MarkMate‑BTEC Privacy & Data‑Protection Policy

Effective Date: 30 May 2025

1. Who we are

MarkMate‑BTEC ("we", "us", "our") is an AI‑powered assessment platform that helps educators grade and give feedback on BTEC coursework.

Controller: MarkMate‑BTEC Ltd, registered in England & Wales, company no. [NUMBER].

Address: [REGISTERED OFFICE].

Data‑Protection Officer (DPO): [NAME], dpo@markmate-btec.com.

2. Scope of this notice

This notice explains how we collect, use, share, store and secure personal data in accordance with the UK GDPR, EU GDPR and the Data Protection Act 2018.

3. What data we collect

CategoryExamplesLawful basis*
Account dataName, e‑mail, role, school/centre, password hashContract
Student work & metadataCoursework text, marks, feedback comments, learner IDsLegitimate interest / Contract (processor)
Usage dataIP address, device type, log files, click‑streamLegitimate interest
Payment dataBilling contact, VAT no., last 4 digits of card, invoicesContract / Legal obligation
Marketing prefsNewsletter opt‑in, event registrationsConsent

*Art 6(1)(a–f) GDPR.

4. How we collect data

  • Directly from you (sign‑up forms, file uploads).
  • Automatically through cookies and similar tech. See § 11.
  • From your institution if they provision your account.

5. How use your data

  • Provide the service – create accounts, run AI‑marking, generate feedback.
  • Improve & secure – debug, monitor abuse, train non‑personalised algorithms.
  • Comply with law – bookkeeping, tax, safeguarding.
  • Inform you – product updates, webinars (you can opt‑out anytime).

6. Student data: our processor role

When teachers upload student work, the school/college remains the Data Controller. MarkMate‑BTEC acts solely as a processor and:

  • processes learner data only on written instructions;
  • implements appropriate technical and organisational security;
  • never uses learner data for marketing or independent profiling;
  • enables the school to meet subject‑access or erasure requests within 30 days.

A separate Data‑Processing Addendum (DPA) is available on request.

7. Children & Age‑Appropriate Design

The platform is designed for educators, but inevitably processes children's data. We follow the ICO's Children's code best‑practice for ed‑tech services, including high‑privacy defaults and no behavioural advertising.

8. Data retention

Data setRetention rule
Teacher accountsLife of contract + 24 months of inactivity
Student uploads90 days after grading (configurable per centre)
Logs12 months, then anonymised
Financial records 7 years (HMRC)

9. Sharing & international transfers

We never sell personal data. We share it only with:

  • Cloud hosting – AWS eu‑west‑2 (London) & backup in eu‑central‑1 (Frankfurt).
  • Customer‑support SaaS – Intercom, EU data‑centre.
  • Payment processor – Stripe, which relies on UK Binding Corporate Rules.

If data moves outside the UK/EEA, we rely on UK Addendum + EU Standard Contractual Clauses (SCCs).

10. Your rights

Under GDPR you can: access; rectify; erase; restrict; data‑port; object; and withdraw consent. To exercise any right, email privacy@markmate-btec.com. You also have the right to complain to the ICO (www.ico.org.uk, tel 0303 123 1113).

11. Cookies & similar technologies

We use:

  • LoCloud hosting – AWS eu‑west‑2nEssential – session management, CSRF protection (markmate_session).
  • Analytics – understand feature usage (_ga, Google Analytics 4, IP‑anonymised).
  • Support chat – real‑time help (intercom‑id‑*).

On your first visit we display a banner asking for consent to non‑essential cookies. You can adjust settings anytime at Cookie Preferences.

12. Automated decision‑making

Our AI provides grading suggestions only. Final marks remain under the teacher's control, so no solely automated decisions with legal or similar significant effect are made.

13. How we secure data

  • TLS 1.3 in transit, AES‑256 at rest.
  • ISO 27001‑certified hosting.
  • Role‑based access; MFA for staff; annual penetration tests.
  • Incident‑response plan with 72‑hour breach notification.

14. Changes to this notice

We may update this notice periodically. Material changes will be emailed to registered users at least 14 days before they take effect.