Data Use
Draft published 11 August 2026 · factually expanded 25 August 2026 · schools section expanded 31 August 2026 · Progress Path Ltd · provisional, awaiting UK solicitor review
What we collect and why
- First name: so we can address you personally in updates.
- Email address: so we can send Founding Family updates and launch news.
- School or agency name and phone number (schools and fostering agencies only): so we can identify and contact your organisation about the founding partner programme. The phone number is optional.
How it is used
Your information is used only to manage your application and keep you updated about Progress Path. We do not use it for advertising, and we do not sell or share it with third parties.
Where it is processed
We use Mailchimp to store sign-up information and send emails. Mailchimp is a widely used, GDPR-compliant email platform. No other third-party tool currently receives your data through this site.
If your school becomes a Founding School partner
This section describes how school access works. The school view is built and in testing. It has not launched publicly, and it remains subject to a solicitor’s confirmation of the legal basis and to a signed agreement with each partner school.
- You choose the level. Feedback only, where the school can send notes but sees no family information, a summary level, where the school sees a parent-approved progress summary and agreed goals, or specific sharing, where you share one particular observation for a stated purpose and period. There is no option to share everything.
- Default access is narrow. A school never sees a photograph. There is no route in Progress Path that shares one. By default a school also does not see faith information, raw emotional reflections, private messages between you and your child, full behaviour observations, home reward details, information shared with another professional, or anything about siblings.
- Sensitive sharing needs more. If something you share could reveal your child’s mental health, disability, SEND, SEMH or religion, we treat it as special category data. Sharing it requires a clear reason, a defined access period, a separate confirmation, and a record of when access was given and removed.
- Ending access. When a school’s access ends, whether you withdraw it or the partnership itself ends, access stops immediately. Your family’s own account and history continue regardless.
- Never the sole basis for a decision. Progress Path information is never the sole basis for a behaviour sanction, a SEND referral, a SEMH assessment, a safeguarding determination, an exclusion, or any other formal decision about your child.
Progress Path and the partnered school are each expected to be responsible for their own decisions about the information they hold, rather than jointly responsible for each other’s. This is a starting position, not a final legal conclusion, and it will be confirmed with a solicitor before any school partnership goes live.
Mailchimp, the platform above, holds only what you type into an application form on this website. For a school or fostering agency that is a work email, name, organisation, organisation type, role, registration number if you give one, postcode and an optional phone number. For a family it is your first name, surname, contact number, email address and, only if you choose to fill that box in, your children’s ages. Nothing else reaches it: no child’s name, no behaviour, SEND, SEMH or faith information, and nothing at all from inside the app.
Schools and agencies: who is responsible for what
Progress Path Ltd (company 17318199, registered in England and Wales) is the data controller for the family’s account: the parent’s details, the child’s records inside the app, and the settings that govern who can see them.
Your school or agency becomes responsible in its own right for anything you view, record or act on, from the moment you view it. That is the part your own policies already cover, and it is why you need your own basis for holding it rather than relying on the parent’s permission to us. We are not asking you to take our word for that. We are telling you so you can put it through your usual process before you say yes.
What the school can see, and what it cannot
Can see: the packs and focus areas a family has chosen, whether the family is actively using the system, progress over time, and a plain summary of the shape of how a child is doing.
Cannot see: free-text reflections, private notes between a parent and child, photographs, anything from a different child, and anything at all once a parent withdraws. A shared Proud Moment shows only its title, its category and its date. The photograph itself is never included.
Progress Path does not diagnose, clinically risk score or rate a child. It calculates the rewards your family has agreed and describes observable patterns from information your family recorded. Those calculations and patterns remain within the family.
Our lawful basis, and yours
Ours, for the family relationship, is the parent’s consent, together with performance of our terms with them. Consent is specific to your organisation, recorded, and withdrawable in one action.
Yours will be your own. Most schools rely on public task for pupil data, but this is a voluntary family programme rather than a statutory education function, so legitimate interests may be the better fit. Your DPO should decide, not us.
Where the school-related data lives
United Kingdom. Our backend runs in the London region (eu-west-2). No routine transfer outside the UK.
Security, stated plainly because a Designated Safeguarding Lead will ask: every table in the system has row-level security enforced at the database, and family isolation, per-child grants, professional and observer scoping, and revoked-adult access have each been proven by automated tests against the hosted environment rather than asserted. We can provide the current evidence pack on request.
Sub-processors: Supabase (hosting and database, UK), Netlify (website hosting), Mailchimp (application forms and sign-up emails only; it holds no information from inside the app and no child’s name), Resend (sending transactional account, invitation and notification emails), Google Fonts (serving the typefaces on this website and the app).
How long we keep school-related data
While the partnership is live, plus a defined period after it ends.
A founding partnership runs for one school term. There is no automatic end date. Access closes when the family administrator ends the partnership or withdraws sharing. Withdrawal closes the view immediately, and we confirm to the administrator when it has closed.
Any family can ask for a copy of their data, or its deletion, by emailing admin@progresspath.uk. We answer within one month.
Your DPIA
You will almost certainly need one. Processing children’s data through a new system, with a form of ongoing visibility, is exactly the case the ICO expects a Data Protection Impact Assessment to cover, and doing one is good practice even where it is not strictly required.
We will give you, on request and before you commit: what is collected and why, the retention position, where it is hosted, the security evidence above, the sub-processor list, and how consent and withdrawal work. That is most of the input side of your assessment. The risk judgement and the sign-off remain yours.
The school view is built and in testing. Founding partners will be the first to use it and help shape it before it opens more widely. Progress Path is not a clinical intervention and not a safeguarding tool. It creates no safeguarding route and never acts as an intermediary. Your existing procedures are unchanged.
How long we keep it
We keep your information for as long as you remain subscribed. You can unsubscribe at any time using the link in any email we send, or by emailing us directly.
Your choices
You can ask to see the information we hold about you, ask us to correct it, or ask us to delete it, at any time, by emailing admin@progresspath.uk.
Inside the app: the actual data flow (staging testing)
The sections above describe this website. The staging app's data flow is as follows. Every category is created by your family, is private to your family, and is held with the providers listed on the Privacy Policy (database and files in London; invitation email through Ireland).
| What | Why | Who can access it | Kept for |
|---|---|---|---|
| Adult account (email, password) | Sign-in and account security | You; our systems for authentication | Until the family is deleted |
| Family record (setup answers, routines, observations, reflections, rewards) | Running your family's Progress Path | Your family's signed-in adults, within their permissions | Until you change or delete it, or the family is deleted |
| Child profiles (name, age, date of birth, education setting) | Age-appropriate wording and rhythms | Your family's adults; the child's own device sees only its own view | Until deleted |
| Photographs and documents (Proud Moments, up to 4 MB) | Keepsakes your family chooses to save | Your family's adults; the child's own device for that child's items | Until removed or the family is deleted (media is deleted first) |
| Voice notes (up to 120 seconds, 3 MB) | Little messages between grown-up and child | Same as photographs | Same as photographs |
| Faith and reflection preferences | Only to shape wording, if you chose it | Your family's adults; never shown to a school | Until changed or deleted |
| Invitation records (invitee email, role, permissions) | Bringing in a trusted adult safely | The family's admin; the invitee receives the email | Links expire after 7 days; records until the family is deleted |
| Audit trail (who did what, no child content) | Account security and accountability | Our systems; not a family-facing feature | 365 days, then deleted automatically |
| Operational metrics (content-free events, hashed family id) | Understanding whether the product works | Our systems only | 90 days, then deleted automatically |
How access ends
You can revoke an invited adult at any time, and their access stops. You can cancel every child device code at any time, and those devices stop immediately; codes are also time-limited and checked by the server on every request. Invitation links are single use and expire after 7 days.
Exports and deletion
From Settings you can download your family's record as a file, and you can permanently delete the whole family with a typed confirmation; photographs and voice notes are deleted first, then the records. You can also permanently delete one child's profile and media from Settings, with a typed confirmation naming that child; the child's photographs and voice notes are deleted first, that child's device codes stop immediately, and the rest of the family is untouched. Only a content-free security record is kept, on the 365-day schedule above. If you would rather we do it for you, email admin@progresspath.uk. Audit and metric records delete themselves on the schedules above.
Schools: the standing principles
The school sharing model above has not launched, and the app contains no school access today. When it exists, two principles already hold by design: a school receives only the limited information a parent specifically chooses to share, for the purpose and period the parent set, and a school never receives blanket access to the family account. Whether Progress Path and a partner school act as separate controllers, joint controllers, or in a controller-processor relationship is not legally settled: it is a design intention that remains, together with the required written agreement, awaiting UK solicitor review.
← Back to Progress Path