Qwixl Academy

Privacy Policy

Qwixl Ltd (company number 17353629). Last updated: 24 July 2026.

Last updated: 24 July 2026 Legal entity: Qwixl Ltd (company number 17353629), Old Furnace Cottage, Greendale, Oakamoor, Stoke-On-Trent, ST10 3AP, United Kingdom Product: Qwixl Academy (academy.qwixl.com and related Academy API hosts)

This Privacy Policy explains how personal data is handled when you use Qwixl Academy (“Academy”, “the Service”). It is written for the public Academy website (including sign-in) and for Authorised Users (staff, pupils, and parents/carers).

Academy is a B2B schools product. For pupil, staff, and parent personal data used for teaching and school administration (“Customer Data”), the school, academy, or multi-academy trust named on the Academy Order Form (“the School”) is the data controller. Qwixl Ltd (“Qwixl”, “we”, “us”) is the data processor under a Data Processing Agreement (UK GDPR Article 28).

This policy does not replace:

Where the signed Academy pack and this public policy differ on contractual or processor obligations between Qwixl and the School, the signed pack prevails. Trust and diligence overview: Security & compliance.


Key points

This is a summary. The full policy below has a common part (Part A) and audience-specific parts (Part B).

Jump to: Part A — Common · Sign-in providers (Google / Microsoft) · Website visitors · Pupils · Staff · Parents and carers · Trust pack links


Full Policy

Part A — Common

1. Who we are

Qwixl Ltd provides Academy as software-as-a-service to UK schools and trusts.

RoleWhoWhat they decide
Controller (Customer Data)The School named on the Academy Order FormPurposes and means of processing pupil, staff, and parent data for teaching and school administration; role access; Optional Wonde permissions; parent visibility within product rules; school privacy notices
Processor (Customer Data)Qwixl LtdHosts Academy; processes Customer Data only on the School’s documented instructions (including in-product configuration), except where UK law requires otherwise
MIS integrationWonde (School’s separate arrangement)School–Wonde terms apply. Academy syncs categories under Qwixl’s standard Required / Optional / Not requested schedule
Limited independent controller (Qwixl)Qwixl LtdBilling contact and payment records where Qwixl is the contracting party for fees; Qwixl corporate/staff records; strictly necessary website security logs and cookie-preference storage on Academy public pages; contents of messages you send directly to Qwixl (for example support@qwixl.com)

Contact (Qwixl): privacy@qwixl.com · security@qwixl.com · support@qwixl.com Postal: Qwixl Ltd, Old Furnace Cottage, Greendale, Oakamoor, Stoke-On-Trent, ST10 3AP, United Kingdom ICO: registration details available on request from privacy@qwixl.com

For questions about your school’s use of Academy, contact the School’s Data Protection Officer or data protection lead first.

2. What this policy covers

This policy applies to:

It does not cover:

3. The personal data we process

Depending on your role and the School’s configuration, Academy may process:

CategoryExamples
Identity and accountName, display name, email, role, school/trust/site affiliation, unique identifiers used in Academy
AuthenticationCredentials, SSO tokens (including Google, Microsoft, MyLogin, or SAML where enabled), session and multi-factor metadata
Organisation and timetableClass/year group links, lessons, rooms, periods, staff assignments (often via Wonde)
Learning activityAssignments, submissions, marks, feedback, progress summaries, planner/resources use
AI tutor / generative featuresPrompts, responses, tutor chat history via Standard LLM or school BYOK where configured; AI image generation only if the Order Form enables it
Typing telemetryTiming, pauses, and corrections inside Academy answer fields only (not activity outside the Service)
MIS-synced context (Wonde)Fields under the Wonde Permissions Schedule that the School has granted (Required categories are a condition of the Service; Optional may be declined)
SEN status and signalsSEN-related fields from MIS where synced; screening-style platform signals for professional review
Parent linkageParent/carer account link to pupil(s); parent feature activity
Support and communicationsSupport tickets and service emails
Billing (billing contacts)Billing contact details; payment method metadata via Stripe where the Order Form uses Stripe (card numbers are held by Stripe)
Technical and securityIP address, device/browser type, login events, failed logins, audit logs for sensitive access

We do not require national insurance numbers or payroll data to operate Academy staff accounts unless the School separately stores additional fields.

4. Roles, lawful bases, and instructions

School as controller. The School determines the lawful basis for processing Customer Data. Bases schools commonly rely on for Academy include:

Special category data. SEN status, related MIS fields, and SEN-related signals that reveal or infer health or learning needs may be special category data (Article 9). The School decides the Article 9 condition. Qwixl’s recommended ROPA position for Academy SEN screening and related typing telemetry is Article 9(2)(g) (substantial public interest) with DPA 2018 Schedule 1 Paragraph 18 (safeguarding of children), with the School’s Appropriate Policy Document. That recommendation does not decide the School’s basis. Qwixl processes such data only as processor under the School’s instructions, with Close Contact and role-based access.

Qwixl as processor. Qwixl processes Customer Data under the Academy DPA. Qwixl does not decide the School’s teaching, SEN, or parental-communication purposes, and does not assume the School’s statutory education or safeguarding duties.

Limited Qwixl controller processing. Where Qwixl acts as independent controller (section 1), we process that data to perform our contract with the School, to secure Academy public pages, to respond to messages you send us, and to meet legal obligations. We do not build advertising profiles from Academy use.

5. How we use personal data

We use personal data to:

We do not sell personal data. We do not use personal data for third-party advertising. We do not use identifiable pupil Personal Data (including Customer pupil Content such as tutor chats and submissions) to train foundation models for other customers or for marketing. Sub-processors providing model inference may process Content solely to generate responses for the School’s use, subject to the DPA.

6. Close Contacts and anonymised views

Close Contacts for a pupil means, as the product permits: the pupil; a linked parent or carer; a class teacher or SENCO after sharing/unlock rules; and school administrators configured for operational need.

AudienceWhat they receive
Close ContactsIdentifiable pupil records and SEN-related signals as permitted for that role
Other Authorised Users without Close Contact rightsAnonymised and/or aggregated views only (for example class or department rollups), with k-anonymity floors where applied (for example minimum cohort sizes; small buckets suppressed)
Qwixl product development and analysisAnonymised or aggregated data only

There is no silent whole-class broadcast of identifiable SEN detail by default. This aligns with Qwixl’s mission of additional visibility for learners whom standard procedures often miss, without replacing statutory SEN practice.

7. Sharing and sub-processors

Personal data may be disclosed to:

Sub-processors (summary). The live register is in the Academy DPA (Annex III) and may be shown in the in-app Legal Centre. As at the date of this policy:

Sub-processorPurposeNotes
SupabaseDatabase, authentication, storageWest EU (eu-west-1)
VercelHosting of the Academy web applicationEU regions (Dublin / London)
WondeMIS integration API when the School connects WondeUK; School–Wonde terms also apply
OpenRouter and underlying LLM providersAI tutor / content generation; AI image generation only if Order Form = OnEU exchange routing for production (eu.openrouter.ai)
Resend (or named successor)Adult transactional email (invites, notifications)No pupil education records are sent via Resend
StripePayment processing where usedAuthorised only where billing via Stripe appears on the Order Form; card details held by Stripe

Material sub-processor changes follow the DPA notice and objection process (typically at least 30 days’ prior notice where practicable). Schools authorise these sub-processors under the Academy DPA.

Identity providers (Google, Microsoft, MyLogin, school SAML IdPs) process authentication data under their own terms with you or the School; they are not listed above as Qwixl sub-processors for teaching content.

8. International transfers

Customer Data is primarily processed in the United Kingdom and/or European Economic Area. Where a sub-processor processes personal data outside the UK (or in a country without UK adequacy), Qwixl relies on appropriate safeguards such as the UK International Data Transfer Agreement (IDTA) and/or the UK Addendum to the EU Standard Contractual Clauses, with any supplementary measures required. Details are available to Schools under the DPA and on request to privacy@qwixl.com.

9. Anonymised and aggregated data

Qwixl may retain and use anonymised or aggregated data that does not identify a living individual (and cannot reasonably be re-identified) for product improvement, security, capacity planning, and analytics. Once anonymised, that data is not Personal Data. Identifiable pupil content is not used to train foundation models for other customers.

10. Retention

Retention follows the Academy DPA, MSA exit rules, and the School’s retention schedule. Product design targets (not a substitute for the School’s policy) include:

While the subscription is active

Data typeTypical retention
Account / tenancy / configLife of the subscription
Pupil and staff operational recordsLife of school connection + 12 months after the person leaves the School’s Academy tenancy (or earlier on School-mediated erasure)
Assignment / homework / tutor content3 academic years or School-mediated erasure
SEN signals / detection resultsEnrolment + 12 months
Security / access logsMinimum 12 months
Wonde-derived mirror dataWhile connected; purged on offboarding

Normal end of contract (expiry, convenience, or cause other than non-payment): access ends; 30-day export window; then delete/return within 30 days; certificate of deletion on request (legal holds excepted).

End for non-payment / insolvency: access ends; export and reactivation only after arrears and interest are cleared; 60-day grace retention from termination; thereafter Qwixl may delete Customer Data (except anonymised/aggregated data already outside Customer Data, and except where UK law requires retention). Paying within the grace period restores the 30-day export window from payment clearance (or reactivation if the School renews).

Automated retention enforcement is Planned on the Roadmap Schedule; contractual delete/return duties still apply operationally.

11. Your rights (data subject requests)

Under UK GDPR you have rights including: access; rectification; erasure; restriction; portability (where applicable); objection; and withdrawal of consent where processing relies on consent. Rights are not absolute; exemptions and school statutory duties may apply.

How to exercise rights

  1. 1. School Customer Data (pupil, staff, parent data in a School tenant): contact the School’s DPO / data protection lead first. Qwixl assists the School under the DPA (including via documented support channels) and may provide in-app “My data” / Legal Centre tools where released. Do not treat an email to Qwixl alone as a completed School subject-access request.
  2. 2. Processor / product questions: privacy@qwixl.com.
  3. 3. Qwixl controller processing (for example a support email you sent only to Qwixl, or billing-contact records Qwixl holds as contracting party): privacy@qwixl.com.
  4. 4. Complaints: complain to the School and/or to Qwixl. You may also complain to the Information Commissioner’s Office at any time. From 19 June 2026, additional complaint routes to controllers under the Data Protection Act 2018 (sections 164A / 165 where they apply) may be available — ask your School’s DPO.

We (or the School) respond within one month unless the request is complex or numerous, in line with UK GDPR.

12. Children and safeguarding

Academy is designed for school use. Age, year-group, and parental-consent rules for a given School are set and enforced by the School as controller (and by product configuration). Qwixl is not the Designated Safeguarding Lead. Safeguarding concerns must follow the School’s safeguarding policy. Platform features do not replace those procedures. Report suspected platform abuse or security incidents to security@qwixl.com.

13. Automated processing and SEN signals

Academy may generate profiling-style analytics and SEN-related signals from platform activity. Outputs are for human professional review. Academy does not make solely automated decisions that produce legal or similarly significant effects about a pupil. Signals are not diagnoses and must not replace statutory SEN assessment, the SEND Code of Practice, or clinical judgement.

14. Cookies and similar technologies

Academy uses strictly necessary cookies and local storage for sign-in, session security, and load balancing. Optional analytics or similar technologies apply only where allowed under the Qwixl Cookie Policy and any Academy in-product controls as released. Non-essential cookies rely on consent where PECR / UK GDPR require it. See the Cookie Policy for group practices; Academy-specific controls may be updated as released.

15. Sign-in with Google, Microsoft, or other providers

Where the School (or Qwixl for evaluation accounts) enables social or SSO sign-in:

Google. Academy’s Google OAuth / Workspace sign-in typically requests openid, email, and profile so we can verify the sign-in, obtain your Google account email and basic profile name, and create or link your Academy Authorised User account. We use that information for authentication, account administration, security, and service communications related to Academy. We do not sell Google user data, do not use it for advertising, and do not use Google user data to train foundation models for other customers. We do not request Google scopes to read your Gmail, Drive, or Classroom content for Academy website login unless a future School-enabled integration is separately disclosed in-product and in an updated policy.

Microsoft. Where Microsoft 365 / Entra sign-in is enabled, we receive account identifiers, name, and email needed to authenticate and link your Academy account, on the same limited basis.

School SAML / MyLogin. Where enabled, the School’s identity provider supplies identity assertions under the School’s arrangement with that provider.

After sign-in, further Customer Data in your Academy tenant is processed as described in this policy under the School’s controllership.

16. Website visitors and sign-in pages

When you browse Academy sign-in or public legal pages without an authenticated School session, we may process limited data: server and security logs (including IP address and request metadata); the contents of any form or support message you submit to Qwixl; and cookie-consent preferences. We do not build advertising profiles from that browsing.

17. Security and personal data breaches

Qwixl applies technical and organisational measures appropriate to the risk, including encryption in transit, access controls, role/Close Contact restrictions, and audit logging for sensitive access. No system is completely secure. You must keep credentials safe and report suspected compromise promptly to security@qwixl.com.

If a personal data breach affecting Customer Data occurs, Qwixl notifies the School under the DPA and applicable Incident SLA (where incorporated). The School remains responsible for notifying the ICO and affected individuals where required. Overview for schools and MATs: Security & compliance.

Part B — By audience

18. Pupils

Who is in charge: the School. Qwixl runs Academy for the School.

What we may hold about you: name and class; login; work and answers; typing timing inside Academy answer boxes; messages with the AI helper (if used); information from school systems via Wonde; extra-help / SEN status where the School uses it; screening-style clues for teachers (not a diagnosis).

Who can see named information about you: you, linked parents/carers, and Close Contacts. Other staff usually see group summaries. Qwixl staff only when needed to fix problems or keep Academy safe. Helper companies (hosting, email, AI) process data under contracts the School agrees via the DPA.

Your rights (with a parent/carer or teacher helping if needed): access, correction, erasure in some cases, restriction, objection, portability in some cases, and complaint to the School and the ICO. Ask your teacher or a grown-up to contact the School’s DPO. Qwixl privacy: privacy@qwixl.com.

A longer age-appropriate notice template for Schools is in the Academy legal pack (Privacy notice — pupils). Schools should complete School name and DPO details when issuing it. This public page is not that school-issued notice.

19. Staff

Controller / processor: as in Part A. You must access pupil data only for your authorised professional purpose and must not copy or share it outside School-authorised channels.

Data about you may include identity, work email, role, classes, content you create, support tickets, billing contact fields (if applicable), and security/audit events (including logs when you access sensitive pupil or SEN-related information).

Pupil data you may see follows Close Contact and role rules. SEN-related signals are aids for professional judgement — not diagnoses.

Rights and complaints: School DPO first for Customer Data; privacy@qwixl.com for processor questions or Qwixl controller processing. Unauthorised access may be logged and investigated by the School.

A full staff transparency notice template is in the Academy legal pack (Privacy notice — staff).

20. Parents and carers

As a linked parent/carer you are typically a Close Contact for your child. You may see identifiable information about your child as the product and School allow. You do not automatically see every staff view. The School decides how much SEN-related detail parents receive within product rules.

Formal subject-access and erasure requests about your child’s education records should go to the School. Academy may provide in-app tools for your own account data where released.

Contact the School DPO for rights and complaints about School processing; privacy@qwixl.com for processor/product questions.

A full parent/carer notice template is in the Academy legal pack (Privacy notice — parents and carers).

ResourceWhere
Security & compliance (roles, contracting, pack contents)/security-compliance
This Privacy Policyacademy.qwixl.com/privacy
Academy Terms of Service (website / Authorised User terms)academy.qwixl.com/terms
Qwixl Cookie Policywww.qwixl.com/cookie-policy
Consumer products Privacy Policy (Homework / Milo / Streams) — not Academywww.qwixl.com/privacy
School contract pack (Order Form, MSA, Product Terms, DPA, SLAs, Wonde schedule, notice templates)Issued to the School at proposal / legal review — summarised on Security & compliance
In-app Legal CentreSettings → Legal Centre (authorised School Admin / Senior Staff roles)
Privacy / security / supportprivacy@qwixl.com · security@qwixl.com · support@qwixl.com

22. Changes and contact

We may update this policy and will revise the “Last updated” date above. For material changes we will notify Schools (and, where appropriate, users) by email or in-app notice. School controllers remain responsible for updating their own notices to data subjects where required. New processing purposes that need a different lawful basis will not be introduced solely by silent continued use.

Privacy: privacy@qwixl.com Security: security@qwixl.com Support: support@qwixl.com

*End of Privacy Policy — Qwixl Academy (public) v1.1 — 24 July 2026.*