Privacy Policy
Last updated: 25 May 2026
This Privacy Policy explains how Edway Education Ltd (we, us, our) collects, uses, retains and protects personal data when you use our platform. We are registered with the Information Commissioner's Office (ICO) and operate under UK GDPR and the Data Protection Act 2018.
Who we are
Edway Education Ltd is the data controller for all personal data processed through our platform. Our registered office is in the United Kingdom. All data is stored exclusively within the UK (AWS London, eu-west-2 region).
Data we collect
We collect only what is required to deliver the service:
- Parent account data: name, email address, billing information, support correspondence.
- Child profile data: first name, date of birth, documented SEND designations (if shared), parent-provided learning history.
- Learning data: lesson activity, response patterns, mastery scores, assessment results.
- Technical data: device type, browser, IP address (for security and rate-limiting only), error logs.
We do not collect: behavioural tracking for monetisation, advertising identifiers, health data beyond what parents voluntarily share for educational accommodation, or biometric data.
How we use your data
- To deliver personalised learning to your child.
- To generate progress dossiers for Local Authority presentations.
- To operate the human safety net (escalation to tutors or safeguarding bodies).
- To process subscription payments via Stripe.
- To improve the platform through aggregated, anonymised metrics.
Lawful basis for processing
We rely on the following lawful bases under UK GDPR Article 6:
- Contract: to deliver the service you signed up for.
- Legitimate interest: for security, fraud prevention, and product improvement.
- Legal obligation: for safeguarding reports to statutory bodies.
- Consent: for any optional features (marketing emails, etc.) — withdrawable at any time.
Children's data
Edway's primary users include children aged 10–13. We comply fully with the ICO Age-Appropriate Design Code:
- Data minimisation by default — no field is collected speculatively.
- No profiling for advertising, monetisation, or engagement loops.
- No nudging or dark patterns to extend session time.
- Parents (as legal guardians) hold all consent and access rights.
- Child-facing language is age-appropriate and transparent.
Data retention
Active account data is retained for as long as you remain a subscriber. On account closure:
- Operational data is deleted within 30 days.
- Compliance dossiers and audit logs are retained for 24 months to satisfy potential Local Authority follow-up requests.
- After 24 months, all records (including backups) are cryptographically destroyed.
- Anonymised, aggregated analytics may be retained indefinitely.
Security
- AES-256 encryption at rest.
- TLS 1.3 in transit.
- Role-based access control with row-level security on all database queries.
- SHA-256 cryptographic signatures on all compliance dossiers.
- Regular penetration testing and Cyber Essentials Plus certification.
Your rights
Under UK GDPR you have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Erase your data (subject to the 24-month retention above).
- Restrict processing.
- Data portability — export in JSON or PDF format.
- Object to processing.
- Lodge a complaint with the Information Commissioner's Office.
To exercise any of these rights, email privacy@edway.uk.
Third-party processors
We use the following processors, all UK GDPR compliant:
- MongoDB Atlas: primary database.
- Cloudinary: media storage (lesson audio, uploaded work).
- OpenAI: language model inference (no training on customer data).
- ElevenLabs: voice synthesis (no training on customer data).
- Vercel: application hosting.
- Stripe: subscription billing.
- Brevo: transactional and (opt-in) lifecycle email to parents.
- PostHog (EU cloud): opt-in product analytics for parents only — never used in the child experience, identifies by internal account id, no profiling or session recording.
Contact
Data Protection Officer: dpo@edway.uk
Privacy queries: privacy@edway.uk
General: hello@edway.uk