Skip to content
SchoolTrack

Theme

Security · Trust · Compliance

Built so your school never lands on an ODPC fine list.

Data protection and security are not features we bolted on — they are the third pillar of the product. This page is the public, plain-language version of how we handle your data and your learners' data.

Data Protection Act 2019

Compliant

ODPC registration

Registered data processor

Hosting

Enterprise cloud, isolated per school

Backups

Encrypted, geo-redundant, daily

Encryption in transit

TLS 1.2+

Encryption at rest

AES-256

Breach notification

Within 72 hours of awareness

Independent testing

Annually and on major release

Cornerstones

The four cornerstones

What every school should demand from any platform that touches learner data — and every one is built into SchoolTrack.

01

Capture, version, withdraw

Consent is recorded at enrolment per purpose and per data category. Every change is versioned with a timestamp and the responsible user. Withdrawal is one click and cascades to downstream processing.

02

DSAR, export, deletion

Authorised users export all data for a given subject — learner, guardian or staff — as a structured package. Deletion respects statutory retention but otherwise wipes to schedule, with an audit log of every deletion.

03

Every sensitive action is logged

Marks edits, fee waivers, role assignments, communication sends, medical-record reads — all captured with actor, before and after, IP and user agent. Logs are tamper-evident and exportable for inspections.

04

72 hours, ready to go

If something happens, the platform gives you a pre-drafted ODPC notification, a data-subject impact list and a timeline you can hand to your DPO. Most schools have never had to do this. We do not want yours to be unprepared.

How we operate

A short list of the things we will and won't do.

We will

  • Process Customer Data only on your documented instructions, as your data processor.
  • Notify you within 72 hours of becoming aware of any incident affecting personal data.
  • Give you a signed Data Processing Addendum on request.
  • Publish our sub-processor list and notify you 30 days before any change involving Learner Data.
  • Cooperate fully with any ODPC inspection or data-subject request.

We will not

  • Sell your data. Not anonymised, not aggregated, not ever.
  • Train our own AI models on your data without explicit written agreement.
  • Let AI sub-processors train their general-purpose models on Customer Data.
  • Send a learner's image, name or grade to any third-party advertising network.

Found a vulnerability?

We welcome responsible disclosures from researchers and security teams. Email us with reproduction steps and we will respond within two business days.

[email protected]

Data Protection Officer

Schools, guardians and learners can contact our DPO for any data-subject request or DPA query.

[email protected]

For the full legal terms:

Compliance you can hand to an inspector.

Consent, retention, DSAR and audit are in the product on day one — not on a roadmap.