🧙 Wiz Kids
LearnEdTech Privacy & Procurement

The vendor questions: what to ask an edtech company directly

Position note: we are a vendor, publishing the questions we'd want asked of us — the same acknowledged stake as everything in this pillar. The companion page, reading privacy policies, covers the eleven questions to run against the document; this one covers the live conversation and the checks that need no trust at all.

A privacy policy is a lawyered artifact: it tells you the outer boundary of what a company may do, in language optimized to keep options open. The conversation with an actual human — sales rep, founder, support — leaks different information: what they actually do, what they don't know, and how the company thinks. The craft is asking questions whose honest answers are short and whose evasive answers are audible.

The questions, and what each one tests

  1. "What personal information do you hold about a student, exhaustively? List the fields." The inventory question. A good answer is a short list produced quickly; a bad answer is "only what's needed to provide the service" — that's a purpose, not an inventory, and the deflection is the data point. (Ours fits in a sentence, which is why we ask everyone to ask it.)
  2. "What happens, step by step, when a teacher forgets their password?" The structural probe from the zero-PII page: recovery flows reveal what identifiers really exist. "We email a reset link" from a company claiming minimal data collection has just enumerated an email database.
  3. "Which third parties receive any data from inside your product — analytics, ads, crash reporting, anything?" Then verify (below). "None" is checkable; a list is disclosure; "our trusted partners" is the tracker problem wearing a suit.
  4. "Where is the data hosted, and in what country?" For Australian non-government schools this is the APP 8 offshore question; for government schools it's the state transborder principle, framed more sharply (Victoria's IPP 9). Either way, any vendor should answer in one sentence with a region name.
  5. "When a school leaves, what is deleted, when, and what survives — backups, logs, derived data included?" The deletion-in-practice question; honest answers mention backup retention windows, because real deletion has them.
  6. "Has your product had a breach or security incident? What happened?" Every mature vendor has an honest answer ("no known breaches; here's how we'd notify you" at minimum). Watch for the company that treats the question as hostile — breach handling is where privacy promises get tested for real.
  7. "What does your business model pay for this product — and if it's not our fees, what is it?" The conflict question. Free products have costs; a vendor who can't name theirs has named it.
  8. "Can we see a completed ST4S assessment?" (Australia): the Safer Technologies for Schools assessment is the sector's shared due-diligence instrument; "what's ST4S?" from a vendor selling to Australian schools is itself an answer.
  9. "Do you train, or license others to train, AI models on student data or student-created content?" The question that didn't exist five years ago and now must be asked explicitly — policy silence here is not a no.

The checks that need no trust

What this doesn't replace

The paperwork still matters — the policy questions, contracts, your jurisdiction's process (procurement guide). The conversation and the checks are the triangulation: when the sales answer, the policy text, and the network tab agree, you've learned something durable about the vendor; when they diverge, you've learned more.

References


© Glu IO Pty. Ltd. — Wiz Kids (wiz.kids). Link freely; republication requires permission — see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.