Legal

Data Processing for Schools

How we handle pupil and staff data when a school uses TheStudyStack.

Last updated: 27 September 2026

The short version

  • -The school is the controller of its pupil and class data. We are its processor.
  • -We use school data only to run TheStudyStack for that school. We never sell it, advertise with it or train AI on it.
  • -We tell the school about a data breach within 48 hours of finding it.
  • -We give notice before changing service providers, and the school can object.
  • -When a school leaves, we delete its data within 30 days, or return a copy first if asked.

1.When these terms apply

These terms apply when a school, academy trust or college (the "school") uses TheStudyStack with its pupils. They meet Article 28 of the UK GDPR and form part of the agreement between the school and Liam McClean, the sole trader who runs TheStudyStack ("we", "us"). They take priority over the Terms of Service for school data.

To get a signed copy, or to use your school's or trust's own data processing agreement instead, email privacy@thestudystack.co.uk.

2.Details of the processing

Subject matter
DetailProviding TheStudyStack revision and classroom platform to the school
Duration
DetailWhile the school uses TheStudyStack, then until its data is deleted as described below
Nature and purpose
DetailHosting accounts and classes; storing and displaying pupils' work, marks and progress to their teachers; running homework, live lessons, live quizzes and typing classes; suggesting marks with AI where a teacher or pupil asks; checking usernames and clan names with AI
People
DetailPupils and staff of the school
Types of data
DetailNames, usernames, school email addresses where used, year groups, class membership, answers and drawings, marks and feedback, progress, live lesson and quiz responses, teacher notes, typing adjustments, sign-in and security records
Special category data
DetailNone is requested. Staff should not enter it in free-text fields

3.Our commitments

  • -Instructions: we process school data only on the school's documented instructions. These are this agreement, the settings staff choose in TheStudyStack, and written requests. We tell the school if we think an instruction breaks data protection law.
  • -No other use: we do not sell school data or use it for advertising, marketing profiles or training AI models. The only exception is fully anonymous totals across the whole service, such as how often a question is answered wrongly, which we use to improve questions and which cannot identify a pupil or school.
  • -Confidentiality: only Liam McClean can access school data. Anyone else given access in future will be bound by confidentiality and trained in data protection.
  • -Security: we keep the measures described below in place and review them as the service changes.
  • -Rights requests: we pass any request we receive about school data to the school within 5 working days, and help the school respond, including exporting a pupil's data or deleting it.
  • -DPIAs: we give schools the information they need for a data protection impact assessment, and help with any consultation with the ICO.
  • -Breaches: we notify the school without undue delay, and in any case within 48 hours of becoming aware of a breach affecting its data. We explain what happened, the data and people affected, likely consequences and what we are doing about it, and keep the school updated.
  • -Audits: we provide the information the school reasonably needs to show compliance with this agreement, and allow audits or inspections with reasonable notice.
  • -End of use: when the school asks, we delete its data within 30 days, or return a copy first if requested, and confirm in writing when deletion is complete. Copies in provider backups are overwritten on their normal cycle. Staff can also delete a pupil account at any time, which removes all of that pupil's data, and delete a class, which removes all of its work while pupils keep their accounts.

4.Security measures

  • -Encryption in transit (HTTPS) for all traffic, and encryption at rest by our providers.
  • -Sign-in handled by Clerk. Passwords are never stored by us, and administrator access needs a separate sign-in from an approved email address.
  • -Access checks on every request, so pupils only see their own work and teachers only see work in their own classes. Staff at the school can see the names, usernames, sign-in status and class names of pupil accounts the school created, so they can manage them.
  • -Answer keys withheld from pupils until marking is released.
  • -Invite links and teacher access codes stored hashed or encrypted.
  • -Rate limits on actions such as joining classes, entering teacher codes and sending friend requests.
  • -A log of changes staff make to school-created pupil accounts.
  • -Pupil accounts created by the school cannot use friends and cannot be deleted by pupils. Friends are blocked for all pupils in Years 7 to 9.
  • -The AI model receives only an answer with its question and mark scheme, or a username or clan name to check. It never receives real names or account identifiers.

5.Sub-processors

The school gives general authorisation for us to use these sub-processors. Each is bound by a written contract with data protection obligations at least as strict as ours.

Clerk, Inc.
PurposeSign-in and account security
LocationUnited States
Convex, Inc.
PurposeDatabase and backend
LocationUnited States
Vercel Inc.
PurposeWebsite hosting and AI request routing
LocationUnited States
TypeSafe AI, Inc.
PurposeAI model for marking answers and checking usernames and clan names (no other identifiers)
LocationUnited States

We email the school's contact at least 30 days before adding or replacing a sub-processor. If the school objects on reasonable data protection grounds, we will try to resolve the concern. If we cannot, the school may stop using TheStudyStack and have its data deleted.

6.International transfers

Our sub-processors process data in the United States. Transfers rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, and otherwise on the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, with a transfer risk assessment.

7.The school's responsibilities

  • -Have a lawful basis for using TheStudyStack with pupils, usually public task.
  • -Tell pupils and parents about TheStudyStack in the school's privacy notice.
  • -Make sure its instructions to us are lawful.
  • -Keep staff accounts secure, and remove staff and pupil access when they leave.
  • -Tell us who to contact about breaches and changes to sub-processors.

8.Contact

Email privacy@thestudystack.co.uk for a signed copy, DPIA information, a copy of the sub-processor contracts, or anything else about how we handle school data.