Built so your school never lands on an ODPC fine list.
Data protection and security are not features we bolted on — they are the third pillar of the product. This page is the public, plain-language version of how we handle your data and your learners' data.
Data Protection Act 2019
Compliant
ODPC registration
Registered data processor
Hosting
Enterprise cloud, isolated per school
Backups
Encrypted, geo-redundant, daily
Encryption in transit
TLS 1.2+
Encryption at rest
AES-256
Breach notification
Within 72 hours of awareness
Independent testing
Annually and on major release
The four cornerstones
What every school should demand from any platform that touches learner data — and every one is built into SchoolTrack.
Capture, version, withdraw
Consent is recorded at enrolment per purpose and per data category. Every change is versioned with a timestamp and the responsible user. Withdrawal is one click and cascades to downstream processing.
DSAR, export, deletion
Authorised users export all data for a given subject — learner, guardian or staff — as a structured package. Deletion respects statutory retention but otherwise wipes to schedule, with an audit log of every deletion.
Every sensitive action is logged
Marks edits, fee waivers, role assignments, communication sends, medical-record reads — all captured with actor, before and after, IP and user agent. Logs are tamper-evident and exportable for inspections.
72 hours, ready to go
If something happens, the platform gives you a pre-drafted ODPC notification, a data-subject impact list and a timeline you can hand to your DPO. Most schools have never had to do this. We do not want yours to be unprepared.
A short list of the things we will and won't do.
We will
- Process Customer Data only on your documented instructions, as your data processor.
- Notify you within 72 hours of becoming aware of any incident affecting personal data.
- Give you a signed Data Processing Addendum on request.
- Publish our sub-processor list and notify you 30 days before any change involving Learner Data.
- Cooperate fully with any ODPC inspection or data-subject request.
We will not
- Sell your data. Not anonymised, not aggregated, not ever.
- Train our own AI models on your data without explicit written agreement.
- Let AI sub-processors train their general-purpose models on Customer Data.
- Send a learner's image, name or grade to any third-party advertising network.
Found a vulnerability?
We welcome responsible disclosures from researchers and security teams. Email us with reproduction steps and we will respond within two business days.
[email protected]Data Protection Officer
Schools, guardians and learners can contact our DPO for any data-subject request or DPA query.
[email protected]For the full legal terms:
Compliance you can hand to an inspector.
Consent, retention, DSAR and audit are in the product on day one — not on a roadmap.