The vendor questions: what to ask an edtech company directly
A privacy policy is a lawyered artifact: it tells you the outer boundary of what a company may do, in language optimized to keep options open. The conversation with an actual human — sales rep, founder, support — leaks different information: what they actually do, what they don't know, and how the company thinks. The craft is asking questions whose honest answers are short and whose evasive answers are audible.
The questions, and what each one tests
- "What personal information do you hold about a student, exhaustively? List the fields." The inventory question. A good answer is a short list produced quickly; a bad answer is "only what's needed to provide the service" — that's a purpose, not an inventory, and the deflection is the data point. (Ours fits in a sentence, which is why we ask everyone to ask it.)
- "What happens, step by step, when a teacher forgets their password?" The structural probe from the zero-PII page: recovery flows reveal what identifiers really exist. "We email a reset link" from a company claiming minimal data collection has just enumerated an email database.
- "Which third parties receive any data from inside your product — analytics, ads, crash reporting, anything?" Then verify (below). "None" is checkable; a list is disclosure; "our trusted partners" is the tracker problem wearing a suit.
- "Where is the data hosted, and in what country?" For Australian non-government schools this is the APP 8 offshore question; for government schools it's the state transborder principle, framed more sharply (Victoria's IPP 9). Either way, any vendor should answer in one sentence with a region name.
- "When a school leaves, what is deleted, when, and what survives — backups, logs, derived data included?" The deletion-in-practice question; honest answers mention backup retention windows, because real deletion has them.
- "Has your product had a breach or security incident? What happened?" Every mature vendor has an honest answer ("no known breaches; here's how we'd notify you" at minimum). Watch for the company that treats the question as hostile — breach handling is where privacy promises get tested for real.
- "What does your business model pay for this product — and if it's not our fees, what is it?" The conflict question. Free products have costs; a vendor who can't name theirs has named it.
- "Can we see a completed ST4S assessment?" (Australia): the Safer Technologies for Schools assessment is the sector's shared due-diligence instrument; "what's ST4S?" from a vendor selling to Australian schools is itself an answer.
- "Do you train, or license others to train, AI models on student data or student-created content?" The question that didn't exist five years ago and now must be asked explicitly — policy silence here is not a no.
The checks that need no trust
- Open devtools on the product (and its marketing pages): the network tab lists every third-party request — trackers can't hide from it. Five minutes, no permission needed.
- Do the sign-up with a scratch account: every field the form demands is data they chose to require; compare against their answer to question 1.
- Read the deletion clause, then the retention clause — the distance between them is the real deletion policy.
- Check the age gate against how it actually behaves.
What this doesn't replace
The paperwork still matters — the policy questions, contracts, your jurisdiction's process (procurement guide). The conversation and the checks are the triangulation: when the sales answer, the policy text, and the network tab agree, you've learned something durable about the vendor; when they diverge, you've learned more.
References
- eSafety Commissioner / ST4S (Education Services Australia) — the Australian shared-assessment infrastructure.
- Human Rights Watch (2022). "How Dare They Peep into My Private Life?" — why verification-not-trust is the required posture (the audit findings the sector earned).
- US Department of Education, PTAC — vendor-evaluation guidance (the US analogue tradition).
© Glu IO Pty. Ltd. — Wiz Kids (wiz.kids). Link freely; republication requires permission — see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.