Schools GDPR & DPIA
Last updated: 20 Aug 2026
This document summarises how Novaread processes pupil and school data in line with the UK GDPR and Data Protection Act 2018, and supports a school's Data Protection Impact Assessment (DPIA) before deployment.
1. Roles and responsibilities
- School = Data Controller: The school determines the purposes and means of processing pupil data and is responsible for lawful basis, parental consent, and responding to subject access requests.
- Novaread = Data Processor: Novaread processes pupil data only on the documented instructions of the school, under a written data processing agreement (DPA), and provides the technical and organisational measures below.
2. Data we process (data minimisation)
Novaread is designed around data minimisation. The only pupil data processed is:
- First name — for parent-created profiles, and first name + surname for school-imported rosters. Surnames are stored only so staff can identify pupils in class lists; they are never displayed in the parent or pupil app, leaderboards, or activity feeds, which show first name + last initial only (e.g. "Oliver P.").
- A 6-character student PIN generated on import, used by parents to link a child to their family account via school + PIN login. PINs are random, unique per pupil, and resettable by school staff.
- An optional reading age and year group / class assignment for analytics grouping.
- Reading data: minutes read, books completed, XP, streaks and earned badges.
We do not collect: dates of birth (optional and never required for school use), home addresses, photos of pupils, location data, or special category data.
3. Lawful basis
- For pupils (under 13): Consent under Article 6(1)(a) UK GDPR, given by the parent or person with parental responsibility at account setup. Schools should record this consent and offer an alternative (e.g. paper diary) for families who do not consent.
- For school staff accounts: Performance of a contract (Article 6(1)(b)) — provision of the analytics service under the school licence.
- Legitimate interest for limited service operation (authentication, security logging) under Article 6(1)(f), balanced against pupil privacy rights.
4. International data transfers
Data is stored on the Base44 platform. Where any processing occurs outside the UK, transfers are made only with an appropriate safeguard in place (UK International Data Transfer Agreement or UK Addendum to the EU SCCs) and documented in the DPA.
5. Security measures
- Row-level security isolates each family's data; school analytics run through a role-gated service function that only exposes data to authorised school staff.
- Role-based access control:
school_admin accounts see all classes, students, staff and billing; teacher accounts are restricted to only the classes assigned to them by an admin. - School + PIN login: parents link a child by selecting the school and entering the pupil's 6-character PIN — no surname or password is needed to connect a school pupil.
- Surname display rule: full names are shown only in staff views; the parent/pupil app, leaderboards and activity feeds render first name + last initial only.
- Parental PIN gate prevents children from accessing settings, account data or external links.
- Encryption in transit (TLS) and at rest; secrets managed via the platform secrets store.
6. Retention and deletion
- Pupil reading data is retained only for the duration of the school licence plus a short grace period, unless the parent deletes it sooner.
- Parents can delete a child profile and all its reading data at any time in-app (Settings > Account) or by emailing novareaduk@gmail.com.
- Schools can request bulk deletion of all school-linked data at the end of a licence by contacting us in writing.
- On deletion, the account and all associated data are permanently removed and cannot be recovered.
7. Data subject rights
Parents and pupils retain all UK GDPR rights, exercised through the school as controller:
- Right of access, rectification, and erasure.
- Right to object and right to withdraw consent at any time.
- Right to data portability (CSV export available in the teacher portal).
8. Sub-processors
Novaread uses the following sub-processors: Base44 (app platform and database hosting), Stripe/Google Play/Apple App Store (subscription billing only — no pupil data shared), and an email delivery provider for transactional emails. A full sub-processor list is available on request and is maintained in the DPA.
9. Personal data breach procedure
In the event of a personal data breach, Novaread will notify the school without undue delay and assist the school in notifying the ICO within 72 hours where required, in line with Article 33/34 UK GDPR.
10. DPIA summary
This document supports a school's DPIA. Key residual risks and mitigations:
- Risk: Pupil data exposure. Mitigation: data minimisation, RLS isolation, role-gated analytics, parental consent, and surname hidden from all non-staff views.
- Risk: Unauthorised staff access. Mitigation: role-based access control — school admins see all classes; teachers see only assigned classes. The service-role function verifies the caller's school and role on every request.
- Risk: PIN misuse. Mitigation: PINs are random, unique per pupil, resettable on demand, and valid only when paired with the correct school.
- Risk: Data retention beyond need. Mitigation: in-app deletion, bulk deletion on request, defined retention period.
- Risk: Children seeing settings. Mitigation: parental PIN gate on all settings and external links.
11. Contact
For data protection queries, DPIA support, or to request a copy of our Data Processing Agreement, contact:
- Email: novareaduk@gmail.com
- Website: novaread.co.uk