Privacy Policy
Last updated 23 August 2026 (draft v0.4)
This policy is a draft pending legal review and is not yet QED’s operative Privacy Policy. It has been prepared to be as factually accurate as possible ahead of that review, but it is not legal advice and several items marked below are open questions for our lawyer, not settled positions. It covers the public website, Get Started enquiries, tutor applications, and the parent and tutor dashboards; it does not cover the internal staff admin dashboard or a separate workforce privacy notice for employees and contractors.
1. Who we are
QED Education Group Ltd., a company registered in England and Wales (company number: 10628881), registered office at Gainsborough House, 59–60 Thames Street, Windsor SL4 1TX, UK. We are the data controller for the personal data described in this policy.
Contact for privacy queries: contact@qededucationgroup.com. Whether we are required to appoint a formal Data Protection Officer, and who that should be, is an open question for our legal reviewer to confirm.
We have not yet registered with the Information Commissioner’s Office (ICO) data protection fee register. We intend to confirm and complete that registration as part of legal sign-off.
2. What we collect, and why
- Get Started flow — student date of birth, current school, subjects of interest, parents’ country of residence, contact details, and a timestamped record of the consent choices made when the enquiry was submitted. Used to assess enrolment eligibility and respond to your enquiry.
- Account authentication — name, verified email address, account identifiers, session and security data. Used to provide and secure access to the parent and tutor dashboards.
- Parent dashboard account — your QED identity link, booking history, documents, and plan/hours usage. Used to perform our contract with you.
- Tutor applications — name, email, academic background, teaching experience, subjects and CV. Used to assess suitability for tutoring work and contact applicants about recruitment. Tutor applications are not currently open to the public while we finish work on the recruitment privacy controls.
- Tutor dashboard account — name, contact details, subjects, availability, qualifications, and DBS check outcome (satisfactory/unsatisfactory only). Used to perform our contract with you and meet our safeguarding obligations. This dashboard is still in build and not yet in general use.
- Website and account security — strictly necessary session and security data, and a cookie-preference choice held in your browser’s local storage (not a cookie — see our Cookies Policy). No external product-analytics or marketing service is currently enabled: Vercel Web Analytics and Speed Insights were disabled and their components removed from the site on 21 August 2026.
We only collect what we need for the above. We do not sell personal data.
3. Children’s data
Our tutoring service is aimed at school-age students, and the Get Started flow collects a student’s date of birth as its first step, before anything else. This is personal data of a minor, and roughly three in five enquiries concern a child under 13.
- The implemented enquiry journey creates an account for the adult parent or legal guardian, not for the student, and asks that adult to confirm they are 18 or over and responsible for the enquiry.
- If the student is under 13, we currently rely on that adult’s own declaration that they hold parental responsibility — we do not yet apply any additional verification step. Whether this declaration-only approach is sufficient, or needs stronger verification, is an unresolved question flagged in our internal Data Protection Impact Assessment and is awaiting our lawyer’s decision before we treat it as settled.
- If the student is 13 or older, they may in principle be able to consent in their own right, though in practice it is a parent or guardian who completes the enquiry. The correct legal basis for this age group is also part of the pending legal review.
4. Who we share data with
- Clerk, Inc., our account authentication provider, which processes account identifiers, authentication factors, sessions and security information in the United States on our behalf.
- Vercel, which hosts the website and application and, where enabled, privately stores tutor CV files in Vercel Blob. Application Functions are configured in London (
lhr1), but that setting does not establish the location of every Vercel subsystem, backup, log or subprocessor. - Neon, which hosts the operational Postgres database, confirmed in AWS London (
eu-west-2). - Google, only where an account holder chooses Google sign-in through Clerk.
- No headless CMS or AI runtime is currently connected to this processing.
- We never share data with third parties for their own marketing purposes.
Our authentication provider (Clerk) proves control of an account. QED separately controls the link between that account and a QED person record, and only QED’s own systems determine a person’s role and which records they may access. We do not place educational, family or safeguarding records with our authentication provider.
5. International transfers
Many of our families are based outside the UK and EU, including a significant number in mainland China. Some of our own service providers also process personal data outside the UK — most notably Clerk, our authentication provider, which processes account and authentication data in the United States. We are confirming Clerk’s current UK transfer mechanism, and the applicable contractual safeguards, before treating this as settled.
We do not currently use any China-based service provider for account authentication or hosting, and we have deliberately not enabled a WeChat sign-in option, in part because of the international-transfer question it would raise. If that ever changes, we will update this section and complete the required transfer assessment first.
To be clear: the country you or your child live in does not, by itself, create a transfer issue. What matters is where QED’s own processors and infrastructure are located, which is what this section describes.
6. Retention
- Enquiry data that doesn’t lead to a booking, and contact-form messages: retained for 12 months from submission, then automatically deleted.
- Unsuccessful tutor applications and CVs: retained for 12 months from submission (including the CV file), then automatically deleted, unless the applicant agrees to a longer period.
- DBS check outcomes: the satisfactory/unsatisfactory result is retained only while the tutor is active or under consideration; the certificate itself is never stored. We have reserved a field to hold a specific deletion date for this outcome data, but that period has not yet been set or approved, so it is not yet automatically enforced.
- Account/dashboard data: retained for as long as you have an active account, plus a reasonable period afterwards for legal and accounting purposes.
- Security and access audit records: a retention period for these has not yet been set pending security and legal review.
7. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict or object to processing of, and request a portable copy of your data, and to complain directly to us — we acknowledge complaints within 30 days — or to the Information Commissioner’s Office at ico.org.uk. For a child’s data, a parent or holder of parental responsibility can generally exercise these rights on the child’s behalf. To exercise any of these rights, contact us at contact@qededucationgroup.com; we will coordinate the request across our own systems and our authentication provider, so you do not need to contact each provider separately.
8. Cookies
We use a consent banner that records your choice about non-essential cookies. That choice is currently stored in your browser’s local storage rather than in a cookie. Vercel Web Analytics and Speed Insights are disabled and their components have been removed from the site, and QED’s own custom event hook does not send data to any external analytics provider. See the Cookies Policy for the current technical position.
9. Security
We use reasonable technical and organisational measures to protect your data, including encrypted connections, session controls, access logging, and role-based controls that restrict staff to the data relevant to their work. Signing in alone does not grant access to QED records: the signed-in account must also be linked to an authorised QED identity.
No system is perfectly secure, and we can’t guarantee absolute security of information transmitted over the internet.
10. Changes to this policy
We’ll update this policy as our processing changes and post the revised version here with a new version number and date. Material changes affecting children’s data will be flagged prominently, not just quietly dated.
11. Governing law
This policy is governed by the law of England and Wales.