PRIVACY NOTICE

Last updated: 6 September 2025

This privacy notice for StudyPlans.co.uk (“StudyPlans”, “we”, “us”, or “our”) explains how and why we collect, store, use, and share (“process”) personal information when you use our websites, apps, and related services (the “Services”). Because children may use our Services, we design and operate them with children’s privacy in mind and follow the UK GDPR, the Data Protection Act 2018, and the ICO Age-Appropriate Design Code (Children’s Code).

If you have questions or requests, contact: contact@studyplans.co.uk

QUICK SUMMARY
We collect only what we need to run StudyPlans (for example, account details, learning progress, device information).

  • Children under 13 require parent or guardian consent to create an account.
  • We do not show behaviourally targeted advertising to children and we default child accounts to high-privacy settings.
  • We use trusted service providers (for hosting, security, support) and restrict what they can do with your data.
  • You (or your parent/guardian for under-13s) can access, correct, delete, or object to certain uses of your data.
     

WHO WE ARE AND HOW TO CONTACT US
Controller: StudyPlans operating the website StudyPlans.co.uk
Email: contact@studyplans.co.uk

If we appoint a Data Protection Officer or an EU representative, we will update this notice with their details.

WHAT INFORMATION WE COLLECT
a) Information you (or a parent/guardian) provide
Account details: name or nickname, username, password, age or age band, and (for parents/guardians) email and relationship to the child.
Contact details: email address for verification, service messages, parental consent, and support.
Profile and learning data: classes joined, study plans, assignments, progress, scores, feedback, and content you upload or create.
Support queries: messages and attachments you send to our support team.
Payments (if applicable): payments are processed by independent payment processors. We do not store full card numbers. You will see the relevant provider’s privacy notice at checkout.
We do not intentionally collect special category data (such as health data or data revealing racial or ethnic origin, religion, or sexual orientation). Please do not share such data via the Services.

b) Information collected automatically
Device and usage data: IP address, device and browser type, operating system, language, time zone, pages viewed, and interactions to keep services secure and improve performance.
Approximate location (from IP) for fraud prevention, security, and regional preferences.

c) Information from others
Parents/guardians who create or manage a child’s account or provide consent.
Teachers or schools (if your account is set up via an educator), such as class codes or roster information.
Service providers (for example, anti-abuse or security tools) may provide limited signals to protect users.

HOW AND WHY WE USE YOUR INFORMATION
We process personal information to:
Provide and operate the Services: create and manage accounts, deliver study plans and learning features, save progress, and provide support.

  • Personalise learning on a limited basis: adapt content difficulty or recommendations to your progress. We do not use this profiling for marketing to children.
  • Ensure safety and moderation: detect and prevent fraud, abuse, or breaches of our terms; protect users, especially children.
  • Communicate: service messages such as password resets and account notices, parental verification, and important updates.
  • Research and analytics: understand which features are useful and improve the Services, using data minimisation and aggregation, especially for children.
  • Legal compliance: respond to lawful requests, enforce our terms, and maintain necessary records.
  • We do not engage in behavioural advertising targeted at children.


CHILDREN’S PRIVACY AND PARENTAL CONSENT

  • UK digital consent age is 13. If you are under 13, you must have a parent or guardian’s permission to register and use the Services.
  • We take reasonable steps to verify parental consent (for example, email verification and/or additional checks).
  • Child accounts use high privacy by default: precise geolocation and similar tracking are off; public sharing is limited; profiles are not publicly searchable.
  • We do not use manipulative design that encourages unnecessary data sharing by children.
  • We do not serve targeted ads to children.
  • Parents/guardians can exercise data rights on behalf of their child (see Section 10).
  • If we learn that a child under 13 has registered without verifiable parental consent, we will take steps to delete the account.
     

LEGAL BASES WE RELY ON (UK/EU)

  • We process personal data only when we have a valid legal basis:
  • Contract: to provide the Services and fulfil our agreement with you.
  • Consent: for example, parental consent for under-13s; certain optional features; and non-essential cookies. You can withdraw consent at any time.
  • Legitimate interests: for example, service improvement, security, and analytics, with strong safeguards, especially for child users.
  • Legal obligation: record-keeping and responding to lawful requests.
  • Vital interests: where necessary to help protect someone from harm.
  •  

WHEN WE SHARE YOUR INFORMATION

  • We do not sell personal data. We share information only with:
  • Service providers (processors): hosting, storage, customer support, email delivery, security/anti-abuse, analytics appropriate for child audiences, and payment processing. They act under our instructions and must protect your data.
  • Education partners (if applicable): limited sharing with teachers or schools when your account is linked to a class or code.
  • Legal and safety: law enforcement or regulators when required; to protect users and enforce our terms.
  • Business transfers: in connection with a merger, acquisition, or asset sale; we will ensure appropriate protections and notify you where required.

  • INTERNATIONAL TRANSFERS
    Your data may be processed outside the UK/EEA by our providers. When we transfer data internationally, we use lawful safeguards, such as adequacy regulations/decisions or Standard Contractual Clauses (SCCs) with the UK International Data Transfer Addendum (IDTA) or the UK Addendum to the EU SCCs. You can request details by emailing contact@studyplans.co.uk.


COOKIES AND SIMILAR TECHNOLOGIES
We use cookies and similar technologies to operate the Services, keep them secure, and (optionally) understand usage to improve features.

Strictly necessary cookies are essential and always on.

Analytics/performance cookies are optional and, for children, are used only in a privacy-preserving way.
You can manage your preferences via our cookie banner or your browser settings.

Do-Not-Track: There is no uniform DNT standard today, so we do not respond to DNT signals. We will update this notice if that changes.

If you publish a separate Cookie Notice, link to it from your site.

 

HOW LONG WE KEEP INFORMATION

We keep personal data only as long as needed for the purposes in this notice, then delete or anonymise it.

Typical retention periods:

Account and profile data: while the account is active. If you close the account, we delete or anonymise within a reasonable period (generally within 30–90 days), subject to legal or safety holds.

Learning and progress data: while your account exists. We may retain aggregated, anonymised statistics for product improvement.

Support and communications: generally up to 24 months after resolution.

Security logs: generally up to 12 months.

Backups are retained for limited cycles and then purged.

 

YOUR PRIVACY RIGHTS

If you live in the UK/EEA, you (or for under-13s, your parent/guardian) have the right to:

Access your data and receive a copy.

Rectify inaccurate or incomplete data.

Delete your data (erasure).

Restrict or object to certain processing (especially where we rely on legitimate interests).

Data portability where applicable.

Withdraw consent at any time (this does not affect past processing).

Complain to a supervisory authority (see Section 14).

We will respond within one month or as permitted by law. We may need to verify your identity and, for children’s accounts, confirm the requester’s parental authority.

To exercise your rights, email contact@studyplans.co.uk.

Marketing: If we ever send marketing emails (we do not send marketing to children), you can unsubscribe via the link in the email or by contacting us.

 

SECURITY

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, least-privilege access, monitoring, and staff training. No system is completely secure; if a security incident affects your data, we will notify you and regulators where required by law.

 

THIRD-PARTY LINKS

The Services may link to third-party websites or apps. We are not responsible for their privacy practices. Review their privacy notices before providing personal information.

 

CHANGES TO THIS NOTICE

We may update this notice from time to time. The “Last updated” date shows when it was last changed. If changes are material, we will take reasonable steps to notify you (for example, in-product notice or email).

 

CONTACT AND COMPLAINTS

Questions or requests: contact@studyplans.co.uk
UK regulator (ICO): https://ico.org.uk/make-a-complaint/

 

KID-FRIENDLY SUMMARY 

Hi! We only ask for the information we need to run StudyPlans. If you are under 13, please ask your parent or guardian to help you sign up. We keep your account private by default and do not show ads based on what you do. You or your parent/guardian can ask us to see, fix, or delete your info by emailing contact@studyplans.co.uk.