1. Who We Are
Staffroom ("we", "our", "us") is operated by Staffroompro Ltd, a company registered in England and Wales. Staffroom is a lesson planning application designed for UK primary school teachers. We are committed to protecting your privacy and handling your data in accordance with UK GDPR and the Data Protection Act 2018.
This policy covers the Staffroom web application at staffroom.pro, including all features accessible through the application such as lesson planning, curriculum tools, and the AI assistant. Staffroom is intended for use by adult teachers and education professionals aged 18 and over. It is not directed at, or intended for use by, children under the age of 13 or students of any age.
2. Data We Collect
We practise data minimisation and only collect information that is necessary to provide and improve the Staffroom service. We collect the following personal data:
- Account Information: Email address, name, school name (optional). If you sign in with Google, we receive your name and email address from your Google account. We do not access your Google contacts, calendar, or any other Google data.
- Profile Data: Year group, teaching schemes preferences, curriculum region
- Lesson Data: Objectives, planned lessons, notes, and other content you create within the application
- Payment Data: If you subscribe, payment is processed by Stripe. We do not store your full card details. We receive only a transaction reference, subscription status, and billing email from Stripe.
- Usage Data: How you interact with the application, including page views, feature usage, and performance metrics. This data is collected in aggregate and is not used to identify or profile individual users.
An account is required to use Staffroom. You can create an account using your email address and a password, or by signing in with Google (OAuth). When signing in with Google, we only receive the basic profile information listed above.
3. Legal Basis for Processing
We process your data under the following legal bases:
- Contract: To provide you with the Staffroom service as described in our Terms of Service
- Legitimate Interest: To improve our service, ensure security, and send relevant service updates
- Consent: For optional marketing communications and analytics cookies. You can withdraw consent at any time.
4. How We Use Your Data
We use your data for the following purposes and no others:
- To provide and maintain the lesson planning service
- To personalise your experience with curriculum-specific content
- To process AI-powered features (the Staffroom AI assistant processes your queries to generate lesson suggestions; no personal data is included in AI requests)
- To send service updates and important notifications
- To improve our application based on aggregated, non-identifying usage patterns
- To process payments and manage subscriptions through Stripe
- To detect and prevent fraud, abuse, or security incidents
We do not use your data for advertising, marketing to third parties, behavioural profiling, or any purpose unrelated to providing the Staffroom service.
5. Data Sharing
We share data with the following third-party service providers, who act as data processors on our behalf. Each provider is contractually required to process your data only for the purposes we specify and in accordance with applicable data protection laws. They may not use your data for their own marketing or commercial purposes.
- Supabase: Database hosting and authentication (data stored on EU servers)
- Google (Gemini AI): AI assistant processing. Only the text of your query is sent to Google Gemini. No personal data, account information, or lesson data is included in AI requests.
- Vercel: Application hosting and deployment
- Vercel Analytics: Anonymous, aggregated web analytics. No personally identifiable information or cookies are used. This measures page views in aggregate to help us improve the application.
- Vercel Speed Insights: Performance monitoring, loaded only with your consent via the cookie banner. Measures page load times to help us optimise the application. No personally identifiable information is collected.
- Stripe: Payment processing for subscriptions. Stripe processes your payment card details directly and is an independent data controller for payment data. See Stripe's privacy policy for details.
- Sentry: Error monitoring and application stability tracking. Sentry receives technical error data, which may include your user ID and email address for the purpose of diagnosing issues. It does not receive your lesson content, planning data, or profile preferences.
- Resend: Transactional email delivery (e.g. welcome emails, password resets, service notifications). Resend receives your email address solely for the purpose of delivering emails on our behalf.
We do not:
- Sell your personal data to any third party, for any reason, at any time
- Share your data with third parties for their own marketing purposes
- Allow third-party service providers to use your data beyond the specific service they provide to us
- Share or disclose your lesson content, notes, or planning data to any other users or third parties
6. Data Retention
We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal purposes (such as tax or financial records required by UK law). Aggregated, non-identifying analytics data may be retained indefinitely as it cannot be linked back to you.
7. Your Rights
Under UK GDPR, you have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Correct inaccurate or incomplete personal data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a structured, commonly used, machine-readable format
- Restriction: Request that we limit the processing of your data in certain circumstances
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing
To exercise these rights, you can use the "Delete My Account" option in Account Settings, or contact us at support@staffroom.pro. We will respond to your request within 30 days. To request a portable export of your data, email us at the address above and we will provide your data in a standard format (such as JSON or CSV) within 30 days.
If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies
We use the following types of cookies:
- Essential cookies: Required for authentication and session management. These cannot be disabled as they are necessary for the application to function.
- Analytics cookies: With your consent, we use Vercel Speed Insights to monitor page performance. These do not track you across other websites and do not collect personally identifiable information. Vercel Analytics (anonymous, aggregated page view counts) does not use cookies. You can manage your cookie preferences at any time through the cookie banner.
We do not use advertising cookies, third-party tracking cookies, or any cookies that follow you across other websites or applications.
9. Advertising and Tracking
Staffroom is a subscription-funded service. We do not rely on advertising revenue and therefore:
- We do not display any advertisements (traditional, contextual, or behavioural)
- We do not use behavioural advertising or ad targeting of any kind
- We do not sell or share data with advertising networks or data brokers
- We do not track users across third-party websites or applications
- We do not use cross-device tracking
- We do not build commercial or behavioural profiles of our users
- We do not use data for purposes unrelated to the Staffroom lesson planning service
The only analytics we use (Vercel Analytics) collects anonymous, aggregated performance data to help us improve the application. This data cannot be used to identify individual users.
10. Children's Privacy
Staffroom is designed exclusively for adult teachers and education professionals. It is not intended for, or directed at, children under the age of 13 (or under the age of 16 in jurisdictions where applicable). We do not knowingly collect personal information from children.
If we become aware that we have inadvertently collected personal data from a child under the age of 13, we will take steps to delete that information as quickly as possible. If you believe a child has provided us with personal data, please contact us at support@staffroom.pro so we can take appropriate action.
Teachers may reference student names or details within their own lesson notes and plans. This content is created and controlled by the teacher. Staffroom does not systematically collect, process, or store student personal data as a feature of the product. Any student information entered by a teacher in free-text fields is treated as the teacher's own content and is subject to the same protections as all other user data described in this policy.
11. Education Context
Staffroom is a teacher productivity tool. All data collected is used solely for the purpose of providing the lesson planning service to teachers. Specifically:
- Data is collected and used only for educational planning purposes
- No user data is used for non-educational or commercial purposes beyond providing the service
- Lesson content and planning data is private to each individual teacher and is not shared with other users, schools, or districts
- We do not provide school or district administrator accounts that can access individual teacher data
- Teachers retain full control over the content they create within Staffroom
12. Data Security and Breach Notification
We implement appropriate technical and organisational measures to protect your data, including:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Secure authentication with password hashing and optional Google OAuth
- Role-based access controls limiting internal access to user data
- Regular security reviews of our application and infrastructure
- Use of reputable, security-certified hosting providers (Supabase, Vercel)
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users without undue delay and within 72 hours of becoming aware of the breach, in accordance with UK GDPR requirements. We will also notify the Information Commissioner's Office (ICO) as required by law.
13. International Data Transfers
Your primary data (account information, lesson data, and profile data) is stored on Supabase servers located in the European Union. Some of our service providers may process data outside the UK and EU:
- Vercel (application hosting) may process data in the United States
- Google (AI assistant) may process query data in the United States
- Stripe (payments) may process payment data in the United States
- Sentry (error monitoring) may process technical data in the United States
Where data is transferred outside the UK, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA), Standard Contractual Clauses (SCCs), or reliance on adequacy decisions by the UK Secretary of State, to ensure your data receives an equivalent level of protection.
14. Contact Us
For any privacy-related questions, concerns, complaints, or to exercise your data rights, please contact us at:
Email: support@staffroom.pro
Company: Staffroompro Ltd
Supervisory Authority: Information Commissioner's Office (ICO)
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. When we make material changes:
- We will notify you by email and/or through a prominent notice within the application at least 30 days before the changes take effect
- We will update the "Last updated" date at the top of this policy
- We will provide a summary of what has changed
- Continued use of Staffroom after the notice period constitutes acceptance of the updated policy
We encourage you to review this policy periodically. Previous versions of this policy are available on request by contacting support@staffroom.pro.