ParentPay Group Privacy Notice
Learn how ParentPay Group collects, uses, and protects your personal data in accordance with UK data protection laws.


Privacy Notice
This notice explains how the ParentPay Group uses personal information.
Who we are
The ParentPay group of companies comprises ParentPay (Holdings) Limited and all of its subsidiaries (“ParentPay Group”, “the Group” or “we”).
The Group’s UK operations are conducted through four UK companies, which between them operate all of the Group’s UK products and brands. These companies are ParentPay Group Services Limited, ParentPay Limited, Education Software Solutions Limited and GDPR in Schools Limited.
The Group operates in Germany through ParentPay Deutschland GmbH and its subsidiaries.
The Group operates in the Netherlands through Egengroup Holdings BV and its subsidiaries.
The Group operates development and support hubs in India and Sri Lanka through ParentPay India Private Limited and ParentPay Lanka (Pvt) Ltd respectively.
Please note that this notice deals primarily with the use of personal information in the ParentPay Group’s UK operations. The websites of the German and Netherlands subsidiaries cover the use of personal information within those businesses.
This privacy notice covers:
- Why we use your personal information
- The legal basis for processing
- What personal information we use
- How we use your personal information
- Your rights under data protection legislation
- Sharing personal information with third parties
- How long we may keep your information
- Changes to our privacy notice
- Contact details for our Data Protection Officer
Why we use your personal information
The Group is primarily engaged in the design, development, sales, marketing, supply, operation and maintenance of a software solutions for schools and other educational establishments, including (without limitation) management information systems, financial management systems, payment collection, payment processing, meal management and kitchen management, parent communication and engagement, library and resource management and services related to the provision of these solutions (the “Group Products and Services”).
The Group Products and Services are provided to schools and their parents/guardians pursuant to a contract between us and the schools, Single- or Multi-Academy Trust, Local Education Authority, or catering services provider (“Customers”). Where our Products and Services are used or accessed by parents/guardians (“Users”) directly, they are also governed by terms and conditions that the User agrees to when they sign up.
We process personal data for the following purposes:
- to provide with the Group Products and Services contracted for
- the verification of Customer or User identity where required
- for the prevention and detection of crime, fraud and anti-money laundering
- for the ongoing administration of the Group Products and Services
- to allow us to improve the Group Products and Services
- to ask for opinions and feedback about the Group Products and Services offer surveys
- for research and statistical analysis including payment and usage patterns—We only use the data in an anonymised manner when we use personal data for this purpose.
- to enable us to comply with our legal and regulatory obligations
- to offer new Group Products and Services which are relevant and appropriate, and only to the extent that would be reasonably expected.
If we plan to introduce further processes for the use of your information, we will provide information about that purpose prior to such processing.
The legal basis for processing
Under Data Protection Law, there are various grounds which are considered to be a ‘legal basis for processing’.
The legal basis for processing varies depending on which of the Group Products and Services is being used, and in each case is determined by the Data Controller.
Where the Group acts as Data Processor in providing a particular Group Product or Service, the legal basis is determined by the Customer. Typically, the legal basis in this scenario is:
‘processing is necessary for the performance of a task carried out in the public interest’
and/or
‘processing is necessary for the purposes of legitimate interests pursued by the controller’
Where the Group acts as Data Controller in providing a particular Group Product or Service, the legal basis for processing is based on:
‘processing is necessary for the purposes of legitimate interests pursued by the controller’
Whilst the legal basis does vary depending on the Group Product or Service provided and the circumstances in which they are used, we always operate in full compliance with Data Protection Law and will only process data with a fair and reasonable legal basis for doing so.
What personal information we process
In order to provide the Group Products and Services, the Group may be required to obtain and use (either from the Customer or the User directly) and process various categories of personal information. The exact category of personal data collected and used will vary depending on the Group Product or Service provided and the circumstances in which they are used.
In respect of Group Products and Services provided by Education Software Solutions Limited including (without limitation) school management information systems, finance management systems, library management systems and solutions for further and higher education establishments), the Group acts as Data Processor and the Customer as Data Controller. Accordingly, details of the personal data processed by the Group in these circumstances is provided to the data subjects by the Customer (as Data Controller).
In respect of Group Products and Services provided by ParentPay Limited including (without limitation) payment collection, payment processing, meal management and kitchen management, parent communication and engagement, the Group may act either as Data Processor or Data Controller, depending on the specific Group Product or Service and the circumstance of its use.
The table below sets out the personal data categories relevant to each of the Group Products and Services provided through ParentPay Limited, where the Group may act as Data Controller:
| Data Subject (Who) | Data Category (What) | Description | Product or Service |
|---|---|---|---|
| Student | Forename | This is the forename of the pupil. | ParentPay |
| Student | Surname | This is the surname of the pupil. | ParentPay |
| Student | Known as | This is the name that the pupil is known as. | ParentPay |
| Student | DOB | This is the date of birth of the pupil. | ParentPay |
| Student | Gender | This is the pupil's gender. | ParentPay |
| Student | Year Group | The year the pupil is in. | ParentPay |
| Student | Registration Class | The name of the pupil’s registration class (if any). | ParentPay |
| Student | Salutation | This is the pupil’s salutation. | ParentPay |
| Student | Dietary Requirements | This is the pupil’s special dietary requirements. | ParentPay |
| Student | Postal Address | The student's postal address. | ParentPay |
| Student | Meal Selections and spend history | This is a history of a pupil's meal selections and spends for school meals or non-meal-related items. | ParentPay |
| Parent / Contact | Title | This is the contact’s title (Mr, Mrs, Ms, etc). | ParentPay |
| Parent / Contact | Forename | This is the contact’s forename. | ParentPay |
| Parent / Contact | Surname | This is the contact’s surname. | ParentPay |
| Parent / Contact | Authentication data | Username and password or other authentication tokens. | ParentPay |
| Parent / Contact | Gender | The contact’s gender. | ParentPay |
| Parent / Contact | House Name | The text entered as the contact’s house name. | ParentPay |
| Parent / Contact | Street | The text entered as the contact’s street. | ParentPay |
| Parent / Contact | Locality | The text entered as the contact’s locality. | ParentPay |
| Parent / Contact | Town | The text entered as the contact’s town. | ParentPay |
| Parent / Contact | Postcode | The text entered as the contact’s post code. | ParentPay |
| Parent / Contact | Day Telephone | The contact’s daytime telephone number. | ParentPay |
| Parent / Contact | Home Telephone | The contact’s home telephone number. | ParentPay |
| Parent / Contact | Mobile Telephone | This is the contact’s mobile telephone number. | ParentPay |
| Parent / Contact | This is the contact’s E-mail address. | ParentPay | |
| Parent / Contact | Payment card details | Payment details are forwarded to a 3rd party payment processor. | ParentPay |
| Parent / Contact | Other | This is the contact’s alternative communication method. | ParentPay |
| Parent / Contact | In-app messages | Messages sent from parents to school within the application. | ParentPay |
| Parent / Contact | Trouble ticket data | When users submit trouble ticket information, this gets stored. | ParentPay |
| Parent / Contact | Payment History and balances | This is the contact’s history of payment transactions, including reversals, refunds and withdrawals of funds. | ParentPay |
| Parent / Contact | Shop information | ParentPay can be used as a payment page from externally or internally hosted shop systems. This the information captured as part of that ("shopping basket"). | ParentPay |
| School Staff | Title | This is the staff member’s title (Mr, Mrs, Ms, etc.). | ParentPay |
| School Staff | Forename | This is the staff member’s forename. | ParentPay |
| School Staff | Surname | This is the staff member’s surname. | ParentPay |
| School Staff | Gender | The staff member’s gender. | ParentPay |
| Website Access | IP Address | The network address of your device or internet connection. | ParentPay |
| Website Access | Browser Type and Version | The type of Web Browser your device is using. | ParentPay |
| Website Access | Cookies | Special records in your browser to help the website operate. | ParentPay |
| Website Access | Web Analytics | Generalised information about browsing behaviour and page statistics. | ParentPay |
| Data Subject (Who) | Data Category (What) | Description | Schoolcomms |
|---|---|---|---|
| Student | Achievement records | Achievement records entered into the Schools MIS. | Reporting |
| Student | App status | Is the pupil using the School Gateway app. | Core |
| Student | Assessment reports | Annual assessment reports generated by the school using their MIS. | Reporting |
| Student | Authentication data | Students School Gateway PIN. | Core |
| Student | Bank account details | Bank account details are captured and passed to a 3rd party for authorisation. | Payments |
| Student | Behaviour incident records | Behaviour incidents recorded on the Schools MIS. | Reporting |
| Student | Club Attendance Records | Club attendance which is recorded by school within Schoolcomms. | Clubs |
| Student | Club balances | Separate balances for each club the student attends. | Clubs |
| Student | Club Session Bookings | Club sessions booked by parents or school. | Clubs |
| Student | Curriculum Timetable | This is the pupil's timetable. | Reporting |
| Student | Dinner Bookings | Dinner bookings made by parents or school. | Dinners |
| Student | Dinner plan balance | Dinner plan balance if School uses Schoolcomms Dinners Module. | Dinners |
| Student | Exam timetables | The student’s exam timetables. | Reporting |
| Student | Forename | This is the forename of the pupil. | Core |
| Student | Free School Meals | Whether the pupil is eligible for Free School Meals. | Dinners |
| Student | Gender | This is the pupil's gender. | Core |
| Student | Groups | Active groups set up by the school containing the pupil. | Messaging |
| Student | Identifiers | MIS ID, Roll Number and UPN. | Core |
| Student | In-app messages | Messages sent from parents to school within the School Gateway application. | Messaging |
| Student | Known as | This is the name that the pupil is known as. | Core |
| Student | Linked People | Contacts linked to the child that meet import criteria specified by school. | Core |
| Student | Meal Selections & spend history | Record of student’s meal spend, imported from the cashless retailer, SIMS Dinner money or recorded within Schoolcomms. | Reporting |
| Student | Medical Information | Student Medical Conditions. | Reporting |
| Student | Message History | Email or SMS messages sent to the user by the school or vice versa. | Messaging |
| Student | MIS Groups | Active groups set up in the schools MIS system containing the pupil. | Messaging |
| Student | Mobile OS | This is the operating system (iOS or Android) of the mobile phone used to access School Gateway. | Core |
| Student | Mobile Telephone | Pupil’s mobile phone number used to receive alerts from the school and to verify the pupil’s School Gateway account. | Core |
| Student | Payment card details | Payment card details are captured and passed to a 3rd party for authorisation. | Payments |
| Student | Payment History | Student payment and transaction history. | Payments |
| Student | Paypoint Data | Data used to issue a PayPoint voucher linking a student and payment item. | Payments |
| Student | Postal Address | The student's postal address. | Reporting |
| Student | Pre-admission Status | Students Pre-admission status. | Core |
| Student | Primary email address | Pupil’s email address used to receive communications from the school and to verify the pupil’s School Gateway account. | Core |
| Student | Pupil Premium Questionnaire Results | Results of the School Gateway Pupil Premium Questionnaire. | Core |
| Student | Registration Group | The registration group of the pupil. | Core |
| Student | School Gateway activation date | This is the date the user activated and first logged into the School Gateway portal. | Core |
| Student | Dinner Money Balance | The balance from the school’s cashless retailer or SIMS Dinner Money. | Payments |
| Student | SIMS profile report | This is a SIMS profile report for the student. | Reporting |
| Student | Surname | This is the surname of the pupil. | Core |
| Student | Unexplained absence records | Any unexplained absences recorded by the school for AM or PM registration. | Messaging |
| Student | Year Group | The year group of the Pupil. | Core |
| Parent / Contact | Authentication data | The contact’s School Gateway PIN. | Core |
| Parent / Contact | Bank account details | Bank account details are captured and passed to a 3rd party for authorisation. | Payments |
| Parent / Contact | Forename | This is the contact’s forename. | Core |
| Parent / Contact | House Name | The text entered as the contact’s house name. | Core |
| Parent / Contact | In-app messages | Messages sent from parents to school within the School Gateway application. | Messaging |
| Parent / Contact | Locality | The text entered as the contact’s locality. | Core |
| Parent / Contact | Message History | Email or SMS messages sent to the user by the school or vice versa. | Messaging |
| Parent / Contact | Mobile OS | This is the operating system (iOS or Android) of the mobile phone used to access School Gateway. | Core |
| Parent / Contact | Mobile Telephone | This is the contact’s mobile phone number used to receive alerts from the school and to verify the School Gateway account. | Core |
| Parent / Contact | Parental responsibility status | This marker is used by schools to identify if a contact has parental responsibility over a student (allowed to give consent etc ). | Core |
| Parent / Contact | Payment card details | Payment card details are captured and passed to a 3rd party for authorisation. | Payments |
| Parent / Contact | Payment History and balances | This is the contact's payment and transaction history. | Payments |
| Parent / Contact | Postcode | The text entered as the contact’s post code. | Core |
| Parent / Contact | Primary Email address | Contact’s email address used to receive communications from the school and to verify the contacts School Gateway account. | Core |
| Parent / Contact | Prime Parent Status | Indicates whether a contact is a prime parent or secondary parent. | Core |
| Parent / Contact | School Gateway activation date | This is the date the user activated and first logged into the School Gateway portal. | Core |
| Parent / Contact | School Gateway app status | Identifies whether a user is logged into the School Gateway mobile application. | Core |
| Parent / Contact | Street | The text entered as the contact’s street. | Core |
| Parent / Contact | Surname | This is the contact’s surname. | Core |
| Parent / Contact | Town | The text entered as the contact’s town. | Core |
| Parent / Contact | MIS Contact priority | The priority of contacts connected to a student. (i.e. 1 & 2 may be immediate family whereas 3 & 4 may be distant relatives for emergency contact purposes). | Core |
| School Staff | Authentication data | The staff member’s School Gateway PIN. | Core |
| School Staff | Bank Account Details | Bank account details are captured and passed to a 3rd party for authorisation. | Payments |
| School Staff | Card Details | Payment card details are captured and passed to a 3rd party for authorisation. | Payments |
| School Staff | Club Attendance Records | Club attendance which is recorded by school within Schoolcomms. | Clubs |
| School Staff | Club Balances | Separate balances for each club the staff member attends. | Clubs |
| School Staff | Club Bookings | Club bookings made by staff member or school. | Clubs |
| School Staff | Curriculum timetable | This is the staff member's timetable. | Reporting |
| School Staff | Dinner Bookings | Dinner bookings made by staff member or school. | Dinners |
| School Staff | Dinner Money / Caterer Balance | The balance from the school’s cashless retailer or SIMS Dinner Money. | Payments |
| School Staff | Dinner Plan Balance | Dinner plan balance if School uses Schoolcomms Dinners Module. | Dinners |
| School Staff | Forename | This is the staff member’s forename. | Core |
| School Staff | Groups | Active groups set up by the school containing the pupil. | Messaging |
| School Staff | In-app messages | Messages sent from parents to school within the School Gateway application. | Messaging |
| School Staff | Linked People | MIS contacts linked to the staff member who meet the Schoolcomms import criteria set by the school. | Core |
| School Staff | Meal Spend History | Record of the meal spend, imported from the schools cashless retailer, SIMS Dinner money or recorded within Schoolcomms. | Payments |
| School Staff | Medical Conditions | Staff Member Medical Conditions. | Reporting |
| School Staff | Message History | Email or SMS messages sent to the user by the school or vice versa. | Messaging |
| School Staff | MIS ID | Staff members MIS ID | Core |
| School Staff | Mobile OS version | This is the operating system (iOS or Android) of the mobile phone used to access School Gateway. | Core |
| School Staff | Mobile telephone | The staff member’s mobile telephone number. | Core |
| School Staff | Payment History | The staff members payment history. | Payments |
| School Staff | PayPoint Data | Data used to issue a PayPoint voucher linking a staff member and payment item. | Payments |
| School Staff | Postal Address | The staff member’s postal address. | Core |
| School Staff | Postcode | The staff member’s postal code. | Core |
| School Staff | Primary email | The staff member’s primary email address. | Core |
| School Staff | Role | The staff member’s role at the school. | Core |
| School Staff | School Gateway activation date | This is the date the staff member activated and first logged into the School Gateway portal. | Core |
| School Staff | School Gateway app status | Identifies whether a staff member is logged into the School Gateway mobile application. | Core |
| School Staff | Surname | This is the staff member’s surname. | Core |
| School Staff | Title | This is the staff member’s title (Mr, Mrs, Ms, etc.). | Core |
| Website Access | Browser Type and Version | The type of Web Browser your device is using. | Core |
| Website Access | Cookies | Special records in your browser to help the website operate. | Core |
| Website Access | IP Address | The network address of your device or internet connection. | Core |
| Website Access | Web Analytics | Generalised information about browsing behaviour and page statistics. | Core |
| Data Subject (Who) | Data Category (What) | Description | Product or Service |
|---|---|---|---|
| Student | Forename | This is the forename of the pupil. | Cypad |
| Student | Surname | This is the surname of the pupil. | Cypad |
| Student | DOB | This is the date of birth of the pupil. | Cypad |
| Student | Year | The year the pupil is in. | Cypad |
| Student | Class | The name of the pupil’s registration class. | Cypad |
| Student | Site | The site that the pupil attends. | Cypad |
| Student | Meal Selections and spend history | This is a history of a pupil's meal selections and spends for school meals or non-meal-related items. | Cypad |
| Student | Diet Types | This is the pupil’s special dietary requirements. | Cypad |
| Student | Allergens | This is what the pupil is allergic to. | Cypad |
| Student | Meals consumed | For parents to view meals taken. | Cypad |
| Parent / Contact | Parent Name | This is the parents’ full name. | Cypad |
| Parent / Contact | Username | Username for authentication. | Cypad |
| Parent / Contact | This is the parents’ email address. | Cypad | |
| Parent / Contact | Address1 | The first line of the address. | Cypad |
| Parent / Contact | Address2 | The second line of the address. | Cypad |
| Parent / Contact | City | The city / town entered as the parents’ city. | Cypad |
| Parent / Contact | Postcode | The text entered as the parents’ post code. | Cypad |
| Parent / Contact | Home Telephone | The parents’ home telephone number. | Cypad |
| Parent / Contact | Mobile Telephone | This is the parents’ mobile telephone number. | Cypad |
| Parent / Contact | Pupils associated with the adult | The pupil(s) who relate(s) to the parent. | Cypad |
| Parent / Contact | Meal Selections and transaction history | This is the parents’ history of payment transactions, including reversals, refunds and withdrawals of funds. | Cypad |
| Catering Staff | Name | This is the staff member’s full name. | Cypad |
| Catering Staff | Address | The staff member’s address. | Cypad |
| Catering Staff | Phone Number | The staff member’s contact number. | Cypad |
| Catering Staff | The staff member’s contact email. | Cypad | |
| Catering Staff | Payroll Number | The staff member’s payroll number. | Cypad |
| Catering Staff | Employee Number | The staff member’s employee number. | Cypad |
| Catering Staff | Timesheet Number | The staff member’s timesheet number. | Cypad |
| Catering Staff | Workbook Number | The staff member’s workbook number. | Cypad |
| Catering Staff | Position | The staff member’s level of authority. | Cypad |
| Catering Staff | Qualifications | The staff member’s qualifications. | Cypad |
| Catering Staff | DOB | The staff member’s date of birth. | Cypad |
| Catering Staff | NI Number | The staff member’s National Insurance number. | Cypad |
| Catering Staff | DBS Number & Expiry Date | The staff member’s DBS clearance information. | Cypad |
| Catering Staff | Rate of Pay | How much the staff member is earning. | Cypad |
| Catering Staff | Contract hours | The staff member’s contract hours. | Cypad |
| Catering Staff | Employment start & end date | When the staff member’s employment started and finished. | Cypad |
| Catering Staff | Emergency contact name | The staff member’s emergency contact. | Cypad |
| Catering Staff | Emergency contact relationship | How the emergency contact relates to the staff member. | Cypad |
| Catering Staff | Emergency contact phone number | The contact number of the emergency contact. | Cypad |
| Website Access | IP Address | The network address of your device or internet connection. | Cypad |
| Website Access | Browser Type and Version | The type of Web Browser your device is using. | Cypad |
| Website Access | Cookies | Special records in your browser to help the website operate. | Cypad |
| Website Access | Web Analytics | Generalised information about browsing behaviour and page statistics. | Cypad |
| Data Subject (Who) | Data Category (What) | Description | Product or Service |
|---|---|---|---|
| Student | Forename | This is the forename of the pupil. | BlueRunner Solutions |
| Student | Surname | This is the surname of the pupil. | BlueRunner Solutions |
| Student | DOB | This is the date of birth of the pupil. | BlueRunner Solutions |
| Student | Year | The year the pupil is in. | BlueRunner Solutions |
| Student | Class | The name of the pupil’s registration class. | BlueRunner Solutions |
| Student | Site | The site that the pupil attends. | BlueRunner Solutions |
| Student | Meal Selections and spend history | This is a history of a pupil’s meal selections and spends for school meals or non-meal-related items. | BlueRunner Solutions |
| Student | Diet Types | This is the pupils special dietary requirements. | BlueRunner Solutions |
| Student | Allergens | This is what the pupil is allergic to. | BlueRunner Solutions |
| Student | Meals consumed | For parents to view meals taken. | BlueRunner Solutions |
| Student | Biometric data (fingerprint) | Students’ fingerprints are used to verify their identities for the purposes of using the BRS cashless payment system. | BlueRunner Solutions |
| Catering Staff | Name | This is the staff member’s full name. | BlueRunner Solutions |
| Catering Staff | Address | The staff member’s address. | BlueRunner Solutions |
| Catering Staff | Phone Number | The staff member’s contact number. | BlueRunner Solutions |
| Catering Staff | The staff member’s contact email. | BlueRunner Solutions | |
| Catering Staff | Payroll Number | The staff member’s payroll number. | BlueRunner Solutions |
| Catering Staff | Employee Number | The staff member’s employee number. | BlueRunner Solutions |
| Catering Staff | Timesheet Number | The staff member’s timesheet number. | BlueRunner Solutions |
| Catering Staff | Workbook Number | The staff member’s workbook number. | BlueRunner Solutions |
| Catering Staff | Position | The staff member’s level of authority. | BlueRunner Solutions |
| Catering Staff | Qualifications | The staff member’s qualifications. | BlueRunner Solutions |
| Catering Staff | DOB | The staff member’s date of birth. | BlueRunner Solutions |
| Catering Staff | NI Number | The staff member’s National Insurance number. | BlueRunner Solutions |
| Catering Staff | DBS Number & Expiry Date | The staff member’s DBS clearance information. | BlueRunner Solutions |
| Catering Staff | Rate of Pay | How much the staff member is earning. | BlueRunner Solutions |
| Catering Staff | Contract hours | The staff member’s contract hours. | BlueRunner Solutions |
| Catering Staff | Employment start & end date | When the staff member’s employment started and finished. | BlueRunner Solutions |
| Catering Staff | Emergency contact name | The staff member’s emergency contact. | BlueRunner Solutions |
| Catering Staff | Emergency contact relationship | How the emergency contact relates to the staff member. | BlueRunner Solutions |
| Catering Staff | Emergency contact phone number | The contact number of the emergency contact. | BlueRunner Solutions |
| Various | Support ticket data | When users submit support services tickets information, this gets stored. Depending on the nature of the issue being reported, this may contain various categories of personal data. | BlueRunner Solutions |
| Website Access | IP Address | The network address of your device or internet connection. | BlueRunner Solutions |
| Website Access | Browser Type and Version | The type of Web Browser your device is using. | BlueRunner Solutions |
| Website Access | Cookies | Special records in your browser to help the website operate. | BlueRunner Solutions |
| Website Access | Web Analytics | Generalised information about browsing behaviour and page statistics. | BlueRunner Solutions |
In all cases, we may collect personal information (such as names, addresses, email addresses or telephone numbers) in a number of ways, including when a Customer provides us information about its staff members, where a parent/guardian registers to become a User or when any individual signs up to our newsletters, completes a website form or makes a sales or support enquiry.
We may also collect and store information about how people interact with and use our websites and Customer and User portals, for example the pages viewed, time spent on each page etc. in order to be able to take steps to improve the digital experience. These behaviours including IP addresses are captured within Google Analytics, Power BI and other similar tools. You can read more in our website cookie policy.
How we process your personal information
We use personal information, and some of our employees have access to such information, only to the extent required to provide the Group Products and Services.
We have introduced appropriate technical and organisational measures to protect the confidentiality, integrity and availability of your personal information during storage, processing and transit.
The Group is a Level 1 PCI-DSS certified organisation and are subject to regular and comprehensive security audits. We operate an ISO27001 compliant security programme to help protect personal data at all times.
Some of our support services may involve the use of partners or platforms that operate from Third Countries outside of the EEA. Where this is the case, we ensure that adequate safeguards are established to protect your data.
Your rights under Data Protection Law
You have the following rights if we process your personal data in the course of providing the Group Products and Services.
Right to Access
You have the right of access to your personal information that we process and details about that processing.
You can usually access that information directly within the Group Products and Services. However, should this not be possible, you can raise a Data Subject Access Request (DSAR) to receive this information in another format.
Right to Rectification
You have the right to request that information is corrected if it’s inaccurate. You can usually update your own information using the Group Products and Services (self-service). However, should this not be possible, you can contact us to make the changes on your behalf. In some circumstances, you may have to contact your child’s school, to correct the data held by them and provided to us for processing.
Right to Erasure (Right to be Forgotten)
You have the right to request that your information is removed; depending on the circumstances, we may or may not be obliged to action this request.
Right to Object
You have the right to object to the processing of your information; depending on the circumstances, we may or may not be obliged to action this request.
Right to Restriction of Processing
You have the right to request that we restrict the extent of our processing activities; depending on the circumstances, we may or may not be obliged to action this request.
Right to Data Portability
You have the right to receive the personal data which you have provided to us in a structured, commonly used and machine readable format suitable for transferring to another controller.
Right to lodge a complaint with a supervisory authority
If you think we have infringed your privacy rights, you can lodge a complaint with the relevant supervisory authority. You can lodge your complaint in particular in the country where your live, your place of work or place where you believe we infringed your right(s).
You can exercise your rights be sending an e-mail to dpo@parentpay.com. Please state clearly in the subject that your request concerns a privacy matter, and provide a clear description of your requirements.
Note: We may need to request additional information to verify your identity before we action your request.
Sharing personal information with third parties
We use a range of trusted service providers to help deliver our services. All of our suppliers are subject to appropriate safeguards, operating in accordance with our specific instructions and limitations, and in full compliance with Data Protection law.
These service providers include:
- Hosting providers – to manage our secure enterprise datacentres (6Degrees, AWS, and Microsoft Azure).
- Security providers – to protect our systems from attack (CloudFlare, Imperva, Akamai, and Microsoft).
- Support portals – so users and customers can easily get help (ServiceNow and ZenDesk).
- Email providers – to send out our email notifications or messages sent by Customers using ParentPay Products and Services (Microsoft and FlowMailer).
- Telephony providers – we may record calls for training, quality and security purposes (C-talk, Ring Central and 8×8).
- Training platforms – to train school staff on the use of our services (Learnupon).
- Payment processors (where applicable) – to securely process payments.
- Bank transfer functionality (where applicable) – working with Corvid and Experian.
- SMS providers – to deliver notifications or messages sent by Customers using ParentPay Products and Services.
- Security insight and system logging – working with Rapid7.
- Anonymous web analytics – working with Google.
- Feedback platforms (optional) – working with SurveyMonkey.
- Customer relationship management platforms – working with HubSpot, Microsoft Dynamics, Click Dimensions, and ServiceNow.
- Datacentres, networking and disaster recovery – working with CAE.
- Cloud email delivery – working with Sendgrid (USA hosted)
If we need to change or add additional third parties, we will always update this notice accordingly. We will only disclose your information to other parties in the following limited circumstances
- where we are legally obliged to do so, e.g. to law enforcement and regulatory authorities
- where there is a duty to disclose in the public interest
- where disclosure is necessary to protect our interest e.g. to prevent or detect crime and fraud
- where you give us permission to do so e.g. by providing consent within the Group Products and Services or via an online application or consent form
How long we may keep your personal information
We will only retain information for as long as is necessary to deliver the service safely and securely. We may need to retain some records to maintain compliance with other applicable legislation – for example finance, taxation, fraud and money laundering law requires certain records to be retained for an extended duration, in some cases for up to seven years.
Customer pupil data will typically be removed or anonymised when the following rules are met:
- The pupil has been archived by the Customer for longer than one month.
- The pupil does not have any meal consumption or attendance data within the last 13 months.
- The pupil has not received a payment for any payment item within the last 13 months.
- The pupil balance is zero.
User data will usually be removed or anonymised when the following rules are met:
- They have not logged in for 13 months.
- They have not topped up or spent within the last 13 months.
- User balance is 0 (zero), and all pupil balances are 0 (zero).
- There are no active pupils associated with the account
Customer manager accounts that have been disabled and have not logged in for 13 months, will be removed or anonymised. Other school staff accounts are subject to the same rules as pupils (above).
Message attachments will be removed after 24 months.
File area uploads will be purged after 24 months.
Personal information in trip records will be removed 1 month after trip completion.
It should be noted that Customers will still retain a complete finance audit trail for their statutory requirements. In unusual cases where specific personal information needs to be retained, then this can be facilitated upon request.
Changes to our Privacy Notice
This notice will be reviewed regularly and updated versions will be posted on the Group’s websites.
Contact details for our Data Protection Officer
We have appointed a Data Protection Officer (DPO); their contact details are as follows:
or
Data Protection Officer
ParentPay
Coventry Building Society Arena
Phoenix Way
Coventry
CV6 6GE
