Privacy Policy — physmat.org
This Privacy Policy explains what personal data we collect when you and your child use physmat.org, why we use it, who we share it with, and the rights you and your child have. It is written to be read alongside our Children's Privacy Notice (a shorter, child-readable version), our Cookie & On-device Storage Policy, our AI Tutor Notice, and our Terms of Service.
This service is offered in the United Kingdom. It is not offered in the United States at this time, and we do not target US users.
1. Who we are
The data controller for physmat.org (the "platform", "we", "us") is to be confirmed, a company registered in England and Wales (company number to be confirmed), registered office to be confirmed.
- General/privacy contact: mail@physmat.org
- Data Protection Officer: to be confirmed, contact mail@physmat.org
- ICO registration number: to be confirmed
Our role — controller or processor
- Where a parent or an adult signs up directly (the consumer flow), we are the controller of the personal data involved.
- Where a school enrols its pupils (the school flow), the school is the controller and we act as the school's processor, handling pupil data only on the school's documented instructions under a written Data Processing Agreement. See our School Data Processing Agreement.
2. Who this policy covers
- Children / students who practise on the platform.
- Parents / guardians who create or manage a child's account and (optionally) pay for features.
- Teachers and schools who enrol and support pupils.
Children's data receives heightened protection in line with the ICO's Age Appropriate Design Code (Children's Code).
3. What personal data we collect
We collect only what we need to run the platform. (Card details are never collected or stored by us — see §6.)
| Data | Who | Why |
|---|---|---|
| Email, display name | student, parent, teacher | account creation, login, communication |
| Date of birth / year group | student | age-appropriate content; age assurance |
| Parent email | student | linking a child to a parent/guardian |
| School association | student, teacher | school-flow enrolment and class management |
| Role and consent record | all | how the account was created and on what basis |
| Answers and practice activity | student | grading, progress, the core learning service |
| AI-tutor messages | student (tutor users only) | running the optional AI tutor (see §5) |
| Subscription / payment references | parent or school payer | managing paid access (Stripe identifiers only) |
| Technical/security logs | all | security, abuse-prevention, service operation |
We do not use third-party advertising or analytics trackers, and we do not run tracking cookies or pixels (see the Cookie & On-device Storage Policy).
4. Why we use it, and our lawful basis
We use personal data for the purposes below. The lawful basis for each is being finalised with our DPO/solicitor and will be stated definitively here.
- Running the core service (accounts, the problem bank, grading, progress) — intended basis: performance of a contract /, with a child-competence-to-contract assessment for child accounts.
- The optional AI tutor (see §5) — a separate, opt-in paid feature with its own basis. A child can use the platform fully without it.
- Adaptive practice (the "picker") — OFF by default; only used if a parent/child turns it on.
- Payments — performance of a contract and compliance with legal/accounting obligations.
- Security, abuse-prevention and service integrity — legitimate interests.
- Marketing to parents — only with explicit opt-in consent, off by default, and withdrawable at any time. We never send marketing to a child's account. Operational messages — e.g. receipts, password resets, service notices — are not marketing and are sent as part of the service.
Special-category data is not required by the platform and must never drive adaptive practice.
5. The AI tutor (optional, paid, opt-in)
The AI tutor is an optional add-on that a parent chooses and pays for; it is off until purchased. When a child uses it:
- The child is told they are talking to an AI helper, not a person, that its output may be wrong, and what happens to what they type. See the AI Tutor Notice. AI Act Art. 50 / ICO Std 4.
- What is sent to the AI model is limited to the age band, the difficulty level and the problem text, plus the hint level requested — not the child's name, email, school or account identifier. The interaction is pseudonymous to the model.
- The conversation is processed via to be confirmed. We intend this inference to run within the UK/EU region (eu-west-2).
- Tutor conversations are stored as an audit record and are visible to the child in their own account. They are not shown to parents or teachers.
- If a child types something suggesting they are at risk, we handle it under our Safeguarding Statement — we do not silently ignore it.
6. Payments
Paid features are handled through Stripe. Stripe collects and processes card details directly; we never see or store card numbers. We store only Stripe identifiers (customer and subscription references) and the status of a subscription, to manage access. Stripe acts as a processor/independent controller for payment data per its own terms.
7. Who we share data with (sub-processors)
We use a small set of service providers ("sub-processors") to run the platform. Each is bound to handle data only as instructed.
| Provider | What it handles |
|---|---|
| Amazon Web Services — Cognito | sign-in identity (email, account id) |
| Amazon Web Services — Bedrock / the AI model provider | the optional tutor's pseudonymous prompts/responses |
| Amazon Web Services — RDS, ECS, S3, CloudFront, Secrets Manager, SSM | hosting, storage, content delivery, configuration |
| Stripe | payments and subscriptions (card data held by Stripe, not us) |
| to be confirmed | the optional tutor's pseudonymous prompts/responses |
International transfers. Our intent is to keep personal data, including the tutor's processing, within the UK/EU. Whether any transfer outside the UK occurs depends on the live AI-inference configuration, which must be verified from the running system.
8. Visibility — who can see a child's activity
- A parent linked to a child can see that child's progress and assignments. A parent cannot see the child's AI-tutor conversations.
- A teacher at the child's school can see school-flow pupils' progress and set assignments, subject to the consent rules in the Terms of Service. Default teacher access depends on whether the account was created by the school or by a parent.
- A child can always see their own data, including their own tutor conversations.
We are committed to making it clear to the child, inside the app, when an adult can see their activity.
9. How long we keep data
- Account data is kept while the account is active. When an account is deleted, we remove the child's answers and assignments and anonymise the identifying fields (name, email, parent email, date of birth), keeping only non-identifying statistical fields and an immutable consent/audit record required for accountability. Identity is also removed from our sign-in provider.
- Tutor conversations and access logs are kept for up to 6 months and then deleted on a rolling basis. We are implementing the automated deletion that enforces this.
- Backups are retained for to be confirmed and then expire.
10. Your rights
Under UK data protection law, you (and, where appropriate, your child) have the right to: access your data; rectify inaccurate data; erase data; restrict or object to processing; data portability; and to withdraw consent at any time where we rely on consent. You can exercise these by contacting mail@physmat.org.
You also have the right to complain to the Information Commissioner's Office (ICO) — ico.org.uk, or by post to the address on their website — though we'd ask you to contact us first so we can help.
Decisions about a child (such as adaptive practice) are not made by purely automated means in a way that produces legal or similarly significant effects on the child.
11. Security
We use access controls, encryption in transit, isolated credentials, and audit logging to protect personal data. No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of children's data, and we maintain a breach-response process. to be confirmed
12. Changes to this policy
We may update this policy. If we make a material change, we will tell affected users in an age-appropriate way before it takes effect. The "last updated" date at the top shows the current version.
13. Contact
Questions or requests: mail@physmat.org. Postal: to be confirmed. Data Protection Officer: to be confirmed, contact mail@physmat.org.