Skip to content
LessonBrief

Data Processing Terms

Last updated: 11 July 2026

When you record information about your students, you are the data controller and LessonBrief is your processor. These terms set out how we handle that data on your behalf, and form part of our Terms of Service.

When these terms apply

These Data Processing Terms apply when you use LessonBrief to handle information about your students. They explain how we process that information on your behalf under UK data protection law (the UK GDPR and the Data Protection Act 2018), and they form part of our Terms of Service. If anything here conflicts with the rest of the Terms, these terms apply to your students' personal data.

Our roles

For the information you enter about your students, you are the controller (you decide what to record and why) and we are your processor (we handle it only to provide the service, on your instructions). For your own account information — such as your sign-in email — we are the controller, as described in our Privacy Policy.

What we process, and why

  • Subject matter and purpose: providing the service — turning the notes you enter into drafts and keeping a per-student history for you.
  • Duration: for as long as your account is open, until you delete the data or your account.
  • Types of data: the student labels (initials or nicknames), coarse teaching context, lesson notes, drafts and related records you choose to enter.
  • Categories of people: the students and lessons you record.

We act only on your instructions

We process your students' data only to provide the service to you and as the law requires. Your use of the features is your instruction to us. We will not use that content for our own purposes, will not sell it, and — as explained in the Privacy Policy — do not send it to any third-party AI provider or use it to train AI models.

If we consider that one of your instructions would breach UK data protection law, we will tell you.

Your responsibilities

As the controller, you are responsible for having a proper lawful basis for processing a child's data (usually your tutoring arrangement with their parent or guardian), for giving any privacy information your own arrangements require, and for keeping what you enter to a minimum. You agree to follow the minimisation rules in our Acceptable Use Policy — initials not full names, and no health, diagnosis, contact or other sensitive details.

Confidentiality and security

We keep your students' data confidential and protect it with appropriate technical and organisational measures — including database-level row isolation with a default-deny rule so no other user can see your data, encryption in transit, server-only secret keys, and rate-limiting and bot-protection to reduce abuse.

Anyone we authorise to process your students' data is bound by a duty of confidentiality.

Sub-processors

We use a small number of trusted suppliers to run the service — currently our database and auth provider (Supabase), our host (Vercel), our bot-check provider (Cloudflare) and, where enabled, our error-diagnostics provider (Sentry). They are listed with their roles in our Privacy Policy. We impose data-protection obligations on each sub-processor that are equivalent to those in these terms, and we remain fully liable to you for each sub-processor's performance of its obligations. If we change our suppliers in a way that affects your students' data, we will update that list and you may object.

Transfers outside the UK

Where a supplier processes data outside the United Kingdom, that transfer is protected by appropriate safeguards, such as the UK's International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses, or an equivalent approved mechanism.

Helping you meet your obligations

Taking into account the nature of the service, we will help you respond to requests from the people whose data you hold, and assist with your security, breach-handling and impact-assessment duties. Because you control your data directly, you can satisfy most requests yourself using the export and delete tools in Settings.

If there is a personal-data breach

If we become aware of a breach affecting your students' personal data, we will notify you without undue delay and give you the information you reasonably need to meet your own obligations. Contact us at any time at lessonbrief@proton.me.

Returning or deleting your data

You can export all of your data as a JSON file, and permanently delete your account and all associated data, at any time from Settings. When you delete data or your account, it is removed from the live service; any residual copies in routine encrypted backups age out on their normal cycle.

Demonstrating compliance

We will make available the information you reasonably need to show that we are meeting these terms. Given the size of the service, that will normally be by answering your questions in writing rather than by on-site audit. Email us at lessonbrief@proton.me.

Liability and changes

Except for our responsibilities under data protection law and to our sub-processors set out above — which the law does not allow us to limit in this way — these Data Processing Terms are subject to the limits of liability in our Terms of Service. We may update these terms as the service and the law develop; the date above shows the latest version.