Privacy Management
Statement

1. About this page

This statement explains, in plain language, how Reflective collects, uses, and protects personal data in connection with our education products used by schools, teachers, students, and homeschool families in the United Kingdom, and how we approach our obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act of 2018.

It is written for school Data Protection Officers (DPOs) and data protection leads who need to assess whether our products can be approved for use in their school. Where we have not yet finailised a policy, procedure, or decision, we say so plainly rather than describing something that is not yet in place.

A companion Data Processing Agreement, for schools acting as a data controller, is available as a separate document.

2. Who we are - the data controller

Reflective Learning Education Pty Ltd is the entity responsible for personal data processed through our products in connection with UK schools, and is the data controller referred to throughout this statement (subject to the controller/processor distinction explained in Section 3).

3. Our role: controller or processor?

This distinction matters to your assessment because it determines whose obligations apply to what data, and what contract needs to be in place between us.

  • Where your school creates and manages accounts for your students and staff, your school is generally the data controller for that pupil and staff data, and Reflective acts as a processor, handling data only on your school's documented instructions.
  • Where a parent, learner, or homeschool family signs up directly with us (outside of a school relationship), Reflective acts as the data controller for that individual's data.

4. What personal data we collect

We collect the minimum information needed to provide the service. The table below summarises the categories of data involved.

CategoryWhat this includesWhose data
Student detailsName, email address, grade/class, gender (optional), date of birth (optional)Students
Teacher detailsName, email address, phone numberTeachers
Direct-to-consumer detailsPhone number, email address, payment informationParents/learners who purchase directly (not via a school)
ContactsContact details a user chooses to share (e.g. to invite others or share reports)Any individual whose details a user shares with us
Usage informationActions taken in the product, features used, time on pagesAll users
Device informationIP address, browser/device type, device identifiers, approximate location (device-dependent)All users
Cookies and similar technologiesSession and preference data collected via cookiesAll users

We may also receive limited information from schools or institutions when they set up accounts on behalf of students, rather than collecting it directly from the student. Under Article 14 UK GDPR, this generally requires us to provide the same categories of information as above, at the point the account is created or first used.

5. Why we process this data (our legal basis)

We process personal data to provide the service reliably and securely, which relies mainly on the contract we have with the school or account holder (Article 6(1)(b) UK GDPR). We also rely on legitimate interests (Article 6(1)(f)) for activities such as service improvement and fraud prevention, and on consent (Article 6(1)(a)) where we use data for purposes beyond providing the core service.

The table below is an extract of our Record of Processing Activities (ROPA), setting out each processing activity we are aware of, its purpose, the data involved, and legal basis.

Processing activityPurposeData categoriesData subjectsLegal basis
Account creation & managementProvide and administer user accounts (sign-up, purchase, two-factor authentication)Account informationTeachers, school admins, DTC parents/learnersContract (Art. 6(1)(b))
Delivery of core learning serviceEnable students to use the product's learning featuresStudent detailsStudentsContract (with school or parent) (Art. 6(1)(b))
Contact-sharing / collaboration featuresEnable sharing of learner reports and invitations to other usersContactsIndividuals whose details a user sharesConsent / legitimate interests (Art. 6(1)(a)/(f))
Usage analytics & service improvementImprove the product, develop new featuresUsage informationAll usersLegitimate interests (Art. 6(1)(f))
Device & technical data processingEnable secure access, prevent fraud/abuse, maintain functionalityDevice informationAll usersLegitimate interests / contract necessity (Art. 6(1)(f)/(b))
Cookies and similar technologiesRemember preferences, understand product interactionCookie dataAll users / website visitorsConsent (non-essential) / legitimate interests (strictly necessary)
Product/service messagesGuide usage, communicate service updatesAccount/contact informationAccount holdersLegitimate interests / contract necessity
Aggregated industry insightsProduce aggregated, de-identified insights for the education sectorAggregated/derived dataN/A once aggregated; source data from students/institutionsLegitimate interests (Art. 6(1)(f)), applied to aggregated output only
Visibility within an institution (e.g. leaderboards)Enable collaboration/social features within the same school domainName, basic profile informationUsers within the same institution domainLegitimate interests / contract
Engaging technical sub-processorsEnable hosting, authentication, error monitoring, email delivery, and content delivery via named sub-processors (see Section 7)Varies by sub-processor — see Section 7All usersContract necessity (Art. 6(1)(b)) / legitimate interests
Legal, safety and fraud-prevention disclosuresComply with law, protect safety, prevent fraud or abuseData relevant to the specific requestAny individual involvedLegal obligation / vital interests / legitimate interests (Art. 6(1)(c)/(d)/(f))
Government/public sector aggregated reportingProvide sector-level insight to government or the publicAggregated institutional-level dataN/A (aggregated)Legitimate interests (Art. 6(1)(f))
Account deletion and retention managementFulfil deletion requests; manage data in line with retention position (Section 9)All categoriesAll usersLegal obligation / contract
Adaptive learning / personalisationTailor content or pace within the product based on a student's performanceStudent details, usage informationStudentsContract (Art. 6(1)(b)) — core to service delivery
Progress reporting to parents/guardiansShare summaries of a student's progress or performanceStudent details, usage informationStudents (data shared with parents/guardians)Contract (with school or parent) (Art. 6(1)(b))
Marketing communicationsPromotional communications to schools or direct-to-consumer customers, distinct from in-service product messagesAccount informationProspective and existing school contacts, DTC customersConsent (Art. 6(1)(a)) for individuals, or legitimate interests (Art. 6(1)(f)) for B2B contacts acting in a professional capacity — subject to PECR electronic marketing rules

6. Children's data

Much of the personal data we process relates to children. We collect the minimum student information needed to deliver the service (see Section 4), and student accounts are typically created and managed by the school rather than the child directly.

7. Who we share data with

We do not sell personal data to advertisers or other third parties. We share data with the named sub-processors below, who process it on our instructions to help us provide the service, and in limited circumstances with other users (for example, names shown to other users on the same institution's account) or where required by law. We hold Data Protection Agreements with each sub-processor, incorporated into our terms of service with them.

Sub-processorFunctionLocationUK transfer position
MongoDB AtlasDatabase hostingBelgium (EEA)UK-adequate — Belgium is covered by UK adequacy regulations as an EEA state
Firebase / GoogleUser identity and authenticationUnited StatesClaimed Data Privacy Framework participant — see verification note below
SentryError monitoringUnited StatesClaimed Data Privacy Framework participant — see verification note below
SendGrid (Twilio)Email deliveryUnited StatesClaimed Data Privacy Framework participant — see verification note below
CloudflareContent delivery / network securityUnited StatesClaimed Data Privacy Framework participant — see verification note below
SwarmCDNContent deliveryUnited StatesNo Data Privacy Framework participation stated — see gap note below

8. Where your data is stored and international transfers

Our database hosting is provided by MongoDB Atlas in Belgium, which is where personal data is stored. Belgium is part of the European Economic Area and is covered by the UK's data protection adequacy regulations, so this transfer does not require an additional safeguard.

Our other named technical sub-processors are US-based; transfers to US organisations self-certified under the UK Extension to the Data Privacy Framework (the “UK-US Data Bridge”) are similarly treated as adequate.

Separately from the sub-processor infrastructure above, Reflective Learning Education Pty Ltd (“we”/”us”) is itself incorporated and operating in South Africa. UK personal data being accessed or processed by our own staff or systems in the course of providing the service is a restricted transfer in its own right, regardless of where the underlying database sits. This transfer will be governed by the EU Standard Contractual Clauses (Module 2: Controller to Processor) together with the UK Addendum, as set out in Schedule 4 of the Data Processing Agreement.

9. How long we keep data

Where you have an active account, we retain data for as long as the account exists or as long as needed to provide the service. If an account becomes inactive, student details are archived. We keep data only while there is a continued, valid reason to store or process it.

You, or your school, can request deletion of account data in writing, including enough identifying detail for us to verify the request. We aim to initiate deletion within 30 days of a valid request. Deletion requests from accounts under an active contract may be treated as invalid where deletion would disrupt the service being provided under that contract; in that case, deletion follows contract termination instead. Data is deleted from cloud storage, databases, and backups using secure deletion methods (such as cryptographic erasure or overwriting), with backups cleared in line with the backup retention period agreed with the school. We can provide confirmation of deletion on request.

We will not delete data where we need to keep it to meet a legal obligation, resolve a dispute, enforce an agreement, or for another legitimate business purpose, and we may anonymise data instead of deleting it where appropriate and not otherwise restricted.

10. Keeping data secure

Our ISO 27001 programme is in progress. We track this work through our Sprinto compliance platform, and our compliance status is near 100%, however formal certification still to follow.

Our key infrastructure providers hold independent security certifications: MongoDB Atlas (Belgium) holds ISO 27001:2022 and SOC 2 Type II; Google Cloud Platform, which underpins our authentication service, holds ISO 27001, ISO 27017 (cloud security), ISO 27018 (privacy in the cloud), and SOC 1/2/3.

11. Your rights and how to exercise them

You, or (in the case of a child) your parent or carer, have the following rights under UK GDPR:

RightWhat it means
AccessAsk us to confirm what personal data we hold about you and provide a copy of it.
RectificationAsk us to correct inaccurate or incomplete personal data.
ErasureAsk us to delete personal data, where applicable grounds apply.
RestrictionAsk us to limit how we use your data in certain circumstances.
ObjectionObject to processing carried out on the basis of legitimate interests.
Data portabilityAsk us to provide certain data in a portable, machine-readable format.
Withdraw consentWhere processing relies on consent, withdraw it at any time without affecting past lawful processing.
Complain to the ICOLodge a complaint with the UK Information Commissioner's Office (ico.org.uk) if you believe your rights have not been respected.

Where a school holds the pupil data as controller, requests should usually go to the school first, as they hold the wider record. Where we are the controller (for example, direct-to-consumer accounts), or where a school directs a request to us, you can contact us at privacy@reflective.global.

We handle requests in line with the following statutory and best-practice timescale:

  • We acknowledge receipt of a request promptly.
  • If we need to verify your identity, or clarify what you are asking for, we will do so as early as possible; the response clock runs from receipt of a valid request, or from receipt of satisfactory identification or clarification where this was needed.
  • We respond within one calendar month of a valid request, in line with UK GDPR.
  • Where a request is complex or we have received a number of requests, we may extend this by up to two further months (three months in total). If we do this, we will tell you within the first month, and explain why.

12. If something goes wrong (data breaches)

We take data security seriously and maintain an internal Data Breach Notification Policy covering how we detect, assess, and respond to data breaches. Under this policy, any member of staff who discovers a potential breach must report it to our Information Security Officer immediately. The Information Security Officer then investigates and carries out a documented risk assessment of the potential harm involved. Where that assessment concludes there is a significant risk of harm, notification follows without undue delay, and within 72 hours of us becoming aware where feasible; where a 72-hour notification is not possible, the reasons for the delay are documented and provided.

13. Data Protection Officer

Our Data Protection Officer is:

  • Name: Aidan Wilmot
  • Role: Chief Technology Officer
  • Contact: privacy@reflective.global

14. How we govern data protection

We manage our compliance obligations, including ISO 27001 and UK GDPR, through the Sprinto compliance platform, which provides visibility across our frameworks and entities.

Data protection accountability (as described in the Information Commissioner's Office's accountability guidance) means being able to demonstrate compliance through appropriate policies, procedures, and oversight, not simply asserting it. This statement is part of that ongoing work, and we expect to update it as our UK GDPR programme matures.

15. Changes to this document

We may update this statement from time to time as our practices, or the underlying law, change. Where a change meaningfully affects your rights, we will take reasonable steps to notify schools using our services.

16. Contact us

For questions about this statement or how we handle personal data, contact us at privacy@reflective.global.