1. Information we collect
We collect and process the following categories of personal data:
- Account details: Names, work email addresses, job titles, and school affiliation for staff who request demos, register interest, or access the EdVantage platform.
- Support communications: Messages sent to EdVantage, support notes, and feedback provided through forms or email.
- Usage information: Log and audit data generated when authorised users access the platform, including timestamps, actions performed, device, and browser metadata.
- Student records: Information uploaded by schools (for example student identifiers, support notes, chronology entries, attendance, behaviour, safeguarding, and SEND data). This data is processed strictly under the school's instructions.
- Cookies and website analytics: Essential cookies required to deliver the site and optional analytics cookies when visitors provide consent.
2. How we use information
We use personal data to:
- Provide, maintain, and improve the EdVantage platform and related services.
- Authenticate users, assign permissions, and protect accounts.
- Deliver customer support, onboarding, and product guidance.
- Monitor service reliability, investigate incidents, and meet audit requirements.
- Send operational notices about platform updates, security, or planned maintenance.
- Conduct aggregated analytics to inform product decisions (never to profile individual students).
3. Legal bases for processing
We rely on the following lawful bases under the UK GDPR and Data Protection Act 2018:
- Contract: Processing is necessary to deliver the services agreed with the school or organisation.
- Legitimate interests: Operating, securing, and improving the platform while balancing user privacy expectations.
- Legal obligations: Meeting statutory record-keeping, safeguarding, and regulatory requirements.
- Consent: When visitors opt in to optional communications or analytics cookies. Consent can be withdrawn at any time.
4. Sharing and sub-processors
We only share personal data with trusted service providers that support our operations. Each provider is subject to a written data processing agreement and security review.
- Hosting and infrastructure: Amazon Web Services (AWS) for UK/EU cloud hosting.
We never sell personal data. Any sub-processor changes are communicated to contracted schools in advance.
5. International data transfers
EdVantage hosts data within the United Kingdom. If a sub-processor transfers data outside the UK or European Economic Area, we ensure appropriate safeguards such as Standard Contractual Clauses (SCCs) and enforceable contractual commitments.
6. Data retention
We retain:
- Customer tenancy data for the duration of the contract plus up to 90 days for backup restoration unless a shorter period is requested.
- Support correspondence for up to two years to maintain service history and incident records.
- Prospective customer contact details for 18 months from last interaction unless consent is withdrawn earlier.
- System audit logs for a minimum of 12 months to meet safeguarding and accountability requirements.
Data is securely deleted or anonymised once it is no longer required.
7. Security measures
We implement administrative, technical, and organisational safeguards including:
- Encryption of data in transit (TLS 1.2+) and at rest.
- Role-based access controls with multi-factor authentication for privileged users.
- Network segmentation, automated vulnerability scanning, and continuous monitoring.
- Staff training on safeguarding, confidentiality, and secure handling of student information.
- Regular penetration testing and supplier assessments.
8. Student data responsibilities
Schools remain the data controller for student information added to EdVantage. We process that data solely under the school's documented instructions, implement confidentiality controls, and assist schools with safeguarding and subject access obligations.
9. Your rights
Depending on your role and location you may have rights to:
- Access a copy of the personal data we hold about you.
- Request corrections, updates, or deletion of inaccurate information.
- Object to or restrict processing in certain circumstances.
- Receive data you provided in a structured, commonly used format.
- Withdraw consent where processing relies on consent.
Schools can use the built-in subject access request tooling to fulfil student and guardian requests. Individuals should follow their school’s published data request process.
10. Cookies and similar technologies
Essential cookies maintain session security and load balancing. Optional analytics cookies are only set with consent and are configured to avoid personally identifiable tracking. You can adjust cookie settings through your browser or through in-app privacy controls.
11. Data protection requests
To exercise your rights or raise a concern, contact your school or trust using the data request form or contact route described in its privacy notice. Requests are acknowledged within one calendar month. If you are unsatisfied with the outcome you may escalate to the ICO.
12. Changes to this policy
We will publish any updates to this privacy policy on this page and provide advance notice to contracted schools for material changes. Continued use of EdVantage after updates take effect signifies acceptance of the revised terms.