Legal

Privacy Policy

This notice explains how Sotara Ltd collects, uses and protects personal data in the operation of its business and services, in accordance with UK GDPR and the Data Protection Act 2018.

Last updated: 1 June 2026·Required under: UK GDPR Articles 13–14 & ICO Children's Code

Platform Privacy Notice

This notice covers Sotara's own data controller activities: school contacts, account holders, website visitors, and Sotara staff. It does not cover processing carried out as a data processor on behalf of schools (e.g. image processing under Anonymé).

Who we are

Sotara Ltd is a company registered in England and Wales (Company No. 17162223). We build and operate software applications for UK schools. For the purposes of this notice, Sotara is the data controller.

What personal data we collect and why

School contacts and account holders

When a school signs up or an individual creates an account, we collect: name, job title, school name and address, email address, and phone number. We use this to administer the contract, provide support, and send product updates.

Lawful basis: UK GDPR Article 6(1)(b) (contract) for account administration; Article 6(1)(f) (legitimate interests) for support communications and product updates.

Website visitors

Our website collects technical data (IP address, browser type, pages visited, time on page) via cookies and analytics tools.

Lawful basis: UK GDPR Article 6(1)(a) (consent) for non-essential cookies; Article 6(1)(f) (legitimate interests) for essential analytics.

Marketing and communications

With your consent, we may send emails about new products, updates, or events. You can unsubscribe at any time using the link in any email.

Lawful basis: UK GDPR Article 6(1)(a) (consent).

Sotara staff and contractors

We process employment and engagement data (name, contact details, bank details, NI number, DBS certificate reference, payroll data) to manage our employment relationships and comply with legal obligations.

Lawful basis: UK GDPR Article 6(1)(b) (contract); Article 6(1)(c) (legal obligation). For DBS data: DPA 2018 Schedule 1 Part 1 (employment and safeguarding).

Who we share data with

We use the following sub-processors to deliver our services. All are contractually bound to process data only on our instructions and maintain equivalent security standards.

Sub-processorLocationPurpose
Supabase / AWS (eu-west-2)United Kingdom (London)Database and file storage for all applications
ResendEU / UKTransactional email notifications
StripeUK / EUPayment processing
VercelEU / UKApplication hosting and delivery

International transfers

All school customer data is stored on AWS servers in London (eu-west-2) and does not leave the United Kingdom. For sub-processors whose infrastructure is outside the UK, we rely on UK adequacy decisions or UK International Data Transfer Agreements (IDTAs). Details are available on request.

Retention

DataRetention periodBasis
School contact / account dataDuration of contract + 6 yearsLimitation Act 1980 (potential contract claims)
Website analytics13 months rollingStandard analytics retention
Marketing contactsUntil unsubscribe + 1 yearConsent withdrawn; records kept to evidence withdrawal
Staff employment recordsEmployment + 6 yearsLegal obligation (HMRC, ERA 1996)
DBS certificate referencesSee Safeguarding PolicyDBS Code of Practice

Your rights

Under UK GDPR you have the right to:

  • AccessRequest a copy of personal data we hold about you.
  • RectificationAsk us to correct inaccurate or incomplete data.
  • ErasureAsk us to delete your data in certain circumstances.
  • RestrictionAsk us to restrict processing in certain circumstances.
  • PortabilityReceive your data in a structured, machine-readable format (where processing is based on consent or contract and carried out by automated means).
  • ObjectObject to processing based on legitimate interests or public task.
  • Withdraw consentWhere processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at dpo@sotara.co.uk. We will respond within one calendar month.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

Contact us

Data Controller

Sotara Ltd

Company No. 17162223

43 Harwood House
London SW6 4QP

Data Protection Enquiries

dpo@sotara.co.uk

If you are a pupil or parent with a question about your school's use of Sotara products, please contact your school in the first instance. The school is the data controller for pupil and parent data.