Student Privacy FAQ

STUDENT PRIVACY FREQUENTLY ASKED QUESTIONS (FAQs)

This website and app is operated by EDUCAKE LTD

We take the privacy and data of our users very seriously. This page sets out how we process students’ personal data on behalf of their school, LEA or similar organisation (‘School’) in order for students to use our website and app.

We may update this page from time to time. You should check this page occasionally to ensure you are aware of the most recent version that will apply each time you access our website or app.

Who are we?

EDUCAKE LTD (‘we’ or ‘us’) are a ‘data processor’ on behalf of the School for the purposes of the Data Protection Act 2018, the UK General Data Protection Regulation and any subsequent UK data protection legislation. This means that the School is the ‘data controller’ and we only process students’ personal data in accordance with the School’s instructions.

What information do we process about you?

During the course of accessing our website, app, using our products and services, contacting us, or otherwise dealing with us, you or your School may provide us with a range of personal data which we will use in order to deliver our services to you and your School. This personal information includes:

  • Your name or another unique identifier;
  • Your age, date of birth and/or gender;
  • Your school year and the classes and subjects you are taking;
  • Your contact details (which may include your mobile number and/or email address); and
  • Other related information such as your answers to questions, the quizzes you have created and the time you last logged in, and other activity on the website/app.

Your School may send us information about whether you receive the Pupil Premium. We do not request this information or use this data in any way.

Our website, app and services may collect certain information about you automatically (such as your IP address, MAC address and IMEI number, browser type and version, operating system, geo-location data based on your IP address).

We ask that you please provide to us with information that is accurate, complete and up-to-date.

How we use your data?

We process your data to allow us to deliver our services to you and your School i.e. to allow you to log-in and do your homework and revision, and to allow your teachers to set homework, quizzes and review your work. Our use of your data is strictly in accordance with the contractual agreement we have with your School and we do not process your data unless we are instructed by your School to do so.

We may monitor and record communications with you (such as telephone conversations and emails, if relevant) for the purpose of training, fraud prevention, and/or quality assurance. We may also retain copies of communications and details provided to us by you, for example support requests, account queries, complaints, for internal account management and auditing purposes.

Where do we store your information?

We store your personal data on servers in data centres in the UK, provided by Amazon Web Services (AWS). AWS datacentres are compliant with the international information security standard, ISO 27001.

For more information about AWS’s ISO 27001 certification, please visit this webpage: https://aws.amazon.com/compliance/iso-27001-faqs/

Do we share your information with third parties?

We never share your data to third parties who will call or email you for marketing purposes. Provided we have lawful instructions from your School, we may disclose your personal data to:

  • law enforcement agencies in connection with any investigation to help prevent unlawful activity;
  • a third party purchaser if we sell our business, in which case, customer and user information will be a transferred asset; and
  • our agents and service providers, to the extent that they require access to the data in order to provide goods/services to us, in which case they will be bound by a contract requiring them to process personal data in accordance with the requirements prescribed by data protection law.
How do you keep my data secure?

We will use technical and organisational measures to safeguard your personal data, for example:

  • access to your account is controlled by a password and user name that are unique to you;
  • we store your personal data on secure servers; and
  • payment details are encrypted using SSL/TLS technology (typically you will see a lock icon or green address bar (or both) in your browser when we use this technology).

While we will use all reasonable efforts to safeguard your personal data, you acknowledge that the use of the internet is not entirely secure and for this reason we cannot guarantee the security or integrity of any personal data that are transferred from you or to you via the internet. If you have any particular concerns about your information, please contact us (see ‘How to contact us’ below).

What can I do to keep my information safe?

Do not share your account username and password with anyone else and do not save your log-in details on any public computer or device. If you want detailed information from Get Safe Online on how to protect your information and your computers and devices against fraud, identity theft, viruses and many other online problems, please visit www.getsafeonline.org. Get Safe Online is supported by HM Government and leading businesses.

Are your employees police or DBS checked?

Yes, all employees and contractors with access to the servers or who may visit your School are DBS checked.

Will my data ever leave the UK?

We may transfer your personal data outside of the UK. We will only do this if appropriate safeguards are place in accordance with data protection legislation and where we have instructions from your School to do so. We ensure that your privacy rights are safeguarded and give you remedies in the unlikely event of a security breach.

How long do we keep your personal information?

We keep your personal information for as long as we need to for the purposes of our contract with your School (unless specifically instructed by your School to erase your data) or (if longer) for any period for which we are required to keep personal information to comply with our legal and regulatory requirements.

What rights do you have?

You have a number of rights in relation to your personal data – https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/

Should you (or your parent on your behalf) wish to enforce your rights in respect of how we process their data, this should be directed to your School who will instruct us accordingly.

How to contact us

Please contact us if you have any questions about this page or the information we hold about you.

If you wish to contact us, please send an email to support@educake.co.uk or write to us at FAO: Educake Ltd, 30 St. Giles, Oxford, England, OX1 3LE or call us on 01865 800 808

Use of cookies

For information on the cookies we use and how to control your cookie settings, please visit our Cookie Policy www.educake.co.uk/aboutus/cookiepolicy.