Last updated: 23 August 2026 · Version: 1.0a
EduTables (“we”, “our”, or “us”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, and protect your personal data when you use our website and services (“Service”).
We process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using our Service, you agree to the terms of this Privacy Policy.
EduTables
Based in England & Wales
Email: support@edutables.com
We are the data controller of the personal data you provide when you register an account or interact with our Service.
For the data you upload to the Service (e.g., your own datasets), you remain the data controller, and we act as your data processor by hosting and processing the data on your behalf.
We may collect and process the following data about you:
We use cookies and similar technologies — see our Cookie Policy for details.
We use your data to:
We do not sell or rent your personal data to third parties.
We may share your personal data:
We ensure all third parties process your data in accordance with data protection law.
Our detailed processor commitments, including our published sub-processor list and international transfer safeguards, are set out in full in our Data Processing Agreement, published at this URL and incorporated into our agreement with your organisation.
EduTables offers an optional feature that lets a member of your site connect an external AI assistant — for example Claude, or any other client that speaks the Model Context Protocol — so it can read and, where permitted, edit data on their behalf.
This feature is switched off unless your organisation switches it on. It requires all of the following, and stops working the moment any one of them is removed:
Where you enable it, the AI provider your member connects acts as an additional sub-processor of the personal data in the tables that member can access, which may include pupil or staff records. Before authorising, and again before approving each individual assistant, your administrator is shown exactly which tables and how many records would be readable, and whether the assistant would also be able to change data.
Because the provider is chosen by your member at the point of connection, EduTables cannot name a single sub-processor in advance — any client that speaks the Model Context Protocol can connect. In practice, connections are with one of a small number of major providers. Processing takes place outside the UK (in practice the USA). Based on each provider’s own published data processing terms (last checked 28 August 2026), their transfer mechanism is:
| Provider | Assistant | Transfer mechanism |
|---|---|---|
| Anthropic PBC | Claude | UK Addendum to the EU Standard Contractual Clauses (Module 2/3). Not currently certified under the UK Extension to the EU–US Data Privacy Framework. |
| OpenAI, L.L.C. | ChatGPT | Standard Contractual Clauses with the UK Addendum applied to UK data. May also hold EU–US Data Privacy Framework certification for EU data — check the current DPF register before relying on this. |
| Google LLC | Gemini | UK International Data Transfer Addendum, and certified under the UK Extension to the EU–US Data Privacy Framework as an alternative transfer solution. |
| Microsoft Corporation | Copilot | Standard Contractual Clauses incorporated into its Data Processing Agreement, alongside EU–US Data Privacy Framework certification. Confirm current UK Extension status before relying on this. |
This table reflects each provider’s own publicly stated position at the date above, is not exhaustive (a member may connect any other MCP-capable client), and is not legal advice — providers change their terms and certification status. Before authorising this feature, satisfy yourself as to the current terms on which your chosen provider processes data, and confirm the transfer basis with a data protection adviser before relying on it in your own compliance documentation.
Every request an assistant makes is logged and is reviewable by your administrators, who can withdraw an individual assistant’s access, or the authorisation as a whole, at any time. Withdrawal takes effect immediately and invalidates the credentials already issued.
We retain your personal data only as long as necessary to provide the Service and fulfil the purposes described in this policy, unless a longer retention period is required by law.
Account information is kept for as long as your account is open. Records we generate about how the Service is used — logs — are kept for a fixed period and then deleted automatically by a scheduled job; we do not keep them indefinitely. The periods are:
| What | How long we keep it |
|---|---|
| Sign-in records (success, failure, method) | 12 months — the IP address is removed after 6 months |
| Record of who changed a value in one of your tables (the Activity Log) | Set by your school or organisation — between 6 months and 7 years, and 3 years where they have not chosen. Ask your administrator which applies, or see Site Settings if you are one |
| Record of items (tables, reports, dashboards) that were deleted | 12 months |
| Visits to a public share link, and requests to a data feed — including the visitor’s IP address | 3 months |
| Activity by an AI assistant you have connected to your account | 12 months — the IP address is removed after 6 months |
| Email delivery records (recipient address and whether it arrived) | 12 months |
| In-app notifications | 6 months once read; 12 months otherwise |
| Technical error logs | 3 months |
| Trial and demo enquiries | 12 months after the enquiry is dealt with — the IP address is removed after 3 months |
| Records of data-protection requests we have handled | 6 years, as evidence that the request was honoured. The person is recorded only as an irreversible hash, never by name |
| Financial and billing records | 6 years, as required by UK company and tax law |
Where a log has to be kept for its full period but the IP address in it does not, we delete the IP address earlier, as shown above.
Data you upload to the Service belongs to you (or, for a school account, to your school), so its retention is decided by you and set out in our agreement with your organisation, not by this table.
You can request deletion of your account and data at any time by contacting us at support@edutables.com.
We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or misuse. However, no system is completely secure, and we cannot guarantee absolute security of your data.
Under UK data protection law, you have the right to:
To exercise your rights, please email us at support@edutables.com. We will respond within one month.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk if you believe we have mishandled your data.
If we transfer your data outside the UK, we ensure appropriate safeguards are in place to protect your data in accordance with UK data protection laws.
The optional AI Assistant Access feature described in section 4a involves a transfer outside the UK, and is the one feature that does so only if your organisation has explicitly authorised it. See that section for the safeguards relied on.
We may update this Privacy Policy from time to time. Any changes will be posted on this page with the updated date.
If you have any questions about this Privacy Policy or how we handle your data, please contact us: