PRIVACY POLICY

Privacy Policy

Last updated: 27.09.2026Effective date: 27.09.Resseti Educational Technologies

01 //1. Who we are

This Privacy Policy applies to the services and platforms operated by Resseti Ltd ("Resseti", "we", "us", or "our"), registered in England and Wales with registered office at 3 Bannold Court, Waterbeach, Cambridge. Our data protection registration number with the UK Information Commissioner's Office (ICO) is [ZA ].

If you have any questions about this Privacy Policy, our data practices, or how your personal data is handled, you can contact our Data Protection lead at privacy@resseti.com.

Depending on how you interact with our platform and diagnostic tools (such as Lumina), we operate under two distinct roles under UK and EU data protection law:

ContextOur RoleData SubjectsDetails
School contracts (Lumina pilot / institutional license)Data ProcessorStudents, teachers, school administratorsWe process student work, marks, and teacher feedback strictly on the written instructions of the school under a Data Processing Agreement (DPA). The school remains the Data Controller.
Website visitors, school enquiry contacts, individual pilot signupsData ControllerWebsite visitors, prospective partner staff, enquiry submittersWe determine the purposes and means of processing contact details, technical logs, communication records, and prospective pilot inquiries.

02 //2. Data we collect

We only collect personal data that is necessary to fulfill our institutional service commitments, maintain platform security, and respond to educator enquiries.

CategoryTypes of DataSource
School / Teacher Contact DataName, school email address, school name, job title / role, department, enquiry message detailsProvided directly by you via forms, emails, or pilot agreements
Student Assessment & Work DataStudent pseudonymised identifier / student ID, assessment responses, typed answers, step-by-step working, marks awarded, diagnostic failure-point classifications [Delete or amend if handwriting upload is added.]Provided by the school or entered by the student through the Lumina interface under the school's account
Technical & Usage DataIP address, browser type, device information, operating system, page views, session timestamps, diagnostic error logs [List any analytics tool used on 10Web.]Collected automatically via server logs and essential cookies when you access the platform
Communications DataCorrespondence between you and Resseti regarding support, pilot feedback, or product enquiriesDirect communications

We do not intentionally collect any special category personal data (such as health data, biometric data, or racial/ethnic origin) or criminal convictions data.

03 //3. How we use data and our lawful bases

Under the UK GDPR and EU GDPR, we must have a valid lawful basis to process your personal data. Where we act as a Data Controller, the table below outlines our purposes and lawful bases. Where we act as a Data Processor on behalf of a school, our processing is governed by our contract with the school (Article 28 DPA).

PurposeData UsedLawful Basis (GDPR / UK GDPR)
Providing the Lumina diagnostic engine to schoolsStudent assessment data, teacher accountsPerformance of contract (where school is controller, processed under DPA / Art. 28)
Responding to pilot enquiries and school demonstrationsSchool / teacher contact data, communicationsLegitimate interests (evaluating and establishing institutional partnerships) or Contract preparation
System security, error diagnosis, and infrastructure stabilityTechnical & usage logsLegitimate interests (maintaining platform resilience and security) / Legal obligation
Diagnostic model evaluation and rule-layer refinement (using aggregated, de-identified data only)De-identified assessment step patternsLegitimate interests (ensuring diagnostic precision; individual personal data is never used for external model training) [confirm]
Legal and regulatory complianceAll categories where requiredCompliance with a legal obligation

04 //4. Children, schools and AI

Summary Note

The short version for students:

We only see the work you type or submit to find where you lost marks in an exam question. We do not sell your data, we do not track you across other websites, and we do not use your answers to train public AI models. Your school controls your data.

School-Governed Architecture

When Lumina is deployed within an educational institution, the school is the Data Controller. We process student responses strictly as instructed by the school. Students cannot create public consumer profiles, interact with unregulated external forums, or share content publicly through our diagnostic engine.

No Advertising, No Commercial Profiling

We maintain an absolute prohibition on advertising and commercial tracking. We do not display third-party advertisements, do not build behavioral profiles for commercial exploitation, and do not broker or monetize user data under any circumstance.

Diagnostic Inference & AI Infrastructure

Lumina maps student answers to mark-scheme criteria (such as M1, A1, B1 criteria) and isolates process errors at specific method steps. Where artificial intelligence models or rule layers are utilized:

  • Inputs submitted for diagnostic inference are strictly confined to the academic response and marking criteria.
  • We contractually enforce zero-retention and zero-training policies with our inference infrastructure providers [confirm with provider terms]. Student submissions are not ingested into open training corpora.
  • Diagnostics serve solely to assist teachers and students in understanding procedural step errors, not to generate autonomous, unreviewable disciplinary decisions.

05 //5. Who we share data with

We do not sell, rent, or trade personal data. We share data only with trusted third-party sub-processors necessary to deliver our services, enforce security, or comply with statutory legal mandates.

Sub-processorPurposeLocationSafeguards
VercelHosts the Setura appUK (London)[confirm]
AnthropicRuns the Claude AI model that classifies steps the rules cannot. Receives working only, no names or IDs.US[confirm transfer safeguard]
Supabase [planned, confirm]Stores accounts and diagnostic recordsUK (London region) [confirm]
10WebHosts resseti.comUS[confirm]
Microsoft (Exchange Online)Business email, including correspondence with schools, enquiries and invoicesUK Data processing agreement, encryption in transit
Tide, with Adyen N.V. for card paymentsIssues invoices and receives payments. Card payments made through Tide Payment Links are processed by Adyen.UK (Tide), Netherlands (Adyen)PCI-DSS compliant, DPA

Where personal data is transferred outside the UK or European Economic Area, we implement required legal transfer mechanisms including UK International Data Transfer Agreements (IDTA) or European Commission Standard Contractual Clauses (SCCs).

06 //6. Retention, security and your rights

Data Retention Schedule

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by statutory record-keeping obligations.

Data TypeRetention PeriodRationale / Trigger
Student Assessment Data (under school contract)Deleted within 24 months of school contract termination or upon school requestSchool control and contract lifecycle
School Enquiry & Pilot Contact RecordsRetained for 5 years from last active correspondenceMaintaining institutional relationship history and pilot audit
Technical Server & Security LogsRetained for  12 monthsThreat monitoring, diagnostic troubleshooting, and incident response
Inactive User AccountsRemoved or anonymised after 2 years of total inactivityData minimisation principles

Security Measures

We implement technical and organizational security controls designed to protect information from unauthorized access, accidental loss, disclosure, or alteration:

  • Encryption: All data in transit is encrypted using modern TLS (Transport Layer Security 1.3), and stored data is encrypted at rest using AES-256 standard encryption.
  • Access Controls: Role-based access control (RBAC), multi-factor authentication for administrative staff, and strict principle-of-least-privilege access.
  • Monitoring & Audit: Continuous logging and security reviews of infrastructure components.

Your Statutory Rights

Under UK and EU data protection laws, individuals hold specific statutory rights regarding their personal data:

  • Right of access: You can request a copy of the personal data we hold about you.
  • Right to rectification: You can ask us to correct inaccurate or incomplete data.
  • Right to erasure: You can ask us to delete your personal data under certain conditions.
  • Right to restrict processing: You can ask us to pause processing your personal data.
  • Right to data portability: You can request transfer of your data to another organization.
  • Right to object: You can object to processing based on legitimate interests.

How to exercise your rights:

For students using Lumina through a school: Because the school is the Data Controller, requests should be submitted directly to your school's data protection officer. We will assist your school in fulfilling valid requests.

For direct enquiries and website users: Email us at privacy@resseti.com. You also maintain the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or your relevant European supervisory authority.

[Resseti Ltd] — Information GovernanceVersion 1.0