Privacy Management
Statement
1. About this page
This statement explains, in plain language, how Reflective collects, uses, and protects personal data in connection with our education products used by schools, teachers, students, and homeschool families in the United Kingdom, and how we approach our obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act of 2018.
It is written for school Data Protection Officers (DPOs) and data protection leads who need to assess whether our products can be approved for use in their school. Where we have not yet finailised a policy, procedure, or decision, we say so plainly rather than describing something that is not yet in place.
A companion Data Processing Agreement, for schools acting as a data controller, is available as a separate document.
2. Who we are - the data controller
Reflective Learning Education Pty Ltd is the entity responsible for personal data processed through our products in connection with UK schools, and is the data controller referred to throughout this statement (subject to the controller/processor distinction explained in Section 3).
3. Our role: controller or processor?
This distinction matters to your assessment because it determines whose obligations apply to what data, and what contract needs to be in place between us.
- Where your school creates and manages accounts for your students and staff, your school is generally the data controller for that pupil and staff data, and Reflective acts as a processor, handling data only on your school's documented instructions.
- Where a parent, learner, or homeschool family signs up directly with us (outside of a school relationship), Reflective acts as the data controller for that individual's data.
4. What personal data we collect
We collect the minimum information needed to provide the service. The table below summarises the categories of data involved.
| Category | What this includes | Whose data |
|---|---|---|
| Student details | Name, email address, grade/class, gender (optional), date of birth (optional) | Students |
| Teacher details | Name, email address, phone number | Teachers |
| Direct-to-consumer details | Phone number, email address, payment information | Parents/learners who purchase directly (not via a school) |
| Contacts | Contact details a user chooses to share (e.g. to invite others or share reports) | Any individual whose details a user shares with us |
| Usage information | Actions taken in the product, features used, time on pages | All users |
| Device information | IP address, browser/device type, device identifiers, approximate location (device-dependent) | All users |
| Cookies and similar technologies | Session and preference data collected via cookies | All users |
We may also receive limited information from schools or institutions when they set up accounts on behalf of students, rather than collecting it directly from the student. Under Article 14 UK GDPR, this generally requires us to provide the same categories of information as above, at the point the account is created or first used.
5. Why we process this data (our legal basis)
We process personal data to provide the service reliably and securely, which relies mainly on the contract we have with the school or account holder (Article 6(1)(b) UK GDPR). We also rely on legitimate interests (Article 6(1)(f)) for activities such as service improvement and fraud prevention, and on consent (Article 6(1)(a)) where we use data for purposes beyond providing the core service.
The table below is an extract of our Record of Processing Activities (ROPA), setting out each processing activity we are aware of, its purpose, the data involved, and legal basis.
| Processing activity | Purpose | Data categories | Data subjects | Legal basis |
|---|---|---|---|---|
| Account creation & management | Provide and administer user accounts (sign-up, purchase, two-factor authentication) | Account information | Teachers, school admins, DTC parents/learners | Contract (Art. 6(1)(b)) |
| Delivery of core learning service | Enable students to use the product's learning features | Student details | Students | Contract (with school or parent) (Art. 6(1)(b)) |
| Contact-sharing / collaboration features | Enable sharing of learner reports and invitations to other users | Contacts | Individuals whose details a user shares | Consent / legitimate interests (Art. 6(1)(a)/(f)) |
| Usage analytics & service improvement | Improve the product, develop new features | Usage information | All users | Legitimate interests (Art. 6(1)(f)) |
| Device & technical data processing | Enable secure access, prevent fraud/abuse, maintain functionality | Device information | All users | Legitimate interests / contract necessity (Art. 6(1)(f)/(b)) |
| Cookies and similar technologies | Remember preferences, understand product interaction | Cookie data | All users / website visitors | Consent (non-essential) / legitimate interests (strictly necessary) |
| Product/service messages | Guide usage, communicate service updates | Account/contact information | Account holders | Legitimate interests / contract necessity |
| Aggregated industry insights | Produce aggregated, de-identified insights for the education sector | Aggregated/derived data | N/A once aggregated; source data from students/institutions | Legitimate interests (Art. 6(1)(f)), applied to aggregated output only |
| Visibility within an institution (e.g. leaderboards) | Enable collaboration/social features within the same school domain | Name, basic profile information | Users within the same institution domain | Legitimate interests / contract |
| Engaging technical sub-processors | Enable hosting, authentication, error monitoring, email delivery, and content delivery via named sub-processors (see Section 7) | Varies by sub-processor — see Section 7 | All users | Contract necessity (Art. 6(1)(b)) / legitimate interests |
| Legal, safety and fraud-prevention disclosures | Comply with law, protect safety, prevent fraud or abuse | Data relevant to the specific request | Any individual involved | Legal obligation / vital interests / legitimate interests (Art. 6(1)(c)/(d)/(f)) |
| Government/public sector aggregated reporting | Provide sector-level insight to government or the public | Aggregated institutional-level data | N/A (aggregated) | Legitimate interests (Art. 6(1)(f)) |
| Account deletion and retention management | Fulfil deletion requests; manage data in line with retention position (Section 9) | All categories | All users | Legal obligation / contract |
| Adaptive learning / personalisation | Tailor content or pace within the product based on a student's performance | Student details, usage information | Students | Contract (Art. 6(1)(b)) — core to service delivery |
| Progress reporting to parents/guardians | Share summaries of a student's progress or performance | Student details, usage information | Students (data shared with parents/guardians) | Contract (with school or parent) (Art. 6(1)(b)) |
| Marketing communications | Promotional communications to schools or direct-to-consumer customers, distinct from in-service product messages | Account information | Prospective and existing school contacts, DTC customers | Consent (Art. 6(1)(a)) for individuals, or legitimate interests (Art. 6(1)(f)) for B2B contacts acting in a professional capacity — subject to PECR electronic marketing rules |
6. Children's data
Much of the personal data we process relates to children. We collect the minimum student information needed to deliver the service (see Section 4), and student accounts are typically created and managed by the school rather than the child directly.
7. Who we share data with
We do not sell personal data to advertisers or other third parties. We share data with the named sub-processors below, who process it on our instructions to help us provide the service, and in limited circumstances with other users (for example, names shown to other users on the same institution's account) or where required by law. We hold Data Protection Agreements with each sub-processor, incorporated into our terms of service with them.
| Sub-processor | Function | Location | UK transfer position |
|---|---|---|---|
| MongoDB Atlas | Database hosting | Belgium (EEA) | UK-adequate — Belgium is covered by UK adequacy regulations as an EEA state |
| Firebase / Google | User identity and authentication | United States | Claimed Data Privacy Framework participant — see verification note below |
| Sentry | Error monitoring | United States | Claimed Data Privacy Framework participant — see verification note below |
| SendGrid (Twilio) | Email delivery | United States | Claimed Data Privacy Framework participant — see verification note below |
| Cloudflare | Content delivery / network security | United States | Claimed Data Privacy Framework participant — see verification note below |
| SwarmCDN | Content delivery | United States | No Data Privacy Framework participation stated — see gap note below |
8. Where your data is stored and international transfers
Our database hosting is provided by MongoDB Atlas in Belgium, which is where personal data is stored. Belgium is part of the European Economic Area and is covered by the UK's data protection adequacy regulations, so this transfer does not require an additional safeguard.
Our other named technical sub-processors are US-based; transfers to US organisations self-certified under the UK Extension to the Data Privacy Framework (the “UK-US Data Bridge”) are similarly treated as adequate.
Separately from the sub-processor infrastructure above, Reflective Learning Education Pty Ltd (“we”/”us”) is itself incorporated and operating in South Africa. UK personal data being accessed or processed by our own staff or systems in the course of providing the service is a restricted transfer in its own right, regardless of where the underlying database sits. This transfer will be governed by the EU Standard Contractual Clauses (Module 2: Controller to Processor) together with the UK Addendum, as set out in Schedule 4 of the Data Processing Agreement.
9. How long we keep data
Where you have an active account, we retain data for as long as the account exists or as long as needed to provide the service. If an account becomes inactive, student details are archived. We keep data only while there is a continued, valid reason to store or process it.
You, or your school, can request deletion of account data in writing, including enough identifying detail for us to verify the request. We aim to initiate deletion within 30 days of a valid request. Deletion requests from accounts under an active contract may be treated as invalid where deletion would disrupt the service being provided under that contract; in that case, deletion follows contract termination instead. Data is deleted from cloud storage, databases, and backups using secure deletion methods (such as cryptographic erasure or overwriting), with backups cleared in line with the backup retention period agreed with the school. We can provide confirmation of deletion on request.
We will not delete data where we need to keep it to meet a legal obligation, resolve a dispute, enforce an agreement, or for another legitimate business purpose, and we may anonymise data instead of deleting it where appropriate and not otherwise restricted.
10. Keeping data secure
Our ISO 27001 programme is in progress. We track this work through our Sprinto compliance platform, and our compliance status is near 100%, however formal certification still to follow.
Our key infrastructure providers hold independent security certifications: MongoDB Atlas (Belgium) holds ISO 27001:2022 and SOC 2 Type II; Google Cloud Platform, which underpins our authentication service, holds ISO 27001, ISO 27017 (cloud security), ISO 27018 (privacy in the cloud), and SOC 1/2/3.
11. Your rights and how to exercise them
You, or (in the case of a child) your parent or carer, have the following rights under UK GDPR:
| Right | What it means |
|---|---|
| Access | Ask us to confirm what personal data we hold about you and provide a copy of it. |
| Rectification | Ask us to correct inaccurate or incomplete personal data. |
| Erasure | Ask us to delete personal data, where applicable grounds apply. |
| Restriction | Ask us to limit how we use your data in certain circumstances. |
| Objection | Object to processing carried out on the basis of legitimate interests. |
| Data portability | Ask us to provide certain data in a portable, machine-readable format. |
| Withdraw consent | Where processing relies on consent, withdraw it at any time without affecting past lawful processing. |
| Complain to the ICO | Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) if you believe your rights have not been respected. |
Where a school holds the pupil data as controller, requests should usually go to the school first, as they hold the wider record. Where we are the controller (for example, direct-to-consumer accounts), or where a school directs a request to us, you can contact us at privacy@reflective.global.
We handle requests in line with the following statutory and best-practice timescale:
- We acknowledge receipt of a request promptly.
- If we need to verify your identity, or clarify what you are asking for, we will do so as early as possible; the response clock runs from receipt of a valid request, or from receipt of satisfactory identification or clarification where this was needed.
- We respond within one calendar month of a valid request, in line with UK GDPR.
- Where a request is complex or we have received a number of requests, we may extend this by up to two further months (three months in total). If we do this, we will tell you within the first month, and explain why.
12. If something goes wrong (data breaches)
We take data security seriously and maintain an internal Data Breach Notification Policy covering how we detect, assess, and respond to data breaches. Under this policy, any member of staff who discovers a potential breach must report it to our Information Security Officer immediately. The Information Security Officer then investigates and carries out a documented risk assessment of the potential harm involved. Where that assessment concludes there is a significant risk of harm, notification follows without undue delay, and within 72 hours of us becoming aware where feasible; where a 72-hour notification is not possible, the reasons for the delay are documented and provided.
13. Data Protection Officer
Our Data Protection Officer is:
- Name: Aidan Wilmot
- Role: Chief Technology Officer
- Contact: privacy@reflective.global
14. How we govern data protection
We manage our compliance obligations, including ISO 27001 and UK GDPR, through the Sprinto compliance platform, which provides visibility across our frameworks and entities.
Data protection accountability (as described in the Information Commissioner's Office's accountability guidance) means being able to demonstrate compliance through appropriate policies, procedures, and oversight, not simply asserting it. This statement is part of that ongoing work, and we expect to update it as our UK GDPR programme matures.
15. Changes to this document
We may update this statement from time to time as our practices, or the underlying law, change. Where a change meaningfully affects your rights, we will take reasonable steps to notify schools using our services.
16. Contact us
For questions about this statement or how we handle personal data, contact us at privacy@reflective.global.

