Short version: For the website, we collect the minimum we need to respond to school enquiries and people who want to work with us, and to send the newsletter. For the Cloak for Schools student platform, your school is the data controller, we are the processor, and data is hosted in the UK — the full detail is in section 10. We don’t sell data, we don’t use trackers, and you can ask us to delete anything we hold about you at any time.
What this policy covers
Cloak for Schools is more than one thing — this website, the free activities and the schools platform — and the data story is different for each part. This policy covers all of them — use the split below to find the bit you care about:
| Product | Who it’s for | Data position | Details |
|---|---|---|---|
| This website (getcloak.tech) | Anyone — teens, parents, school staff | What you submit through our forms or by email — school enquiries, newsletter sign-ups, registrations to work with us, direct emails — plus standard server logs and the technical data our hosting and font providers receive when a page loads. | Sections 1–9 |
| Cloak for Schools student platform | Licensed schools, their staff and students | UK-hosted. The school is the controller and Solid Code Solutions is the processor, under a data processing agreement signed before any of a school’s student data is processed. | Section 10 |
The free interactive mini-games and activities on this site (Would You Click?, Spot the Fake, and so on) need no login and ask for no personal data. Your answers are processed in your browser and are never sent to us. One of the games remembers a best score on your own device (see section 6), and that’s the whole story — so they aren’t listed separately above.
1. Who we are
Cloak for Schools is cyber safety education for secondary schools and their students. It’s a product of Solid Code Solutions Ltd, an IT consultancy based in Leamington Spa, UK.
For the purposes of UK GDPR and the Data Protection Act 2018, the data controller for this website is:
- Solid Code Solutions Ltd
- Registered address: 20 - 22 Wenlock Road, London, England, N1 7GU
- Company number: 08750436
- ICO registration: ZC141966
- Privacy contact: info@solidcodesolutions.co.uk
2. What we collect
We collect the information you submit through our forms or by email. Our hosting and font providers also receive standard technical information (such as your IP address) when you visit a page — that row is in the table too.
| When | What we collect | Why |
|---|---|---|
| You talk to us about your school, or contact us as a parent | Your name, email, school or trust name and role, plus two optional fields: for a trust, how many schools it has, and anything you choose to write in the "anything else you’d like us to know?" box | To reply to you about Cloak for Schools and, for a trust, put together a quote |
| You subscribe to the newsletter | Your email address | To notify you when we publish new content |
| You register interest in working with us | Your name, email, and your role and experience, plus two optional fields: roughly how much time you could give, and anything you choose to write in the “anything else you’d like us to know?” box | To talk to you about paid work on Cloak for Schools and, if it goes ahead, to agree it with you |
| You email us directly | Your email address and anything you choose to put in the message | To reply to you |
| You visit any page | Standard server logs (IP address, browser type, pages viewed, timestamp) held by our hosting provider | Security, abuse prevention, basic operational diagnostics |
We do not currently use website analytics (e.g. Google Analytics), advertising trackers, or social media pixels. If we add any of these in future, we’ll update this policy and add a cookie consent banner first.
The table above covers the website only. Student data in the Cloak for Schools platform is covered in section 10.
3. Why we use it (lawful basis)
- School enquiries — legitimate interests (UK GDPR Article 6(1)(f)). You’ve contacted us on behalf of your school about a service for it, and replying, answering questions and putting together a quote is exactly what you’d expect us to do with your details. Any licence that follows is a contract with your school, not with you personally, so we don’t rely on the "contract" basis for your contact details.
- Registering interest in working with us — steps taken at your request before entering into a contract (UK GDPR Article 6(1)(b)). You’ve asked us to consider you for paid work, and talking it through with you and agreeing it is part of that.
- Direct emails and other correspondence — legitimate interests in replying to you and keeping a record of what was said.
- Newsletter — consent. You’ve opted in by submitting the form, and you can withdraw it at any time — every email carries an unsubscribe link, or you can just ask us to remove you.
- Server logs — legitimate interests in keeping the site secure and operational.
- Cloak for Schools student data — we process it as a processor on the school’s documented instructions, so the lawful basis is the school’s to decide (for most schools, their public task in providing education). See section 10.
4. If you’re under 18
Cloak for Schools is aimed at secondary school students aged 11–16. We’re aware that many of our visitors are minors, and we follow the ICO’s Age Appropriate Design Code (the "Children’s Code").
What that means in practice:
- We don’t ask students for personal information. The "Talk to us about your school" form is for school staff and parents, and registering interest in working with us is for school staff; neither is for students, and the free activities need no login — your answers stay in your browser and are never sent to us.
- The newsletter is written for school staff and isn’t meant for under-18s. If you’re a student you don’t need it: everything new lands on the free activities and On the Radar pages with no sign-up. If we find a subscription belongs to someone under 18, we’ll remove it.
- If you use Cloak for Schools through your school, your school is in charge of your data — section 10 explains what your teachers can and can’t see and who to ask about it.
- We don’t profile you, target advertising at you, or share your data with anyone for marketing purposes.
- If a parent or guardian is concerned about data we hold about a young person, they can contact us at the address in section 12 and we’ll act on it promptly.
5. Who we share data with
We don’t sell your data. We share it only with the providers we use to actually run the site and respond to you:
- Netlify — hosts this website and processes our form submissions, including school enquiries, newsletter sign-ups and registrations to work with us, on our behalf. Netlify runs every submission through Akismet, a spam-filtering service operated by Automattic, before it reaches us. See Netlify’s privacy policy.
- Google Fonts — serves the typefaces used on this site. Loading the page sends your IP address to Google so the fonts can be delivered. See Google’s privacy policy.
- Our email provider — Microsoft 365 handles the inboxes we use to reply to you.
We don’t currently use a third-party email-marketing platform: newsletter sign-ups are simply stored as form submissions with Netlify until we send an update. If we ever add a dedicated email provider, we’ll update this policy first.
We may also disclose data where we’re legally required to (for example, in response to a court order, or to protect someone from serious harm).
The providers above run the website. The Cloak for Schools student platform uses a separate, UK-hosted set of sub-processors that are kept entirely apart from our marketing tools — that list is in section 10.
6. Cookies and tracking
This website does not set any cookies on your device, and we don’t use analytics or advertising trackers.
One of the free games (Swipe to Survive) uses your browser’s local storage to remember your best score. That information never leaves your device, isn’t linked to you, and is cleared whenever you clear your browser’s site data.
The Cloak for Schools platform (app.getcloak.tech) sets a small number of cookies that are strictly necessary to keep you signed in and to protect your account from forged requests. None of them is used for tracking or analytics, and none contains your name or any lesson data. The sign-in cookies are removed when you sign out; all of them expire on their own within 24 hours at most. To clear them sooner, clear your browser’s site data for getcloak.tech and its subdomains. Because they’re strictly necessary for the service you’ve asked for, the law doesn’t require a consent banner for them.
Remembered school code. Separately from the cookies above, the student sign-in page keeps your school code in local storage so it’s pre-filled next time. This is a convenience, not a requirement: signing in works exactly the same if you type the code each time, and the stored value is never used to decide what you can see. The school code identifies your school, not you, and is never sent anywhere except back to the sign-in form. At the moment the sign-in page stores it after every successful sign-in and there is no switch to turn that off: clearing the site data for app.getcloak.tech removes it, but it will be stored again the next time you sign in on that device. We are adding a "don’t remember my school code" option to the sign-in page, and until it’s there we don’t claim this storage meets the preference exception — we’re telling you about it so you can decide.
Third-party services we link to (for example LinkedIn) will set their own cookies once you click through to them. Their cookie policies apply on their own sites.
7. How long we keep data
- School enquiries — kept for up to 3 years from last contact, then deleted, unless you become a paying customer (in which case standard business records apply).
- Newsletter subscribers — kept until you unsubscribe, then promptly removed.
- Registrations to work with us — if no work follows, deleted within 6 months of our last contact with you. If we go on to work together, your details become part of the records for that work, and we’ll tell you how long we keep them when we agree it.
- Email correspondence — kept for up to 2 years for reference, unless there’s a reason to keep it longer (e.g. an ongoing project).
- Server logs — typically rotated and deleted by our host within 30 days.
Retention for the Cloak for Schools student platform works differently and is set out in section 10, with the definitive schedule confirmed in each school’s data processing agreement.
8. International transfers
Some of the providers we use for the website are based in the United States and may process your data there:
- Netlify (US) — website hosting and form submissions. Netlify is certified under the UK Extension to the EU–US Data Privacy Framework. Its spam filtering is provided by Automattic’s Akismet (US) under Netlify’s own sub-processor terms.
- Google (US) — Google Fonts delivery. Google is certified under the UK Extension to the EU–US Data Privacy Framework.
- Microsoft 365 — the inboxes we reply from. Our tenancy stores mail in Microsoft’s UK/EU data-centre regions; any transfer to the EEA is covered by the UK’s adequacy regulations. Some Microsoft support and service operations can involve access from the United States; those transfers to Microsoft Corporation are covered by its certification under the UK Extension to the EU–US Data Privacy Framework, with the EU Standard Contractual Clauses and UK Addendum in Microsoft’s Data Protection Addendum as a fallback.
Transfers to the United States are made to providers certified under the UK Extension to the EU–US Data Privacy Framework, and only for the data covered by each provider’s certification. Transfers to the EEA rely on the UK’s adequacy regulations. If we ever transfer data to a destination or provider not covered by either, we’ll rely on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum — EU clauses on their own are not a valid safeguard for a UK transfer.
The Cloak for Schools student platform is different. Student data is resident in the United Kingdom (Microsoft Azure UK regions), with no routine transfer of student data outside the UK. The platform’s only email — account-access information for authorised school staff — is sent through Microsoft Azure Communication Services, also UK-located, and never carries lesson or progress data. See section 10 for the detail.
9. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct anything that’s inaccurate or out of date
- Delete your data ("right to be forgotten") in most circumstances
- Object to us processing your data, or restrict how we use it
- Take your data with you in a portable format
- Withdraw consent at any time (e.g. unsubscribe from the newsletter)
To exercise any of these, email us using the address in section 12. We’ll respond within one month. Some rights are qualified — for example, we can’t erase a record we’re legally required to keep, and portability applies to data you gave us that we process by consent or under a contract. If we can’t meet a request in full, we’ll explain why.
These rights, exercised with us, cover the data we hold as controller: website enquiries, newsletter sign-ups, registrations to work with us, correspondence, and the platform’s security records of sign-in attempts that don’t match a recognised school account (see section 10). For student and staff data we process in Cloak for Schools on a school’s behalf, your school is the controller, so make the request to your school — we’ll support the school in responding, and if you contact us first we’ll point you to the right person there.
If you’re unhappy with how we’ve handled your data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator. We’d appreciate the chance to put things right first, but it’s your call.
10. The Cloak for Schools platform
Cloak for Schools is a student-facing online safety learning platform, licensed to schools, where students work through interactive lessons and teachers assign tasks and see progress on a dashboard. The platform is live at app.getcloak.tech and is offered to schools as an annual subscription licence.
This section describes how the platform handles student data. The binding, school-specific detail — including the data schema, retention periods and sub-processor list — is set out in a Data Processing Agreement (DPA) that is signed before any of a school’s student data is processed. This notice stays accurate for every school; the DPA adds the school-specific processing instructions and contractual detail that sit on top of it.
Controller and processor
For the student platform, your school (or trust) is the data controller and Solid Code Solutions Ltd is the data processor. We process student data only on your documented instructions, for the purpose of delivering the lessons and reporting progress back to you — never for our own marketing, and never to train AI models. We provide a DPA (UK GDPR Article 28), a sub-processor list, a retention schedule, and support for your Data Protection Impact Assessment (DPIA) as part of onboarding.
What data the platform collects
The platform is built around data minimisation: it collects only what students need to complete lessons and what teachers need to see progress. Where a school prefers, students can be identified by a pseudonymous ID rather than a full name. The data model is:
| Data | Example | Why |
|---|---|---|
| Student identity | First name and last name (or a pseudonymous ID / display name, at the school’s choice) | So students can log in and teachers can see whose work is whose |
| Class / cohort | Year group, class or teaching group | To assign work and group progress for a class or year |
| Account / log-in | Sign-in credentials: a username and password issued by Cloak for Schools for students, and a school work email address for staff | To authenticate students and staff securely |
| Security records | Sign-in events (successful and failed) with the IP address and browser type of the device used, plus a record of significant actions such as account changes, exports and deletions. These are held against account IDs, never names or email addresses | To spot suspicious sign-ins, investigate problems, and give your school an audit trail of its own data |
| Learning activity | Lesson and activity completion status, scores/answers to fixed-choice questions, time spent, last-active date. For lessons on sensitive topics, recording is deliberately coarser: completion and objective-level status only — individual answers are not stored | To show teachers progress and let students resume where they left off |
| Staff accounts | Teacher / DSL / admin name, work email, role and permissions | To give the right staff the right access and produce reports |
What the platform deliberately does not collect. In line with the safeguarding design set out in the schools FAQ, there are no free-text boxes asking students to describe things that have happened to them or to other people, and no student-to-student messaging. The platform does not seek special-category data (such as health, religion or ethnicity), does not track students’ browsing outside the platform, and does not build advertising or behavioural profiles. Answers are to scenario-based, fixed-choice questions — not disclosures — and on sensitive topics individual answers are not stored at all, so a student’s responses can never be read as implying personal experience.
Accounts and sign-in
Your school creates and manages every account, from the class list it uploads (described below) — students don’t self-register, no student enters personal data to create an account, and no student account is linked to a personal email address. We process only the account information needed to give students and staff secure access, and students should contact their school for help signing in.
We protect account information with encryption, secure password storage (passwords are never stored in a form we can read) and access controls. Access to school data is limited to authorised people who need it for their role, and we record security events to protect accounts and investigate problems (see the security-records row above, and the retention rules below).
Where needed, we send account-access information to authorised school staff by email through Microsoft Azure Communication Services. Those emails never contain lesson or progress data, and staff are asked to handle them with the same care as a printed login slip.
Class lists, MIS data — and why it’s kept separate from marketing
Today, a school creates student and class accounts by uploading a CSV class list exported from its Management Information System (MIS), or by adding students one at a time from the dashboard. Only the fields listed above are needed, and we ask schools not to include anything else in the upload: no contact details, safeguarding flags, SEN, attendance, medical or other sensitive MIS fields.
A direct MIS sync through an approved connector such as Wonde is planned but not yet live. No school data is shared with a connector until that feature ships and your school chooses to switch it on; when it does, it will pull only the fields listed above, and we’ll update this policy and give schools notice under the sub-processor terms below before it takes effect.
Student data and marketing are fully partitioned. The student platform runs on separate, UK-hosted infrastructure with its own database. Student records are never added to the newsletter list or any marketing tool, and are never used to contact students or their families for marketing. The providers that run the website (section 5) have no access to platform data, and vice versa.
Access controls, roles and audit logs
Access is role-based and least-privilege — staff see only the data their role needs:
- Teacher — the progress of their own assigned classes.
- DSL / safeguarding lead — the school-configured view appropriate to their role.
- School admin — accounts and settings for their own school.
- MAT / trust admin — an aggregate view across the trust’s schools, where a trust licence applies.
Solid Code Solutions staff access to school data is restricted to the minimum needed to run and support the service, and significant actions (such as account changes, exports and deletions) are recorded in audit logs, alongside the sign-in events described in the table above. Each school’s audit log is stored with its own data and is available to that school on request through our support contact in section 12 — one school can never receive another’s. Self-service retrieval from the dashboard is planned.
Where it’s hosted and how it’s secured
- UK data residency. Student and school data is hosted on Microsoft Azure in UK regions (UK South / UK West). There is no routine transfer of student data outside the UK.
- Encryption. Data is encrypted in transit (TLS) and at rest.
- Separation. Each school’s data is logically separated so one school cannot see another’s.
- Backups. Backups are held within the UK region and are subject to the same retention and deletion rules as live data.
- Certification. Solid Code Solutions holds Cyber Essentials and is registered with the ICO. The platform is designed to meet the ICO’s Children’s Code.
- AI. AI is used behind the scenes to spot emerging scams so lessons stay current; a human reviews and approves everything before it reaches a classroom, and AI never touches student data.
Sub-processors
These are the only sub-processors that may handle student or school data:
| Sub-processor | What it does | Location |
|---|---|---|
| Microsoft Azure | Cloud hosting, database and backups for the platform | United Kingdom |
| Microsoft Azure Communication Services | Sends the platform’s account-access emails to authorised school staff. These emails never carry lesson or progress data | United Kingdom |
| Wonde (planned — not yet live) | Secure one-way sync of the agreed fields from your MIS, only if your school opts in once the feature ships. No school data is shared with Wonde today | United Kingdom |
The definitive, contractual sub-processor list is provided with your DPA, and we give schools advance notice of any new or replacement sub-processor so you can object before it takes effect.
Keeping, exporting and deleting student data
- During your subscription — we keep student records for as long as they’re needed to deliver the service to your school.
- Security records — sign-in events and audit entries (including the IP address and browser type recorded with them) are kept for the life of your subscription, so a concern raised months later can still be investigated, and are deleted with the rest of your school’s data. Sign-in sessions stop working the moment they expire and are removed on the same schedule.
- Sign-in attempts we can’t match to a school — if someone tries to sign in with an account we don’t recognise, we record the IP address and browser type of the attempt (never the details that were typed) so we can spot abuse. These records belong to no school, so Solid Code Solutions holds them as controller on the legitimate-interests basis of keeping the service secure, and deletes them within 12 months.
- Export. Your school’s data is yours. Ask us through the support contact in section 12 and we’ll supply an export of your student records and progress data (as CSV) at any time; self-service export from the dashboard is planned. Exports never include individual answers to lessons on sensitive topics — those are never stored in the first place.
- Deletion. At the end of a subscription, we delete your school’s student data — audit log and security records included, and from backups on their normal cycle — no later than 30 days after it ends, unless you ask us to delete it sooner or the law requires us to keep it. A school can also request deletion of an individual student’s record at any time.
The exact retention periods are confirmed in your DPA. Because your school is the controller, requests from students or parents to access, correct or delete data are handled through the school; we support the school in responding to them.
If you’re a student using Cloak for Schools
Your school gave you your account, and your school is in charge of your data. Your teachers can see your name or username, your class, which lessons you’ve done and how you scored on the fixed-choice questions. On lessons about sensitive topics they can only see that you completed it — never which answers you picked. Nobody at Cloak for Schools reads your answers, there’s no messaging between students, and the platform never looks at what you do outside it.
If you want to see, correct or delete your data, or you’re worried about something, talk to a teacher or the person at your school who looks after data protection — they can act on it straight away. You can also email us using the details in section 12 and we’ll make sure it gets to the right person at your school.
For your procurement and DPO
Before any school goes live, we provide the documents a school’s data protection review needs: a signed DPA, the sub-processor list, a retention schedule, and support for your DPIA. To request these, contact us using the details in section 12.
11. Changes to this policy
If we change this policy in a way that materially affects you (for example, if we add analytics or change who processes your data), we’ll update the ‘last updated’ date at the top of this page and, where appropriate, notify you by email or with a banner on the site.
12. Contact us
For anything privacy-related — data requests, questions, complaints, or concerns about a young person’s data — get in touch:
- Email: info@solidcodesolutions.co.uk
- Post: Solid Code Solutions Ltd, 20 - 22 Wenlock Road, London, England, N1 7GU