Schools & data
Version 1.0 · For schools using STRETCH. This agreement sets out how STRETCH handles pupil data on your behalf, and satisfies Article 28 of the UK GDPR. It is offered on these standard terms; if your data protection officer needs changes, email us.
UK GDPR = the United Kingdom General Data Protection Regulation. DPA 2018 = the Data Protection Act 2018.
1. The parties
| Role | Party |
|---|---|
| Controller | The School (the customer named on the order or invoice) |
| Processor | Stretch Study Ltd, company number 17346479, registered office 2 Wolseley Gardens, London, W4 3LP |
The School decides why and how pupil data is used, and is therefore the controller. STRETCH acts only on the School's documented instructions, and is therefore the processor. Nothing in this agreement makes STRETCH a controller of pupil data.
2. What is processed, and why
| Item | Detail |
|---|---|
| Subject matter | Providing the STRETCH vocabulary and Latin learning platform to the School's pupils. |
| Duration | For as long as the School's subscription or pilot runs, plus the deletion period in clause 10. |
| Nature and purpose | Creating pupil accounts, delivering questions, recording answers and progress, and presenting that progress to the School's staff. |
| Categories of data subject | Pupils; teaching and administrative staff nominated by the School. |
| Categories of personal data | Pupils: first name or nickname, surname initial, year group, class, username, PIN, learning progress and answer history. Staff: name, work email address, job title, and which classes they are assigned to. |
| Special category data | None. STRETCH does not collect health, ethnicity, religion, biometric or any other special category data, and asks the School not to enter any. |
| Children's data | Yes. Most pupils are under 13. STRETCH follows the ICO Age Appropriate Design Code. |
3. STRETCH's obligations
STRETCH shall:
- process personal data only on the School's documented instructions, including on international transfers, unless required otherwise by law — in which case STRETCH will tell the School first, unless the law forbids it;
- ensure everyone authorised to process the data is under a duty of confidentiality;
- take the security measures set out in clause 5;
- respect the conditions in clause 6 before engaging any sub-processor;
- assist the School in responding to requests from pupils, parents or staff exercising their rights;
- assist the School with security, breach notification and data protection impact assessments;
- delete or return the data as set out in clause 10;
- make available the information needed to demonstrate compliance, and allow audits under clause 9.
If STRETCH believes an instruction from the School breaches data protection law, STRETCH will say so promptly.
4. No advertising, no profiling, no sale
STRETCH does not use pupil data for advertising, does not profile children for commercial purposes, and does not sell data to anyone. There are no advertising networks, analytics trackers or data brokers in the product.
STRETCH keeps anonymised aggregate statistics — counts and averages such as how many classes ran, how many pupils took part, and average progress across a cohort. These carry no names, usernames or identifiers and cannot be traced back to any individual. This is not personal data and falls outside this agreement.
5. Security
- All traffic is encrypted in transit using HTTPS.
- Data is encrypted at rest by the database provider.
- Access is controlled by row-level security policies in the database, so one school cannot see another school's data.
- Staff access is scoped: a teacher sees only the classes assigned to them; a school administrator sees the whole school.
- Administrative access to the underlying database is limited to named individuals at STRETCH.
- Pupil passwords are visible to the assigned teacher by design, so that class credentials can be printed and handed out. This is a deliberate operational decision, disclosed here so the School can assess it.
6. Sub-processors
The School gives general authorisation for the sub-processors below. STRETCH will give at least 30 days' notice before adding or replacing one, and the School may object on reasonable data protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | European Union |
| Netlify | Website hosting and content delivery | United States / global edge network |
| Stripe | Payment processing (School billing contacts only — no pupil data) | United States / EU |
Each sub-processor is bound by written terms offering protection equivalent to this agreement.
7. International transfers
Pupil data is held in the European Union. Where personal data is transferred outside the United Kingdom, STRETCH relies on the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, as applicable to the sub-processor concerned. Copies are available to the School on request.
8. Personal data breaches
STRETCH shall notify the School without undue delay, and in any event within 24 hours of becoming aware of a personal data breach affecting the School's data. The notification will describe what happened, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken.
The School, as controller, is responsible for notifying the Information Commissioner's Office where required. STRETCH will provide reasonable assistance.
9. Audit
STRETCH shall make available to the School the information necessary to demonstrate compliance with Article 28 of the UK GDPR, and shall allow and contribute to audits, including inspections, conducted by the School or an auditor it appoints. Audits shall take place on reasonable notice, no more than once in any twelve-month period unless a breach has occurred, and shall not unreasonably disrupt STRETCH's operations.
10. Return and deletion
- The School may export its data at any time during the subscription.
- On the School's written request, or on the agreement ending, STRETCH shall delete the School's personal data within 30 days.
- Deleted data may persist in encrypted backups for up to 30 days before being overwritten.
- A pupil who leaves may be removed by the School at any time, and their record and progress are deleted.
- STRETCH retains anonymised aggregate statistics as described in clause 4, and invoices and accounting records for six years as UK tax law requires. Those records concern the School, not pupils, and are used for no other purpose.
11. Assisting with pupil and parent requests
Requests from pupils, parents or staff should be directed to the School in the first instance, as controller. If STRETCH receives such a request directly, it will forward it to the School promptly and will not respond substantively without the School's instruction, except to acknowledge receipt. STRETCH will help the School respond within the statutory time limit.
12. General
- This agreement forms part of, and is subject to, the School's subscription terms with STRETCH.
- If there is a conflict between this agreement and the subscription terms on data protection, this agreement prevails.
- This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Signing
This agreement takes effect when the School begins using STRETCH, and no signature is required for it to apply. If your data protection officer needs a countersigned copy for your records, email studiokingelin@gmail.com and we will send one within two working days.
Questions about this agreement, our security, or our sub-processors are welcome and answered properly — they are the right questions to be asking.