Version 2026-09.This agreement forms part of the NeurofiED Educator terms. It applies when a school, tutoring organisation or other educator (“the Educator”, “you”) uses the NeurofiED platform to create and manage accounts for its pupils. For that data the Educator is the controller and NeurofiED Ltd (“the Company”, “we”) is the processor, within the meaning of the UK GDPR and the Data Protection Act 2018.
An owner or admin of your organisation accepts this agreement from the educator dashboard. We record who accepted it and when, and the version accepted. Pupil accounts cannot be created until it has been accepted.
1. Subject Matter And Duration
We process pupil personal data on your behalf for as long as your organisation has an active NeurofiED licence, plus the retention period in section 7 for archived pupils.
2. Nature And Purpose Of The Processing
Providing the NeurofiED learning platform to your pupils: sign-in, lessons, tests and homework, progress tracking, the AI study companion (where you have left it enabled), and reporting to the teachers you authorise.
3. Categories Of Data And Data Subjects
Data subjects: pupils enrolled by your organisation (typically aged 7 to 16) and the staff you invite as members.
Pupil data: first and last name; the platform sign-in identifier we generate (in the form first.last@yourschool.neurofied.co.uk, which is a username, not a mailbox); year group and class membership; an optional pupil number (UPN) and parent or carer email address, if you choose to record them; learning progress, test attempts and results; homework submissions; AI companion questions and replies; and the record of your parental-consent confirmation.
Staff data: name, email address and role within the organisation.
We never email pupil identifiers, and pupil data is never used for marketing.
4. Your Obligations As Controller
You confirm that you have a lawful basis for the processing and, for every pupil you create or import, that parental consent has been obtained where it is required. You are responsible for the accuracy of the data you provide, for choosing which staff may see which pupils, and for archiving pupils who leave.
5. Our Obligations As Processor
We will:
- process pupil data only on your documented instructions, which are the platform's features as you configure them;
- ensure that everyone processing the data on our behalf is bound by confidentiality;
- apply the technical and organisational measures described in our Privacy Policy (encryption in transit and at rest, role-based access, audit logging of privileged actions, annual review);
- assist you with subject access and other data-subject requests: a pupil's profile, progress and results can be exported as JSON from the educator dashboard at any time;
- notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your pupils;
- make available the information needed to demonstrate compliance and allow audits you reasonably request, on 30 days' notice and no more than once a year unless a breach has occurred.
6. Sub-processors
We use the sub-processors listed in section 8 (“Who We Share Data With”) of our Privacy Policy. Each is bound by a written agreement with equivalent protections. We will give you at least 30 days' notice before adding a sub-processor that will process pupil data; you may object on reasonable grounds, and if we cannot resolve the objection you may terminate the licence for the affected service.
7. Retention, Archiving And Deletion
- Archiving.When you archive a pupil, sign-in is disabled immediately and the pupil's seat is released.
- Retention. Archived pupil data is kept for three months so that a pupil who returns can be restored with their progress intact.
- Deletion. After three months a nightly job permanently deletes the account, its progress, its sign-in identity and its AI companion transcripts. Test results are retained only in anonymised, aggregate form for platform statistics. Audit-log entries recording the deletion are kept as described in the Privacy Policy.
- End of licence. When your licence ends, every remaining pupil is archived and the same three-month clock starts. You may request earlier deletion at any time.
8. International Transfers
Pupil data is stored in the United Kingdom or the European Economic Area. Where a sub-processor processes data outside the UK, transfers are covered by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
9. AI Study Companion
The AI companion is enabled by default for every pupil and can be switched off for the whole organisation, for a class, or for an individual pupil. Teachers you authorise can read a pupil's companion transcript, and pupils are told this on the companion screen. Companion prompts and replies are deleted 90 days after they are created, or earlier under section 7.
10. Term And Changes
This agreement lasts for the duration of your licence and the retention period after it. We may issue a new version; you will be asked to accept it in the dashboard, and the previous version continues to apply until you do. Earlier versions are listed in the version history below and are available on request.
Version History
| Version | Date | Change |
|---|---|---|
| 2026-09 | September 2026 | First version for the launch of school licences. |
Questions about this agreement can be sent to contact@neurofied.co.uk.