At a glance
EdPsych Connect Limited is the data controller. Every processing activity is registered in our Record of Processing Activities, every high-risk activity carries a Data Protection Impact Assessment, and every subprocessor is bound by a written data processing agreement.
1. Introduction
EdPsych Connect Limited ("we", "our", "us") is committed to protecting the privacy and security of your personal information. This policy explains how we collect, use, disclose, and safeguard information when you use our educational psychology platform, and it sets out the rights available to you under United Kingdom data protection law.
As a provider of services to educational institutions and professionals in the United Kingdom, we adhere to the highest standards of data protection, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and the Information Commissioner's Office Age Appropriate Design Code (the Children's Code).
The controlled register of every processing activity we operate is our Record of Processing Activities (ROPA). Each activity in this policy is cross-referenced to its ROPA identifier (for example, R-01) so that it can be traced directly to the controlled record. The ROPA, in turn, cites the Data Protection Impact Assessments (DPIAs) that govern every high-risk activity.
2. Who is the data controller
EdPsych Connect Limited, registered in England and Wales under company number 14989115, is the data controller for all personal data processed through the platform, save where we operate as a data processor for a school, local authority or other institutional subscriber under a written data processing agreement. In those cases the institutional customer is the controller and EdPsych Connect Limited is the processor.
3. Information we collect
3.1 Information you provide directly
- Account information (ROPA
R-01): name, email address, organisation, role, and professional credentials. - Assessment data (ROPA
R-02): ECCA assessment responses, observations, and results for children and young people. - EHCNA and EHCP content (ROPA
R-03): draft and issued plan content, amendments, reviews, panel papers, and evidence bundles. - Case management data (ROPA
R-04): child and young-person information, intervention plans, progress notes, safeguarding flags and disclosures. - Training records (ROPA
R-05): course enrolments, completion, CPD hours, and certificates. - Payment information (ROPA
R-06): billing address and payment details processed through a PCI DSS compliant payment processor.
3.2 Information collected automatically
- Usage data (ROPA
R-07): features accessed, time spent, and actions taken within the platform. - Technical data (ROPA
R-08): IP address, browser type, device information, and operating system, limited to what is required to deliver and secure the service. - Audit and security logs (ROPA
R-09): access records, administrative actions, and authentication events retained for information-security purposes.
4. How we use your information
4.1 Primary purposes
- Providing and improving our educational psychology services.
- Conducting ECCA cognitive assessments and generating professional reports.
- Managing EHCNA and EHCP workflows, and tracking amendments and reviews.
- Delivering training courses and tracking continuing professional development hours.
- Facilitating intervention planning and progress monitoring.
- Processing payments and managing subscriptions.
- Providing customer support and responding to enquiries.
4.2 Lawful basis for processing under UK GDPR
- Contract performance (Article 6(1)(b)) — processing necessary to provide the services you or your organisation have contracted for.
- Legal obligation (Article 6(1)(c)) — compliance with United Kingdom education law, data protection law, and safeguarding obligations.
- Public task (Article 6(1)(e)) — where we process on behalf of a local authority carrying out statutory EHCNA duties under the Children and Families Act 2014.
- Legitimate interests (Article 6(1)(f)) — platform improvement, security, fraud prevention, and debt recovery, subject to a documented balancing test.
- Consent (Article 6(1)(a)) — only where consent is the genuine lawful basis, for example optional feedback surveys. Consent is never used as the lawful basis for delivering core services.
5. Special category data
We process special category data, including information about children's health, special educational needs, and disabilities. We rely on the following specific Article 9 and Data Protection Act 2018 Schedule 1 conditions:
- Article 9(2)(h) — provision of health or social care services, read with Schedule 1 Part 1 paragraph 2.
- Article 9(2)(g) and Schedule 1 Part 2 — reasons of substantial public interest, covering safeguarding and support for children at risk.
- Article 9(2)(b) and Schedule 1 Part 1 paragraph 1— employment, social security and social protection where relevant.
We apply enhanced safeguards to special category data, including strict role-based access, encryption in transit and at rest, detailed audit logging, and the appropriate policy document required by the Data Protection Act 2018.
6. Data sharing and disclosure
6.1 Within your organisation
For institutional subscriptions, data is shared with authorised users within your local authority, multi-academy trust or school as configured by your administrator. Role-based access control governs what each user can see and do.
6.2 Subprocessors
We use carefully selected subprocessors. Some are always required to deliver the service; others are optional and depend on tenant configuration or feature enablement. The authoritative list is our subprocessor register, which is available on request and is kept in step with the ROPA.
Active (core service)
- Hosting and edge runtime — United Kingdom or European Economic Area region configured per deployment.
- Database — managed PostgreSQL service.
- Payment processing — PCI DSS compliant payment processor.
- Transactional email delivery.
- Media storage and content delivery, with adaptive bitrate streaming for video.
Optional or feature-dependent
- AI assistance providers — only where a feature has been enabled by the institutional administrator.
- Caching and rate limiting — only where configured.
- Operational monitoring — error and uptime telemetry limited to information-security purposes.
Every subprocessor is bound by a written data processing agreement, is required to meet UK GDPR obligations, and is subject to periodic review. We do not share personal data with advertisers, data brokers or social-media platforms, and we do not permit subprocessors to use data for their own advertising or model-training purposes.
6.3 Legal requirements
We may disclose information when required by law, court order, or to protect the rights, safety, and security of individuals, particularly in safeguarding contexts.
7. Data retention
Retention periods follow the schedule below, which is the same schedule recorded in the ROPA. Where a professional or statutory requirement mandates a longer period, the longer period applies.
- Assessment records: retained for seven years after last access, aligned with professional guidance.
- EHCNA and EHCP documents: retained according to the commissioning local authority's retention schedule.
- Training records: retained for seven years to support CPD verification.
- Account data: retained for the duration of the active subscription plus two years.
- Audit and security logs: retained for one year online and an additional six years in cold storage.
8. Your rights under UK GDPR
You have the following rights:
- Right of access — request copies of your personal data.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure — request deletion, subject to legal retention requirements.
- Right to restrict processing — limit how we use your data.
- Right to data portability — receive data in a structured, commonly used and machine-readable format.
- Right to object — object to processing based on legitimate interests.
- Rights in automated decision-making — no solely automated decision with legal or similarly significant effect is made on the platform. AI-assisted content is reviewed and approved by a qualified professional before it is relied on.
To exercise any right, contact our Data Protection Officer at dpo@edpsychconnect.com. We respond within one calendar month and extend by a further two months only where a request is complex, in line with UK GDPR Article 12.
9. Security measures
- Transport-layer security (TLS 1.2 or later) in transit.
- Encryption at rest for all database and media storage.
- Multi-factor authentication available for every account and required for privileged roles.
- Role-based access controls with least-privilege defaults.
- Comprehensive audit logging of data access and administrative action.
- Regular independent security testing, including penetration testing.
- Mandatory data-protection and safeguarding training for every member of staff.
- Alignment with Cyber Essentials, ISO/IEC 27001:2022 and SOC 2 criteria, as recorded in the readiness documents.
10. Children's privacy and the Age Appropriate Design Code
EdPsych Connect is designed for use by educational professionals and by parents and carers acting on behalf of a child. We apply the fifteen standards of the Information Commissioner's Office Age Appropriate Design Code to every part of the platform that is likely to be accessed by a child. A public summary is available on our Children's Code statement, and the controlled self-assessment is held at docs/compliance/CHILDRENS_CODE_SELF_ASSESSMENT.md.
11. International data transfers
Some subprocessors may process data outside the United Kingdom and the European Economic Area. Where international transfers occur, we use appropriate safeguards, including the United Kingdom International Data Transfer Agreement (IDTA), the United Kingdom Addendum to the European Commission Standard Contractual Clauses, or reliance on a United Kingdom adequacy determination where one exists. Transfer risk assessments are recorded in the ROPA.
12. Cookies and tracking technologies
The platform sets a single strictly necessary session cookie to keep a signed-in user authenticated and sets no analytics, advertising or cross-site tracking cookies. Full details are in our Cookie Policy.
13. Data Protection Impact Assessments
We maintain Data Protection Impact Assessments for every high-risk processing activity, including:
- EHCNA statutory advice generation and special category data processing.
- Analytics and operational telemetry.
- Transactional marketing communications.
- Business continuity, disaster recovery and backup.
- Single sign-on and federated identity integrations.
A summary of each DPIA is available on request; the controlled copies are held at docs/compliance/DPIA_*.md.
14. Changes to this policy
We review this policy on every material release and at least annually. Significant changes will be communicated by email and in-product notification. Continued use after changes indicates acceptance of the updated policy.
15. Contact us
For privacy-related questions or to exercise your rights:
- Data Protection Officer mailbox: dpo@edpsychconnect.com
- Privacy team: privacy@edpsychconnect.com
- Address: EdPsych Connect Limited, registered office as recorded at Companies House.
- Company number: 14989115 (registered in England and Wales).
- ICO registration: held as a data controller with the Information Commissioner's Office.
16. Regulatory authority
You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the United Kingdom supervisory authority for data protection:
- Website: ico.org.uk
- Helpline: 0303 123 1113
Professional standards: services are delivered by registered educational psychologists, and every registered practitioner adheres to the Health and Care Professions Council Standards of Conduct, Performance and Ethics and to the British Psychological Society Code of Ethics and Conduct. All data handling complies with those obligations.