Privacy notice

Epsilon Academy uses the personal data of students and parents only to run tuition, keep children safe and meet the law. We never sell data, never show adverts and never use data for marketing to children. Version 1, [date].

1. Who we are

Epsilon Academy is run by [legal name], [address]. We are the data controller. Contact us about your data at [privacy email]. ICO registration number: [number].

2. What this notice covers

The Epsilon Academy learning platform at app.epsilonacademy.co.uk, used by students in Years 7 to 13, their parents or guardians, and our teachers.

3. What we collect and why

DataComes fromWhy we use itLawful basis
Name, email, year group, subjects, exam boardParent or student request formTo create and run the accountContract with the parent (UK GDPR Art 6(1)(b))
Parent's name and email, link to their childParentContact about the child's learning and attendanceContract (6(1)(b))
Answers, working, scores, practice levels, Rigel check resultStudentTo mark work, find the right level and plan lessonsContract (6(1)(b)) or legitimate interests (6(1)(f))
Discovery answers: mindset, study habits, sleep and study timesStudentTo suggest study methods; a teacher always decidesLegitimate interests (6(1)(f))
Wellbeing answers, for example feeling very stressed or overwhelmedStudentTo let a trained adult check the child is safe[to be confirmed]
Session times, sign-in times, attendance, parent explanationsSystem, parentTo support attendance and tell parents about missed sessionsContract (6(1)(b))
Record of parental consentParentTo show permission was given before the account was usedLegal obligation / accountability (6(1)(c))
Sign-in records and an activity logSystemSecurity and to investigate problemsLegitimate interests (6(1)(f))

We do not collect exact location, photos, voice, biometric data or payment card details on this platform.

4. Automatic suggestions and decisions

The platform makes some suggestions automatically. A person can always review them.

5. Extra care for children

We follow the ICO's Age Appropriate Design Code (the Children's code).

6. Who can see what

PersonCan see
The studentTheir own work, plan, levels, sessions and messages
The parent or guardianTheir child's plan progress, levels, Rigel result, sessions, attendance and messages. Not the child's Discovery answers or wellbeing answers
The student's teacherEverything about the students assigned to them, including Discovery and wellbeing answers
Epsilon Academy owner and the Designated Safeguarding LeadEverything, to run the service and keep children safe

If we believe a child is at risk of harm, we may share information with parents, the local authority, the police or other services, as safeguarding law requires.

7. Other organisations that handle the data

OrganisationRoleWhere
HostingerHosts our server and stores the data[UK or EU data centre]
CloudflareDirects web addresses (DNS) to our serverDoes not store platform data

We use an AI service ([Anthropic or Google]) to suggest weekly study-habit tips. It receives only a code number (like S-482913), year group, subjects, levels and study-habit scores. It never receives names or emails. If the owner switches them on, it can also receive typed answers and working (with names, emails, phone numbers, links and postcodes removed first) and wellbeing flags written in our own words. A teacher approves each tip before the student sees it, unless the owner turns approval off. Coded data is still personal data, so the AI provider acts as our processor under contract and must not use it to train its models. The provider is in [country]; transfers are protected by [safeguard].

We use an email service ([Brevo or Postmark]) to send sign-in codes, attendance alerts, new-plan notices and wellbeing alerts to staff. It receives the recipient's name and email address and the message. Wellbeing alerts never name the child. The service acts as our processor under its data processing terms.

8. Security

Passwords are stored scrambled (hashed), never readable. Connections use encryption (https). Each person sees only what their role allows, and access is logged. Backups are taken every night.

9. How long we keep data

DataKept for
Access requests that are not approved3 months
Account, learning and attendance recordsWhile the account is open, then 12 months, then deleted
Safeguarding recordsAs safeguarding guidance requires, usually until the child turns 25
Consent recordsWhile the account is open, then 6 years
Activity and sign-in log12 months
Backups30 days, rolling

10. Your rights

You can ask to see, correct or delete your data, to restrict or object to how we use it, or to receive a copy to take elsewhere. Where we rely on consent, you can withdraw it at any time. Students can use these rights themselves when they are old enough to understand them. We reply within one month. Email [privacy email].

11. Complaints

If you are unhappy with how we handle data, tell us first at [privacy email] or in any other way that suits you. We will acknowledge your complaint within 30 days, look into it, keep you updated and tell you the outcome. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

12. Cookies

We use one essential cookie to keep you signed in. It lasts up to 3 days and is not used for tracking. We use no analytics or advertising cookies.

13. Changes

We will update this notice when the platform changes, and tell parents about important changes.

Back to Epsilon Academy