Privacy Policy

Last updated

This policy explains what information InstituteOnClick collects, why we collect it, and the choices available to the schools that use the platform. We have written it in plain language rather than legal shorthand.

Who controls the data

The school — not InstituteOnClick — decides what records are entered into the platform and how they are used. The school is the data controller; we process that data on the school's instructions in order to provide the service.

This distinction matters for student records in particular: requests to access, correct or delete a student's information should go to the school, which can act on them directly inside the platform.

Information we collect

The platform holds the records a school needs in order to operate:

  • Account details for staff, students and guardians — names, roles, contact details and login credentials.
  • Academic records such as enrolment, attendance, timetables, assignments, marks and report cards.
  • Financial records including fee schedules, invoices and payment status.
  • Operational and technical logs — actions taken in the app, plus IP address, browser and device information used to keep accounts secure.

How the information is used

Data is used to run the service the school has signed up for: authenticating users, displaying the right records to the right roles, sending transactional messages such as verification and password-reset emails, processing subscription billing, and diagnosing faults.

We do not sell personal information, and we do not use student data to serve advertising.

Who else can see it

Access outside the school is limited to what is needed to deliver the service:

  • Service providers that host the application, deliver email and process payments, acting under contract and only on our instructions.
  • Our own staff, where access is necessary for support or maintenance requested by the school.
  • Authorities, where disclosure is genuinely required by law.

Security

Access within a school is governed by role-based permissions, so each user sees only the records their role allows. Traffic between the browser and the platform is encrypted, passwords are stored using one-way hashing, and administrative actions are attributable to the account that performed them.

No system is immune to compromise. If a breach affects a school's data, we will notify the school so it can meet its own obligations to families and regulators.

Retention

Records are kept for as long as the school's account is active, because schools are generally required to retain academic records for a period set by their own regulator. After an account closes, data is deleted or returned according to the arrangement made with the school at that time.

Cookies and analytics

The platform sets cookies that are necessary for signing in and keeping a session open. Our public marketing pages also use Google Analytics to understand which pages are visited; IP addresses are anonymised. Analytics does not run inside the authenticated application, and browser controls can be used to block these cookies.

Children's data

Student records are entered by the school in its role as controller, under the legal basis that applies in its jurisdiction. We do not knowingly collect information directly from a child, and accounts are always created and administered by the school.

Changes to this policy

If this policy changes materially, we will update the date above and notify schools through the platform before the change takes effect.

Questions about this document? Contact [email protected].