Applies to all education applications operated by Inspiring Teachers.
Last updated: 10 Jul 2026 · Version: 1.0
This statement explains how Inspiring Teachers builds, hosts and secures its apps, and how we handle personal data as a data processor on behalf of the organisations that control each app. It complements, and is not a substitute for, each app’s privacy notice, which describes what a specific app collects, why, who controls it, and your rights.
Inspiring Teachers is a charity registered in England and Wales (charity no. 1187045), Quill, Marsh Lane, Taplow, Buckinghamshire SL6 0DF, United Kingdom. We partner with Ministries of Education and in-country partner organisations across sub-Saharan Africa, and we build and operate the technology platform behind the apps above.
ICO registered under no.: CSN6060190
Contact: info@inspiringteachers.org
Data protection contact: Tom Lewis, tom.lewis@inspiringteachers.org
Data protection law (UK GDPR; South Africa’s POPIA; Zambia’s Data Protection Act 2021; Uganda’s Data Protection and Privacy Act 2019; Ghana’s Act 843) distinguishes a controller (POPIA: Responsible Party), who decides why and how data is processed and carries primary accountability, from a processor (POPIA: Operator), who processes on the controller’s documented instructions.
For apps deployed by our partners, we act as processor. The organisation that deploys each partner app is the data controller and is identified in that app’s privacy notice. We process personal data only on each controller’s documented instructions under a written Data Processing Agreement (DPA), and we notify the controller if an instruction appears to breach the law. Where Inspiring Teachers itself determines the purposes and means (our own SmartCoach), we act as controller, and that app’s notice says so.
Separately, we act as controller for personal data relating to our own operations, such as correspondence sent directly to us (including data protection enquiries) and visits to our website; this processing is covered by our website privacy notice.
For the partner apps, the personal data we process is defined by the controller and described in that app’s privacy notice. It includes: identifiers (names, learner/user IDs), limited contact details, school/class identifiers, assessment responses and scores, metadata/logs, and audio recordings used for speech and reading assessment. Data subjects include learners (including children under 18), educators, school administrators and assessors. Children’s data and voice recordings are treated as sensitive, and we process special-category data only where strictly necessary and authorised in writing by the controller.
The controller decides what data is collected. We do not use one controller’s data for any other purpose, controller or app; we do not sell personal data, use it for advertising, or build advertising profiles.
We use a limited set of vetted sub-processors. Each may only process personal data to provide its service to us, is bound by contract to obligations no less protective than our DPAs, and (for the partner apps) is authorised by the controller and listed in the DPA’s sub-processor register, which is the authoritative list for each app. We remain fully liable for our sub-processors and notify controllers in advance of any intended change.
Current register
| Sub-processor | What it does | Location |
|---|---|---|
| AWS | Hosting, storage, compute, networking, authentication, outbound messaging | Cape Town, South Africa |
| Salesforce | Data storage and transformation | Stockholm, Sweden (EU) |
| Anthropic | AI processing | USA (multi-region) |
| Sentry | Error monitoring and debugging | Iowa, USA |
| Slack | Internal communication within Inspiring Teachers | US data centres |
| Google (Firebase) | Outbound transactional messaging (e.g. OTPs) and application monitoring | US data centres |
| Meta | Outbound transactional messaging (e.g. OTPs) | US data centres |
Where audio or assessment data is processed by an AI sub-processor for speech or reading scoring, we ensure by contract that: the data is not used to train the provider’s models; retention is limited to what the task requires; the processing region and lawful basis are defined by the controller; and outputs are subject to human review (no solely automated decisions about a learner). AI processing will be covered in the DPIA for the relevant app.
By default, we host and store personal data for our sub-Saharan African partners and projects in the AWS Africa (Cape Town) Region in South Africa. Hosting in-region keeps data on the continent and close to the data subjects it concerns, and Cape Town is currently the only cloud region in Africa that meets our requirements for security, reliability and scale. Any departure from this default is agreed with the relevant controller and recorded in the DPA. Where a sub-processor listed in section 4 processes data outside South Africa, that processing is authorised by the controller and safeguarded as described in that section.
Our team is distributed across multiple countries and continents. Where staff access personal data remotely from outside the country in which it is stored, we treat that access as a cross-border transfer (under POPIA section 72 and the corresponding provisions of other applicable laws). Such access is limited to what a person’s role requires, protected by multi-factor authentication, logged, and covered by the transfer safeguards agreed with the relevant controller in the DPA. The access controls we apply are described in section 6.
We protect personal data with technical and organisational measures that implement the minimum security measures contracted in each DPA. We are formalising these measures into a documented information security management system aligned with ISO/IEC 27001:2022, with implementation underway in 2026 supported by an independent external security advisor. We are not yet certified against the standard. The measures below are our key controls, not an exhaustive list; our full Statement of Applicability and current evidence of controls are available to controllers on request.
Alongside our ISO/IEC 27001 alignment, we are formalising three further areas: (i) standardised international transfer instruments for each sub-processor and destination (UK IDTA / EU SCCs with UK Addendum, and POPIA s.72 binding agreements), replacing the transfer safeguards currently agreed case by case in each DPA; (ii) a documented DPIA programme covering each app, which we maintain with and on behalf of each controller; and (iii) a programme of independent penetration testing, with summary findings made available to controllers. Current status is available to controllers on request.
| Measure | What we do | Annex A controls |
|---|---|---|
| Governance and policies | Documented security policies with defined roles and responsibilities | A.5.1, A.5.2 |
| Access control | Least-privilege, role-based access; rights reviewed and revoked on role change or exit | A.5.15, A.5.18, A.8.2, A.8.3 |
| Authentication | Multi-factor authentication for privileged accounts | A.5.17, A.8.5 |
| Encryption | Encryption of personal data in transit and at rest | A.8.24 |
| Secure development | Change management, code review and security testing across segregated environments | A.8.25, A.8.28, A.8.29, A.8.31, A.8.32 |
| Security awareness | Security and data protection training for staff and assessors | A.6.3 |
| Logging and monitoring | Centralised logging of system and access events; monitoring for anomalous activity | A.8.15, A.8.16 |
| Vulnerability management | Identification, assessment and remediation of technical vulnerabilities | A.8.8 |
| Incident management | Procedures for detecting, assessing and responding to incidents; controller notification per section 7 | A.5.24, A.5.25, A.5.26 |
| Sub-processor management | Vetting, contractual controls and oversight of sub-processors per section 4 | A.5.19, A.5.20, A.5.22, A.5.23 |
| Physical security | Inherited from our cloud provider; verified via its independent assurance reports | A.7 (via A.5.23) |
| Deletion and return | Secure deletion and certified return of personal data per section 9 | A.8.10 |
| Backup and disaster recovery | Tested backup and recovery procedures with defined recovery objectives | A.8.13, A.5.29, A.5.30 |
| Personnel confidentiality | All staff, contractors and field assessors who process personal data are bound by written confidentiality obligations that survive the end of their engagement | A.6.2, A.6.6 |
| Privacy and protection of PII | Identification and fulfilment of data protection obligations for each app and jurisdiction, as set out in this statement and each DPA | A.5.34 |
| Malware protection | Anti-malware protection on managed endpoints, kept current and centrally monitored | A.8.7 |
| Remote working | Defined remote working arrangements for our distributed team, with access safeguards as described in section 5 | A.6.7 |
We monitor the platform for security incidents. We notify the affected controller without undue delay and in any event within 48 hours of becoming aware of an actual or suspected incident, including (to the extent known) the nature of the incident, affected data and categories, likely consequences, and the measures taken or proposed. The controller notifies its supervisory authority and affected individuals where required; we support that process.
If we receive a request for personal data from a government body, law enforcement agency or court, we redirect the requester to the relevant controller and notify the controller promptly, unless we are legally prohibited from doing so. We do not disclose personal data voluntarily. Where a legally binding demand compels disclosure and we cannot redirect it, we challenge requests that are overbroad or that we believe lack a valid legal basis, and we disclose only the minimum the demand requires. We impose equivalent obligations on our sub-processors through the contracts described in section 4.
Individuals exercise their rights through the controller of the relevant app (see that app’s notice). We refer any request we receive to the controller and do not respond directly unless authorised, and we provide the technical means and reasonable assistance for the controller to respond in time.
We retain personal data only as the controller instructs and the law allows. On the controller’s instruction, or on termination or expiry of our agreement, we return or securely delete the personal data we hold and certify completion in writing, and ensure sub-processors do the same. Backups are deleted on a defined rolling cycle.
We maintain cyber/privacy liability insurance at the levels and within the timeframes required by our DPAs. We make available the information needed to demonstrate compliance, including third-party assurance where available, and allow for and contribute to audits by the controller or its nominated auditor on reasonable notice.
We may update this statement to reflect changes to the platform, our sub-processors or the law. We revise the “Last updated” date and, for material changes, notify our partner controllers.
Register your details below to secure your
discount towards a Fellowship.