Privacy Policy

Last updated: June 17, 2025

1. Introduction

This Privacy Policy explains how Curriculum Tracker ("we," "us," "our") collects, uses, and protects data on behalf of the schools and trusts ("you," "your") that use our service. This document is designed to provide you with the information necessary to complete your Data Protection Impact Assessment (DPIA) and to be transparent about our data processing activities.

2. What Data We Collect

Our application is designed to be privacy-focused by collecting the minimum amount of data necessary to provide our curriculum tracking service. We do not collect or process any personal data relating to students.

The data we process falls into the following categories:

3. How We Use Your Data (Purpose of Processing)

We process the collected data strictly to provide and improve the Curriculum Tracker service. The purposes include:

4. Usernames and Personal Data

The fields in our system that may contain directly identifiable personal information are the user's first name, last name, and email address. We require an email address for authentication, particularly for password-free OAuth logins.

Your school or trust, in its role as Data Controller, is responsible for the accuracy of this information and for ensuring you have a lawful basis for providing it.

5. Data Security

We take data security seriously. All user passwords are "hashed" using a modern, secure algorithm, meaning we never store plaintext passwords. Our application also uses secure session management techniques to protect user accounts.

6. International Transfers & Hosting Locations

All personal data that we control are stored and processed exclusively in secure data centres located in the United Kingdom and provided by Hostinger UK. We do not transfer your personal data outside the UK.

7. Data Sharing and Third Parties

We do not sell, rent, or share any of the data you provide with third parties for marketing or other purposes. Data is processed only within our secure environment to provide the Curriculum Tracker service.

8. Data Retention

Data is retained for the duration of our service agreement with your school or trust. School and Trust administrators are responsible for the data lifecycle. We will delete your school's data upon termination of the contract or upon receiving a verified request from an authorized representative of your school.

9. Administrator Deletion Rights

Authorised school and trust administrators can permanently delete staff accounts—and all associated personal data—at any time via the administration consoles. Deletions take effect immediately in the live environment and propagate to encrypted backups within 6 weeks.

10. Contact Us

If you have any questions about this Privacy Policy or our data processing practices, please contact us at:

Contact Email Address