Privacy notice
Draft for review. Text in [square brackets] must be completed by the school, and this notice should be checked by the school's Data Protection Lead or legal adviser before the service is used with real pupil data.
1. Who we are
This service lets parents tell the school they have arrived, lets prep rooms book children in and out, and lets reception confirm each hand-over.
| Data controller | [Spratton Hall School legal entity name], [address]. ICO registration number [number]. The school decides why and how pupil and staff information is used. |
|---|---|
| Data Protection Lead / DPO | [name], [email], [telephone] |
| Data processor | [Provider name / company], [address], which builds and runs the service on the school's instructions under a written data processing agreement (UK GDPR Article 28). |
2. What information we collect
| About pupils | Full name, year group, collection room, whether they normally stay for prep, and a collection password stored only in scrambled (hashed) form. Each day: whether they were registered into prep, when a collection was requested, released and handed over, and the three-letter collection code. |
|---|---|
| About parents and carers | We do not ask for or store parents' names, email addresses or phone numbers. When a parent checks in we record the time, the internet (IP) address the request came from, and a random device reference used only to slow down repeated wrong passwords. |
| About staff | Name, work email address, role, room, login and logout times, internet (IP) address and type of device, and a record of the actions they take (registering, releasing, handing over). |
We do not collect special category data (such as health or ethnicity), photographs, location tracking or biometric data.
3. Why we use it and our lawful basis
The information is used only to make sure each child is handed to an authorised adult safely, to keep an accurate record of who was collected, when and by whose authority, and to keep the service secure.
The school's lawful basis under UK GDPR Article 6 is [legitimate interests (Art. 6(1)(f)) in safeguarding pupils and running the school safely / public task (Art. 6(1)(e)) for maintained schools — school to confirm], supported by its safeguarding duties (including the statutory guidance Keeping Children Safe in Education). Where legitimate interests is used, the school has carried out [a legitimate interests assessment and a Data Protection Impact Assessment (DPIA)].
No decisions are made about anyone by automated means, and the information is never used for marketing or sold.
4. Where the information is kept
- The database is hosted by Supabase in its London (eu-west-2) region, in the United Kingdom.
- The web pages are delivered by Cloudflare. The pages themselves contain no pupil data, but Cloudflare handles internet traffic, including IP addresses, to deliver and protect the service. Where this involves processing outside the UK, it is covered by appropriate safeguards such as the UK International Data Transfer Addendum or the UK–US data bridge. [Provider to confirm current sub-processor terms.]
- A current list of sub-processors is available from [contact].
5. How long we keep it
| Collection records, registers and activity log | Until the end of the school term in which they were made, then deleted automatically. If term dates have not been entered, nothing is kept for more than 120 days. |
|---|---|
| Staff login and logout records | As above. |
| Parent's check-in ticket (on the server) | Deleted after 24 hours. |
| Failed password attempts | Deleted after 24 hours. |
| Pupil records | While the pupil is at the school. The school removes leavers [within X weeks of the end of the school year]. |
| Staff accounts | While the member of staff needs access. Accounts are switched off immediately when access is no longer needed and deleted [within X weeks]. |
Records may be kept longer only if needed for a specific safeguarding concern or legal claim, in line with the school's own records retention policy.
6. Who can see it
- Parents never see any child's name or details through the service, including their own child's. Their phone only shows "waiting", the collection code, or "collected".
- Room staff see only the children collected from their own room.
- Reception sees the children waiting to be handed over and those collected that day.
- School administrators can see and manage all records.
- The processor accesses data only to support and maintain the service, on the school's instructions.
Information is not shared with anyone else unless the law requires it (for example, to the police or children's services for safeguarding reasons).
7. How the information is protected
- All connections are encrypted (HTTPS/TLS), and data is encrypted at rest by the hosting provider.
- Collection and staff passwords are stored only as salted hashes (bcrypt) and cannot be read by anyone, including the school and the provider.
- Database rules check every request, so each login can only see and do what its role allows.
- Repeated wrong passwords from the same device are blocked for 10 minutes.
- Each hand-over requires a one-time code shown only on the parent's phone.
- Staff screens can be restricted to the school's own network, and reception can be restricted to one registered computer.
- Staff are signed out automatically at the end of each school day, and every login, logout and action is recorded.
- Only school administrators can change passwords or create logins.
If a personal data breach occurs, the processor will tell the school without undue delay, and the school will report it to the ICO within 72 hours where required.
8. Cookies and storage on your device
The service does not use advertising, analytics or tracking cookies. It uses only small items of browser storage that are strictly necessary for it to work, so no consent banner is needed under the Privacy and Electronic Communications Regulations (PECR):
- Parent's phone: a random device reference (to slow down password guessing) and, for the open browser tab only, the collection ticket. Your child's name and password are never stored on your phone.
- Staff devices: the login session, the chosen room (for administrators), and on the reception computer a registration key.
Fonts are loaded from Google Fonts and code libraries from jsDelivr and cdnjs, which receive your IP address as part of delivering those files. [Provider may self-host these to remove this.]
9. Children
The service is designed to be used by parents, carers and school staff, not by children. It holds only the minimum information about pupils needed to keep them safe at collection, in line with the ICO's Age Appropriate Design Code (Children's Code) principles of data minimisation and privacy by default.
10. Your rights
Under UK data protection law you have the right to:
- be told how your information is used (this notice);
- ask for a copy of your information (a subject access request);
- ask for inaccurate information to be corrected;
- ask for information to be deleted or its use restricted, where the law allows;
- object to the use of your information where it relies on legitimate interests.
Parents and carers can usually exercise these rights on behalf of their child. To make a request, contact the school's Data Protection Lead: [email]. The school will normally respond within one month.
11. Complaints and the Information Commissioner's Office
Please raise any concern with the school first at [email]. If you are not satisfied, you can complain to the UK regulator:
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk/make-a-complaint
12. Laws, guidance and standards
- UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.
- Privacy and Electronic Communications Regulations 2003 (PECR), which cover cookies and device storage.
- ICO Age Appropriate Design Code (the Children's Code).
- Keeping Children Safe in Education (Department for Education statutory guidance).
- Information security: the service is built following the principles of ISO/IEC 27001 and the National Cyber Security Centre's guidance. [The provider does not currently hold ISO/IEC 27001 or Cyber Essentials certification — update this if certification is obtained.]
- The hosting providers maintain their own independent security certifications, for example SOC 2 and ISO/IEC 27001. [Provider to confirm the current certificates.]
We will update this notice if the service changes. The version and date at the top show when it last changed.