Date: October 2025
Review Date: October 2026
Coordinator: Head
Nominated Governor: Claire Farmer
Version: v10.25

Refreshed for OSA 2023 + Diamond AI — signed off April 2026

This policy was refreshed on 2026-04-29 to align with Online Safety Act 2023 (phased duties on user-to-user services), DfE Cyber Security Standards for Schools 2024, DfE Filtering and Monitoring Standards 2024, Generative AI in Education (DfE 2025), ICO Children’s Code, and the Haven’s Diamond AI posturework with AI; do not offload decisions to AI; do not defer entirely from AI.

Status: live — signed off 29 April 2026 by Proprietor and Governing Body.

Linked Policies:

1. Purpose

This agreement sets out the digital expectations for all The Haven staff. It ensures that every interaction, post, message, and online activity reflects our safeguarding, inclusion, and professional standards.

It aims to protect:

  • Learners and families from harm or data misuse

  • Staff from reputational, legal, or safeguarding risk

  • The Haven’s digital integrity and community trust

Signing this agreement confirms that you understand, commit to, and will uphold these standards in all professional and digital contexts.

2. Scope

This agreement applies to all The Haven employees, contractors, volunteers, mentors, and governors who use digital technology for any work-related purpose — including laptops, phones, and online platforms (Pencil Spaces, Canvas, Google Workspace, TutorCruncher). Note: The Haven does not use unmoderated community chat platforms (e.g. Discord) for any work-related learner communication.

3. Core Principles

To ensure safe and lawful use of digital and AI-based tools, the following roles have defined responsibilities:

DSL/SENCO - Lead on confidentiality for safeguarding / SEND data. Ensure staff follow this guidance; report breaches to the DPO.

All staff - Follow the expectations in this agreement, and seek advice if unsure.

DPO (CEO) - Ensure compliance with UK GDPR, monitor incidents, maintain records, and configure AI and data-retention settings — with technical support from the school’s Systems Manager - ensuring AI tools and Workspace remain The Haven-owned and compliant.

Safety First

  • I will protect learners’ digital identities and never share identifying details online.

  • I will report any online concern, threat, or breach immediately- safeguarding concerns to the DSL; data-security or technical breaches to the DPO.

  • I will not access, download, or distribute harmful or extremist material.

  • I will not engage privately with learners or families via personal devices or accounts.

Professional Conduct

  • I will use The Haven-approved platforms only for communication and learning.

  • I will maintain clear professional boundaries in all digital interactions.

  • I will not post, forward, or “like” content that could undermine The Haven’s values or professionalism.

  • I will respect copyright, consent, and attribution in all digital materials.

Responsible Technology Use — Haven Diamond AI Posture

The Haven follows a Diamond AI posture: we work with AI as a collaborative tool, we do not offload professional, safeguarding, pedagogical or relational decisions to AI, and we do not defer entirely from AI where it supports inclusive, accessible learning. This is the third position between uncritical adoption and blanket avoidance.

In practice, I commit to the following:

  • I will not use AI or automation tools without declaring and verifying them under The Haven’s Responsible Use of AI Policy v10.26.

  • I will not input confidential or learner-identifiable information into AI systems or public tools.

  • I will critically assess AI outputs for bias, inaccuracy, or ethical risk before using or sharing them.

  • I will not delegate safeguarding, behavioural, SEND, or pastoral decisions to AI. AI may support pattern-spotting or summarisation, but the professional judgement remains with the named role-holder.

  • I will not avoid AI tools categorically where their use would meaningfully reduce barriers to learning for neurodivergent learners — instead I will engage with them under the Diamond posture and within the boundaries of this agreement.

Data Protection

  • I will secure all devices with passwords and multi-factor authentication.

  • I will encrypt and store data in approved The Haven systems only.

  • I will lock or log out of all systems when unattended.

  • I will immediately report any suspected breach or phishing attempt.

Respect and Inclusion

  • I will promote an inclusive, neurodiversity-affirming online environment, using person-respecting language and communication.

  • I will challenge or report discriminatory or harmful online behaviour.

  • I understand that racism, sexism, ableism, homophobia, or transphobia online are safeguarding concerns, not “opinions.”

4. Safeguarding and Visibility

  • I understand that online visibility is part of safeguarding: camera use, tone, and engagement are professional signals learners interpret.

  • I will maintain clear visibility when teaching online and use only approved digital backgrounds.

  • I recognise that my digital conduct forms part of my safeguarding responsibility under KCSIE 2025 and The Haven DSL Addendum.

5. Cyber Security Responsibilities

  • I will complete The Haven’s annual cyber and online safety training.

  • I will update devices and software as prompted.

  • I will not install unapproved apps or plugins on The Haven systems.

  • I will use personal devices for work only when encrypted and approved by IT/DPO.

  • I will complete annual training on the safe and ethical use of AI and digital tools as part of The Haven’s online-safety programme.

6. Reporting Concerns

Any breach, error, or concern — even if accidental — must be reported to:

  • DSL for safeguarding-related incidents

  • DPO for data or cyber issues

  • Line Manager for general professional concerns

Reports will be handled supportively, in line with The Haven’s Low-Level Concerns and Grievance Policies.

7. Acknowledgment and Signature

I confirm that I have read, understood, and agree to follow the The Haven Staff Safer Internet Agreement (including its expectations for AI and data-protection practice) and agree to follow it in all professional digital activity. I understand that:

• I must protect learner and staff data at all times;

• I must use AI tools only within school-approved systems; and

• I will report any breach or concern immediately to the DPO or DSL.
I understand that failure to uphold these standards may lead to proportionate action under the Staff Conduct Policy v10.25.

| | | | | | | | | | | | | | |