Privacy Notice

Privacy Notice for Schoolcomms Users

Schoolcomms, part of ParentPay limited, is engaged in the design, development, sales, marketing, supply, maintenance and operation of payment collection, payment processing, parent communication and management information systems and services for the education market.

This notice explains to Schoolcomms Users (“you/your”) how ParentPay (“we/us”) use your personal information.

This privacy notice covers:

  • Why we use your personal information
  • The legal basis for processing
  • What personal information we use
  • How we use your personal information
  • Your rights under data protection legislation
  • Sharing personal information with third parties
  • How long we may keep your information
  • Changes to our privacy notice
  • Contact details for our Data Protection Officer

Why we use your personal information

The Schoolcomms payment solutions and communication platforms provided to schools and their parents, are governed by a contract between us and the schools, Multi-Academy Trust or a Local Education Authority (“Schoolcomms Customer”), and also the Terms and Conditions that you agree with when you sign up (“Schoolcomms User”).

We process your personal data for the following purposes:

  • to provide you with the service activated and registered for
  • the verification of your identity where required
  • for the prevention and detection of crime, fraud and anti-money laundering
  • for the ongoing administration of the service
  • to allow us to improve the products and services we offer to our customers
  • to ask for your opinion about our products and offer surveys
  • for research and statistical analysis including payment and usage patterns
    • We only use the data in an anonymized manner when we use your data for this purpose.
  • to enable us to comply with our legal and regulatory obligations
  • to offer new products and services to you which are relevant and appropriate, and only to the extent that would be reasonably expected.

If we plan to introduce further processes for the use of your information, we will provide information about that purpose prior to such processing.

The legal basis for processing

Under Data Protection Law, there are various grounds which are considered to be a ‘legal basis for processing’.
The legal basis for processing should be determined by the Data Controller.

Where we are the Data Processor, the legal basis is determined by the Customer. Typically, the legal basis in this scenario is:
‘processing is necessary for the performance of a task carried out in the public interest’
or
‘processing is necessary for the purposes of legitimate interests pursued by the controller’

Where we are the Data Controller, the legal basis for processing is based on:
‘processing is necessary for the purposes of legitimate interests pursued by the controller’

It should be noted that in some circumstances this legal basis may vary, however, we always operate in full compliance with Data Protection Law and will only process data with a fair and reasonable legal basis for doing so.

What personal information we process

In order to carry out these services, we obtain (either from the Customer and/or from you directly) and process the following information:

Data Subject (Who)Data Category (What)DescriptionModule
StudentAchievement recordsAchievement records entered into the Schools MIS.Online Reporting
StudentApp statusIs the pupil using the School Gateway appCore
StudentAssessment reportsAnnual assessment reports generated by the school using their MIS.Online Reporting
StudentAuthentication dataStudents School Gateway PINCore
StudentBehaviour incident recordsBehaviour incidents recorded on the Schools MIS.Online Reporting
StudentClub Attendance RecordsClub attendance which is recorded by school within SchoolcommsClubs
StudentClub balancesSeparate balances for each club the student attendsClubs
StudentClub Session BookingsClub sessions booked by parents or schoolClubs
StudentCurriculum TimetableThis is the pupil's timetable.Online Reporting
StudentDinner BookingsDinner bookings made by parents or school.Dinners
StudentDinner plan balanceDinner plan balance if School uses Schoolcomms Dinners ModuleDinners
StudentExam timetablesThe students exam timetablesOnline Reporting
StudentForenameThis is the forename of the pupil.Core
StudentFree School MealsWhether the pupil is eligible for Free School Meals.Dinners
StudentGenderThis is the pupil's genderCore
StudentGroupsActive groups set up by the school containing the pupil.Messaging
StudentIdentifiersMIS ID, Roll Number and UPNCore
StudentIn-app messagesMessages sent from parents to school within the School Gateway applicationMessaging
StudentKnown asThis is the name that the pupil is known as.Core
StudentLinked PeopleContact's linked to the child that meet import criteria specified by schoolCore
StudentMeal Selections and spend historyThis is a record of the students meal spend, this is imported from the schools cashless retailer, SIMS Dinner money or recorded within Schoolcomms DinnersOnline Reporting
StudentMedical InformationStudent Medical ConditionsOnline Reporting
StudentMessage HistoryEmail or SMS messages sent to the user by the school or vice versaMessaging
StudentMIS GroupsActive groups set up in the schools MIS system containing the pupilMessaging
StudentMobile OSThis is the operating system (iOS or Android) of the mobile phone used to access School Gateway.Core
StudentMobile TelephoneThis is the pupil’s mobile telephone number used to receive alerts from the school and to verify the pupil’s School Gateway account.Core
StudentPaypoint DataData used to issue a Paypoint voucher linking a student and payment itemPayments
StudentPostal AddressThe student's postal addressOnline Reporting
StudentPre-admission StatusStudents Pre-admission statusCore
StudentPrimary email addressThis is the pupil’s primary email address used to receive communications from the school and to verify the pupil’s School Gateway account.Core
StudentPupil Premium Questionnaire ResultsResults of the School Gateway Pupil Premium QuestionnaireCore
StudentRegistration GroupThe registration group of the pupil.Core
StudentSchool Gateway activation dateThis is the date the user activated and first logged into the School Gateway portal.Core
StudentSIMS Dinner Money / Cashless Retailer BalanceThe balance from the schools cashless retailer or SIMS Dinner MoneyPayments
StudentSIMS profile reportThis is a SIMS profile report for the studentOnline Reporting
StudentSurnameThis is the surname of the pupil.Core
StudentUnexplained absence recordsAny unexplained absences recorded by the school for AM or PM registration.Messaging
StudentYear GroupThe year group of the Pupil.Core
ContactAuthentication dataThe contact’s School Gateway PINCore
ContactBank account detailsBank account details are captured and passed to a 3rd party for authorisationPayments
ContactForenameThis is the contact’s forename.Core
ContactBilling AddressBilling address details are captured and shared with payment service providers so that they can complete important security and fraud checks for processing card payments.Payments
ContactHouse NameThe text entered as the contact’s house name.Core
ContactIn-app messagesMessages sent from parents to school within the School Gateway applicationMessaging
ContactLocalityThe text entered as the contact’s locality.Core
ContactMessage HistoryEmail or SMS messages sent to the user by the school or vice versaMessaging
ContactMIS Contact priorityThe priority of contacts connected to a student. (i.e. 1 & 2 may be immediate family whereas 3 & 4 may be distant relatives for emergency contact purposes).Core
ContactMobile OSThis is the operating system (iOS or Android) of the mobile phone used to access School Gateway.Core
ContactMobile TelephoneThis is the contact’s mobile telephone number used to receive alerts from the school and to verify the contacts School Gateway account. Mobile number is shared with payment service providers so that they can complete important security and fraud checks for processing card payments.Core, Payments
ContactParental responsibility statusThis is a marker used by schools to identify if a contact has parental responsibility over a student (allowed to give consent etc. ).Core
ContactPayment card detailsPayment card details are captured and passed to a 3rd party for authorisation.Payments
ContactPayment History and balancesThis is the contact's payment and transaction historyPayments
ContactPostcodeThe text entered as the contact’s post code.Core
ContactPrimary Email addressThis is the contact’s primary email address used to receive communications from the school and to verify the contacts School Gateway account. Email address is shared with payment service providers so that they can complete important security and fraud checks for processing card payments.Core, Payments
ContactPrime Parent StatusIndicates whether a contact is a prime parent or seconday parentCore
ContactSchool Gateway activation dateThis is the date the user activated and first logged into the School Gateway portal.Core
ContactSchool Gateway app statusIdentifies whether a user is logged into the School Gateway mobile application.Core
ContactStreetThe text entered as the contact’s street.Core
ContactSurnameThis is the contact’s surname.Core
ContactTownThe text entered as the contact’s town.Core
Staff MemberAuthentication dataThe staff member’s School Gateway PINCore
Staff MemberBank Account DetailsBank account details are captured and passed to a 3rd party for authorisationPayments
Staff MemberBilling AddressBilling address details are captured and shared with payment service providers so that they can complete important security and fraud checks for processing card payments.Payments
Staff MemberCard DetailsPayment card details are captured and passed to a 3rd party for authorisation.Payments
Staff MemberClub Attendance RecordsClub attendance which is recorded by school within SchoolcommsClubs
Staff MemberClub BalancesSeparate balances for each club the staff member attendsClubs
Staff MemberClub BookingsClub bookings made by staff member or school.Clubs
Staff MemberCurriculum timetableThis is the staff members timetable.Online Reporting
Staff MemberDinner BookingsDinner bookings made by staff member or school.Dinners
Staff MemberDinner Money / Caterer BalanceThe balance from the schools cashless retailer or SIMS Dinner MoneyPayments
Staff MemberDinner Plan BalanceDinner plan balance if School uses Schoolcomms Dinners ModuleDinners
Staff MemberForenameThis is the staff member’s forename.Core
Staff MemberGroupsActive groups set up by the school containing the pupil.Messaging
Staff MemberIn-app messagesMessages sent from parents to school within the School Gateway applicationMessaging
Staff MemberLinked PeopleMIS contacts linked to the staff member who meet the Schoolcomms import critera set by the school.Core
Staff MemberMeal Spend HistoryThis is a record of the staff members meal spend, this is imported from the schools cashless retailer, SIMS Dinner money or recorded within Schoolcomms DinnersPayments
Staff MemberMedical ConditionsStaff Member Medical ConditionsOnline Reporting
Staff MemberMessage HistoryEmail or SMS messages sent to the user by the school or vice versaMessaging
Staff MemberMIS IDStaff members MIS IDCore
Staff MemberMobile OS versionThis is the operating system (iOS or Android) of the mobile phone used to access School Gateway.Core
Staff MemberMobile telephoneThis is the contact’s mobile telephone number used to receive alerts from the school and to verify the contacts School Gateway account. Mobile number is shared with payment service providers so that they can complete important security and fraud checks for processing card payments.Core, Payments
Staff MemberPayment HistoryThe staff members payment historyPayments
Staff MemberPayPoint DataData used to issue a Paypoint voucher linking a staff member and payment itemPayments
Staff MemberPostal AddressThe staff member’s postal addressCore
Staff MemberPostcodeThe staff member’s postal codeCore
Staff MemberPrimary emailThis is the contact’s primary email address used to receive communications from the school and to verify the contacts School Gateway account. Email address is shared with payment service providers so that they can complete important security and fraud checks for processing card payments.Core, Payments
Staff MemberRoleThe staff member’s role at the schoolCore
Staff MemberSchool Gateway activation dateThis is the date the staff member activated and first logged into the School Gateway portal.Core
Staff MemberSchool Gateway app statusIdentifies whether a staff member is logged into the School Gateway mobile application.Core
Staff MemberSurnameThis is the staff member’s surname.Core
Staff MemberTitleThis is the staff member’s title (Mr, Mrs, Ms, etc.).Core
OtherBrowser Type and VersionThe type of Web Browser your device is usingCore
OtherCookiesSpecial records in your browser to help the website operateCore
OtherIP AddressThe network address of your device or internet connectionCore
OtherWeb AnalyticsGeneralised information about browsing behaviour and page statisticsCore

How we process your personal information

We use your personal information, and some of our employees have access to such information, only to the extent required to carry out the services for you and on behalf of the Customer.

We have introduced appropriate technical and organisational measures to protect the confidentiality, integrity and availability of your personal information during storage, processing and transit.

We are a Level 2 PCI-DSS certified organisation and operate an ISO27001 compliant security programme to help protect your data at all times.

The Schoolcomms Products and Services only processes your personal information in the UK.

Some of our supporting services (for example Microsoft CRM), might use cloud platforms that operate from Third Countries outside of the EEA. Where this is the case, we ensure that adequate safeguards are established to protect your data.

Your rights under Data Protection Law

Right to Access

You have the right of access to your personal information that we process and details about that processing.
You can usually access that information directly within the Schoolcomms Products and Services (self-service). However, should this not be possible, you can raise a Data Subject Access Request (DSAR) to receive this information in another format.

Right to Rectification

You have the right to request that information is corrected if it’s inaccurate.  You can usually update your own information using the Schoolcomms Products and Services (self-service). However, should this not be possible, your child’s school will need to correct the data held by them and provided to us for processing.

Right to Erasure (Right to be Forgotten)

You have the right to request that your information is removed; depending on the circumstances, we may or may not be obliged to action this request.

Right to Object

You have the right to object to the processing of your information; depending on the circumstances, we may or may not be obliged to action this request.

Right to Restriction of Processing

You have the right to request that we restrict the extent of our processing activities; depending on the circumstances, we may or may not be obliged to action this request.

Right to Data Portability

You have the right to receive the personal data which you have provided to us in a structured, commonly used and machine readable format suitable for transferring to another controller.

Right to lodge a complaint with a supervisory authority

If you think we have infringed your privacy rights, you can lodge a complaint with the relevant supervisory authority. You can lodge your complaint in particular in the country where your live, your place of work or place where you believe we infringed your right(s).

You can exercise your rights be sending an e-mail to dpo@parentpay.com. Please state clearly in the subject that your request concerns a privacy matter, and provide a clear description of your requirements.

Note: We may need to request additional information to verify your identity before we action your request.

Sharing personal information with third parties

We use a range of trusted service providers to help deliver our services. All of our suppliers are subject to appropriate safeguards, operating in accordance with our specific instructions and limitations, and in full compliance with Data Protection Law.

These service providers include:

  • Payment Processors- to securely process your bank transfer and card payments (we do not see, or store payment card details)
  • SMS Providers – to send out our SMS notifications or messages sent by Customers using Schoolcomms Products and Services
  • Email Providers – to send out our email notifications or messages sent by Customers using Schoolcomms Products and Services
  • Hosting Providers – to manage our secure enterprise datacentres
  • Security Providers – to protect our systems from attack
  • Telephony Providers – we might record calls for training, quality and security purposes
  • Support Portal (ZenDesk) – so that you can easily ask for help
  • Wonde (Data Integrator) – so that schools can safely manage their data
  • Feedback Platforms (Optional) – working with SurveyMonkey
  • Datacentres, networking and disaster recovery – working with CAE
  • Bank Transfer functionality – working with PayGate

We may also have access to your personal information as part of delivering the service.

If we need to change or add additional third parties, we will always update our Privacy Notice accordingly.

We will only disclose your information to other parties in the following limited circumstances

  • where we are legally obliged to do so, e.g. to law enforcement and regulatory authorities
  • where there is a duty to disclose in the public interest
  • where disclosure is necessary to protect our interest e.g. to prevent or detect crime and fraud
  • where you give us permission to do so e.g. by providing consent within the Schoolcomms Products and Services or via an online application or consent form

How long we may keep your personal information

We will only retain information for as long as is necessary to deliver the service safely and securely. We may need to retain some records to maintain compliance with other applicable legislation – for example finance, taxation, fraud and money laundering law requires certain records to be retained for an extended duration, in some cases for up to seven years.

Changes to our Privacy Notice

This policy will be reviewed regularly and updated versions will be posted on our websites.

Contact details for our Data Protection Officer

We have appointed a Data Protection Officer (DPO); their contact details are as follows:

dpo@parentpay.com

or

Data Protection Officer

ParentPay

Coventry Building Society Arena

Phoenix Way

Coventry

CV6 6GE