EW
EduWrite

Privacy Policy

Last updated: 31 July 2026

EduWrite (“we”, “us”, “our”) is a handwriting-first learning platform for UK primary schools. We are committed to protecting the privacy of teachers, students, school administrators, and visitors to our platform. This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over that data.

This policy is written in plain English so it can be understood by the teachers, school administrators, and (where appropriate) parents and carers who rely on it. It complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).

1. Who we are

EduWrite is the data controller for the personal data described in this policy. This means we decide how and why your personal data is processed. For school deployments, the school itself may also act as a joint controller for the student and class data it provides to us.

Contact details: EduWrite, support@eduwrite.app. If you are a school customer, your primary contact is the administrator named in your deployment agreement. We will respond to privacy enquiries within 30 days, as required by UK GDPR.

2. What personal data we collect

We collect only the personal data needed to deliver the service (data minimisation). This includes:

Teacher and school administrator data

  • Account data: full name, work email address, password (stored as a one-way hash).
  • School data: school name, organisation ID, role within the school (teacher or administrator).
  • Usage data: activities created, classes managed, assignments given, and feedback provided.
  • Authentication data: JWT session tokens stored in your browser's sessionStorage. We do not use third-party tracking cookies.

Student data

  • Display name: a name chosen by the teacher for identification in class. Where possible, display names are used instead of legal names.
  • Class and year group: used to assign age-appropriate content (Reception to Year 6).
  • Stroke data: the handwriting strokes a child produces on a tablet, including timing and pressure. This is personal data because it can identify a child through their handwriting.
  • Submission records: completed activities, scores, and teacher feedback.
  • Device data: the tablet is authorised via a QR code at the school level. Students do not log in with personal credentials, and we do not collect student contact details or geolocation.

SaaS platform data

  • Admin data: SaaS support staff accounts, impersonation audit logs, billing and plan information for school organisations.

3. Lawful basis for processing

We rely on the following lawful bases under UK GDPR Article 6:

  • Contract (Art. 6(1)(b)): processing teacher, student, and school data to deliver the service you or your school has signed up for.
  • Legal obligation (Art. 6(1)(c)): retaining billing and audit records where required by law.
  • Legitimate interests (Art. 6(1)(f)): platform security, fraud prevention, and product improvement. These interests are balanced against the privacy rights of users, particularly children.
  • Consent (Art. 6(1)(a)): where we ask for consent (for example, optional analytics), it can be withdrawn at any time.

For children's data, we rely on the school's contractual relationship and the school's authority to act on behalf of parents and carers. Schools are responsible for ensuring appropriate parental or carer awareness is in place before student data is provided to EduWrite.

4. How we use your data

  • To create and manage teacher, administrator, and student accounts.
  • To assign, deliver, and mark handwriting and learning activities.
  • To show teachers what children actually write, in real time, so they can support learning.
  • To run handwriting recognition (OCR) and AI analysis on stroke data so teachers receive learning aids. Recognition outputs are learning aids only and are never used as the sole basis for assessment decisions.
  • To maintain tenant isolation: one school cannot access another school's data.
  • To keep immutable audit logs of administrative actions (for example, SaaS impersonation events).
  • To provide customer support and respond to privacy enquiries.

We do not use personal data for profiling, targeted advertising, or nudge techniques targeted at children, in line with the ICO Age Appropriate Design Code.

5. Who we share data with

We do not sell personal data. We share data only with the following categories of recipient:

  • Cloud infrastructure providers: hosting, database, and object storage (TBD provider). All providers are bound by written agreements that prohibit use of customer data for their own purposes.
  • Recognition providers: handwriting OCR and AI analysis providers, configured per deployment. Stroke data is sent only to the provider selected for your environment and is not retained by those providers beyond what is needed to return a result, except where contractually agreed.
  • Your school: teachers and administrators within your school can see the data for their own classes and students, scoped by orgId.
  • Legal and regulatory bodies: where required by law, court order, or to safeguard a child. Safeguarding disclosures follow the school's own safeguarding policy and DSL (Designated Safeguarding Lead) procedures.

6. International transfers

Personal data is stored and processed primarily in the United Kingdom and the European Economic Area. Where any transfer to a country outside the UK/EEA is necessary (for example, to a US-based recognition provider), it is made only under an appropriate safeguard such as UK International Data Transfer Agreements, the UK Addendum to the EU Standard Contractual Clauses, or reliance on a recognised adequacy decision. A list of countries to which data is transferred is available on request.

7. Data retention

  • Active accounts: data is retained for as long as the school remains a customer.
  • Churned accounts: when a school closes its account, there is a 30-day retention window to allow for late-payment recovery. After that, an automated job (DeleteChurnedTenantsJob) permanently wipes all tenant data (strokes, submissions, classes, teachers) by org_id. Each wipe is recorded as an immutable event in our audit logs.
  • Staff offboarding: when a teacher leaves a school, their account is deactivated (is_active = false). Their JWT is rejected on every subsequent request. Historical submissions, strokes, and student data are preserved so the school retains continuity; an administrator can reassign their classes.
  • Audit logs: SaaS admin audit logs are retained for the longer of (a) 6 years or (b) the period required by applicable law.

8. Children's data

EduWrite is designed for children aged 4 to 11 (Reception to Year 6). We apply the ICO Age Appropriate Design Code and, where applicable, COPPA:

  • High privacy by default: student accounts expose the minimum data needed to take part in activities.
  • No profiling or nudge techniques targeted at children.
  • No targeted advertising. EduWrite contains no advertising of any kind.
  • Display names are used instead of legal names where possible.
  • No student contact information (email, phone) is collected.
  • No geolocation is collected from student devices.
  • Verifiable parental consent: schools are responsible for obtaining appropriate consent or authority from parents and carers before student data is provided to EduWrite, in line with the school's data protection and acceptable use policies.

9. Your rights

Under UK GDPR you have the following rights. You can exercise any of them by contacting us at support@eduwrite.app.

  • The right to be informed — this policy.
  • The right of access — a copy of the personal data we hold about you.
  • The right to rectification — correcting inaccurate or incomplete data.
  • The right to erasure — also known as the “right to be forgotten”, subject to legal exceptions (for example, retaining audit logs).
  • The right to restrict processing — limiting how we use your data while a concern is resolved.
  • The right to data portability — receiving your data in a structured, machine-readable format.
  • The right to object — to processing based on legitimate interests or for direct marketing (we do not market to children).
  • Rights in relation to automated decision-making and profiling — we do not carry out solely automated decision-making with legal or similarly significant effects on individuals.

For student data, requests are typically made by the school administrator or, via the school, by a parent or carer. We will verify identity before disclosing personal data and will respond within one month (extendable by two further months for complex requests, with explanation).

10. Cookies and similar technologies

The Teacher Portal uses sessionStorage to hold your authentication token while you are signed in. This is cleared when you close the browser tab. We do not use third-party advertising or tracking cookies. Where optional analytics are enabled, they are governed by a separate consent prompt and can be withdrawn at any time.

11. Security

  • Authentication: teachers sign in with email and password; passwords are stored as one-way hashes. JWTs are short-lived and refreshed automatically.
  • Tenant isolation: every database query is scoped by org_id taken from the validated token, never from client input. One school cannot access another school's data.
  • Default-deny APIs: every API endpoint and real-time event handler requires authentication and authorisation unless explicitly marked as public.
  • Encryption: data is encrypted in transit (HTTPS) and at rest in the database and object storage.
  • Access control: stroke data and submissions are stored in access-controlled storage, never in public buckets.
  • Audit: SaaS admin actions (including impersonation) are immutably logged.

If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the ICO within 72 hours of becoming aware of it, and notify affected individuals without undue delay where the risk is high.

12. Changes to this policy

We may update this policy as the platform evolves. The “Last updated” date at the top of this page will reflect the most recent change. Where a change materially affects how we process children's data, we will notify affected schools directly before the change takes effect.

13. How to complain

If you have a concern about how we handle personal data and we cannot resolve it, you have the right to complain to the Information Commissioner's Office (ICO), the UK's independent data protection authority:

  • Website: https://ico.org.uk
  • Phone: 0303 123 1113 (local rate) or 01625 545 745
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would, however, appreciate the chance to address your concerns before you contact the ICO.

14. Contact us

For any privacy question, request, or complaint, contact us at support@eduwrite.app. Schools with a named data protection coordinator should route requests through that coordinator where possible.


© 2026 EduWrite. EduWrite® and the EduWrite logo are trademarks of EduWrite. Handwriting recognition is provided as a learning aid and should not be used as the sole basis for assessment decisions.