Back to policies

Privacy Policy

How EduInsight handles personal data for schools, organisations and users.

Published
4 May 2026
Last updated
5 January 2026
Next review
5 January 2026
Version
Version 1

Who this policy covers

This Privacy Policy explains how EduInsight handles personal data in EduInsight Observe, including account data, school data, observation records, feedback, uploaded evidence, reports and exports.

Schools, trusts, local authorities, federations and other customer organisations normally act as controller for the personal data they upload or generate in EduInsight. EduInsight acts as processor when providing the platform and related support services, except where it acts as controller for its own account, billing, security and service administration records.

The platform is designed for UK schools, multi-academy trusts, local authorities, school groups and education organisations.

Data we process

EduInsight may process user names, email addresses, school or organisation membership, roles, staff and group records, observation notes, template answers, feedback, acknowledgements, report filters, audit logs, billing contact details and support correspondence.

Uploaded evidence may include documents, images or other files added by authorised users. Customers should only upload evidence that is relevant, proportionate and appropriate for their school improvement processes.

We do not require special category data to use the platform. If customers choose to include sensitive information in observations or evidence, they remain responsible for ensuring they have a lawful basis and appropriate safeguards.

How data is used

We use customer data to provide the platform, manage accounts, support observation and feedback workflows, generate dashboards, produce reports and PDF exports, maintain security, resolve support requests and meet legal obligations.

We do not sell customer data. We do not use school observation or feedback content for advertising.

Where directory integrations are enabled, EduInsight uses authorised directory information only to help customers review, link or create relevant users according to their confirmed settings.

Security and access

EduInsight uses secure cloud infrastructure providers, encrypted connections using HTTPS, provider-managed encryption at rest, role-based access controls and auditable support access.

Access to customer data is limited to authorised users and authorised EduInsight support personnel where access is necessary to provide support, investigate issues, maintain security or meet legal requirements.

Support access is logged and can be reviewed. We avoid exposing internal infrastructure details in public policy documents for security reasons.

Your rights and contact

Individuals may have rights under UK GDPR and the Data Protection Act 2018, including rights of access, rectification, erasure, restriction and objection. Requests relating to school-controlled data should normally be made to the relevant school or organisation.

For privacy enquiries, contact privacy@eduinsightobserve.com.

This policy is governed by the laws of England and Wales.

Security note

These public policies intentionally use general security descriptions. We do not publish exact infrastructure providers, deployment locations, internal routes or implementation-level operational details.

This policy is reviewed regularly to ensure compliance.

Back to policies
Privacy Policy | EduInsight Observe | EduInsight Observe