Privacy Policy

Version 1.2 · Effective 2026-08-24

1. Who We Are and Data Controller

EdToolkit ("we", "us", "our") operates the classroom.edtoolkit.com and homeschool.edtoolkit.com web applications. We act as the Data Controller under the UK General Data Protection Regulation (UK GDPR), the UK Data Protection Act 2018 (DPA 2018), and the EU GDPR for the personal data processed through our services.

2. What Data We Collect and Why

In accordance with the UK GDPR data minimisation principle, we collect only the personal data necessary to provide and operate our educational planning services: - **Account Credentials & Identification:** Email address, display name, and authentication credentials (passwords are cryptographically hashed and never stored or accessible in plaintext). - **Educational & Profile Data:** Teaching role, grade/subject focus, classroom settings, or homeschool family information (child profile names/labels, birth year/age bracket, grade level) provided directly by the account holder. - **Service & AI Planning Content:** Lesson plans, curriculum units, rubric criteria, quiz questions, and portfolio artifacts created or saved by you within the platform. - **Payment & Subscription Data:** Payment processing and billing are handled by our Merchant of Record partner, **Creem** (creem.io / Armitage Labs). When you purchase a subscription, payment card details, billing address, and tax information are collected directly by Creem in a PCI-DSS compliant environment. We store only customer identifiers, subscription identifiers, plan identifiers, and status timestamps. We never store or have access to your full payment card details. - **Technical & Security Data:** IP addresses, session timestamps, device identifiers, and error logs collected to maintain platform security, prevent abuse, and ensure service availability.

3. Legal Basis for Processing (UK GDPR & EU GDPR)

Under Article 6 of the UK GDPR and EU GDPR, we process personal data under the following lawful bases: - **Contractual Necessity (Article 6(1)(b)):** Processing necessary to create your account, provide AI lesson planning and productivity tools, manage subscriptions, and deliver the services outlined in our Terms of Service. - **Legal Obligation (Article 6(1)(c)):** Processing necessary to comply with financial, tax, corporate reporting, and statutory regulatory requirements. - **Legitimate Interests (Article 6(1)(f)):** Processing necessary to secure our applications, protect against fraudulent sign-ups, debug software errors, and optimize platform performance, where these interests do not override your fundamental rights and freedoms. - **Consent (Article 6(1)(a)):** Optional processing such as marketing communications and non-essential cookies, which requires your explicit opt-in and can be withdrawn at any time.

4. Children's Data & Family Safeguards (UK & COPPA)

Our homeschool application is designed exclusively for adult account holders (parents and legal guardians) to organize home education: - Children do not have direct accounts, independent access, or login credentials. - Any child profile information (such as first name/nickname, age, grade) is entered voluntarily and managed solely by the parent or guardian. - We do not knowingly collect personal data directly from children under 13 or under 16 without parental consent. - Child profile data is never sold, shared with third-party advertisers, or used for behavioral profiling. - Parents can edit, export, or permanently delete child profiles at any time through their account dashboard.

5. Data Retention & Erasure Schedule

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations: - **Active Accounts:** Data is retained for the duration of your account's active lifecycle. - **Account Deletion (Right to Erasure):** When you request account deletion through our self-service deletion feature, your personal account records, profiles, plans, projects, generated artifacts, and events are permanently purged from active databases immediately, and any recurring Creem subscription is cancelled. - **Backups:** Residual database backups are permanently purged within a rolling 30 to 90-day retention cycle.

6. Your Data Rights under UK GDPR

Under Chapter 3 of the UK GDPR and DPA 2018 (and EU GDPR where applicable), you have enforceable statutory rights regarding your personal data: - **Right of Access (Article 15):** You can request a copy of the personal data we hold about you (Subject Access Request). - **Right to Rectification (Article 16):** You can correct inaccurate or incomplete personal information at any time via your account settings. - **Right to Erasure / 'Right to be Forgotten' (Article 17):** You can delete your account and all associated data at any time via the self-service Account Deletion feature or by contacting privacy@edtoolkit.com. - **Right to Restriction of Processing (Article 18):** You can request that we restrict processing of your data under certain circumstances. - **Right to Data Portability (Article 20):** You can export your data in a structured, commonly used, and machine-readable JSON/CSV format. - **Right to Object (Article 21):** You can object to processing based on legitimate interests or direct marketing. - **Right to Withdraw Consent (Article 7(3)):** Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing prior to withdrawal. To exercise any of these rights, use the in-app settings or contact our Data Privacy team at **privacy@edtoolkit.com**. We respond to all verified requests within one calendar month.

7. Data Security and Regional Storage

We employ technical and organizational measures to safeguard your personal data: - **Encryption:** All data in transit is encrypted using modern TLS (HTTPS). Sensitive stored credentials use industry-standard cryptographic hashing. - **Regional Data Governance:** European and UK user data is stored within certified European Union (eur3 / europe-west1) and UK (europe-west2) cloud data centres hosted on Google Cloud Firebase infrastructure, compliant with ISO/IEC 27001, SOC 2, and GDPR standards. - **Access Controls:** Production database access is strictly restricted, authenticated, and audited.

8. Third-Party Sub-Processors & Merchant of Record

We engage vetted third-party service providers (sub-processors) to deliver platform functionality, each governed by Data Processing Agreements (DPAs) or Standard Contractual Clauses (SCCs): - **Google Cloud Platform / Firebase:** Hosting, authentication, multi-region database storage, and Cloud Functions (EU/UK regions). - **Creem (creem.io / Armitage Labs):** Merchant of Record (MoR) and payment gateway. Handles payment processing, tax/VAT calculation and remittance, customer billing portal, and PCI-DSS compliance. - **Google Gemini API:** AI model processing for curriculum and lesson plan generation (prompts are processed ephemerally for output generation and not used to train global public foundation models without consent).

9. International Data Transfers

Where personal data is transferred outside the United Kingdom or the European Economic Area (EEA), we ensure adequate safeguards are in place in compliance with Chapter V of the UK GDPR. This includes utilizing UK International Data Transfer Agreements (IDTAs), UK Addendums to EU Standard Contractual Clauses (SCCs), or transfers to countries recognized by the UK government and European Commission as providing an adequate level of data protection.

10. Supervisory Authority and Complaints

If you are based in the United Kingdom and have concerns about how your data is handled, you have the right to lodge a complaint with the UK supervisory authority: **Information Commissioner's Office (ICO)** - Website: [ico.org.uk](https://ico.org.uk) - Helpline: 0303 123 1113 - Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom If you reside in the EEA, you may also lodge a complaint with your local EU Data Protection Authority.

11. Contact Us

For questions regarding this Privacy Policy, UK GDPR compliance, or data subject requests: - **Email:** privacy@edtoolkit.com / dpo@edtoolkit.com - **Response Commitment:** Within 30 days of receipt.
Terms of ServiceBack to sign up