# 4. Session Management & Privacy

User Type: **Student**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 4. Session Management & Privacy

### 4.1 Session Management
**What it does:** Manages the Student's authenticated sessions across devices. The Student can see all active sessions, sign out of individual sessions or all sessions at once, and control "remember me" behavior. Sessions are subject to inactivity timeouts, concurrency limits, and are terminated on password reset or account suspension.

**Sub-features:**
- Active sessions list: device type, browser/app, location, last active time, current session marker
- Sign out of a single session from the list
- "Sign out everywhere" to terminate all sessions except the current one
- Inactivity timeout: idle sessions are automatically signed out after a policy-defined period
- Concurrency limit: a maximum number of simultaneous sessions per account
- "Remember me" behavior: extended session persistence on trusted devices
- Session termination on password reset and on account suspension
- New-device login notification (email alert when a new device signs in)
- Session event logging (created, extended, terminated, timeout)
- Audit logging of the session management

**Student User Journey:**
1. Student opens Profile → "Security" → "Active sessions" and sees a list: this device (iPhone, current), a laptop (last active 2 hours ago), and a tablet (last active yesterday).
2. Student clicks "Sign out" next to the tablet; the session is terminated and the list updates.
3. Student clicks "Sign out everywhere"; all sessions except the current one are terminated and a confirmation is shown.
4. Later, Student signs in from a new device; the registered email receives a "New sign-in to your account" notification with device and location.
5. Student is idle on the web for longer than the inactivity timeout; on returning, the session has expired and Student is returned to the login screen with a "You were signed out due to inactivity" notice.
6. Student opens the profile menu → "Security activity" and confirms the session events (created, terminated, timeout) are recorded with timestamps.

**Rules & Edge Cases:**
- The current session is never terminated by "Sign out everywhere".
- Inactivity timeouts are policy-defined; the Student is notified when a session expires due to inactivity.
- The concurrency limit caps simultaneous sessions; exceeding it terminates the oldest session.
- A password reset or account suspension terminates all sessions immediately.
- New-device logins trigger an email notification to the registered address.
- Session events (created, extended, terminated, timeout) are logged with device, IP, and timestamp.
- The session management is audit-logged with the account, the action, and the timestamp.

### 4.2 Privacy & Consent
**What it does:** Gives the Student control over their personal data and the consents that govern its use. The Student can review what data is collected, manage communication preferences, request a copy of their data (data portability), and request account deletion, in line with the platform's privacy policy and applicable regulations.

**Sub-features:**
- Privacy policy access from the profile and at registration
- Data collection summary: what data is collected and why
- Communication preference management (email, SMS, in-app) per category
- Data portability: request a copy of the Student's data in a standard format
- Account deletion request with a confirmation and a cooling-off period
- Consent records: what consents were given and when
- Minor-specific consent: parent consent status visible where applicable
- Deletion handling: data removed or anonymized per the retention policy
- Consent and deletion event logging
- Audit logging of the privacy and consent

**Student User Journey:**
1. Student opens Profile → "Privacy" and reads the privacy policy and a plain-language summary of what data is collected and why.
2. Student opens "Communication preferences" and turns off SMS notifications while keeping email and in-app on.
3. Student opens "Your data" and clicks "Request a copy"; the system confirms the request and will deliver the data in a standard format within the policy window.
4. Student opens "Consent records" and sees the list of consents given (terms, privacy, parent consent) with timestamps.
5. If Student later decides to leave, they open "Account" → "Delete account", read the consequences, enter their password to confirm, and the deletion enters a cooling-off period.
6. During the cooling-off period, Student can cancel the deletion by logging in; after it ends, the data is removed or anonymized per the retention policy.
7. Student opens the profile menu → "Account activity" and confirms the consent and deletion events are recorded with timestamps.

**Rules & Edge Cases:**
- The privacy policy is accessible at registration and from the profile at all times.
- Communication preferences are per-channel and per-category; changing them takes effect immediately.
- A data portability request is fulfilled within the policy window in a standard, machine-readable format.
- Account deletion requires password confirmation and a cooling-off period during which it can be cancelled.
- After deletion, personal data is removed or anonymized per the retention policy; legally required records are retained as mandated.
- For minors, parent consent status is tracked and visible where applicable.
- Consent and deletion events are logged with timestamp and the specific consent or action.
- The privacy and consent actions are audit-logged with the account, the action, and the timestamp.
