty days to cancel, then the server checks every blocker again. People keep their accounts and the organisation’s historical records remain retained.

Ask us the hard question

If a specific certification, clause or date decides your purchase, ask before you sign. You will get the real answer, in writing.