SchoolDesk holds school records, and most of them are about children. Your school decides what is recorded and for how long; we host the software and act on the school's instructions. We do not sell data, show adverts, profile children, or train our own models on pupil records. Data is stored on Google Cloud in Belgium. If you want to see, correct or delete a record, ask your school first — they can reach everything we can.
Who we are
SchoolDesk is a school management platform operated by SpringKnight LTD, a company registered in England and Wales under company number 15060534, at 9 St. Georges Place, Brighton, East Sussex, BN1 4GB, United Kingdom. In this policy, “we”, “us” and “SchoolDesk” mean SpringKnight LTD.
Data protection questions, access requests and complaints go to [email protected], marked for the attention of the Data Protection Lead, or by post to the address above.
This policy covers every part of the SchoolDesk service:
- The SchoolDesk web application used by school administrators and teachers
- The SchoolDesk Staff mobile app for teachers and school staff
- The SchoolDesk Guardian mobile app for parents and guardians
- The SchoolDesk Classroom web application
- Our website at schooldesk.cc
Who is responsible for your data
This distinction matters, because it determines who you ask when you want something changed or deleted.
Your school is the data controller. The school decides what pupil, guardian and staff records to keep, what to enter, and how long to keep them. It is the school's data. If you are a parent, guardian, pupil or member of staff, your school is your first point of contact for any question about your records.
We are the data processor. We host and operate the software on the school's behalf and act on the school's instructions. We do not decide what is collected about your child, and we do not use school data for our own purposes.
We are a controller for a narrow set of our own data: the account details of the people who administer SchoolDesk, our billing records, and the support correspondence we exchange with you.
Each school signs a Data Processing Agreement with us setting out these roles, the categories of data we process, and our obligations as processor under Article 28 of the UK GDPR.
What personal data we process
What a given school actually stores depends on which SchoolDesk modules it uses. This is the full range the platform supports.
| Who | What we may hold |
|---|---|
| Pupils | Name, date of birth, sex, photograph, admission and reference numbers, class and year group, guardian relationships, admission and enrolment history, attendance records, exam marks and report comments, behaviour and diary notes, clinic and health visit notes, canteen purchases, transport and check-in records, and documents uploaded by the school |
| Parents and guardians | Name, relationship to the pupil, phone number, email address, linked pupils, fee balances and payment history, and messages and notifications sent to you |
| Staff | Name, email address, phone number, role and permissions, employment and payroll details where the school uses that module, and records of actions taken in the system |
| Anyone signing in | Authentication tokens, device identifiers for push notifications, and technical logs of requests to our servers |
Health data. Where a school uses the clinic module, records may include health information about a pupil. This is special category data under Article 9 of the UK GDPR and is treated accordingly.
What we do not do. We do not sell personal data. We do not share it with advertisers. We do not build advertising profiles, and we do not use pupil data to train machine-learning models of our own.
Children's data
Most of the people whose data SchoolDesk holds are children. We take that as the starting point rather than an afterthought.
- The school authorises the processing, not the child. A pupil is not asked to agree to anything in order to be enrolled. The school holds the relationship with the family and is responsible for telling parents what it records and why.
- Children do not normally hold SchoolDesk accounts. Access is through school staff and through guardian accounts held by adults. Where a school chooses to issue pupil logins, those accounts see only that pupil's own records.
- No advertising, ever. We do not show adverts, we do not profile children for marketing, and we do not pass their data to anyone who would.
- No automated decisions about a child. Nothing in SchoolDesk decides a pupil's grade, placement or discipline on its own. Staff make those decisions; the software records them.
- Photographs. Pupil photographs are stored so staff can identify children. They are visible to school staff and, where the school enables it, to that pupil's own guardians.
If you are a parent and you want to know what your child's school holds, ask the school. They can see everything we can, and the request is theirs to answer.
Why we process it, and our lawful basis
Under the UK GDPR every use of personal data needs a lawful basis. Ours:
| What we do | Lawful basis |
|---|---|
| Run the school's records — admissions, attendance, exams, timetables, reports | Contract (Art. 6(1)(b)), performed on the school's instructions as processor |
| Send fee notices, receipts and payment reminders to guardians | Contract, and the school's legitimate interests in collecting fees owed to it (Art. 6(1)(f)) |
| Send attendance, announcement and event notifications | Legitimate interests of the school in communicating with families |
| Record clinic and health visits | Contract for the basic record, and Art. 9(2)(h) for the health element, relied on by the school as the body providing health care to its pupils |
| Keep our own account, billing and support records | Contract, and legal obligation for accounting records (Art. 6(1)(c)) |
| Keep security and error logs | Legitimate interests in keeping the service working and secure |
| Send you marketing about SchoolDesk | Consent, which you can withdraw at any time. This applies only to business contacts, never to parents or pupils |
Where we rely on legitimate interests, we have weighed those interests against the rights of the people concerned. You can ask us for that assessment.
Signing in with Google
SchoolDesk offers “Sign in with Google” on the web application and on both mobile apps. If you use it, Google tells us three things and nothing more: your email address, your basic profile (name and profile picture), and an OpenID identifier confirming the sign-in is genuine. We request no other scopes.
We use that information for one purpose — to match you to an existing SchoolDesk account and log you in. We do not read your Gmail, your Drive, your Calendar or your Contacts, and we do not ask Google for permission to.
Google API Services Limited Use. SchoolDesk's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data to others except as needed to provide the service, we do not use it for advertising, we do not sell it, and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with the law, or where the data has been aggregated and anonymised.
You can sign in with an email address and password instead. Using Google is never required.
Who else sees the data
We use a small number of specialist providers to run SchoolDesk. Each is bound by contract to process data only on our instructions, and each sees only what it needs for its own job. We do not sell data to anyone, and none of these providers is an advertiser.
| Provider | What it does | What it sees |
|---|---|---|
| Google Cloud | Hosts the application, the database, uploaded files and secrets | All school data, at rest and in transit |
| Paystack | Card and mobile-money fee payments | Payer name, email, phone, amount, reference |
| Hubtel | Mobile-money payments and payment OTPs | Payer name, phone, amount, reference |
| ClickPesa | Mobile-money payments | Payer name, phone, amount, reference |
| Pesapal | Card and mobile-money payments | Payer name, email, phone, amount, reference |
| Kowri | Payment processing | Payer name, phone, amount, reference |
| Arkesel | SMS to guardians and staff | Recipient phone number and message text |
| Twilio | SMS to guardians and staff | Recipient phone number and message text |
| SMTP2GO | Transactional email — receipts, invitations, password resets | Recipient email address and message content |
| OneSignal | Push notifications to the mobile apps | Device token, user identifier, notification text |
| Sentry | Error and crash reporting | Technical error details, which can include the identifier of the user who hit the error |
| Google Gemini, DeepSeek, xAI | Optional AI writing features | Only the text a member of staff submits to that feature |
We also disclose data where the law requires it — a court order, a regulatory demand, or a safeguarding obligation — and to our professional advisers where necessary. If SpringKnight is ever sold or merged, school data passes to the buyer under the same terms, and schools will be told before that happens.
An up-to-date list of subprocessors is available from [email protected]. Schools are notified before we add a new one.
AI features
Some parts of SchoolDesk can draft text for a member of staff — report comments, for example. These features call Google Gemini, DeepSeek or xAI.
- They run only when a member of staff asks. Nothing is sent to an AI provider in the background.
- Only the text submitted for that request is sent. The provider does not receive your database, your pupil list, or anything else.
- The output is a draft. A member of staff reads, edits and approves everything before it reaches a pupil or a guardian. No AI output is published automatically, and no AI system makes a decision about a pupil.
- We do not train models on school data. Our contracts with these providers do not permit them to train on data we send.
Staff are asked to keep identifying details out of AI prompts where the task does not need them — a report comment can be drafted from the marks without the child's full name.
Where the data is stored
SchoolDesk runs on Google Cloud in the europe-west1 region, whose data centres are in St Ghislain, Belgium. The application servers, the database and uploaded files all live there. Backups stay in the same region.
Schools using SchoolDesk are located in a number of countries, including Ghana, Liberia and Tanzania. This means data about pupils in those countries is stored in Belgium and accessed from the school's own country. Where a transfer leaves the UK or the European Economic Area, we rely on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, together with the safeguards our cloud and communications providers have in place.
A few providers process data outside Europe by the nature of what they do — an SMS to a Ghanaian phone number is delivered by a Ghanaian operator, and a payment through a local mobile-money provider is processed locally. Those transfers are necessary to perform the service the school has asked for.
Our own staff access school data only to operate and support the service, and only when there is a reason to — a support request, an investigation into a fault, or a security incident.
How long we keep it
| Data | Kept for |
|---|---|
| Pupil, guardian and staff records | As long as the school's contract with us is active, and the school decides what to keep within that |
| All school data after a contract ends | 90 days, then permanently deleted. Within that window a school can request a full export |
| Financial and payment records | 7 years from the transaction, to meet accounting and tax obligations |
| Backups | 35 days on a rolling basis, after which they are overwritten |
| Security and application logs | 90 days |
| Error reports | 90 days |
| Support correspondence | 3 years from the last message |
| Marketing contacts | Until you unsubscribe, and 2 years after the last interaction |
A school can ask us to delete specific records at any time, and we will do so unless the law requires us to keep them. Deletion from live systems is immediate; the record disappears from backups as those backups age out within 35 days.
How we protect it
- Encryption in transit. Every connection to SchoolDesk uses HTTPS. The mobile apps and the web application will not talk to our servers over an unencrypted connection.
- Encryption at rest. The database, file storage and backups are encrypted by Google Cloud.
- Secrets are never in the code. Database credentials, API keys and signing keys are held in Google Secret Manager and injected into the running service at deploy time.
- Separation between schools. Every request is scoped to the school the signed-in user belongs to. A user at one school cannot read another school's records.
- Role-based permissions. What a member of staff can see and do is governed by the privileges their school grants them. A class teacher does not automatically see payroll or finance.
- Monitoring. Errors and anomalies are reported to our logging and error tracking systems, and reviewed.
- Least-privilege access for our own team. Production access is limited to the engineers who need it.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects personal data, we will notify the affected schools within 72 hours of becoming aware of it, with what we know at that point, and follow up as we learn more. Schools, as controllers, are then responsible for notifying their own regulator and the affected families, and we will give them whatever they need to do that.
If you believe you have found a security vulnerability in SchoolDesk, email [email protected] with the details. We will acknowledge you within two working days.
Your rights
Under the UK GDPR and equivalent laws you have the right to:
- Know what personal data is held about you or your child, and get a copy of it
- Correct anything inaccurate or incomplete
- Erase data, where there is no lawful reason to keep it
- Restrict how it is used while a dispute is resolved
- Object to processing based on legitimate interests
- Portability — receive your data in a structured, machine-readable format
- Withdraw consent where consent is what we relied on
Ask your school first. For anything about a pupil, guardian or staff record, the school is the controller and holds the decision. School administrators can view, correct, export and delete records directly in SchoolDesk without involving us.
If the school needs our help, or your request is about data we hold as controller — your SchoolDesk account, our billing records, our correspondence with you — write to [email protected]. We respond within one month, as the law requires, and will tell you if a complex request needs longer. There is no charge.
If you are unhappy with how we have handled it, you can complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint or by calling 0303 123 1113. If you are outside the UK, you can complain to your own country's data protection authority — in Ghana, the Data Protection Commission. We would rather you came to us first so we can put it right.
Cookies, storage and analytics
In the SchoolDesk application, we store only what is needed to keep you signed in: an authentication token and your session and language preferences, held in your browser's local storage or, on mobile, in the device's secure storage. These are strictly necessary, so they do not require a cookie banner. We set no advertising or tracking cookies in the application.
On this website, we use Google Analytics to count visits and see which pages are read. This tells us nothing about individual pupils or school data — the website has no access to school records.
Error reporting. When something goes wrong, our error tracking receives a technical report about the fault. This can include the identifier of the signed-in user who encountered it, so we can trace what happened.
Push notifications. If you install a SchoolDesk mobile app and allow notifications, a device token is held so we can deliver them. Turn notifications off in your device settings and the token stops being used.
Changes, and how to reach us
If we change this policy in a way that materially affects how personal data is handled, we will tell schools by email at least 30 days before the change takes effect, and update the version and date at the top of this page. Minor corrections take effect when published.
SpringKnight LTD
Company number 15060534, registered in England and Wales
9 St. Georges Place, Brighton, East Sussex, BN1 4GB, United Kingdom
[email protected]
For data protection matters, address your message to the Data Protection Lead. We aim to reply within two working days and always within one month.
This policy was last reviewed on 22 September 2026.