Privacy Policy
Last updated: 27 July 2026
This policy explains what BlueAcorn Education does with personal data – staff and students at the schools that use the platform. Section 4 is the important one for a school assessing us: it lists every outside company that sees the information a school puts in, and says plainly which of them see student work.
1 Who is responsible
BlueAcorn Education is operated by BlueAcorn Education Ltd, a company registered in England and Wales under company number 17363744, with its registered office at 66 Paul Street, London, England, EC2A 4NA. Our ICO registration number is ZC207937.
Contact us about anything in this policy at [email protected], or write to us at the address above.
Our role depends on whose data it is:
- For student personal data, and for the staff accounts a school provisions, the school (or its academy trust or local authority) is the controller and we are a processor. We handle that data only to provide the platform, on the school’s documented instructions.
- For our own limited processing – keeping the platform secure, investigating abuse, monitoring reliability, managing our commercial relationship with the school, and handling enquiries from people who register their interest – we are the controller.
If you are a student or a parent, your school is the right first point of contact for questions and requests about your data.
2 Information about school staff
| What | Why |
|---|---|
| Name, email address, role (student, teacher, administrator) and school identifier | To create and run the account, apply the right permissions and show the right dashboards. |
| A salted, hashed password – or, where a school uses single sign-on, an identifier and tokens from Google Workspace or Microsoft Entra ID | To sign users in. We store a one-way hash, never the password itself. |
| Two-factor authentication secret, held encrypted, and recovery codes | To verify a one-time code at sign-in, where 2FA is enabled. |
| The content staff create: lessons, presentations, assignments, quizzes, classes and uploaded resources | To generate, store and show that work. |
| Session records, IP address, browser and device characteristics, and sign-in timestamps | To keep sessions valid, detect a session moving to a new device and prompt for re-authentication. |
| Server logs, traces and error records | To keep the platform working and secure. |
| Name, email address and school submitted through the “register interest” form | To respond to the enquiry and arrange access. We are the controller for this. |
We do not run advertising and we do not sell personal data. There is no advertising pixel and no advertising or marketing tracker anywhere in the platform. We do use an application monitoring tool, which is described in section 8.
3 Information about students
Students use accounts their school creates for them. We never contact students directly and we never market to them. The student data we hold is:
- Account details – name, school email address, year or class enrolment, and role.
- Learning and progress data – lesson and module completion, quiz and exercise submissions, scores, achievements, assignment status and progress over time.
- Work submitted – typed answers, and drawings or handwritten answers made on the platform’s whiteboard, which are saved as images.
- Operational data – session records, IP address, device and browser characteristics and sign-in times, used for security.
Typed answers and whiteboard images are sent to an AI model to be marked, and the mark and feedback are returned to the student and their teacher. Section 4 sets out exactly who that is and where.
We do not ask for, and schools should not enter, more than a student’s name, school email and their work. In particular please do not include dates of birth, home contact details, medical or SEN information, safeguarding notes or any other special category data.
Student data is used only to provide the platform to the school. We do not analyse it for our own purposes, we do not sell it, we do not use it for advertising, and we do not train any AI model on it. The AI provider that sees student work is contractually barred from training its models on what we send it.
4 Who else sees it
We use a small number of outside companies to run the platform. Each acts only on our instructions, under a written contract that includes the data protection terms required by Article 28 of the UK GDPR. The “sees student data” column is the one to check if your school is assessing this service.
| Company | What it does | Where | Sees student data |
|---|---|---|---|
| Anthropic | AI models that generate lesson material and mark typed answers and whiteboard drawings | Contracted through Anthropic Ireland, Limited; processed in the United States | Yes – the answer or drawing being marked |
| Fly.io | Hosts the application | United Kingdom (London) | Yes – in transit |
| Aiven (on DigitalOcean infrastructure) | Hosts the database where everything is stored | Amsterdam, Netherlands | Yes |
| Bunny.net | Content delivery network that stores and serves presentation and slide assets | European Union, delivered from a global edge network | No – teaching resources only |
| Coralogix | Application monitoring, error tracking and browser session recording (see section 8) | European Union | Yes – through recordings of on-screen activity and error data |
| Amazon Web Services | S3 storage, in an account we control, holding the archive of monitoring data and session recordings | United Kingdom (London) | Yes – within those archived recordings |
| ZeptoMail (Zoho) | Sends transactional email – invitations, assignment notifications and password resets | European Union | Name and email address only |
| Google and Microsoft | Single sign-on, where a school has enabled it | European Union / United States | No – identity only, and only for schools that use SSO |
BA Productivity is not an outside company – it is us. It is another service run by BlueAcorn Education Ltd, so signing in to it with a BlueAcorn Education account keeps that information with the same company. It has its own privacy policy covering what it does with information there, and student data from this platform is not shared with it.
What this means in practice. Student work leaves our systems in one place: when a typed answer or a whiteboard drawing is sent to Anthropic to be marked, and the mark comes back. Anthropic is contractually prohibited from training its models on what we send it, and we contract with its Irish entity. Section 5 explains that transfer in detail.
The other providers – the CDN, transactional email and single sign-on – either see no student data at all or see only a name and email address. Hosting and the database do hold it, but inside the UK and the EEA (see section 5).
We may also disclose information if we are legally required to, or to establish, exercise or defend legal claims. If we are ever involved in a merger, acquisition or sale of the business, personal data may be transferred as part of it, and we will tell affected schools.
5 Sending information outside the UK
Where information is stored. The application runs on Fly.io in London, United Kingdom, and the database is hosted by Aiven, on DigitalOcean infrastructure, in Amsterdam, the Netherlands. The Netherlands is covered by UK adequacy regulations, so information stored there has the same protection as it would in the UK. Presentation and slide assets are stored with Bunny.net in the European Union and served from its global edge network. Monitoring data and session recordings are processed by Coralogix in the European Union and archived to Amazon S3 storage in an AWS account we control in London, United Kingdom. Nothing is stored at rest outside the UK or the EEA.
Where it is sent to be processed. One provider, and only one, receives data from outside our own systems: Anthropic, in the United States. Marking an answer means sending the typed answer or the whiteboard image to Anthropic and receiving the mark and feedback back, and generating lesson material means sending the teacher-authored topic and notes.
The United States is not covered by UK adequacy regulations, so that transfer needs an appropriate safeguard under Chapter V of the UK GDPR. Because we are a UK company, our contract is with Anthropic Ireland, Limited rather than Anthropic’s US entity, and a transfer to Ireland is covered by UK adequacy regulations. The processing itself still takes place in the United States. That onward transfer is governed by Anthropic’s data processing addendum, which is incorporated into our commercial agreement with them and includes the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum. Under it Anthropic acts as our processor and we remain the processor for the school. Anthropic publishes its own sub-processors at anthropic.com/subprocessors and must give notice before adding one.
Where any other provider processes data outside the UK or an adequate country, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another safeguard permitted under Chapter V, and carry out a transfer risk assessment.
6 Why we are allowed to use it
For student data and school-provided staff data, the school determines the lawful basis and gives us instructions. For a state school this is normally the performance of a public task in providing education; a school should have decided and recorded this before use, and should have given students and parents appropriate privacy information.
For the limited processing where we are the controller, we rely on:
- Contract – to provide the platform to the school and manage our agreement with it.
- Legitimate interests – keeping the platform secure, preventing and investigating abuse, monitoring reliability and improving the product, and responding to enquiries. We have considered the rights of the people involved and do not believe these uses affect them unfairly.
- Legal obligation – keeping tax and accounting records and responding to lawful requests.
7 How long we keep it
- School, staff and student learning data – kept while the school is an active customer and for up to 12 months after it stops using the platform, unless the school asks us to delete it sooner.
- Work submitted by students – including whiteboard images – kept on the same basis as learning data, and deleted with the account or class it belongs to.
- Security, session and audit records – IP address, device characteristics, session identifiers and timestamps – up to 180 days. Expired and revoked sessions are purged automatically.
- Monitoring data and session recordings – held live in Coralogix for its standard retention period, and stored in our own S3 bucket in London, where an automatic lifecycle rule deletes them after 100 days. Superseded versions of a file are deleted after 30 days.
- Password reset and invitation links – short-lived and single-use; the record expires automatically.
- Sign-in sessions – up to seven days, or until the user signs out.
- Backups – may retain data for up to 35 days before being overwritten.
- Register-interest enquiries – up to 24 months from the last contact, unless you ask us to remove them sooner.
- Billing and accounting records – for as long as tax law requires, normally six years.
If a school, as controller, instructs us to delete student data, we will take steps to delete it within 30 days, subject to any legal obligation and to the backup retention period above.
8 Cookies and session recording
The session cookie
The platform sets a cookie named sid. It holds the sign-in session, cannot be read by scripts, is
sent only over HTTPS in production, and lasts up to seven days. It is strictly necessary for the platform to work,
so it does not require consent.
We also store a device identifier in your browser’s local storage, under device_fp, derived
from characteristics such as screen size, timezone, language and platform. It is used only to notice when a
session appears on a different device or browser and to ask for a password again. It is not used for advertising
or cross-site tracking.
Application monitoring and session recording
Pages on the platform are monitored by Coralogix, and this includes session recording. The monitoring tool records on-screen activity in the app – pages visited, clicks, navigation, browser console messages and errors – so that we can diagnose faults and see where the platform is going wrong. For a signed-in user, recordings are associated with their user ID, name and email address. This applies to staff and students alike.
We use it only to keep the platform working and secure, and we do not use it to assess individuals. The data is processed in the European Union and archived to storage we control in London. If your school does not want session recording enabled for its users, contact us at [email protected].
Session recording is not strictly necessary to deliver the platform. We rely on our legitimate interest in diagnosing faults and securing the service, together with the school’s instruction as controller, and we keep the scope to what we need. We set no advertising cookies and no advertising or marketing tracker of any kind. If we add non-essential analytics in future, we will update this policy and put an appropriate consent mechanism in place first.
9 Security
Traffic is encrypted with HTTPS and the database connection is encrypted in transit. Passwords are stored as a salted one-way hash and are never recoverable. Two-factor authentication secrets are stored encrypted. Sign-in and password-reset endpoints are rate-limited, reset and invitation tokens are single-use and short-lived, and sensitive actions can require a password to be re-entered. Standard HTTP security headers are applied. Access to the production database is limited to the people who need it.
No service can promise perfect security. If a breach affects personal data and is likely to be a risk to the people involved, we will notify the school without undue delay so that it can meet its own obligations as controller, and we will notify the ICO where the law requires us to.
10 Your rights
Under UK data protection law you can ask for a copy of your personal data, have it corrected or deleted, restrict or object to how it is used, and receive it in a portable format, in each case where those rights apply.
For student data and school-provisioned accounts, requests should go to the school, which is the controller. We will help the school respond. Where we are the controller – for example for a register-interest enquiry, or for security records we keep in our own right – email [email protected] and we will respond within one month.
If you are unhappy with how your information has been handled, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put things right first.
11 Children
The platform is used by children, because schools enrol their students on it. It is not directed at children independently of their school: students cannot create their own accounts, we do not market to them, and we do not collect information from a child except through the account their school has provisioned.
We handle children’s data as a processor for the school. We use it only to provide the platform, we do not profile children, we do not target them with advertising, and we do not train any model of our own on their work. Where student work is sent to Anthropic for marking, that provider is contractually barred from training its models on it and does not retain it for its own purposes.
We have had regard to the ICO’s Age Appropriate Design Code in designing the platform. If you believe a child has created an account outside a school, tell us and we will remove it.
12 Changes and contact
We will update this policy as the platform changes, and will post the new version here with a new date. If a change materially affects how we handle personal data, we will tell schools by email or in the app before it takes effect.
Questions, requests or complaints: [email protected], or write to BlueAcorn Education Ltd, 66 Paul Street, London, England, EC2A 4NA.