OMNIAInclusion
HomeFeaturesConnectionsEvidence basePricingInsightsFree ToolsAboutFAQContactSign in
All documents
Ask a question
OMNIA INCLUSION LTD

ADEK Digital Policy Self-Attestation

Version 1.1Updated 1 June 2026Self-attestation
OMNIA Inclusion

OMNIA Inclusion Ltd's clause-by-clause mapping against the ADEK School Digital Policy (v1.1, September 2024, compliance effective AY 2025/26).

Version: 1.1 Last updated: 1 June 2026 Status: Self-attestation by OMNIA Inclusion Ltd. Not independently audited.

This document is provided to assist Abu Dhabi private schools with their ADEK due-diligence obligations when adopting third-party EdTech. It is a self-attestation, not an external audit certificate. Schools remain responsible for their own ADEK compliance.


Scope

This attestation covers OMNIA Inclusion Ltd's processing of pupil, staff, and parent data on behalf of ADEK-regulated Abu Dhabi private schools using the OMNIA SEND platform.

ADEK Digital Policy v1.1 is structured around five pillars. Each row below maps OMNIA's practice against the pillar's headline requirements.


Pillar 1 — Governance & accountability

RequirementOMNIA's positionEvidence
Named accountable owner for digital systemsOMNIA Inclusion Ltd as data processor; School DPO as controllerUAE Addendum §2.3, §2.4
Documented vendor due diligencePublic sub-processor list; DPIA; security overview/legal/sub-processors, /legal/dpia, /legal/security
Annual review of vendor complianceUAE Addendum §7.3 commits both parties to 12-monthly reviewUAE Addendum §7.3
Board-level visibilitySchool admin dashboard surfaces all processing, audit log, DSARBuilt into product

Pillar 2 — Data protection & privacy

RequirementOMNIA's positionEvidence
Lawful basis under PDPLSchool confirms lawful basis in UAE Addendum §2.4(b)UAE Addendum §2.4
Special-category data handling (SEND, health)All such data treated as special-category; access restricted to authorised staffUAE Addendum §4.4
Parental notification / consent modelConfigurable per school in Admin → School → SetupBuilt into product
Data-subject rights (access, correction, deletion)30-day SLA; runbook published/legal/pdpl-dsr-runbook
Cross-border transfer safeguardsContractual safeguards + school instruction (interim pending PDPL Executive Regulations); schools may elect Azure OpenAI BYOK in uaenorth to keep AI processing inside the UAEUAE Addendum §3.2
AI data residency (BYOK)BYOK supports Azure OpenAI in uaenorth (Dubai data centre) under the school's own Azure tenancy; key AES-256-GCM-encrypted at rest, never returned to clientBuilt into product; school's own Azure DPA
Sub-processor transparencyLive public list; change-notification template ready/legal/sub-processors, /legal/subprocessor-change-template

Pillar 3 — Cybersecurity & infrastructure

RequirementOMNIA's positionEvidence
Encryption in transitTLS 1.2+ enforced on all endpoints/legal/security
Encryption at restAES-256 at the database and storage layer (Supabase/AWS eu-west-1)/legal/security
Access controlRLS enforced per school; explicit school_id scoping on every server functionCodebase-enforced
MFA for privileged accountsMandatory TOTP for admin / superadmin rolesBuilt into product
Audit loggingTamper-evident audit_logs and system_audit_logs tables; admin-visibleBuilt into product
Backup & disaster recoveryDaily managed backups via Supabase; 7-day point-in-time recovery/legal/security
Incident responseBreach SOP published; UAE Data Office + School notified per PDPL §9 timelines/legal/breach-sop, UAE Addendum §2.3(c)
Penetration testingAnnual third-party pen test (in progress — first test scheduled before first UAE go-live)Plan documented

Pillar 4 — Safeguarding & pupil welfare

RequirementOMNIA's positionEvidence
No use of pupil data for AI trainingExplicit prohibition in UAE Addendum §2.3(e)UAE Addendum §2.3
PII scrubbing before any AI gateway callAn enforced server-side chokepoint (scrubPii/scrubMessages) always runs on plan generation calls (Anthropic Claude) — but it is best-effort, defence-in-depth scrubbing, not a guarantee: free-text fields can still leak PII through. Natural language query parsing uses Google Gemini but receives query strings only — no pupil data transmitted for this function.Codebase-enforced (see code comment in src/lib/ai-gateway/scrub.ts); confirmed from Edge Function review
AI suggestion filtering via Available Interventions RegisterSchool-specific register of deliverable programmes filters all AI plan suggestions — AI will not suggest programmes the school cannot implementBuilt into product
Restricted access to SEND / health dataRole-based access; pastoral / SENCo / inclusion lead onlyBuilt into product
Pupil voice & parent voice — private tokensRate-limited, hashed, expiring tokensBuilt into product
No third-party advertising or tracking on pupil dataConfirmed — no ad networks; analytics is first-party only/legal/cookies

Pillar 5 — Acceptable use & digital citizenship

RequirementOMNIA's positionEvidence
Aligned with School's Acceptable Use PolicyOMNIA does not override; supplements School's AUPUAE Addendum §1.2
Pupil-facing surfaces appropriate for agePupil voice surfaces use age-appropriate language; no open chatBuilt into product
No exposure to external content without School controlClosed system — no public social or chat surfacesBuilt into product
Staff training materials availableIn-product user guide; CPD module/guide, /admin/cpd

Scope decisions

Arabic-language UI. Provided in the parent portal, where the non-English-fluent population sits — parents, not staff. Parents view plans, outcomes and review notes with live AI-translated content across Arabic and 80+ other languages, with right-to-left layout support. Staff-facing surfaces (plan authoring, admin, inspection tooling) are English-only by design, matching the English-medium operating model of OMNIA's target schools, which hire SENCos and inclusion leads for English-medium qualifications. Platform-wide translation is not planned: extending translation to legally sensitive, AI-drafted content (SEND plans, statutory terminology) would introduce real mistranslation risk, and would route more content through the AI gateway — compounding the best-effort, not-a-guarantee PII-scrubbing caveat above. This is a considered boundary, not a backlog item.


Outstanding items

  1. Independent penetration test — scheduled before first UAE school go-live. Will be added to evidence pack on completion.
  2. ISO 27001 certification — not currently held. Roadmap item for FY 2026/27.

Sign-off

This attestation is signed by OMNIA Inclusion Ltd's accountable officer. The School's DPO is welcome to request supporting evidence for any row above.

OMNIA Inclusion Ltd Signed: _________________________________ Title: _________________________________ Date: _____ / _____ / 20___

This document is published by OMNIA Inclusion Ltd and is subject to change. For the current version visit omnia-inclusion.com/legal/adek-attestation.
OMNIA Inclusion Ltd
Company no. 17228173 · ICO: 00014144622
omnia-inclusion.com · hello@omnia-inclusion.com
© 2026

OMNIA

Every SEND decision, grounded in evidence.

Product

  • Features
  • Pricing & ROI
  • Get started
  • Trust & Security
  • Insights

For your school

  • England (EHCP)
  • Wales (ALN)
  • Scotland (ASN)
  • Northern Ireland (SEN)
  • Ireland (NCSE)
  • UAE (ADEK)
  • Dubai schools (KHDA)
  • Qatar (MOEHE)
  • Australia (NDIS)
  • New Zealand (ORS)
  • United States (IDEA/504)
  • IB World Schools
  • Multi-Academy Trusts

Guides & comparisons

  • All guides
  • Provision mapping guide
  • SEN support plan vs pupil passport
  • SEND management software
  • Provision Map comparison & migration guide

About OMNIA

  • About
  • Evidence base
  • Founding schools
  • Frameworks & acknowledgements
  • FAQ
  • Legal
  • Accessibility
  • hello@omnia-inclusion.com

© 2026 OMNIA Inclusion Ltd · Registered in England & Wales · Company no. 17228173 · ICO registration no. 00014144622