ZStat
ZStat Sign in Start free

Data protection and architecture assurance

Generated by this installation on 2026-08-02 06:41:45. Every figure below was read from the running system rather than written by hand.

Download as Word For your ICT directorate, data protection officer or procurement file.

Summary

This document was generated on 2026-08-02 06:41:45 by the ZStat installation itself. Every figure in it was read from the running system at that moment rather than written by hand, so it describes this installation and not a general specification.

Delivery model: Hosted by ZStat. On ZStat infrastructure. Each institution has its own database; individual accounts share a pooled one.

Data controller: The institution, or the individual researcher, is the data controller. ZStat is the processor.

Analysis engine version 2.70.0, offering 91 statistical procedures. Plan definitions version 2.0.0.

Where the data is held

This is a hosted installation. Respondent data is held on ZStat infrastructure, and ZStat acts as processor on the controller's instructions.

Database "zstat_main" on host "127.0.0.1", containing 34 table(s).

Schema version: 11 migration(s) applied, the most recent being 0011_identity_verify.sql.

Integrity controls

22 database trigger(s) are installed. These are enforced by the database rather than by the application, so they hold even against a direct connection and against a defect in the web layer.

Recorded analyses, answers, audit entries, plan history and withdrawal records are append-only. An answer cannot be edited or deleted individually; a withdrawal is honoured by deleting the respondent, which cascades, so an n cannot change without a record of why.

Answers cannot be written at all without a live write authorisation issued by the collection service after its compliance, consent and instrument checks pass. A direct insert into the answers table is refused by the database.

Every recorded analysis carries the SHA-256 digest of the data it consumed and of the specification that produced it, together with the engine and procedure versions, so any figure in a report can be traced to the data and software that produced it.

Consent, withdrawal and retention

Withdrawal route implemented and reachable: Yes. This is checked by looking for the mechanism, not asserted.

A respondent withdraws using a code they were given at submission, with no account, no password and no reason required. Their answers are deleted rather than flagged. A record of the withdrawal is kept with counts and dates and nothing that identifies them, so the study can explain why its totals changed.

Audit logging active: Yes. Audit entries record the actor, the action, the entity and a hash of the address, never the address itself.

Retention is enforced by a scheduled sweep that deletes respondents past the period their study recorded, running from the date each respondent answered rather than from the date the study was created. A sweep that would remove more than half a study stops and requires explicit confirmation.

What is not the case

Direct identifiers encrypted at rest: No. Respondent codes are pseudonymous and studies hold no names by default, but the codes themselves are stored in plain text. Where a study declares sensitive categories, the compliance check blocks collection for this reason.

This document is an engineering statement about how the software behaves. It is not legal advice and it cannot tell you whether a particular study is lawful. Have your data protection officer review the notice and the assessment.

If the licence lapses

These remain available and are never withheld: signing in, reading every recorded result, exporting the data, exporting the report, honouring a withdrawal, running the retention sweep.

These pause until the licence is renewed: creating a study, collecting new responses, adding people to a study, running a new analysis.

A lapsed licence stops new work. It never withholds data or the ability to export it. Under NDPA 2023 the account holder is the data controller and remains legally obliged to produce, correct and delete that data on request - software that blocks them has manufactured a compliance breach for its own customer.

Email

Transport: log.

No tracking pixel is placed in any message, no open tracking is performed and no link is rewritten through a redirect. The tips list uses double opt-in, records the consent with its wording version, and carries one-click unsubscribe headers so a mail client can act without the message being opened.

This installation, at the moment of generation

Studies: 1. Respondents: 0. Recorded analyses: 0. Withdrawals honoured: 0. Audit entries: 2.

This document reports what the software does. It is not legal advice. If anything here does not match what you were told in a sales conversation, this page is the one that was generated from the code.