GDPR

Revision as of 11:13, 8 August 2026 by Anthony (talk | contribs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Personal data in the United Kingdom is governed by the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Schools in the EU/EEA are covered by the EU GDPR. These impose strict controls on how organisations collect and process personal data.

Under this legislation your school is the data controller and we are a data processor acting on your documented instructions. We are committed to meeting our obligations in that role, and we keep our technical and organisational security measures under continual review.

It is our policy to keep data private, secure and safe. We do this in several ways, including:

  • Data is collected only for specific, explicit and legitimate purposes.
  • Sensitive data is encoded whilst on, and before it leaves, your computer.
  • Data is further encrypted with AES-256 encryption locally and/or with us (optionally turned off — see below).
  • Passwords are stored with us as one-way salted hashes.
  • TLS is used to ensure data is private during communication.
  • Data is retained only for as long as necessary, and to a published schedule.
  • Regular backups are made in case we ever need to recover data.
  • Personal data can be exported in a machine-readable format at any time.

Why encryption is optional for some customers:

A small number of our customers are outside the UK and EU. In those cases we necessarily send data to those countries so that the school can edit its own reports. Some of those countries do not permit the use of encryption, and for that reason we provide the option to turn off local and/or server-side encryption. The default is local off, server on. In any event, data is encoded and is never stored in plain text.

The settings are found in Admin > School Details. We recommend leaving local encryption off so that, in the event of a local hard drive fault, recovery software has a better chance of working.

Where is data stored?

Our servers and data storage are provided by DreamHost (DreamHost, LLC, Brea, California, USA). Backups are held on a secure server managed by Deluxe Pixel Limited in Preston, United Kingdom.

Because DreamHost processes data in the United States, this involves a restricted transfer under UK GDPR. That transfer is covered by appropriate safeguards under Article 46:

  • DreamHost's Customer Data Processing Addendum incorporates the Standard Contractual Clauses approved by the European Commission in 2021 (Schedule D, Module Two — controller to processor).
  • These are supplemented by the International Data Transfer Addendum issued by the UK Information Commissioner's Office (Annex III; ICO template B.1.0, laid before Parliament on 2 February 2022).

We have carried out a Transfer Risk Assessment in line with ICO guidance, and review it periodically. A copy is available to schools on request.

Note: the EU–US Privacy Shield framework, referred to in earlier versions of this page, was invalidated by the Court of Justice of the European Union in July 2020. We do not rely on it, nor on its successor the UK Extension to the EU–US Data Privacy Framework. Our transfers rest on the contractual safeguards described above, which are not affected by changes to those adequacy arrangements.

Our sub-processors:

We use the following sub-processors in providing the service:

Sub-processor Purpose Location
DreamHost, LLC Hosting, data storage and backup USA
Deluxe Pixel Limited Off-site backup United Kingdom

We will give schools notice before adding or replacing a sub-processor.

How long we keep data:

Data Retention
Reports and report data Retained while the licence is active, and for one year after it ends unless the school asks in writing for earlier deletion
Pupil photographs and artwork Deleted at the end of the academic year in which they were uploaded
Backups Overwritten on a rolling 30 day cycle
Website logs Encrypted and deleted after 72 hours

Schools may request deletion of their data at any time by writing to us. Administrators can also export all school data to a machine-readable file at any point — see GDPR backups.

Why we would sometimes provide third parties with your information:

Examples of circumstances in which this could arise are if a school asked us to work directly with a third-party support team it uses, or if we were legally compelled to provide information — for example on a valid request from the police or a court, such as for a set of past reports for a particular pupil.

We will not disclose school data to any third party except where legally required, and we will notify the school of any such request unless we are prohibited from doing so.

Who has access to your information:

  • Only a small number of staff have access to school licence credentials. Our admin system checks IP address as well as password and will refuse a login if either is incorrect.
  • All our staff are DBS (Disclosure and Barring Service) checked.
  • All passwords are stored as one-way salted hashes — which is why we cannot recover a teacher's password, only replace it.
  • Direct database access is restricted to specific IP addresses. All other access must go through our web API, which requires a valid username and password.
  • Our web API does not use cookies or sessions, which avoids cookie hijacking and session fixation attacks.
  • Full backups are taken daily between 2am and 3am to a secure machine in a separate location from the main server.

Our registration with the ICO:

Enforcement of the UK GDPR is overseen by the United Kingdom's supervisory authority, the Information Commissioner's Office (ICO). It ensures that organisations follow the rules and that the rights of data subjects — the people whose data is being processed — are properly protected.

We are registered with the Information Commissioner's Office (ID: ZA551060). You can download a copy of our certificate here.

Your data protection contact:

Specify your data protection contact

Under the UK GDPR, organisations processing personal data at large scale, processing certain special categories of data, or which are a public authority or body, may need to designate a Data Protection Officer (DPO) and, where relevant, a UK or EU representative. This is the person we would normally contact about data protection matters.

Administrators will see a screen similar to this one if we do not yet know who to contact at your school.

Within the program, administrators will also find a GDPR option in the Administrator menu showing who you told us about and when.

Administrators can also back up all school data to a machine-readable file.

Rights of individuals:

Because your school is the data controller, requests from parents, pupils or staff to access, correct or delete personal data should be made to the school in the first instance. We will assist you in responding to any such request. If a request is made directly to us, we will pass it to the school rather than responding ourselves.

Contact us:

If you would like to discuss GDPR, data protection, or how we process data, please email our Data Protection Officer and we will get back to you as soon as possible.