Privacy Policy

Last updated: 28 July 2026 · Version 2026-07-28

Feedback Flows Ltd · Company No. 16948031 · ICO ZC132812

We do not sell personal data. Feedback Flows is funded by credits and subscriptions you purchase. We do not sell, rent or trade teacher or student data to advertisers.

1. Who we are

This Privacy Policy explains how Feedback Flows Ltd (“we”, “us”) processes personal data when you use https://feedbackflows.org and related services (the “Service”).

  • Registered office: C/O Vantage Accounting, 1 Cedar Office Park, Cobham Road, Wimborne, United Kingdom, BH21 7SB
  • Companies House number: 16948031
  • ICO registration: ZC132812
  • Data protection contact: admin@feedbackflows.org
  • Support: support@feedbackflows.org

2. Our roles under UK GDPR

We act in two distinct roles depending on the data:

  • Controller for account-holder (teacher/staff) data — registration, billing, login/session metadata, support tickets, marketing preferences and product analytics about how you use the Service.
  • Processor for student data that you (or your school / training provider) upload or enter into the Service. You (or your organisation) remain the controller of that student data; we process it only on your documented instructions as set out in our Data Processing Agreement.

3. Personal data we process — account holders

CategoryExamplesPurpose / lawful basis
Identity & contact Email, name, job title, organisation, profile image Provide and administer your account (contract); communicate about the Service
Credentials Password hash (pbkdf2:sha256 — we never store plaintext passwords) Authentication and security (contract / legitimate interests)
Billing Stripe customer/subscription IDs, payment amounts and status (card details handled by Stripe) Process payments (contract); legal obligation for records
Usage & security Login times, IP address, user agent, session keys, page/tab activity trail, credit usage Security, abuse prevention, product improvement, admin support (legitimate interests)
Preferences Notification prefs, AI anonymisation toggle, feedback style, theme, dashboard layout Personalise the Service (contract / legitimate interests)
Marketing Marketing email preference and consent timestamp Send tips/offers only with consent (consent — PECR)
Support Tickets and replies you send us Provide support (contract / legitimate interests)

4. Personal data we process — students (on your instructions)

When you use marking, integrity, tutoring or related tools you may upload or enter student personal data. Typical categories include:

  • Student name, optional email, date of birth, gender, EAL flag, location, profile notes
  • Year groups, subject tags and class memberships
  • Submitted work (text, files, images), marks, AI-generated feedback, annotations
  • Audio transcripts and visual notes (Video Marker), AI-detection scores, writing samples / fingerprints
  • Meeting notes, diary notes, calendar items and reporting summaries that reference students
  • Work uploaded by a student themselves via a private assignment submission link (no student account is created; the file is associated with the teacher’s roster)

Marking-as-a-service (outsourced marking): where a school or training provider purchases marking carried out by Feedback Flows staff, our authorised administrators may read and mark submitted student work on the Controller’s instructions. That work is held in separate client-school records accessible only to platform administrators (not to other customers). AI tools may still be used as part of that workflow under the same sub-processor arrangements as self-serve marking.

Lawful basis for our processing of student data: we process it as your processor under Article 28 UK GDPR, on the instructions in our DPA and your configuration of the Service. You must ensure you have a lawful basis (and any required parental/learner notices) to upload student data to us.

5. Children's data

The Service is designed for education professionals aged 18+. Students (including children under 18) are data subjects whose information may be processed when teachers upload their work. We do not knowingly offer accounts directly to children.

As processor we:

  • Process student data only to deliver the features you request
  • Do not use student data for advertising or to sell profiles
  • Offer optional / enterprise-mandated anonymisation that replaces known student names in many AI marking prompts (see section 8)
  • Delete student data when you delete a student or your account, or when you instruct us under the DPA

6. Sub-processors and international transfers

We use carefully selected sub-processors listed on our Sub-processors page. Key transfers outside the UK include OpenAI (United States) for AI features. Where personal data is transferred internationally we rely on appropriate safeguards such as the UK International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, as described for each sub-processor.

In addition to listed sub-processors, the following disclosures may occur on your instructions:

  • API webhooks: if you configure a callback URL for the public API, we POST job-status notifications (job identifiers, type, status and a results URL — not the full student work payload) to the URL you choose. That endpoint is under your control.
  • Enterprise scheduled email reports: enterprise managers may configure recipients for analytics digest emails (optionally including an AI-generated narrative). Recipients may include addresses that are not Feedback Flows account holders; managers are responsible for ensuring those recipients are authorised.
  • Emailing marking results to a student: a teacher may send marks and feedback to a student email address stored on the student profile.

7. Retention

DataRetention
Account, students, marking results, transcripts, detection runsUntil you delete them or delete your account (no automated purge of marking history today)
Assignment submission files on diskDeleted after 30 days; database row retained as expired
Temporary Video Marker media filesDeleted after ~72 hours; transcripts/feedback in the database remain until you delete the job/account
Page & tab activity trail90 days
Database backups~14 days (compressed backups)
Login events after account deletionPreserved in anonymised form (user ID nulled) for security auditing
Cookie consent preference6 months (then we ask again)
Job applications (CV and contact details)Held in our email system only — typically up to 6 months for unsuccessful applicants, then deleted; successful applicants retained as needed for employment records

8. Artificial intelligence

To deliver AI features we send content you submit (often including student work) to OpenAI’s API. Under OpenAI’s API terms, customer content is not used to train OpenAI’s public models; processing is for fulfilling your request. You remain responsible for reviewing AI outputs before sharing them with learners or using them in formal decisions.

Anonymisation: you may enable “anonymise student data for AI” (or your enterprise may require it). When enabled, known student names in many marking and feedback prompts are replaced before being sent to the AI provider. This control is not currently applied to every pathway — notably the AI Detector (sentence scoring), Whisper audio transcription and vision/OCR image analysis may still send raw content. We are transparent about this so schools can choose workflows appropriately.

9. Cookies and analytics

Essential cookies are required for login and security (session, cookie-consent preference, and Cloudflare Turnstile challenge cookies on registration). Non-essential analytics cookies (Google Analytics and our unique-visitor cookie) and related homepage visit logging are off until you opt in via the cookie banner. We do not use session-recording or heatmap tools. See the Cookie Policy and Cookie settings.

10. Job applicants

If you apply via our careers form we collect your name, email, phone number, location, optional free text and a CV file (PDF or Word). Applications are emailed to admin@feedbackflows.org; we do not store applicant CVs in the product database. Lawful basis: legitimate interests in recruiting staff (and, where applicable, steps prior to entering a contract). Unsuccessful applications are typically retained for up to 6 months in our email system and then deleted. To exercise rights in relation to an application, contact admin@feedbackflows.org.

11. Staff access and support

Named Feedback Flows platform administrators may access customer accounts to provide support, investigate abuse, or deliver marking-as-a-service. Support access may include impersonation (logging in as your user to reproduce an issue). Every impersonation session is logged with the administrator’s identity, target account, IP address, user agent, and start/end times, and sessions auto-expire after 30 minutes. Administrators are bound by confidentiality obligations. Student data viewed in support remains subject to this Policy and the DPA.

12. Your rights

Depending on your role and the data, you may have rights to access, rectify, erase, restrict, object, and data portability.

  • Download your data: Profile → Download Data
  • Delete your account: Profile → Danger Zone (deletes associated student and job data we hold for that account)
  • Marketing: opt out anytime in Profile or via unsubscribe links in emails
  • Contact: admin@feedbackflows.org

You also have the right to complain to the Information Commissioner’s Office (ICO). Our ICO registration number is ZC132812.

If you are a student (or parent) seeking access to student data held in Feedback Flows, please contact the school or teacher who is the controller; we will assist them under the DPA.

13. Security

Measures include (non-exhaustive):

  • Hosting on AWS Lightsail in London (eu-west-2); PostgreSQL database in the same UK region
  • Background job queue (Celery) with Redis as broker/result backend on our own UK application server — queued job metadata does not leave our infrastructure
  • TLS encryption in transit; HTTPS with HSTS in production
  • Password hashing (pbkdf2:sha256), HttpOnly / Secure / SameSite session cookies, CSRF protection
  • Login and signup rate limiting; Cloudflare Turnstile on registration
  • Idle auto-logout option; session revocation; zip-slip protection on archives
  • Admin impersonation audit trail; enterprise audit logs and optional AI anonymisation mandates

We do not currently offer multi-factor authentication. Database backups are compressed; they are not separately encrypted by our backup scripts. We continuously improve controls and will update this notice when material changes land.

14. Changes

We may update this Policy. Material changes will be reflected by a new version date. If you previously accepted Terms/Privacy, we may show a non-blocking notice asking you to review and re-acknowledge.

15. Contact

Questions: admin@feedbackflows.org or our Contact page.