This notice is current and in force. It has been reviewed internally, by us, against the Information Commissioner’s published guidance — not by a lawyer. We will update it whenever anything changes.
This is the standard privacy notice for the Ember Learning platform, operated by Ember Learning Ltd. Versions written for young people are further down this page: one for students aged 7–11 and one for students aged 11–16. They say the same things in fewer words, and students see them inside the platform.
1. Who we are
Ember Learning Ltd, registered in England and Wales, company number 17131451. Registered office: 52a Spring Grove Road, Hounslow, London TW3 4BN.
ICO data protection registration: ZC221565, registered 13 August 2026.
Person responsible for data protection (as registered with the ICO): Jack Bradley — jack@emberlearning.co.uk. Director: Mahesh de Zoysa — mahesh@emberlearning.co.uk.
For safeguarding matters: Designated Safeguarding Lead (DSL) — Jack Bradley, jack@emberlearning.co.uk. Deputy DSL — Mahesh de Zoysa, mahesh@emberlearning.co.uk.
Our role in data protection
Our data protection role varies by processing activity:
- Processor (acting on the Local Authority’s instructions): for core teaching delivery — sessions, attendance, curriculum delivery, LA reporting. The LA is the controller.
- Controller: for safeguarding decisions and platform operations (audit logging, email delivery, error monitoring). We determine the purposes and means.
- Joint controller (with the LA): for LA progress reporting, where both parties determine purposes.
In practice we work with each LA under both a Data Processing Agreement (Article 28) and a Joint Controller Arrangement (Article 26). If you have questions about which party controls specific processing, contact us.
2. Who this notice is for
This notice covers personal data we process about:
- Children receiving teaching through us
- Parents and carers of those children
- Teachers delivering sessions on the platform
- Local Authority caseworkers commissioning our provision
- Visitors to this website
3. What information we collect
About children
| Category | Examples |
|---|---|
| Identity | First name, last name, preferred name, date of birth |
| Educational | Year group, key stage, school, subjects needing support |
| Special educational needs | EHCP (Education, Health and Care Plan) content, accessibility requirements |
| Wellbeing | Engagement notes, behavioural observations, motivators, things that put the young person off learning |
| Safeguarding | Concerns logged by teachers, DSL responses, body-map images (if applicable) |
| Sessions | Date and time of sessions, attendance, lesson topics, chat messages |
| Communication | Who can be contacted on the child’s behalf |
About parents and carers
Name, contact email, contact phone, relationship to child, communication preferences.
About teachers
Name, contact details, DBS check reference, right-to-work documentation, safeguarding training records, payroll details.
About LA caseworkers
Name, contact details, role, the LA they work for.
Information we do not collect
- Geolocation data
- Cookies or trackers for advertising or analytics
- Information from social media or advertising networks
- Voice biometrics — we do not analyse session audio
One third-party script does run on the platform: Cloudflare Turnstile, on the sign-in and password pages. It tells a person from an automated attack, and to do that it receives an IP address and browser signals. It is a security control, not an analytics or advertising tool — see sections 6 and 12.
4. Where we get information from
Much of the data we process about a young person comes from someone other than the young person themselves. Under Article 14 UK GDPR we are required to tell you where we got it:
| About… | We get it from… |
|---|---|
| Identity, year group, school | The Local Authority commissioning the provision |
| EHCP content | The LA or parent / carer, as a document upload |
| Intake interview notes | The parent or carer at intake, via an administrator |
| Session data and chat messages | The young person directly, during sessions |
| Teacher observations | The teacher, about the young person |
| Parents and carers | The parent or carer themselves; the LA |
| Teachers | The teacher themselves, at onboarding |
| LA caseworkers | The LA |
5. Why we use information, and our legal basis
| What we do | Legal basis |
|---|---|
| Provide teaching | Article 6(1)(e) UK GDPR — public task (the LA’s statutory duty under Section 19 Education Act 1996) |
| Process EHCP and health data | Article 9(2)(g) — substantial public interest; DPA 2018 Schedule 1 Part 2 §6 (statutory purposes — the LA’s duties under Section 19 Education Act 1996 and Part 3 of the Children and Families Act 2014) |
| Record safeguarding concerns and alert the DSL | Article 6(1)(e) public task — we are commissioned to discharge part of the LA’s safeguarding duty under Children Act 2004 s.11; Article 9(2)(g) substantial public interest, DPA 2018 Schedule 1 Part 2 §18 (safeguarding of children and of individuals at risk) |
| Hold teachers’ DBS and vetting records | Article 10 criminal offence data; DPA 2018 Schedule 1 Part 1 §1 — employment, social security and social protection |
| Pay teachers | Article 6(1)(b) — contract with the teacher |
| Report to the LA | Article 6(1)(e) — public task |
| Send service emails (progress reports, scheduling) | Article 6(1)(e) |
| Audit log of who accesses what | Article 6(1)(c) legal obligation; legitimate interests (defence in depth) |
We do not use a young person’s data for advertising, marketing, or any commercial purpose beyond delivering the provision the LA has commissioned.
6. Who we share information with
Subprocessors
The full list is here, in the notice itself, so there is one place to look and nothing to go stale behind a link:
- Supabase — database, authentication, storage. Hosted in the EU (Republic of Ireland). DPA in place.
- Digital Samba — secure video for live sessions. Hosted in the EU (Spain, with infrastructure in Germany, the Netherlands and Switzerland); not the UK. A data processing agreement is not yet signed — their published agreement refers to EU law only, and we are in correspondence about it. Sessions are live video only: no session is recorded, so no session content is stored by them.
- Resend — email delivery. US company; standard contractual clauses. DPA in place.
- Oak Academy — curriculum content provider. We send only lesson IDs; no data about a young person flows to Oak.
- Vercel — hosting infrastructure and error monitoring. The application runs on Vercel’s servers, which include locations outside the UK and EU; transfer under Vercel’s standard contractual clauses. DPA in place.
- Cloudflare (Turnstile) — bot protection on sign-in and password pages; receives IP address and browser signals; US company, UK/EU data transfer under its standard contractual clauses.
Everyone else
- The commissioning Local Authority receives reports about progress, attendance and outcomes, as joint controller.
- Parents and carers see their own child’s progress reports, attendance, and the teacher’s notes from each session. They do not see live session content or the session chat.
- The Designated Safeguarding Lead can reach safeguarding records, session notes, attendance, messages, session recordings, data reporting, compliance records and the platform’s access logs — the context a safeguarding decision needs. They may share concerns with statutory agencies — police, social services — where required by law.
- Statutory bodies, when legally required: police, the ICO, courts, child protection authorities.
Observing a live session
A caseworker from the commissioning Local Authority may ask to observe a live session. We approve the request first, and the student and their parent or carer are told before it happens. The observer joins visibly, with camera and microphone on, and is announced to everyone in the room. There is no hidden observation mode. An approval covers one session — not a series, and not a recording.
We do not share with advertisers, data brokers, analytics services that profile users, marketing services, or any AI provider. Section 8 names every provider that processes personal data outside the UK or EU, and the safeguard each one operates under.
7. How long we keep information
| Type | Retention | Basis |
|---|---|---|
| Commissioned-teaching data (sessions, progress, session notes) | Date of birth + 25 years | IRMS standard for child protection records |
| Safeguarding records | Date of birth + 25 years minimum; records of sexual abuse retained indefinitely | KCSIE; IICSA recommendation; Working Together |
| EHCP content | Date of birth + 25 years | Aligns with safeguarding retention |
| Session messages (chat) | Date of birth + 25 years | Safeguarding audit trail |
| Session recordings (only when consented, and recording is not yet in use) | 6 months, or at least 8 years where a safeguarding concern is linked to the session | Session Recording Policy ET-SRP-002 v1.1 §6.2; Section 19 provision |
| Operational data (invoices, attendance) | 7 years after the end of the provision | HMRC requirements; LA contract obligations |
| Audit logs (identifying details) | 12 months, then anonymised | Proportionate to operational need |
| Email outbox | 90 days after sending, then purged | Data minimisation |
After the retention period, data is either securely deleted or fully anonymised. Safeguarding data is never automatically deleted — it goes through an annual manual review.
8. Where information is stored, and where it is processed
Storage. Personal data is stored in the EU. The database, the authentication records and every uploaded file live in Supabase’s EU region (Republic of Ireland). Live video runs through Digital Samba in the EU.
Processing. Storing data in one place and running an application are not the same thing, and we would rather say so than imply otherwise:
- The application itself runs on Vercel, whose servers include locations outside the UK and EU. Requests to the platform — and the personal data in them — are processed there, under Vercel’s standard contractual clauses.
- Email is sent through Resend, a US company, under its standard contractual clauses.
- Cloudflare Turnstile sees the IP address and browser signals of anyone loading a sign-in or password page, under its standard contractual clauses.
No personal data is sent to any AI provider — see section 10.
9. Your rights
You have the right to:
- See what data we hold about you (Article 15 — subject access)
- Correct information that is wrong (Article 16 — rectification)
- Ask us to delete your information in some circumstances (Article 17)
- Object to processing in some circumstances (Article 21)
- Restrict processing in some circumstances (Article 18)
- Data portability in some circumstances (Article 20)
- Withdraw consent for any consent-based processing, at any time
Young people have the same rights as adults under UK GDPR. Students and parents can exercise them from the “Your data” page inside the platform, or by emailing mahesh@emberlearning.co.uk. We respond within one month, extendable by up to two further months for complex requests.
You also have the right to complain to the Information Commissioner’s Office, or by phone on 0303 123 1113.
10. AI processing
The platform does not use AI to process any personal data about a student or mentee. No AI provider is engaged, and no personal data is sent to any AI provider. The platform contains designed-but-disabled provisions for AI-assisted features — for example, pre-session briefing drafts — and they process nothing.
A consent preference we record but do not act on. At intake we ask the responsible adult whether they consent to AI processing for their child, and that preference is stored on the student’s record and shown to teachers and administrators. Nothing acts on it, because no AI processing takes place: no provider is configured, and the code that would have read uploaded documents has been deleted. We keep the field because consent is the gate any future feature would have to pass. If AI processing were ever introduced we would update this notice and ask for fresh consent first — a preference recorded today is not permission for a feature that did not exist when it was given.
If AI features are introduced in future, before any processing starts we will sign a data processing agreement with the provider, document any international transfer under Standard Contractual Clauses, update our Data Protection Impact Assessment and this notice, obtain sign-off from our Designated Safeguarding Lead, and disclose the arrangement to commissioning bodies. Safeguarding disclosures will never be processed by AI under any circumstances.
The same absolute exclusion applies to uploaded education and health documents — EHCPs, IEPs, educational psychology reports and medical plans. These are stored for a named person to read and are not processed by any automated system. This is not a setting that could be switched on: the code that read them has been removed, and automated tests fail the build if such a path is reintroduced.
11. Security
- Data encrypted in transit (TLS 1.3) and at rest
- Strict role-based access control enforced at database level (Postgres row-level security)
- Multi-factor authentication required for administrator and DSL accounts
- Audit log of every access to sensitive data about a young person
- Circuit breakers on external calls, to prevent cascade failures
- Structured logging with PII redaction — no names or email addresses in logs
- Every teacher DBS-checked before any contact with a young person
- Annual security review
12. Cookies
The platform uses only essential cookies: the Supabase authentication session, a CSRF protection token, and a short-lived Cloudflare Turnstile cookie set on sign-in and password pages so that bot protection can work. We do not use advertising cookies, analytics cookies, cross-site tracking or social-media embed cookies, and nothing we set follows you between sites. Because every cookie is strictly necessary — Turnstile’s included, since it protects accounts — no consent banner is required (PECR Regulation 6 exemption).
This website sets no cookies at all, and loads no analytics or advertising scripts. See section 13.
13. Visitors to this website
This page is part of our marketing website, and section 2 says visitors to it are covered by this notice — so here is what happens when you use it. The website is a set of static pages. It sets no cookies, loads no analytics, no advertising and no third-party tracking scripts, and there is nothing here to consent to. Two forms are the only places it collects anything.
The contact form
It collects your first and last name, your email address, your organisation if you give one, the enquiry type you pick from the list, and your message. We use it to answer you, and we keep your IP address in memory for a minute purely to rate-limit the form.
Nothing is stored on a server. The form sends one email to our team through Resend and writes to no database, so your message lives in our mailbox and nowhere else, for as long as we keep the email. Legal basis: legitimate interests — answering someone who has asked us a question.
The teacher application form
It collects your first and last name, email address, phone number if you give one, the subjects you teach, and your message. We email you a confirmation and our team a copy, both through Resend, and — unlike the contact form — we create a screening record for you on the platform, because that is the start of safer recruitment. That record is recruitment data and is kept under the retention rules for it, not the ones in section 7, which are about young people.
14. Changes to this notice
When we materially change this notice we will update the date at the top, email registered users 14 days before the change takes effect, and highlight what changed.
15. Contact us
- Data protection, the person named on our ICO registration — Jack Bradley: jack@emberlearning.co.uk
- General questions about your data, and rights requests: mahesh@emberlearning.co.uk
- Safeguarding concerns — Jack Bradley, DSL: jack@emberlearning.co.uk
- To complain: us first, then the ICO
- By post: Ember Learning Ltd, 52a Spring Grove Road, Hounslow, London TW3 4BN — the registered office, and the address held against ICO registration ZC221565
For students aged 7–11
This is what a student aged 7 to 11 sees inside the platform. It is the same notice, in plainer words.
How we look after your information
When you use Ember Learning, we have to keep some information about you so that your teacher can help you learn. This page tells you what we keep, who can see it, and how to ask questions. Read it slowly. If you don’t understand something, ask a grown-up.
What do we keep?
- Your name and how old you are
- What year group you’re in
- The subjects you’re working on
- Notes from your teacher about your lessons
- Anything you type in the chat during a lesson
If you have an EHCP (a plan that helps you with school), we keep a copy of that too. It is kept safely, and only the people who run Ember Learning can open it — not your teacher.
Where did we get your information?
- Your local council told us your name, your age, and your school.
- Your parent or carer told us about what helps you learn and what you find difficult.
- Your EHCP, if you have one, was sent to us by your council or your parent.
- Your teacher writes notes after your lessons about how the lesson went.
- You — anything you type in the chat during a lesson comes from you.
Who can see your information?
- Your teacher can see what they need to plan your lessons.
- Grown-ups at Ember Learning can see your information to help with safety and timetables.
- The safety grown-up, called the DSL, can see anything to do with keeping you safe.
- Your parent or carer can see how your lessons are going, and the notes your teacher writes.
- The local council who arranged your lessons can see how you’re doing.
Sometimes a person from the council may join one lesson to see how it is going. You will always know before, and you will see them. Nobody watches your lesson in secret.
Who can’t see your information?
- Other students.
- Anyone outside Ember Learning who isn’t on the list above.
- Adverts. We don’t show ads. Ever.
- Companies that try to sell you things.
Do we use AI?
No. AI is a clever computer program. We don’t use one with your information. Real people do everything here — your teacher and our team. If that ever changes, we will tell you and your parent or carer first.
Your rights
- You can see what we have about you.
- You can tell us if something is wrong. We’ll fix it.
- You can ask us to remove information about you. Some things we have to keep — we’ll explain.
How long do we keep your information?
We keep your information for a long time — until you are a grown-up, about 25 years after your birthday. This is because the law says we have to keep safety records in case they are needed. When the time is up, we delete it.
We do not record lessons at the moment. If we ever do, your grown-up has to say yes first. Then we keep the recording for 6 months. If it is part of keeping you safe, we keep it for at least 8 years.
If you’re worried
Tell a grown-up first. You can also tell:
- Your teacher
- An admin at Ember Learning — mahesh@emberlearning.co.uk
- The safety lead, Jack — jack@emberlearning.co.uk
- A group called the ICO that checks we’re being fair: ico.org.uk
You can also call Childline on 0800 1111 if you need to talk to someone about anything.
Who we are
Ember Learning is run by a company called Ember Learning Ltd. Its company number is 17131451. We are on the ICO’s list of people who look after information. Our number on that list is ZC221565, and we went on that list on 13 August 2026. You can show these numbers to a grown-up if they want to check who we are.
For students aged 11–16
This is what a student aged 11 to 16 sees inside the platform.
Your information at Ember Learning
This page tells you what information we keep about you, who can see it, and what your rights are. There is a longer version above if you want all the details. Either way, read it. It’s about you.
What we keep
- Your name, date of birth, year group, key stage and school
- The subjects you need support with
- Your EHCP if you have one — kept separately, and seen only by the people who run Ember Learning, never your teacher
- Things that motivate you and things that put you off learning, so your teacher can help you better
- Notes from your teacher after each lesson — what was covered, how it went, what to focus on next
- Chat messages you send during sessions, kept for safeguarding
- If you ever raise a safeguarding concern, the record of it
What we don’t keep
- We don’t track where you live. No GPS, no location.
- We don’t show ads.
- We don’t share you with marketing companies.
- We don’t keep recordings of your video sessions, unless that is switched on for a specific reason and you are told.
Where did we get your information?
- Your Local Authority told us your name, date of birth, year group and school when they referred you.
- Your parent or carer told us about what helps you learn, during an intake interview.
- Your EHCP, if you have one, was sent to us by your LA or your parent.
- Your teacher writes notes after each lesson about how it went.
- You — what you type in chat during a lesson, and anything you tell your teacher directly.
We are required by law (Article 14 UK GDPR) to tell you where your data came from.
Who can see what
| Who | What they can see |
|---|---|
| You, in the app | Your sessions, your teacher’s name, your subjects |
| Your teacher | Everything they need to plan and run your lessons |
| Admin at Ember Learning | Your full record, for timetabling, safety and billing |
| The DSL (Designated Safeguarding Lead) | Safeguarding records, your teacher’s session notes, your attendance, messages, recordings, and the logs of who looked at what |
| Your parent or carer | Your progress reports, your attendance, and your teacher’s notes from each session — but not your live session chat |
| Your Local Authority caseworker | Reports about how your sessions are going. They can also ask to watch one session — see below |
| Other students | Nothing about you. They can’t see your account. |
Someone from the council watching a session
A caseworker can ask to join one of your sessions to see how it is going. We have to agree to it, and you and your parent or carer are told before it happens. They join with their camera and microphone on, and everyone is told they are there. Nobody watches a session in secret. One yes covers one session — not a whole term, and not a recording.
Do we use AI?
No — we don’t use AI with your information. Everything about your learning is written and decided by real people: your teacher and our team.
If we ever start using AI to help — for example, to help your teacher prepare — we will update this notice first, tell you clearly, and ask for permission where the law requires it. The things you tell us to keep you safe will never be given to an AI.
We do ask your parent or carer at the start whether they would agree to it. We write that answer down, and nothing uses it. If that changes, we will ask again.
Your data, your rights
- See your data. Get a copy of everything we keep about you.
- Correct your data. Tell us if something’s wrong.
- Delete your data. Ask us to remove information about you. Some safeguarding records have to be kept by law — we’ll explain which.
- Object. Ask us to stop using your data in a particular way.
- Withdraw consent. If we’re using your data because you agreed to it, you can take that agreement back.
- Complain. Email us first; if we don’t help, go to the ICO.
You don’t need a parent’s permission to use these rights. If you are under 13 we will usually involve a parent or carer in the response, because UK law makes that the default for younger children.
Where your information lives
Your information is stored in the EU: the database and files are with Supabase in Ireland, and live video with Digital Samba in the EU.
The app itself runs on servers belonging to a company called Vercel, and some of those are outside the UK and the EU. Our email is sent by a US company called Resend. Both have signed the legal agreement the law asks for when data is handled outside the UK — standard contractual clauses. None of your information is sent to an AI.
How long we keep your information
Your teaching records — sessions, progress, notes — until you are about 32, which is your date of birth plus 25 years. That is the standard set by the IRMS, who write the record-keeping rules for schools. It means your records are there all through your childhood and into adulthood, in case they are ever needed.
Safeguarding records: at least until you are 32, sometimes longer. Records about serious concerns may be kept indefinitely. This isn’t our choice — it is what the law requires.
Recordings: we don’t record sessions at the moment. If that changes, and only where consent has been given, a recording is kept for 6 months — or at least 8 years if a safeguarding concern is linked to that session.
Short-term things: emails we send are kept for 90 days, and audit logs of who looked at what are kept for 12 months and then made anonymous.
If you have a problem
- Talk to your teacher, or your parent or carer
- Email Mahesh, the director: mahesh@emberlearning.co.uk
- Jack Bradley, the DSL, handles anything about safety: jack@emberlearning.co.uk
- Outside Ember Learning: Childline on 0800 1111 (free and confidential), NSPCC on 0808 800 5000, or the ICO for data complaints
Who we are
Ember Learning is run by Ember Learning Ltd, a company registered in England and Wales. Our company number is 17131451. We are registered with the ICO — the UK’s data protection regulator — as ZC221565, registered on 13 August 2026. If you complain to the ICO about us, that is the number they will ask for.
If you have a question about your information, email Jack Bradley. He is the person named on our ICO registration who looks after data protection: jack@emberlearning.co.uk.