Data protection information
Last updated: 3 August 2026
This page exists so a school can complete its own Data Protection Impact Assessment. If your DPO needs something that is not here, email privacy@classmind.co.uk and we will add it.
At a glance
| Where data is stored | United Kingdom. Dedicated server in Manchester |
| Pupils' access | None. Pupils have no accounts and never use ClassMind |
| Pupil identifiers | An anonymous code chosen by the teacher, not a name |
| Sent to the AI provider | The prompt only. Full pupil names are removed first |
| AI prompt and output text | Not retained by us at all |
| Used to train AI models | No |
| Transfers outside the UK | One: prompt content to Anthropic in the US, under the ICO's UK Addendum |
| Two-factor authentication | Mandatory on every account |
- 1. Who we are and our role
- 2. What we process
- 3. Lawful basis
- 4. Special category and safeguarding data
- 5. AI processing and model training
- 6. Where data is stored and transfers
- 7. Sub-processors
- 8. Retention
- 9. Security measures
- 10. Data subject rights and erasure
- 11. Breach notification
- 12. Completing your DPIA
1. Who we are and our role
ClassMind is operated by Revamp Automation, based in Corsham, Wiltshire, United Kingdom. Contact: privacy@classmind.co.uk.
Our role depends on the data:
- Teacher account data (name, work email, school name, class profile, subscription status) — we are the controller. The teacher signs up directly with us.
- Pupil-related data a teacher enters (anonymous pupil codes, attainment notes, SEND notes) — we act as a processor. The school determines why that data exists; we only hold it to provide the service to the teacher.
Where we act as a processor, the terms at Data Processing Agreement apply. Schools do not need to negotiate a separate contract; those terms are our Article 28 agreement and can be relied on as they stand.
An important note on how teachers reach us. Teachers usually sign up individually rather than through a school procurement process. That means a school may not know a member of staff is using ClassMind. We recommend schools decide their position on staff use of AI tools and tell staff what is permitted. Our in-app guidance tells teachers not to enter pupil information their school has not authorised.
2. What we process
| Category | Data | Data subjects |
|---|---|---|
| Account | Name, email address, hashed password, two-factor status | Teachers |
| Class profile | School name, class name, year group, class size, teaching preferences, EAL and SEND counts, reading age spread | Teachers (school context) |
| Pupil records | An anonymous pupil code chosen by the teacher, plus free-text attainment and support notes | Pupils |
| Generated content | Lesson plans, worksheets, reports, knowledge organisers, IEPs and other outputs the teacher saves | Teachers, indirectly pupils |
| Uploads | Documents a teacher chooses to upload as reference material | Depends on the document |
| Usage | Which features are used and when, token counts and cost. Prompt and output text are not retained — see section 8. | Teachers |
| Audit log | Sign-in events, administrative access with a recorded reason, deletions | Teachers, our administrators |
We do not collect data from pupils. Pupils do not have accounts and never access ClassMind. All pupil-related data is entered by a teacher.
The pupil intake field accepts an anonymous code chosen by the teacher, not a name. The application is built around that code, and reports are generated using a neutral placeholder which is replaced with the code in the teacher's browser after generation.
3. Lawful basis
- Teacher account data: contract (UK GDPR Art 6(1)(b)) — we need it to provide the service the teacher signed up for. Analytics and marketing cookies rely on consent.
- Pupil-related data: the school determines the lawful basis, normally public task (Art 6(1)(e)). We process it only on the school's and teacher's instructions.
4. Special category and safeguarding data
ClassMind is not designed to hold special category data, and we ask schools not to use it for that purpose. We do not ask for SEND diagnoses, medical information, attendance, behaviour records, family circumstances or safeguarding information.
Free-text fields could technically be used to enter such information, so we have built controls rather than relying on a warning alone:
- Persistent on-screen guidance at every pupil-related free-text field and at every upload point.
- Automatic detection that warns the teacher, as they type, when text looks like it contains an NHS number, a Unique Pupil Number, a date of birth, EHCP detail, social care, safeguarding or court and family information.
- Where that detection triggers, we record only the category that was flagged, never the text, so the pattern can be monitored without copying the data.
- The pupil intake field takes an anonymous code rather than a name.
The detection warns but does not block, so that a false positive cannot cost a teacher their work. It reduces the risk; it does not eliminate it. Schools should treat ClassMind as a resource-authoring tool and keep safeguarding records in their own MIS or safeguarding system.
5. AI processing and model training
ClassMind uses the Anthropic Claude API to generate resources. When a teacher generates something, the prompt for that resource is sent to Anthropic. This can include the school name, year group, topic, and the notes the teacher has written.
- Content is not used to train AI models. Anthropic's commercial API terms state that inputs and outputs submitted through the API are not used to train its models.
- Full pupil names are not sent. The report tool substitutes a neutral placeholder before the prompt leaves our server.
- Prompt and output text are not stored by us. We record token counts and cost for billing only.
- Uploaded reference material is labelled as untrusted data in the system prompt, so instructions hidden inside an uploaded document are not treated as commands to the model.
- Every output is a draft. Teachers review, edit and approve before anything reaches pupils or parents. See AI safety.
6. Where data is stored and transfers
ClassMind data is stored in the United Kingdom. The application and database run on a dedicated server in Manchester. Teacher accounts, class profiles, pupil records and saved outputs do not leave the UK, so no transfer mechanism is needed for storage.
The one transfer outside the UK: Anthropic is based in the United States, so the prompt for a resource is sent there at the moment a teacher generates it. Nothing else is transferred, and the prompt is not retained by us afterwards. What is and is not included in that prompt is set out in section 5.
That transfer is covered by the UK Addendum to the EU Standard Contractual Clauses — the Approved Addendum (version B.1.0) issued by the Information Commissioner under section 119A(1) of the Data Protection Act 2018. It is incorporated into Anthropic's Data Processing Addendum, which forms part of the Commercial Terms under which we use the Claude API. Anthropic's DPA states that the UK Addendum applies to any processing subject to the UK GDPR.
We have carried out a transfer risk assessment covering this transfer. Schools may request a copy at privacy@classmind.co.uk.
7. Sub-processors
| Sub-processor | Purpose | Location | Applies when |
|---|---|---|---|
| Anthropic | AI generation of teaching resources | United States | Every generation |
| Hostinger | Application and database hosting (dedicated server) | United Kingdom (Manchester) | Always |
| Google (Drive) | Saving a generated deck to the teacher's own Google Drive | Global | Only if the teacher connects their Google account |
| Google Analytics | Website analytics | Global | Only with cookie consent |
Email is not outsourced. Transactional email — sign-in codes and password resets — is sent by our own mail server on the same UK infrastructure, so two-factor codes are not handled by a third party.
The Google Drive connection is optional, initiated by the teacher, and uses a permission scope limited to files ClassMind itself creates. It cannot read the rest of a teacher's Drive.
We will give notice of changes to this list on this page.
8. Retention
| Data | Retention |
|---|---|
| AI prompt and output text | Not retained. Discarded once the response is returned |
| Account and class profile | While the account is active; deleted within 30 days of closure |
| Pupil records and saved outputs | Until the teacher deletes them or closes the account |
| Generated export files | 72 hours, then automatically purged |
| Assistant chat history | Most recent 10 per teacher; older entries removed automatically |
| Support conversations | 90 days |
| Uploaded reference documents | Not retained. Text is extracted in memory and the file is deleted immediately |
9. Security measures
Measures in place under UK GDPR Article 32:
- HTTPS with HSTS for all traffic; passwords stored using bcrypt.
- Two-factor authentication is mandatory on every account, using a one-time code sent by email at sign-in.
- One active session per account. Sessions time out after 60 minutes idle and 24 hours absolute, and are revoked on password change, password reset and account lock.
- Every teacher's data is scoped to their own account at the database query level. Cross-account access was specifically tested for and not found.
- Administrative access to a teacher's workspace requires a recorded reason, is written to an audit log, and expires automatically.
- Administrators cannot see AI prompt or output text, or assistant chat content.
- Content Security Policy, CSRF protection on all state-changing actions, and rate limiting on sign-in, password reset and AI usage.
- Metadata is stripped from exported documents, and export filenames do not contain pupil identifiers.
- The codebase is reviewed for security regularly. The most recent reviews were in June and July 2026, with findings remediated.
10. Data subject rights and erasure
Teachers can access, correct, export and delete their own data in the app, or by emailing privacy@classmind.co.uk.
For pupil-related data, the school is the controller and should direct requests to us. We will assist within the statutory timescales. Because pupil records are stored against an anonymous code chosen by the teacher, the school or teacher will normally need to identify which record relates to the pupil.
On account closure we delete account data, class profile, pupil records and saved outputs. Because prompt and output text is never retained, there is no separate copy of pupil-related content in our logs to erase.
11. Breach notification
Where we act as processor, we will notify the school without undue delay after becoming aware of a personal data breach affecting its data, with the information the school needs for its own assessment and any Article 33 notification to the ICO within 72 hours.
Where we act as controller, we will notify the ICO within 72 hours where the threshold is met, and affected individuals where required.
So that we can reach you, schools using ClassMind at scale should send a data protection contact address to privacy@classmind.co.uk. Because teachers usually sign up individually, we may otherwise have no contact route into the school.
12. Completing your DPIA
The school is the controller for pupil data and completes the DPIA. This page is written to supply what a DPIA asks for. Points worth recording in your assessment:
- The tool is used by staff, not pupils.
- Pupil identifiers are anonymous codes chosen by the teacher, and full names are not sent to the AI provider.
- Prompt and output content is not retained by ClassMind.
- There is a transfer to the United States for AI generation — see section 6.
- The main residual risk is a teacher entering more pupil information than necessary into free text. Section 4 sets out the controls; your staff guidance is the other half.
- Outputs are drafts requiring teacher review before use.
If your DPO needs anything further, email privacy@classmind.co.uk.
This page is provided to help schools meet their own obligations. It is information about our service, not legal advice.