Marc Jones, trading as Emeejay Assess ("we", "us") – a sole trader based in the UK – provides phonics and maths assessment tracking tools for primary schools, available at emeejay.com. This policy explains what personal data we collect, why, and how we protect it.
Contact: marc@emeejay.com.
ICO registration: we are registered with the UK Information Commissioner's Office (ICO) as a data controller, registration reference ZC226219.
Two groups of people have personal data processed through Emeejay Assess:
Because pupil data is entered and controlled by the school, the school is the data controller for pupil personal data, and we act as a data processor, processing that data only on the school's documented instructions. This relationship is set out in a separate Data Processing Agreement between us and each school. If you are a parent or pupil with a question about data held in Emeejay Assess, please contact the school directly in the first instance – see section 9.
We do not collect any data directly from pupils, and pupils never interact with the service themselves.
If a school subscribes, payment is handled entirely by our payment provider, Stripe. We do not store card numbers or full payment details ourselves – we only hold the school's subscription status and Stripe customer/subscription reference IDs.
We do not use analytics or advertising cookies or trackers. Our authentication provider stores a session token in your browser's local storage so you stay signed in between visits – this is not shared with any advertiser and is not used to track you across other websites.
For staff account data, we process it to perform our contract with the school (providing the service the school has signed up to) and for our legitimate interest in operating and securing the service.
For pupil data, we process it strictly as instructed by the school under our Data Processing Agreement. The school, as data controller, is responsible for identifying its own lawful basis for processing pupil data – for state schools this is typically the performance of a public task related to education; independent schools more often rely on contract or legitimate interests.
Some fields – in particular the additional needs (SEND) flag – may be capable of revealing information about a child's health or disability, which is "special category data" under Article 9 of the UK GDPR. Where this is recorded for safeguarding-related purposes, the applicable condition is typically the safeguarding of children and of individuals at risk condition at Schedule 1, Part 2, paragraph 18 of the Data Protection Act 2018 – which requires the school, as controller, to have an Appropriate Policy Document covering this processing (most schools already hold one as part of their safeguarding policy suite). Schools should confirm this reflects their own circumstances with their Data Protection Officer.
Pupil and staff account data is stored in a database hosted by our infrastructure provider, Supabase, in their London, UK data centre (AWS region eu-west-2). Each school's data is isolated from every other school's using database-level security rules (Row Level Security), so no school can see another school's pupils or results.
Data in transit is encrypted using HTTPS/TLS. Passwords are hashed and salted by Supabase Auth and are never visible to us.
Some parts of our infrastructure – specifically the serverless functions that handle subscription checkout and payment webhooks – currently run on servers located in the United States (via our hosting provider, Vercel). These functions handle billing events rather than pupil assessment data, but personal data that does pass through them (such as a staff member's name or email address used for billing) is transferred outside the UK as a result. Both Vercel and Stripe incorporate the UK International Data Transfer Addendum to the EU Standard Contractual Clauses into their own data processing agreements – this is the safeguard recognised by the ICO for this type of transfer, and it's the mechanism we rely on for these transfers.
We share limited personal data with the following service providers ("sub-processors"), each of whom is contractually required to protect it:
We do not sell personal data. We do not use pupil or staff data for advertising or marketing to third parties. We do not use personal data to train AI or machine learning models.
We will only disclose personal data to other third parties where required by law, or to protect the safety of a pupil or member of staff in a genuine safeguarding emergency – and, where practicable, we will inform the school first. Schools remain responsible for their own safeguarding policies and statutory duties; this section doesn't override or replace those.
We retain pupil and staff data for as long as the school's account remains active, and in line with instructions from the school. When a school's subscription ends, we retain data for a grace period of 30 days to allow reactivation, then permanently delete it, unless the school instructs us to delete it sooner, or we are required to retain it for longer by law.
Depending on whether you are a school staff member or the parent/guardian of a pupil, you may have rights to access, correct, delete, or restrict the use of personal data, and to object to certain processing.
Because schools are the data controller for pupil data, requests relating to pupil data should be made to the school in the first instance; we will support the school in responding to such requests. Staff members can contact us directly (see section 9) about their own account data.
You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) if you believe your data has been mishandled.
Marc Jones, trading as Emeejay Assess
marc@emeejay.com
We may update this policy from time to time as the service or our suppliers change. We will update the "last updated" date at the top of this page and, for material changes affecting pupil data, notify schools directly.