Skip to main content
Legal

PRIVACY POLICY

How we handle personal data — on this website, and inside the platform where we process student records on behalf of a school.

Last updated 23 August 2026

Two different roles

This policy covers two situations that are legally distinct, and it matters which one applies to you.

Where Skoolarz is the controller. For this website, our sales and support correspondence, and our own business records, we decide what personal data is collected and why. That is the first half of this policy.

Where Skoolarz is a processor. Student, parent and staff records inside a school's instance belong to that school. The school decides what is collected, who may see it and how long it is kept; we process it on the school's documented instructions under a written agreement. If you are a parent or student, your school — not Skoolarz — is the organisation to approach about your records, and we will direct you back to them.

Data we collect on this website

  • Contact form submissions — the name, email address, school name, telephone number and message you send us. We use these to reply to you and to maintain a record of the enquiry.
  • Server logs — IP address, browser user agent, requested URL and timestamp, generated automatically by our web server and retained for security and troubleshooting.
  • Anti-spam checks — form submissions are checked with Google reCAPTCHA, which involves your interaction with the form being assessed by Google. See our cookie notice for detail.
  • Analytics — where enabled, aggregate measurement of page visits via Google Tag Manager. This is described, and can be declined, in the cookie notice.

We do not sell personal data, we do not share it with advertising networks, and we do not build marketing profiles from your browsing of this site.

Data inside the platform

A school instance typically contains: student names and dates of birth, guardian names and contact details, the relationship between them, class allocation, attendance records, coursework and grades, fee plans, invoices and payment records, bus route assignment, and account credentials for each user. Schools may add further fields; what a school chooses to record is the school's decision.

Skoolarz staff access to that data is limited to what is needed to provide support, is limited by role, is time-bound, and is logged. We do not browse school data for product research and we do not use student records to train machine-learning models.

PurposeBasis
Replying to an enquiry you sent usYour request, and our legitimate interest in responding
Providing the platform to a schoolContract with the school; the school's own basis applies to the underlying records
Security logging and abuse preventionLegitimate interest in keeping the service secure
Billing and statutory accounting recordsContract and legal obligation
Optional analyticsConsent, which you can withdraw

Who we share it with

We use a small number of service providers, and we would rather name the categories than hide them in a clause:

  • Hosting and infrastructure — the data centre region named in the school's contract.
  • Transactional email delivery — for invitations, notifications and announcement emails.
  • Live class video — Jitsi Meet, where a school enables live classes.
  • SMS delivery — a regional gateway, where a school enables SMS.
  • Payment processing — where enabled, handled by the payment provider. Card details never reach Skoolarz systems.

The current list, with jurisdictions, forms an annex to each school's agreement and is updated when it changes. We do not transfer school data outside the agreed region without written agreement, and we disclose data to authorities only where legally compelled — in which case we will notify the school unless prohibited from doing so.

How long we keep it

  • Website enquiries — 24 months from last contact, unless you ask us to delete sooner.
  • Server logs — 90 days.
  • School platform data — for the life of the agreement, and then for the period stated in that agreement before deletion. A full export is provided on termination.
  • Billing records — as required by applicable accounting law.

Your rights

Depending on where you are, you may have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to certain processing, and to receive it in a portable format.

For data we hold as controller — website enquiries, correspondence — write to us and we will respond within 30 days. For records inside a school's instance, contact the school; they hold the decision, and we will support them in fulfilling your request.

Security

Data is encrypted in transit. Access is role-based and logged. Managed instances are backed up daily with point-in-time recovery retained for 30 days, and restores are rehearsed on a schedule rather than assumed. We are not currently certified against ISO 27001 or SOC 2, and we say so plainly rather than implying otherwise. Further operational detail is on the security page.

Children's data

The platform necessarily holds data about children, and every design decision around it is made on that basis. Student accounts are created by the school, not self-registered. Students see only their own records. Parent access is established through a guardian link held by the school, and that link can be ended and audited — because custody arrangements change. We do not market to students, we do not show advertising in the platform, and we do not use student data for any purpose beyond providing the service to the school.

Changes and contact

If we change this policy materially we will update the date at the top and notify schools under contract in advance. Historic versions are available on request.

Questions about this policy, or a request relating to your data, can be sent through the contact form marked for the attention of the data protection contact.