Privacy Policy
Last updated: 31 July 2026
EduWrite (“we”, “us”, “our”) is a handwriting-first learning platform for UK primary schools. We are committed to protecting the privacy of teachers, students, school administrators, SaaS support staff, and visitors to our platform. This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over that data.
This policy is written in plain English and complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018). This SaaS administration platform is a restricted environment; the policy below applies platform-wide.
1. Who we are
EduWrite is the data controller for the personal data described in this policy. This means we decide how and why your personal data is processed. For school deployments, the school itself may also act as a joint controller for the student and class data it provides to us.
Contact details: EduWrite, support@eduwrite.app. We will respond to privacy enquiries within 30 days, as required by UK GDPR.
2. What personal data we collect
We collect only the personal data needed to deliver and administer the service (data minimisation). This includes:
Teacher and school administrator data
- Account data: full name, work email address, password (stored as a one-way hash).
- School data: school name, organisation ID, role within the school.
- Usage data: activities created, classes managed, assignments given, and feedback provided.
Student data
- Display name: a name chosen by the teacher. Where possible, display names are used instead of legal names.
- Class and year group: used to assign age-appropriate content (Reception to Year 6).
- Stroke data: the handwriting strokes a child produces on a tablet, including timing and pressure. This is personal data because it can identify a child through their handwriting.
- Submission records: completed activities, scores, and teacher feedback.
- Device data: the tablet is authorised via a QR code at the school level. Students do not log in with personal credentials, and we do not collect student contact details or geolocation.
SaaS platform data
- Admin data: SaaS support staff accounts, impersonation audit logs, billing and plan information for school organisations.
- Audit logs: immutable records of administrative actions including
UPDATE_PLAN,DELETE_ORGANIZATION, andIMPERSONATE.
3. Lawful basis for processing
We rely on the following lawful bases under UK GDPR Article 6:
- Contract (Art. 6(1)(b)): processing teacher, student, and school data to deliver the service.
- Legal obligation (Art. 6(1)(c)): retaining billing and audit records where required by law.
- Legitimate interests (Art. 6(1)(f)): platform security, fraud prevention, and product improvement, balanced against the privacy rights of users, particularly children.
- Consent (Art. 6(1)(a)): where we ask for consent (for example, optional analytics), it can be withdrawn at any time.
For children's data, we rely on the school's contractual relationship and the school's authority to act on behalf of parents and carers.
4. How we use your data
- To create and manage teacher, administrator, and student accounts.
- To assign, deliver, and mark handwriting and learning activities.
- To run handwriting recognition (OCR) and AI analysis on stroke data so teachers receive learning aids. Recognition outputs are learning aids only and are never used as the sole basis for assessment decisions.
- To maintain tenant isolation: one school cannot access another school's data.
- To keep immutable audit logs of SaaS administrative actions, including impersonation events.
- To provide customer support and respond to privacy enquiries.
We do not use personal data for profiling, targeted advertising, or nudge techniques targeted at children, in line with the ICO Age Appropriate Design Code.
5. Who we share data with
We do not sell personal data. We share data only with the following categories of recipient:
- Cloud infrastructure providers: hosting, database, and object storage. All providers are bound by written agreements that prohibit use of customer data for their own purposes.
- Recognition providers: handwriting OCR and AI analysis providers, configured per deployment.
- Your school: teachers and administrators within your school can see the data for their own classes and students, scoped by
orgId. - Legal and regulatory bodies: where required by law, court order, or to safeguard a child.
6. International transfers
Personal data is stored and processed primarily in the United Kingdom and the European Economic Area. Where any transfer to a country outside the UK/EEA is necessary, it is made only under an appropriate safeguard such as UK International Data Transfer Agreements, the UK Addendum to the EU Standard Contractual Clauses, or reliance on a recognised adequacy decision.
7. Data retention
- Active accounts: data is retained for as long as the school remains a customer.
- Churned accounts: 30-day retention window for late-payment recovery, after which an automated job (
DeleteChurnedTenantsJob) permanently wipes all tenant data byorg_id, recorded as an immutable audit event. - Staff offboarding: teachers are deactivated (
is_active = false); JWTs are rejected on every subsequent request. Historical data is preserved for school continuity. - Audit logs: SaaS admin audit logs are retained for the longer of (a) 6 years or (b) the period required by applicable law.
8. Children's data
EduWrite is designed for children aged 4 to 11 (Reception to Year 6). We apply the ICO Age Appropriate Design Code and, where applicable, COPPA:
- High privacy by default: student accounts expose the minimum data needed to take part in activities.
- No profiling or nudge techniques targeted at children.
- No targeted advertising. EduWrite contains no advertising of any kind.
- Display names are used instead of legal names where possible.
- No student contact information (email, phone) is collected.
- No geolocation is collected from student devices.
- Verifiable parental consent: schools are responsible for obtaining appropriate consent or authority from parents and carers before student data is provided to EduWrite.
9. Your rights
Under UK GDPR you have the following rights. You can exercise any of them by contacting us at support@eduwrite.app.
- The right to be informed — this policy.
- The right of access — a copy of the personal data we hold about you.
- The right to rectification — correcting inaccurate or incomplete data.
- The right to erasure — subject to legal exceptions (for example, retaining audit logs).
- The right to restrict processing — limiting how we use your data while a concern is resolved.
- The right to data portability — receiving your data in a structured, machine-readable format.
- The right to object — to processing based on legitimate interests or for direct marketing.
- Rights in relation to automated decision-making and profiling — we do not carry out solely automated decision-making with legal or similarly significant effects on individuals.
We will verify identity before disclosing personal data and will respond within one month (extendable by two further months for complex requests, with explanation).
10. Cookies and similar technologies
We do not use third-party advertising or tracking cookies. Authentication tokens are held in browser storage for the duration of a signed-in session. Where optional analytics are enabled, they are governed by a separate consent prompt and can be withdrawn at any time.
11. Security
- Authentication: passwords are stored as one-way hashes. JWTs are short-lived and refreshed automatically. SaaS admin sessions are shorter (1 hour) when impersonating.
- Tenant isolation: every database query is scoped by
org_idtaken from the validated token, never from client input. - Default-deny APIs: every API endpoint and real-time event handler requires authentication and authorisation unless explicitly marked as public.
- Encryption: data is encrypted in transit (HTTPS) and at rest.
- Access control: stroke data and submissions are stored in access-controlled storage, never in public buckets.
- Audit: SaaS admin actions (including impersonation) are immutably logged to
saas_audit_logs.
If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the ICO within 72 hours of becoming aware of it, and notify affected individuals without undue delay where the risk is high.
12. Changes to this policy
We may update this policy as the platform evolves. The “Last updated” date at the top of this page will reflect the most recent change. Where a change materially affects how we process children's data, we will notify affected schools directly before the change takes effect.
13. How to complain
If you have a concern about how we handle personal data and we cannot resolve it, you have the right to complain to the Information Commissioner's Office (ICO), the UK's independent data protection authority:
- Website: https://ico.org.uk
- Phone: 0303 123 1113 (local rate) or 01625 545 745
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would, however, appreciate the chance to address your concerns before you contact the ICO.
14. Contact us
For any privacy question, request, or complaint, contact us at support@eduwrite.app.
© 2026 EduWrite. EduWrite® and the EduWrite logo are trademarks of EduWrite. Handwriting recognition is provided as a learning aid and should not be used as the sole basis for assessment decisions.