ActivityOS processes your school's data on your instructions, stores it in Germany, keeps each school's records separate, and gives you a starter DPIA to complete for your own files.
Part 1: Security and data protection overview
1At a glance
Question
Answer
Who runs ActivityOS?
Stephen Butterworth, a sole trader trading as ActivityOS, Conwy, Wales
Our role
Data processor for your school's data. You are the controller.
Where is data stored?
Germany (Frankfurt), on Supabase
Do you sell or advertise with our data?
No. Data is used only to provide, secure and support the service.
How are schools kept apart?
Row-level security in the database, so each school sees only its own records
Encryption
TLS in transit; encrypted at rest; weekly backups encrypted with AES-256 before storage
Sensitive data
Health information and DBS records are supported but optional. You decide what to enter.
Breach notice
Within 48 hours of us becoming aware
Sub-processors
Listed in section 4 and in Schedule 2 of the DPA, with 30 days' notice of changes
For pupil, parent and staff data, the school is the controller and ActivityOS is the processor. The school decides why and how the data is used; ActivityOS acts only on its documented instructions.
The school needs a lawful basis for what it records, tells parents how their data is used, gets consent from a parent or guardian where it relies on consent, and decides which staff can see what.
ActivityOS provides and secures the platform, uses only the sub-processors listed here, helps the school answer data requests, and tells the school promptly about any breach.
ActivityOS as controller: for the account details of the school's users (sign-in, billing, support), ActivityOS is a separate controller. That is covered by the Privacy Policy, not the DPA.
3What data we process
The school chooses what to enter. The platform can hold the following:
Pupils (many are children): name, date of birth, school attended, class enrolments, attendance, progression, competition entries and results, notes.
Parents, guardians and emergency contacts: name, email, phone, relationship to the pupil, collection notes.
Consents: photograph, social media, performance, medical treatment and health data consents, with dates.
Staff: name, email, role and permissions, and DBS check level, dates and certificate number if the school chooses to record them.
Billing: invoices, payment status and references, the school's bank details, direct debit mandate references and the last two digits of a parent's bank account. Full card numbers never reach ActivityOS.
Communications: messages between teachers and parents, email delivery and open status, push notification subscriptions.
Technical: sign-in details, plus IP address and browser information recorded when someone accepts the terms or submits a public registration form.
Special category data. Pupil health information (allergies, medical conditions, emergency action, GP details) is optional. If the school records it, it needs a condition under Article 9 of the UK GDPR and should enter only what it needs.
Criminal offence data. DBS records for staff are optional and need a basis under Article 10 and the Data Protection Act 2018.
4Where data goes
Customer data is stored in Germany. The other providers process data only as described. Where a provider is outside the UK and EEA, a lawful transfer mechanism applies (the UK-US Data Bridge, or standard contractual clauses with the UK Addendum). The full detail is in Schedule 2 of the Data Processing Agreement.
Provider
What it does
Data involved
Location
Supabase
Database and sign-in
All customer data
Germany (Frankfurt)
Cloudflare
Hosts the app, runs server-side processing, network security
Data while a request is handled; nothing stored in its databases
Global network
Resend
Sends email (invoices, reminders, account emails, messages to parents)
Recipient names and addresses, message content, delivery status
United States
Stripe
Card payments and subscription billing
Payer name, email, amounts, references
UK, EEA, US
GoCardless
Direct debit, only if the school turns it on
Parent name and email, mandate and payment references
UK, EEA
Google Drive
Stores weekly backups
Encrypted backup files; Google cannot read them
Global
Browser push services (Google, Apple, Mozilla)
Delivers push notifications
Notification text, which can include a pupil's name, and a subscription token
US and global
ActivityOS gives at least 30 days' notice before adding or replacing a provider. A school can object on reasonable data protection grounds.
5How data is protected
Encryption. TLS in transit. The database provider encrypts data at rest. Weekly backups are encrypted with AES-256 before they are stored, and the storage provider does not hold the key.
Separation between schools. Every table uses row-level security, so each school's data is visible only to its own authorised users. Parents can see only records linked to their own children.
Role-based access. The school's owner decides which modules each staff member can use. Account settings are limited to the owner.
Signed-in access for sensitive actions. Server-side routes that send email or change accounts require a signed-in user. Payment and email provider notifications are signature-checked before they are acted on.
Locked-down public surfaces. Public pages show only the fields a visitor needs. Uploaded logos are restricted by file type and size.
Browser protections. Security headers are set on the app, and the database and spreadsheet libraries used by the app are served from ActivityOS rather than loaded from a public CDN.
Limited internal access. Production systems are accessible only to the people who need them.
Regular internal review. The database access rules and server code are reviewed regularly. The latest review, in October 2026, covered separation between schools, public data exposure and who may call each server route.
Changes to measures. ActivityOS may improve its measures but will not reduce the overall level of protection.
6Rights, breaches and retention
Data subject requests. The school answers requests from parents and pupils. ActivityOS helps through the platform's tools (viewing, exporting, correcting and deleting records) and directly where needed. If someone contacts ActivityOS about a school's data, the request is passed to the school and not answered on its behalf.
Personal data breaches. ActivityOS tells the school without undue delay, and within 48 hours of becoming aware. The notice says what happened, who and how many records are affected, the likely consequences, what has been done, and who to contact. ActivityOS helps the school meet its own duty to tell the ICO and affected people.
Retention and deletion.
Data
How long
Students, classes, festivals and events the school deletes
Held 30 days, then permanently deleted
Invoices the school deletes
Held 6 years (financial records), then permanently deleted
Declined registration requests
Deleted after 90 days
School account closed
Export available for 30 days, then deleted from live systems within a further 30 days
Encrypted backups
Replaced weekly; gone no later than 6 weeks after live data is deleted
On request, ActivityOS confirms in writing that deletion is complete.
Audit and information. On reasonable written request ActivityOS provides the information needed to show compliance with Article 28 of the UK GDPR, and the school may audit once in any 12 months (see clause 12 of the Data Processing Agreement).
Part 2: DPIA starter for schools
7DPIA starter: how to use it, and the description of processing
A data protection impact assessment (DPIA) is the school's document, because the school is the controller. This starter has the ActivityOS side already filled in. Add your own context where it says School to complete, then sign it off in section 10 and keep it with your records. It follows the ICO's DPIA structure.
Do you need one? Many small activity schools do not have to do a DPIA, but it is good practice, and sensible where you record health information, work with large numbers of children, or are asked for one by a parent, a franchisor or a venue. If you are unsure, the ICO's screening checklist is on its website.
Nature of the processing
The school uses ActivityOS to manage classes, timetables, enrolments, attendance, invoices and payments, competition entries and results, events, uniform orders and messages to parents. Data is collected from parents (through the school or the registration form) and entered by staff. It is stored in a database in Germany, shown to authorised staff and linked parents, emailed or notified to parents, and deleted under the retention rules in section 6. Data is not sold or used for advertising, and ActivityOS does not make automated decisions about pupils.
Scope
Data types: see section 3.
Special category data: health information, optional. Criminal offence data: staff DBS records, optional.
School to complete: approximate number of pupils, parents and staff; how long you keep records; which optional fields you use.
Context
Most pupils are children. Parents or guardians are the main contacts and are the only parent-side users.
Parents can see only records linked to their own children.
School to complete: how parents are told about their data (privacy notice), whether parents would expect this use, and any concerns raised.
Purposes
Running the school efficiently and safely: knowing who is in each class, collecting fees, keeping emergency and medical information available to staff, and keeping parents informed.
School to complete: your lawful basis for each purpose (for example contract for fees, legitimate interests for registers, consent for photos), and your Article 9 condition if you record health information.
8DPIA starter: necessity and proportionality
Is the processing needed for the purposes? Class lists, attendance, invoices and contact details are needed to run a school. Health information is needed only where it affects a child's safety in class.
Is there a less intrusive way? Paper registers and spreadsheets hold the same data with fewer protections: no access controls, no encryption, easy to lose. A purpose-built system with role-based access and a contract with the provider is generally the safer option.
Data minimisation. The school decides what to enter. Health, DBS and consent fields are optional, and the school should leave them empty unless it needs them.
Accuracy. Staff can correct records at any time, and parents can see their own child's details in the portal and ask the school to correct them.
Storage limits. Deleted records are purged on a fixed schedule (section 6); the school can delete records at any time.
Information for parents. The school's privacy notice should say that ActivityOS is used as a processor, and that data is stored in Germany with the providers listed in section 4.
Processor compliance. The Data Processing Agreement is accepted at signup and records the version and the time. It includes sub-processor controls, 48-hour breach notice, help with data requests and a right to audit.
International transfers. Data is stored in the EEA, which the UK treats as adequate. Other providers use the UK-US Data Bridge or standard contractual clauses with the UK Addendum.
School to complete: whether anything above does not match how you use the system.
9DPIA starter: risks and safeguards
Rate the likelihood and severity of each risk for your own school (low, medium or high) in your copy, and record what you will do about any that stay high.
Risk to individuals
ActivityOS safeguards
What the school should do
Another school sees your pupils' data
Row-level security on every table; each school sees only its own records; tested across schools
Keep your own staff list current; remove access when someone leaves
A parent sees another family's data
Parents can see only records linked to their own children
Check the parent email on each pupil is correct before inviting
Staff see more than they need
Owner sets module access per staff member; settings limited to the owner
Give each teacher only the modules they need
Health or medical details exposed or out of date
Access limited by role; optional field; encrypted in transit and at rest
Record only what is needed; review medical details each term
Email sent to the wrong person
Emails go to the address on the record; the email route accepts only signed-in users, and reminders come from scheduled jobs
Keep parent emails accurate; check before sending bulk messages
Someone takes over a staff account
Sign-in required for server actions; email confirmation on signup
Use a strong, unique password; remove staff accounts when people leave
A provider has a breach
Written contracts with each provider; 48-hour notice to the school; encrypted backups
Know who to tell: your own ICO reporting duty applies if risk to individuals is likely
Data kept longer than needed
Fixed deletion schedule; school can delete at any time; deletion confirmed in writing on request
Decide your own retention periods and delete old pupils and records
Data sent outside the UK without protection
Stored in Germany; other providers covered by the UK-US Data Bridge or standard contractual clauses with the UK Addendum
Mention the providers in your privacy notice
Parents not told how data is used
Terms and DPA require the school to inform parents
Publish a privacy notice that names ActivityOS as a processor
Loss of access to records
Weekly encrypted backups
Export key records (class lists, medical details) from time to time
A child's photo or performance consent is not recorded
Consent fields with dates are available
Record consent from a parent or guardian and update it when it changes
10DPIA starter: school sign-off
I have completed every School to complete item above
I have a lawful basis for each purpose, and an Article 9 condition if I record health information
My privacy notice tells parents that ActivityOS is used as a processor, where data is stored, and who the providers are
Only staff who need access have it, and I know how to remove it
I know my own duty to report a breach to the ICO within 72 hours where required, and I have the contact for ActivityOS (hello@activityos.co.uk)
I have a date to review this assessment (at least once a year, or when I start using new features)
School name: ______________________
Completed by (name and role): ______________________
Date: ______________________
Next review: ______________________
If a risk stays high after the safeguards above, the school should take advice before going ahead. The ICO helpline and guidance are available at ico.org.uk.
This pack is information about how ActivityOS works. It is not legal advice, and it does not replace the school's own assessment.