Privacy Policy

Important Notice to Schools and Educational Partners

This Privacy Policy has been prepared in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Elevate & Co is committed to the highest standards of data protection and privacy for all students, parents, and guardians we work with.

We work exclusively with schools and educational institutions and understand the heightened sensitivity of data relating to children and young people. This policy explains clearly and transparently how we collect, use, store, and protect personal data.

Version 1.1 | Effective Date: July 2026 | Review Date: July 2027

1. Who We Are

Elevate & Co (‘we’, ‘us’, ‘our’) is an educational services provider operating in the United Kingdom. We deliver tutoring and educational support services to students, working in partnership with schools and educational institutions.

DetailInformation
Business NameElevate & Co
Websitewww.elevateandco.uk
Country of OperationUnited Kingdom
Regulatory FrameworkUK GDPR / Data Protection Act 2018
Data ControllerElevate & Co
Contact for Data EnquiriesPlease use the contact details on our website

2. Scope of This Policy

This Privacy Policy applies to:

  • All students whose data is provided to us by schools or directly by parents/guardians
  • Parents, guardians, and carers of students
  • School staff and contacts with whom we work
  • Visitors to our website (www.elevateandco.uk)

This policy covers all personal data we process whether collected directly, through our website, via school referrals, or through our student management platform, TutorBird.

3. Our Legal Basis for Processing

Under the UK GDPR, we are required to identify and rely upon a lawful basis for each type of processing we carry out. We rely on the following lawful bases:

Lawful BasisWhen We Rely On It
Legitimate Interests (Art. 6(1)(f))For operational activities necessary to deliver educational services, including scheduling, communication, and reporting to schools.
Contractual Necessity (Art. 6(1)(b))Where processing is necessary to fulfil our service agreement with schools or parents/guardians.
Legal Obligation (Art. 6(1)(c))Where we are required to retain or share data to comply with applicable laws, such as safeguarding legislation.
Consent (Art. 6(1)(a))For optional activities such as marketing communications or photography. Consent can be withdrawn at any time.
Vital Interests (Art. 6(1)(d))In emergency situations where processing is necessary to protect the life of a student.

Where we process special category data (such as information about a student’s health, learning difficulties, or SEND needs), we rely additionally on Article 9(2)(g) (substantial public interest, education and safeguarding purposes) and/or explicit consent.

4. Personal Data We Collect

4.1 Student Data

When schools refer students to us or parents/guardians register directly, we may collect:

  • Full name and date of birth
  • Year group and school name
  • Academic performance information and subject areas
  • SEND (Special Educational Needs and Disabilities) information, where relevant and provided
  • Medical or health information that may affect delivery of services (e.g., dyslexia, ADHD)
  • Attendance and session records
  • Progress notes and tutor observations
4.2 Parent / Guardian Data
  • Full name and relationship to student
  • Home address
  • Email address and telephone number
  • Payment and billing information (processed securely, see Section 8)
4.3 School Contact Data
  • Name and job title of school contacts (e.g., SENCO, Head of Year)
  • School name and address
  • Work email address and telephone number
4.4 Website Data
  • IP address and browser information (collected automatically via cookies)
  • Pages visited and duration of visit
  • Enquiry form submissions

Special Category Data: Heightened Protection

We recognise that information about students’ learning difficulties, SEND status, health conditions, or other sensitive characteristics constitutes ‘special category data’ under Article 9 of the UK GDPR. Such data is handled with the utmost care, stored securely within TutorBird, and accessed only by staff with a legitimate need, in line with the technical and organisational measures set out in Section 10.

5. How We Use Personal Data

We use personal data strictly for the following purposes:

PurposeDetails
Service DeliveryScheduling and managing tutoring sessions; tracking attendance and progress.
CommunicationContacting parents/guardians regarding sessions, progress updates, and invoices. Liaising with school contacts.
Progress ReportingProducing written or verbal progress reports for schools and parents/guardians.
Invoicing & PaymentsGenerating invoices and processing payments securely.
SafeguardingFulfilling our duty of care and legal safeguarding obligations in relation to children.
Legal ComplianceMeeting our obligations under UK law, including data protection and education legislation.
Service ImprovementAnalysing anonymised, aggregated data to improve the quality of our tutoring programmes.

We do not use student data for marketing purposes. We will never sell personal data to third parties.

6. TutorBird: Our Student Management Platform

6.1 What is TutorBird?

Elevate & Co uses TutorBird (operated by Port 443 Inc.) as our dedicated student management platform. TutorBird enables us to securely manage student profiles, session scheduling, attendance records, invoicing, and communication with parents and guardians.

TutorBird’s website is available at www.tutorbird.com. Under UK GDPR, TutorBird acts as a Data Processor on our behalf, processing data only in accordance with our documented instructions. Elevate & Co remains the Data Controller for all student and parent data held within TutorBird.

6.2 Data Held in TutorBird

The following categories of data relating to your students/children may be stored within TutorBird:

  • Student name, contact details, and school information
  • Parent/guardian name and contact details
  • Session history, attendance records, and progress notes
  • Invoice and payment records
  • Any notes or documents uploaded by our tutors
6.3 TutorBird’s Data Protection Commitments

TutorBird operates in accordance with applicable data protection laws and maintains the following security measures:

TutorBird Security & Compliance Highlights

  • Secure HTTPS (TLS) encryption for all data in transit
  • Data stored on secured, access-controlled servers
  • Role-based access controls, staff only access data relevant to their role
  • Regular security monitoring and system updates
  • No sale or disclosure of personal data to third parties for advertising
  • Compliance with applicable privacy legislation
  • Payment processing handled by PCI-DSS compliant third parties (Stripe / PayPal Braintree), card details are never stored directly in TutorBird

TutorBird confirms that personal data is used solely to provide and maintain their service, and not for advertising or profiling purposes. TutorBird’s full privacy policy is available at: www.tutorbird.com/privacy-policy

6.4 International Data Transfers

TutorBird is operated by a Canadian company (Port 443 Inc.) and data may be processed in Canada and/or the United States. Under UK GDPR, transfers of personal data outside the UK require appropriate safeguards. We note that:

  • Canada has been granted an adequacy decision by the UK for commercial organisations subject to Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).
  • Where data is processed in the United States, TutorBird has confirmed it takes steps to ensure adequate controls are in place before any transfer occurs. We are seeking further confirmation from TutorBird as to the specific transfer mechanism used (for example, Standard Contractual Clauses or the UK International Data Transfer Addendum) and will update this policy once confirmed.

If you have specific concerns about international data transfers in relation to your students’ data, please contact us to discuss further.

7. Sharing of Personal Data

7.1 Who We Share Data With

We do not share personal data with third parties except in the following limited circumstances:

RecipientBasis for Sharing
Partner SchoolsProgress reports and attendance summaries shared with the referring school contact. Only relevant, agreed information is shared.
TutorBird (Port 443 Inc.)As our student management platform provider. Governed by TutorBird’s own privacy policy and applicable law; we are in the process of confirming a signed Data Processing Agreement is in place and will update this policy accordingly.
Payment ProcessorsStripe or PayPal Braintree for secure payment processing. They operate under their own PCI-DSS compliant privacy frameworks.
Safeguarding AuthoritiesIn circumstances where we have a legal duty to report concerns about a child’s welfare, we may share information with the relevant statutory authority (e.g., Local Authority, police). We will notify the Data Controller (school/parent) where legally permissible.
Legal / Regulatory BodiesWhere required by law, court order, or regulatory obligation.

We will never sell, rent, or trade personal data to any third party for commercial purposes.

8. Payment Information

All payment processing is handled by PCI-DSS compliant third-party processors (Stripe and/or PayPal Braintree). We do not store, process, or have access to full payment card details. When you make a payment:

  • Your payment details are entered directly into the secure payment processor’s interface
  • Card details are encrypted and handled entirely by the payment processor
  • We retain only non-sensitive billing information (e.g., invoice amounts, payment confirmation) for accounting purposes

9. Data Retention

We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required by law. Our retention periods are as follows:

Data TypeRetention Period
Active student recordsFor the duration of the tutoring relationship plus 2 years after the last session
Financial / invoice records7 years (required by HMRC / UK tax law)
Safeguarding recordsIn accordance with applicable safeguarding guidance, typically until the individual reaches age 25
Website enquiry data12 months from date of enquiry
Marketing consentsUntil consent is withdrawn, then 3 years

Upon expiry of the retention period, personal data is securely deleted or anonymised. You may request earlier deletion of your data subject to our legal obligations (see Section 11, Your Rights).

10. How We Protect Your Data

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration. This section sets out the specific measures we apply and how we assess and manage data protection risk.

10.1 Technical Measures

The following technical controls are applied across our systems and TutorBird:

  • Encryption in transit: all data transmitted to and from TutorBird and our internal systems is protected using HTTPS encryption.
  • Encryption at rest: personal data held within TutorBird is stored on secured, access-controlled servers in accordance with TutorBird’s own security measures. [Elevate & Co to confirm the specific encryption standard applied with TutorBird before publication.]
  • Two-Factor Authentication (2FA): TutorBird provides 2FA as a security feature. Elevate & Co requires all staff with access to TutorBird to enable 2FA on their accounts as a condition of use, and requires MFA on internal systems holding personal data.
  • Access control: role-based access control (RBAC) restricts staff to only the data required for their role; access to student records, SEND information, and safeguarding notes is limited to staff with a defined, legitimate need.
  • Password policy: enforced minimum password complexity, mandatory periodic password changes, and a prohibition on shared or generic login credentials.
  • Account lockout and session controls: automatic session timeouts and account lockout after repeated failed login attempts.
  • Device security: company devices used to access student data are protected by disk encryption, up to date anti-malware software, and remote wipe capability in the event of loss or theft.
  • Patching and vulnerability management: operating systems, applications, and TutorBird’s platform are kept up to date with security patches, and vulnerabilities are tracked and remediated on a risk-prioritised basis.
  • Network security: firewalls and monitoring are in place to detect and prevent unauthorised network access.
  • Backups: encrypted backups are taken regularly, stored securely, and periodically tested to confirm they can be restored.
  • Audit logging: access to student and parent records within TutorBird is logged, allowing us to review who has accessed particular records and when.
10.2 Organisational Measures
  • Staff access to personal data is limited to those with a legitimate need, applying the principle of least privilege.
  • All team members complete data protection training before gaining access to student data, with periodic refresher training thereafter.
  • Tutors and staff working directly with children undergo appropriate vetting, including Disclosure and Barring Service (DBS) checks where required.
  • Staff sign confidentiality undertakings covering the handling of student and parent data.
  • Access permissions are reviewed periodically, and access is revoked immediately when a staff member changes role or leaves the organisation.
  • We maintain a Record of Processing Activities (ROPA) setting out what data we hold, why, and where it is stored.
  • We conduct periodic internal reviews of our data handling practices and this Privacy Policy.
  • We maintain, or are in the process of confirming, a Data Processing Agreement with each processor who handles personal data on our behalf, including TutorBird and our payment processors.
10.3 Risk Management and Assessment

We take a structured approach to identifying and mitigating data protection risks. Data Protection Impact Assessments (DPIAs) are carried out for new or higher-risk processing activities, and risks are reviewed on an ongoing basis. The table below sets out the principal risks we consider and the measures in place to manage them:

Risk AreaMitigating Measures
Unauthorised accessMFA on all staff accounts; role-based access control; encryption in transit and at rest; network firewalls and monitoring; audit logging of record access.
Data breachDocumented incident response plan; breach detection and logging; internal breach register; assessment of severity and notification to the ICO within 72 hours where required (Section 10.4); notification to affected schools and individuals without undue delay.
Inappropriate account accessLeast-privilege, role-based permissions; periodic access reviews; immediate revocation of access on role change or staff departure; account lockout after failed login attempts; activity logging to identify unusual access patterns.
Third-party / processor misuseDue diligence carried out on all processors (including TutorBird and payment processors) before onboarding; signed Data Processing Agreements setting contractual obligations and audit rights; restrictions preventing processors from using data for advertising or profiling; periodic review of processor compliance.
Lack of transparencyPublication and regular review of this Privacy Policy; maintenance of a Record of Processing Activities; provision of Data Processing Agreements to schools on request; cooperation with schools’ Data Protection Officers on DPIAs, audits, and Subject Access Requests.

Risk assessments and DPIAs are reviewed periodically and whenever a significant change is made to how student data is collected, stored, or shared (for example, a change of processor or a new system integration).

10.4 Breach Notification

In the event of a personal data breach that is likely to result in a risk to individuals’ rights and freedoms, we will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach, in accordance with Article 33 of the UK GDPR. Where required, we will also notify affected individuals and partner schools without undue delay.

11. Your Rights Under UK GDPR

Under the UK General Data Protection Regulation, individuals (including parents acting on behalf of their children) have the following rights:

RightWhat It Means
Right of AccessYou may request a copy of all personal data we hold about you or your child (Subject Access Request).
Right to RectificationYou may ask us to correct inaccurate or incomplete data without undue delay.
Right to ErasureYou may request deletion of personal data where it is no longer necessary, consent has been withdrawn, or processing is unlawful. Note: certain legal obligations may require us to retain some data.
Right to Restrict ProcessingYou may ask us to pause processing of your data in certain circumstances, e.g., while accuracy is verified.
Right to Data PortabilityYou may request your personal data in a commonly used, machine-readable format to transfer to another controller.
Right to ObjectYou may object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.
Rights re: Automated DecisionsWe do not make solely automated decisions that significantly affect individuals.
Right to Withdraw ConsentWhere processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us using the details on our website (www.elevateandco.uk). We will respond within one calendar month. We may ask you to verify your identity before processing your request.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe we have not handled your data correctly. The ICO can be contacted at: www.ico.org.uk or by telephone: 0303 123 1113.

12. Children’s Data: Additional Protections

As an educational provider working directly with children and young people, we apply heightened protections to student data:

  • We do not use student data for profiling, targeted advertising, or any commercial purpose beyond service delivery
  • We only process the minimum amount of student data necessary to deliver our services (data minimisation principle)
  • SEND information and other sensitive data is flagged, restricted, and accessible only to relevant staff, in line with the access controls described in Section 10
  • We support schools in fulfilling their data protection obligations and can provide Data Processing Agreements upon request
  • We take our safeguarding duties seriously and will always prioritise a child’s safety and welfare

13. Cookies and Website Analytics

Our website (www.elevateandco.uk) may use cookies to improve your experience. Cookies are small text files stored on your device. We may use:

  • Session Cookies, required for the website to function correctly
  • Preference Cookies, to remember your settings and preferences
  • Analytics Cookies, to understand how visitors use our website (e.g., Google Analytics in anonymised form)

You can control cookie preferences through your browser settings. Disabling certain cookies may affect website functionality. A cookie consent notice is displayed upon your first visit to our website.

14. Information for Schools

We understand that schools share responsibility for the personal data of their pupils and must satisfy themselves that any third-party services they use are GDPR compliant. We confirm the following:

Elevate & Co: GDPR Compliance Statement for Schools

  • We act as Data Controller in respect of data we collect directly, and as Data Processor in respect of data shared with us by schools
  • We are prepared to enter into a formal Data Processing Agreement (DPA) with partner schools on request
  • We apply data minimisation principles, we collect and use only the data necessary to deliver our services
  • Student data is stored securely within TutorBird, protected by the technical measures set out in Section 10.1
  • We do not share student data with third parties except as described in this policy
  • We will notify schools without undue delay in the event of a data breach affecting their students’ data
  • We support schools’ Subject Access Request obligations, contact us to coordinate any SAR relating to our held data
  • Staff are trained on data protection; access to data is role-restricted and access rights are reviewed periodically
  • We carry out Data Protection Impact Assessments for higher-risk processing and can share a summary with a school’s Data Protection Officer on request

Schools wishing to enter into a Data Processing Agreement, carry out a due diligence review, or discuss our data protection practices in more detail are encouraged to contact us via our website.

15. Third-Party Links

Our website may contain links to external websites. We are not responsible for the privacy practices or content of those websites and encourage you to read their privacy policies. This policy applies only to Elevate & Co.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or technology. When we make significant changes, we will:

  • Update the ‘Effective Date’ at the top of this document
  • Notify partner schools and registered users via email where appropriate
  • Publish the updated policy on our website

We recommend reviewing this policy periodically. Continued use of our services after changes take effect constitutes acceptance of the updated policy.

17. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or our data handling practices, please contact us:

Contact Details

Elevate & Co

Website: www.elevateandco.uk

For Subject Access Requests, data breach notifications, or to request a Data Processing Agreement, please mark your correspondence clearly with the nature of your enquiry.

If you are a school Data Protection Officer wishing to carry out a data processing review or audit, including in support of a DPIA, we welcome your enquiry and will cooperate fully.

Scroll to Top