Privacy Policy
How EduInsight handles personal data for schools, organisations and users.
- Published
- 4 May 2026
- Last updated
- 5 January 2026
- Next review
- 5 January 2026
- Version
- Version 1
Who this policy covers
This Privacy Policy explains how EduInsight handles personal data in EduInsight Observe, including account data, school data, observation records, feedback, uploaded evidence, reports and exports.
Schools, trusts, local authorities, federations and other customer organisations normally act as controller for the personal data they upload or generate in EduInsight. EduInsight acts as processor when providing the platform and related support services, except where it acts as controller for its own account, billing, security and service administration records.
The platform is designed for UK schools, multi-academy trusts, local authorities, school groups and education organisations.
Data we process
EduInsight may process user names, email addresses, school or organisation membership, roles, staff and group records, observation notes, template answers, feedback, acknowledgements, report filters, audit logs, billing contact details and support correspondence.
Uploaded evidence may include documents, images or other files added by authorised users. Customers should only upload evidence that is relevant, proportionate and appropriate for their school improvement processes.
We do not require special category data to use the platform. If customers choose to include sensitive information in observations or evidence, they remain responsible for ensuring they have a lawful basis and appropriate safeguards.
How data is used
We use customer data to provide the platform, manage accounts, support observation and feedback workflows, generate dashboards, produce reports and PDF exports, maintain security, resolve support requests and meet legal obligations.
We do not sell customer data. We do not use school observation or feedback content for advertising.
Where directory integrations are enabled, EduInsight uses authorised directory information only to help customers review, link or create relevant users according to their confirmed settings.
Security and access
EduInsight uses secure cloud infrastructure providers, encrypted connections using HTTPS, provider-managed encryption at rest, role-based access controls and auditable support access.
Access to customer data is limited to authorised users and authorised EduInsight support personnel where access is necessary to provide support, investigate issues, maintain security or meet legal requirements.
Support access is logged and can be reviewed. We avoid exposing internal infrastructure details in public policy documents for security reasons.
Your rights and contact
Individuals may have rights under UK GDPR and the Data Protection Act 2018, including rights of access, rectification, erasure, restriction and objection. Requests relating to school-controlled data should normally be made to the relevant school or organisation.
For privacy enquiries, contact privacy@eduinsightobserve.com.
This policy is governed by the laws of England and Wales.
Security note
These public policies intentionally use general security descriptions. We do not publish exact infrastructure providers, deployment locations, internal routes or implementation-level operational details.
This policy is reviewed regularly to ensure compliance.