Data Privacy in EdTech: How TheRevisionHub Protects Student Data
When schools adopt new software, data privacy is — rightly — one of the first questions asked. Students are a protected category under GDPR. Schools are data controllers responsible for what happens to the personal data of children in their care.
Our Data Architecture
All student data processed by TheRevisionHub is stored on servers located within the UK and European Economic Area. We do not transfer personal data outside the EEA. Data is encrypted at rest using AES-256 and in transit using TLS 1.3.
What Data We Collect and Why
We collect the minimum data required to provide the service. For students: name, school email address, year group, subject selections, and learning activity data. We do not collect home addresses, phone numbers, financial information, or sensitive personal data categories under GDPR Article 9.
GDPR Compliance Framework
TheRevisionHub operates as a data processor under GDPR. The school is the data controller. We provide a Data Processing Agreement (DPA) to all school customers. Schools should require a DPA from every EdTech vendor they work with.
Data Retention and Deletion
Student data is retained for the duration of the school's contract plus 90 days. At contract termination, all personal data is deleted from our systems within 30 days.