Edvolve
Open navPrivacy Policy Protecting information with care and responsibility.
Last updated 28th July 2026
1. Purpose
At AppyHive Ltd, protecting personal information is fundamental to how Edvolve is designed, developed and operated. Schools trust us with information relating to children, families and staff, and we recognise the responsibility that comes with that trust.
This policy explains how Edvolve protects personal data, safeguards children's privacy and applies security throughout the platform. It forms part of our wider Trust Centre and demonstrates our commitment to meeting the requirements of UK data protection legislation and recognised industry best practice.
Our approach is guided by the principles of:
- UK GDPR (as amended)
- Data Protection Act 2018
- Data (Use and Access) Act 2025 (DUAA)
- Information Commissioner's Office (ICO) guidance
- Security by Design
- Data Protection by Design and by Default
These principles are embedded throughout the Edvolve platform and underpin every stage of product development, deployment and ongoing operation.
2. Our Commitment
Edvolve has been created specifically for schools, academies and multi-academy trusts, where protecting personal information is essential to maintaining trust between schools, families and students.
We are committed to ensuring that personal information is:
- Processed lawfully, fairly and transparently;
- Collected only for legitimate educational and operational purposes;
- Protected through appropriate technical and organisational measures;
- Accessible only to authorised users;
- Retained only for as long as necessary;
- Continually reviewed to maintain compliance with evolving legislation and recognised security standards.
Protecting children's information is not treated as an additional feature or compliance exercise. It forms part of every decision made throughout the design, development and operation of the Edvolve platform.
3. Security by Design
Security is considered from the earliest stages of product development rather than being added after features have been created.
Every new feature, service and system change is assessed to ensure appropriate security controls are incorporated before release. This approach helps reduce risk, minimise vulnerabilities and maintain the confidentiality, integrity and availability of school data.
Our Security by Design principles include:
- Secure software development practices;
- Encrypted communication between devices and servers;
- Role-based access controls;
- Principle of least privilege;
- Secure authentication and password management;
- Regular security updates and platform maintenance;
- Ongoing monitoring of infrastructure and services;
- Secure cloud hosting within the United Kingdom.
Security is continually reviewed throughout the lifecycle of the platform to ensure it remains appropriate as the product evolves.
4. Security by Design in Practice
Security forms part of every stage of the Edvolve development lifecycle.
Rather than being applied after development has been completed, security requirements are considered during planning, software design, implementation, testing and ongoing maintenance.
Before a new feature is released, consideration is given to:
- Authentication requirements;
- Authorisation and user permissions;
- Data sensitivity;
- Visibility of personal information;
- Secure transmission of information;
- Audit and accountability requirements;
- Potential safeguarding implications;
- Risks associated with misuse or unauthorised access; and
- Ongoing maintenance throughout the feature lifecycle.
Only when these considerations have been assessed does functionality become available for production use.
5. Data Protection by Design and by Default
Edvolve has been developed in accordance with the principles of Data Protection by Design and by Default, as required under Article 25 of UK GDPR and supported by guidance issued by the Information Commissioner's Office.
Privacy considerations are incorporated into product planning, system architecture and software development from the outset, ensuring personal information is appropriately protected before any feature becomes available to schools.
Where appropriate, Edvolve applies the following principles:
- Personal information is collected only where necessary;
- Users are provided access only to information relevant to their role;
- Privacy settings are designed to protect information by default;
- Data sharing is restricted to authorised users;
- Personal information is protected throughout its lifecycle;
- Access to sensitive information is controlled, monitored and reviewed.
By embedding privacy into the design of the platform, schools can be confident that data protection forms part of everyday operation rather than relying solely on administrative controls.
6. Children's Privacy
Children's privacy receives particular consideration throughout the design and operation of Edvolve.
The platform has been developed to support schools in delivering educational services while ensuring that children's personal information is processed responsibly, securely and only where appropriate.
Edvolve does not collect personal information from children for advertising, behavioural profiling or commercial marketing purposes. Personal information is processed solely to support the educational, safeguarding, communication and operational requirements of the subscribing school or trust.
Access to student information is strictly controlled through role-based permissions, ensuring that staff, parents and students can only view information appropriate to their role and relationship with the school.
Where schools provide pupil access to Edvolve, information presented to pupils is limited to the services made available by the school, such as homework, timetables, attendance information, behaviour records, school news and secure communication where enabled.
Protecting children's privacy remains a fundamental principle throughout the platform and continues to inform future product development.
7. Data We Process
Edvolve has been designed to support the day-to-day operation of schools, academies and multi-academy trusts. The platform only processes personal information required to provide the services requested by each organisation.
Depending on the features a school chooses to use, this may include information relating to:
- Students;
- Parents and guardians;
- Teaching staff;
- Administrative and support staff;
- Governors and trustees, where applicable; and
- Other authorised users of the platform.
Information processed may include identity information, contact details, attendance records, behaviour information, assessment data, communication history, timetable information, school administration records and other information necessary to support educational delivery and school operations.
Edvolve does not collect personal information that is unnecessary for the services being provided, nor is personal information collected for advertising, behavioural profiling or commercial marketing purposes.
8. Data Minimisation
Edvolve follows the principle of collecting only the personal information necessary to deliver the services required by each school.
Before new functionality is introduced, consideration is given to:
- Whether personal information is genuinely required;
- The minimum information needed for the feature to operate;
- Which users should have access;
- Whether information should be editable or read-only;
- How long information should be retained; and
- Whether additional safeguards are required because of the sensitivity of the information.
This approach helps reduce unnecessary data collection while ensuring schools have access to the information required to fulfil their educational, operational and safeguarding responsibilities.
9. Data Protection by Design in Practice
Privacy considerations are embedded into the design of Edvolve from the earliest stages of product development.
Every feature is reviewed to ensure that:
- Personal information is only processed where necessary;
- Users are presented with information appropriate to their role;
- Privacy settings protect information by default;
- Data sharing is appropriately restricted;
- Information remains accurate and up to date where maintained by authorised users; and
- Appropriate organisational and technical safeguards are applied throughout the lifecycle of the data.
By incorporating these principles into the design process, privacy becomes an integral part of the platform rather than relying solely on administrative procedures.
10. Access Control and Permissions
Access to information within Edvolve is controlled through role-based permissions designed to ensure users only have access to information relevant to their responsibilities.
Depending on their authorised role, users may include:
- School leadership;
- Teaching staff;
- Administrative staff;
- Pastoral staff;
- Parents and guardians;
- Students; and
- Other authorised school users.
Permissions are assigned by authorised school administrators and can be updated as staff responsibilities change.
Edvolve follows the principle of least privilege, meaning users receive the minimum level of access required to perform their role.
11. Encryption and Secure Infrastructure
Edvolve applies multiple layers of technical security to protect information throughout its lifecycle.
These measures include:
- Encryption of data transmitted between user devices and the platform using industry-standard TLS encryption;
- Secure hosting within professionally managed United Kingdom cloud infrastructure;
- Authenticated access to administrative services;
- Secure password storage using industry-recognised hashing techniques;
- Routine security updates and software maintenance;
- Infrastructure monitoring; and
- Regular backup procedures designed to support service resilience and recovery.
- Security controls are reviewed as the platform evolves to ensure they remain appropriate against emerging threats.
12. Data Storage and Retention
Personal information is retained only for as long as necessary to support the educational, operational and legal requirements of each subscribing school or trust.
Retention periods are determined according to:
- Applicable legislation;
- Regulatory guidance;
- School requirements;
- Contractual obligations; and
- Legitimate operational needs.
Where information is no longer required, appropriate procedures are followed to ensure it is securely removed or anonymised where appropriate.
Schools remain responsible for determining appropriate retention periods for the information they control as Data Controllers.
13. Data Controllers and Data Processors
Edvolve operates under the data protection framework established by UK data protection legislation.
In most circumstances:
- The subscribing school, academy or multi-academy trust acts as the Data Controller; and
- AppyHive Ltd. acts as the Data Processor on behalf of the subscribing organisation.
This distinction ensures that responsibilities for personal information remain clearly defined throughout the use of the platform.
The Data Controller
The subscribing school or trust determines:
- What personal information is collected;
- Why the information is processed;
- Which Edvolve services are used;
- Who is authorised to access information;
- How long information should be retained;
- The lawful basis for processing personal information; and
- How requests relating to individual rights are managed.
Schools remain responsible for ensuring their use of Edvolve complies with their own statutory and regulatory obligations.
Data Processor
As Data Processor, AppyHive Ltd processes personal information only on the documented instructions of the subscribing school or trust.
Our responsibilities include:
- Processing personal information securely;
- Maintaining appropriate technical and organisational security measures;
- Protecting the confidentiality of information;
- Supporting schools in meeting their data protection obligations where required;
- Assisting with security incidents affecting the platform;
- Ensuring authorised personnel are subject to appropriate confidentiality obligations; and
- Maintaining appropriate agreements with approved sub-processors where applicable.
AppyHive Ltd does not determine how schools use personal information, nor does it use school data for advertising, profiling or commercial marketing purposes.
14. Individual Rights
Edvolve supports schools in meeting their obligations under UK data protection legislation by enabling the secure management of personal information throughout the platform.
Individuals may have rights including:
- The right to be informed;
- The right of access;
- The right to rectification;
- The right to erasure, where applicable;
- The right to restrict processing;
- The right to object to processing, where applicable; and
- Rights relating to automated decision-making where relevant.
As Data Controller, the subscribing school is responsible for responding to requests relating to these rights.
Where appropriate, AppyHive Ltd will provide reasonable assistance to schools in fulfilling those obligations.
15. Incident Management and Security Monitoring
Protecting personal information requires ongoing monitoring as well as preventative security measures.
Edvolve maintains procedures designed to:
- Monitor platform availability and security;
- Identify potential security events;
- Investigate suspected incidents;
- Apply security updates where appropriate;
- Reduce the likelihood of recurring issues; and
- Support schools where a platform-related security incident requires investigation.
Where a personal data breach affecting the platform is identified, AppyHive Ltd will notify the affected Data Controller without undue delay and provide appropriate information to support their statutory reporting obligations.
16. Accountability and Governance
Security and data protection are ongoing responsibilities rather than one-off compliance exercises.
AppyHive Ltd. maintains documented policies, procedures and operational controls designed to support continuous compliance with applicable legislation and recognised good practice.
These include:
- Regular policy review;
- Ongoing platform maintenance;
- Security monitoring;
- Risk-based decision making;
- Supplier and infrastructure oversight;
- Change management throughout the software development lifecycle; and
- Continuous improvement informed by legislation, guidance and emerging security risks.
Where appropriate, Data Protection Impact Assessments (DPIAs) are undertaken for new processing activities that present a higher risk to the rights and freedoms of individuals.
17. Continuous Improvement
The education sector, technology landscape and regulatory environment continue to evolve.
AppyHive Ltd. regularly reviews the Edvolve platform to ensure security, privacy and operational controls continue to reflect recognised best practice and the changing needs of schools.
This includes reviewing:
- Legislative changes;
- Information Commissioner's Office guidance;
- Platform security;
- Product functionality;
- Customer feedback;
- Emerging threats; and
- Opportunities to strengthen privacy and security throughout the platform.
Our commitment to Security by Design and Data Protection by Design and by Default is not limited to the initial development of Edvolve. These principles continue to guide every stage of the platform's ongoing development.
Protecting personal information is not the responsibility of one organisation alone.
AppyHive Ltd provides the secure platform that schools rely on every day. Schools remain in control of how they use that platform and the information they choose to process. By working together, we help ensure that students, parents, staff and school communities can use Edvolve with confidence.
18. Contact Information
Questions relating to this policy or the processing of personal information within Edvolve should be directed to:
AppyHive Ltd
Email: team@appyhive.co.uk
Where an enquiry relates to personal information processed by a subscribing school or trust, individuals should contact the school directly in the first instance, as the organisation acting as Data Controller.
•••
•••••