# 4. Session Management & Privacy

User Type: **Parent**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 4. Session Management & Privacy

### 4.1 Active Sessions and Sign Out
**What it does:** Shows the Parent their active sessions (devices and locations) and lets them sign out. The Parent can sign out of the current session or remotely sign out another device. This lets the Parent secure their account, which has access to their children's data, especially on shared devices.

**Sub-features:**
- List of active sessions (device, location, time)
- Sign out of the current session
- Remotely sign out another device
- Session list available on web and mobile
- Sign out confirmation
- Session event logging (signed out, remote sign out)
- Audit logging of the active sessions and sign out

**Parent User Journey:**
1. Parent opens Profile → "Security" → "Active Sessions".
2. The active sessions are listed (device, location, time).
3. Parent signs out of the current session.
4. Parent remotely signs out another device.
5. A sign out confirmation is shown.
6. Parent views the session list on the mobile app.
7. Parent opens Profile → "Activity" and confirms the session events are recorded.

**Rules & Edge Cases:**
- The session list shows device, location, and time.
- The current session can be signed out.
- Another device can be remotely signed out.
- Session events (signed out, remote sign out) are logged with the account and the timestamp.
- The active sessions and sign out is audit-logged with the account and the timestamp.

### 4.2 Privacy and Data Controls
**What it does:** Gives the Parent control over their data and privacy. The Parent can view what data the platform holds, download their data, and request account deletion. The Parent can also control how their data is used. This supports the Parent's privacy rights over their account.

**Sub-features:**
- View the data the platform holds
- Download the Parent's data
- Request account deletion
- Control data usage
- Privacy settings on the account
- Privacy event logging (data downloaded, deletion requested)
- Audit logging of the privacy and data controls

**Parent User Journey:**
1. Parent opens Profile → "Privacy".
2. The data the platform holds is shown.
3. Parent downloads their data.
4. Parent controls how their data is used.
5. Parent can request account deletion.
6. The privacy settings are on the account.
7. Parent opens Profile → "Activity" and confirms the privacy events are recorded.

**Rules & Edge Cases:**
- The Parent can view and download their data.
- An account deletion can be requested.
- Data usage can be controlled.
- Privacy events (data downloaded, deletion requested) are logged with the account and the timestamp.
- The privacy and data controls is audit-logged with the account and the timestamp.
