← The Hub
For your Data Protection Officer · DPIA support

Data protection pack

This programme was designed backwards from one principle: the least pupil data that can possibly deliver the teaching. Pupils have no accounts, no logins, no passwords, no email addresses and no profiles. This document gives your DPO what a data protection impact assessment needs.

1. What pupil data is processed, and why

First name and initial only(for example “Amara K”), entered by the teacher, used for class organisation, printed quiz personalisation and the teacher’s per pupil judgement record (working towards, met, exceeded). Lesson delivery records (which class was taught which lesson, when). Anonymous in lesson answer counts. Nothing else: no dates of birth, no photographs, no contact details, no free text about pupils, no special category data. Children in the family product interact through a parent held link token, never an account.

2. Lawful basis and roles

The school is the data controller for pupil data and typically relies on public task for delivering its curriculum. Guided Childhood processes pupil data solely on the school’s instructions as a processor for the teaching service. A data processing agreement is available for signature with the licence. We never use pupil data for advertising, profiling, product analytics or model training, and we never sell or share it.

3. Age appropriate design, by phase

The service spans ages 4 to 18, and the design differentiates by phase as the ICO’s Age Appropriate Design Code expects. EYFS to KS2: pupils never operate the platform, the teacher projects, and pupil participation is on paper. KS3 to KS5: pupils still hold no accounts, and any classroom interaction is through the teacher’s session. The family product’s child screen is reached only through a link the parent creates, holds and can revoke, shows only that child’s own first name, quests and stars, and carries no navigation to any other data.

4. Storage, subprocessors and retention

Data is stored with Supabase (database, EU hosted project region) behind row level security, and the application is served by Vercel. Transport is encrypted throughout. Pupil rows are deleted when the school deletes a class or pupil, and on licence termination all school data is deleted on request or after the retention window agreed in the data processing agreement. Access within Guided Childhood is limited to what operating the service requires.

5. What this platform deliberately does not do

No pupil accounts. No behavioural tracking or advertising. No third party trackers in the lesson player. No pupil generated free text stored from lessons. No disclosure recording: safeguarding concerns belong in the school’s own systems, and every safeguarding flagged module says so to the teacher in writing.

6. Consultation evidence for your DPIA

The ICO expects the views of children and parents to inform a DPIA for services used by children. The parent consultation your school runs before adopting this programme (using the parent pack in this Hub) doubles as that evidence: record the consultation date, what was shared, and any concerns raised, and file it with the DPIA.

This pack supports your DPIA but does not replace it: the school remains responsible for its own assessment. Questions to justin@thesocialbillboard.com and our DPO contact named in the data processing agreement.