Data Protection Pack for Schools

Version 1.0 Last updated 11 October 2026

ActivityOS processes your school's data on your instructions, stores it in Germany, keeps each school's records separate, and gives you a starter DPIA to complete for your own files.

Part 1: Security and data protection overview

1At a glance

QuestionAnswer
Who runs ActivityOS?Stephen Butterworth, a sole trader trading as ActivityOS, Conwy, Wales
Our roleData processor for your school's data. You are the controller.
Where is data stored?Germany (Frankfurt), on Supabase
Do you sell or advertise with our data?No. Data is used only to provide, secure and support the service.
How are schools kept apart?Row-level security in the database, so each school sees only its own records
EncryptionTLS in transit; encrypted at rest; weekly backups encrypted with AES-256 before storage
Sensitive dataHealth information and DBS records are supported but optional. You decide what to enter.
Breach noticeWithin 48 hours of us becoming aware
Sub-processorsListed in section 4 and in Schedule 2 of the DPA, with 30 days' notice of changes
ContractData Processing Agreement, accepted when you create your account
Contacthello@activityos.co.uk

2Who is responsible for what

For pupil, parent and staff data, the school is the controller and ActivityOS is the processor. The school decides why and how the data is used; ActivityOS acts only on its documented instructions.

3What data we process

The school chooses what to enter. The platform can hold the following:

Special category data. Pupil health information (allergies, medical conditions, emergency action, GP details) is optional. If the school records it, it needs a condition under Article 9 of the UK GDPR and should enter only what it needs.

Criminal offence data. DBS records for staff are optional and need a basis under Article 10 and the Data Protection Act 2018.

4Where data goes

Customer data is stored in Germany. The other providers process data only as described. Where a provider is outside the UK and EEA, a lawful transfer mechanism applies (the UK-US Data Bridge, or standard contractual clauses with the UK Addendum). The full detail is in Schedule 2 of the Data Processing Agreement.

ProviderWhat it doesData involvedLocation
SupabaseDatabase and sign-inAll customer dataGermany (Frankfurt)
CloudflareHosts the app, runs server-side processing, network securityData while a request is handled; nothing stored in its databasesGlobal network
ResendSends email (invoices, reminders, account emails, messages to parents)Recipient names and addresses, message content, delivery statusUnited States
StripeCard payments and subscription billingPayer name, email, amounts, referencesUK, EEA, US
GoCardlessDirect debit, only if the school turns it onParent name and email, mandate and payment referencesUK, EEA
Google DriveStores weekly backupsEncrypted backup files; Google cannot read themGlobal
Browser push services (Google, Apple, Mozilla)Delivers push notificationsNotification text, which can include a pupil's name, and a subscription tokenUS and global

ActivityOS gives at least 30 days' notice before adding or replacing a provider. A school can object on reasonable data protection grounds.

5How data is protected

6Rights, breaches and retention

Data subject requests. The school answers requests from parents and pupils. ActivityOS helps through the platform's tools (viewing, exporting, correcting and deleting records) and directly where needed. If someone contacts ActivityOS about a school's data, the request is passed to the school and not answered on its behalf.

Personal data breaches. ActivityOS tells the school without undue delay, and within 48 hours of becoming aware. The notice says what happened, who and how many records are affected, the likely consequences, what has been done, and who to contact. ActivityOS helps the school meet its own duty to tell the ICO and affected people.

Retention and deletion.

DataHow long
Students, classes, festivals and events the school deletesHeld 30 days, then permanently deleted
Invoices the school deletesHeld 6 years (financial records), then permanently deleted
Declined registration requestsDeleted after 90 days
School account closedExport available for 30 days, then deleted from live systems within a further 30 days
Encrypted backupsReplaced weekly; gone no later than 6 weeks after live data is deleted

On request, ActivityOS confirms in writing that deletion is complete.

Audit and information. On reasonable written request ActivityOS provides the information needed to show compliance with Article 28 of the UK GDPR, and the school may audit once in any 12 months (see clause 12 of the Data Processing Agreement).

Part 2: DPIA starter for schools

7DPIA starter: how to use it, and the description of processing

A data protection impact assessment (DPIA) is the school's document, because the school is the controller. This starter has the ActivityOS side already filled in. Add your own context where it says School to complete, then sign it off in section 10 and keep it with your records. It follows the ICO's DPIA structure.

Do you need one? Many small activity schools do not have to do a DPIA, but it is good practice, and sensible where you record health information, work with large numbers of children, or are asked for one by a parent, a franchisor or a venue. If you are unsure, the ICO's screening checklist is on its website.

Nature of the processing

The school uses ActivityOS to manage classes, timetables, enrolments, attendance, invoices and payments, competition entries and results, events, uniform orders and messages to parents. Data is collected from parents (through the school or the registration form) and entered by staff. It is stored in a database in Germany, shown to authorised staff and linked parents, emailed or notified to parents, and deleted under the retention rules in section 6. Data is not sold or used for advertising, and ActivityOS does not make automated decisions about pupils.

Scope

Context

Purposes

Running the school efficiently and safely: knowing who is in each class, collecting fees, keeping emergency and medical information available to staff, and keeping parents informed.

School to complete: your lawful basis for each purpose (for example contract for fees, legitimate interests for registers, consent for photos), and your Article 9 condition if you record health information.

8DPIA starter: necessity and proportionality

School to complete: whether anything above does not match how you use the system.

9DPIA starter: risks and safeguards

Rate the likelihood and severity of each risk for your own school (low, medium or high) in your copy, and record what you will do about any that stay high.

Risk to individualsActivityOS safeguardsWhat the school should do
Another school sees your pupils' dataRow-level security on every table; each school sees only its own records; tested across schoolsKeep your own staff list current; remove access when someone leaves
A parent sees another family's dataParents can see only records linked to their own childrenCheck the parent email on each pupil is correct before inviting
Staff see more than they needOwner sets module access per staff member; settings limited to the ownerGive each teacher only the modules they need
Health or medical details exposed or out of dateAccess limited by role; optional field; encrypted in transit and at restRecord only what is needed; review medical details each term
Email sent to the wrong personEmails go to the address on the record; the email route accepts only signed-in users, and reminders come from scheduled jobsKeep parent emails accurate; check before sending bulk messages
Someone takes over a staff accountSign-in required for server actions; email confirmation on signupUse a strong, unique password; remove staff accounts when people leave
A provider has a breachWritten contracts with each provider; 48-hour notice to the school; encrypted backupsKnow who to tell: your own ICO reporting duty applies if risk to individuals is likely
Data kept longer than neededFixed deletion schedule; school can delete at any time; deletion confirmed in writing on requestDecide your own retention periods and delete old pupils and records
Data sent outside the UK without protectionStored in Germany; other providers covered by the UK-US Data Bridge or standard contractual clauses with the UK AddendumMention the providers in your privacy notice
Parents not told how data is usedTerms and DPA require the school to inform parentsPublish a privacy notice that names ActivityOS as a processor
Loss of access to recordsWeekly encrypted backupsExport key records (class lists, medical details) from time to time
A child's photo or performance consent is not recordedConsent fields with dates are availableRecord consent from a parent or guardian and update it when it changes

10DPIA starter: school sign-off

School name: ______________________

Completed by (name and role): ______________________

Date: ______________________

Next review: ______________________

If a risk stays high after the safeguards above, the school should take advice before going ahead. The ICO helpline and guidance are available at ico.org.uk.

This pack is information about how ActivityOS works. It is not legal advice, and it does not replace the school's own assessment.