Privacy
Last updated 19 September 2026.
EduSpaze is in development and not yet serving pupil data for any school. This page states the intent the platform is built to; it is not a substitute for the agreement a school signs.
Who holds what
A school is the controller of its pupils' and staff data. EduSpaze processes that data on the school's instructions, and a school can export or erase it at any time from its own portal.
EduSpaze holds the school's roster so it can match a pupil to the apps their school has approved, and so a school can see how much those apps are used. It does not hold pupil work, marks, or anything a pupil types into a vendor's product.
What a vendor receives
A vendor never receives a pupil's name, email address or date of birth from EduSpaze. It receives a pseudonymous code — `RB-4213` for a pupil, `STF-0003` for a member of staff — that is meaningful only inside the school that issued it.
A vendor may additionally receive the class and group codes a pupil belongs to, where the school has switched that on, so the pupil lands in the right class. Those codes carry no names either.
- No name, no email, no date of birth, ever.
- Codes are scoped to one school: the same code at another school is a different person, and a vendor cannot ask about a school it has no connection with.
- A code is never renumbered. A renumbered pupil would look like a new person to every vendor, and nobody could undo it.
Telemetry
EduSpaze records when a pupil opened an approved app and for how long, so a school can see whether what it bought is being used. There is no field for scores, content, or free text, and the API refuses anything else.
Guardians
Where a school switches parent access on, a guardian can see which apps their child is connected to, when those connections were made, and how much time was spent. They see no pricing, no spend and no commercial terms — those are between the school and the vendor.
The audit trail
Every change is recorded on an append-only trail held in a separate system with its own database, so the record of what happened cannot be edited by the platform that produced it. Entries about a person are encrypted under a key held per subject.
When a school asks for a person to be erased, that subject's key is destroyed. The trail keeps the shape of what happened — a change was made, at this time, by this role — and loses the ability to say who it was about. This is irreversible by design.
Asking for your data
A member of staff or a guardian should ask their school first: the school holds the relationship and can act immediately from its own portal. Where that is not possible, write to EduSpaze and we will route it to the school and confirm when it is done.
Questions about this page, or a request about your own or your child's data? support@eduspaze.com.
