Privacy Policy

This policy covers use the Chalk Learning web platform, a not-for-profit enterprise by Poteris. Chalk Learning is a trading name of Poteris Ltd, hereafter referred to as "we".

Privacy and Data Protection

We provide an online platform that is for use by teachers, educators and others to generate visual learning materials. This Privacy and Data Protection Notice explains the data we collect, how we use it and how we keep it secure through our systems.

We process personal data so that we can deliver our programme effectively, evaluate impact and work towards our vision of making learning accessible to all.

By processing data, we act as a Data Controller and are registered with the Information Commissioner's Office (ICO).

We will use personal data in accordance with this Privacy and Data Protection Notice, complying with current data protection law and taking safeguards to ensure all personal data is encrypted to keep it safe.

We reserve the right to update our Privacy and Data Protection Policy in line with our charitable goals. If users have any questions or concerns relating to this Privacy and Data Protection Notice, they are encouraged to get in touch at [email protected].

Legal Basis for Processing Personal Data

The basis for processing user data is consent, contractual and/or legitimate interest.

Contractual Requirement

Without the personal data which our users consent for us to use, we would not be able to offer them our services.

Consent

Our users consent for us to process their personal data through an explicit opt-in when registering. By doing so, registered users agree to our use of personal data as outlined in this document. We may also offer users the option to consent to us using their data in additional ways, such as sharing resources with other users.

Legitimate Interest

This is where we have a legitimate reason to process personal data provided that it is reasonable and does not go against what users would reasonably expect from us. Where we rely on legitimate interest to process personal data, our legitimate interest is:

  • Maintaining records of activity on the site for the purpose of protecting against abuse
  • For monitoring and evaluating the impact of the programmes
  • Contacting users to seek consent where needed
  • Contacting potential partners where we have closely aligned goals

Data Collection and Processing

Chalk collects information in the following ways:

  • Users may give us their personal details directly, such as when registering on the site, via our website or engaging with us via social media
  • We may collect information from another source such as directly from a school or another partner organisation
  • We collect usage information from those registered on the site
  • We collect information from users' use of our website. Like all organisations we are able to see details of the user's web browser, operating system, and geographical region, among other details. We may use this information to improve the services we offer. Please also refer to our Cookies information below.
  • We use tracking pixels and analytics tools (including Facebook Pixel) to understand how users interact with our website, measure the effectiveness of our advertising campaigns, and improve our marketing efforts

Using Collected Data

We store the minimal amount of data for us to run our service effectively. In order to provide the best service to our users, we use data in the following ways:

  • To administer the service
  • To evaluate, improve and personalise our service
  • To engage current and potential funders with opportunities to support our work and make what we do possible
  • To carry out research in line with our charitable goals
  • To allow us to communicate with users and respond to enquiries
  • To undertake due diligence and manage risks
Data collectedHow we use the data
Name / EmailTo administer the user's account and contact the user in relation to their account
Use of the serviceUsage information is used in aggregate to monitor and improve the service

Keeping data secure

Our platform is hosted on Vercel and Supabase, and information is stored there. The services are ISO27001 or SOC 2 compliant. The data is encrypted.

This may include in spreadsheets and word processing documents as well as subprocessing via the services listed below. All systems are password protected and restricted to relevant users, and staff laptops are encrypted so that loss would not be expected to result in loss of user data. We operate in a generally paperless environment and do not print documents containing personally identifiable information.

We will only store user data for as long as is necessary and in line with the original purpose that it was collected.

Subprocessors

To be notified of updates to the list of subprocessors, users can register using the form at the bottom of the page.

ServicePrivacy policyUsed for
SupabasePrivacy PolicySite hosting
AWSPrivacy PolicySite hosting
GooglePrivacy PolicyAI model
Eleven LabsPrivacy PolicyAI model
OpenAIPrivacy PolicyAI model
AnthropicPrivacy PolicyAI model
Google WorkspacePrivacy PolicyAuthentication
PineconePrivacy PolicySite hosting
Together AIPrivacy PolicyAI Model
StripePrivacy PolicyPayments
VercelPrivacy PolicySite Hosting
Mail ChimpPrivacy PolicyEmail Platform
Facebook/MetaPrivacy PolicyAdvertising Analytics

Sharing Data

We will keep personal information confidential and not sell or disclose information to advertisers or external parties, except where users have explicitly given permission to do so.

There are some unlikely circumstances in which we would be required to share data without requesting explicit permission from the user. These include if we believe in good faith that we are required to in order to comply with a regulator or court in order to comply with law, regulation, legal process and court order. We may also share information in order to enforce terms of the contract.

We share aggregated usage information in relation to our platform. We also release non personally identifiable aggregated data.

Rights of the Data Subject

The Right to be Forgotten

We will remove or anonymise personal data within 30 days of any request to be removed.

Anonymising data means that any information that is not deleted can no longer be traced back to the person it came from. We would do this if we wanted to keep usage information to better understand the performance of our service. All personally identifying data would be scrubbed and data would be aggregated where applicable.

Data Retention

We will retain personal data only for as long as is necessary for the purpose we collect it.

Changes to this Policy

We will notify users when this Privacy and Data Protection notice changes and provide a jargon-free summary of the changes. In order to receive notification of changes users should register at the bottom of this page.

Right of Access to Data

We will provide users with a copy of their personal data stored with us within 30 days of any request.

Restriction of Processing

We will document, process and respond to any restriction of process request users make.

Data Portability

Our platform is unique and there is no common format for personal data if a user wanted to change educational platforms. If and when a common format is agreed, we will ensure user's data is available in that format.

Incident Response

Any data breach will be reported to appropriate authorities within 72 hours of the breach being found, and we will liaise fully with appropriate authorities to respond to the breach.

Cross Border Data Transfer

Our primary structured data systems that users access are located in the UK. Unstructured data storage is either in the EU or covered by the Data Privacy Framework, an adequacy decision, or Standard Contractual Clauses.

Complaints or Queries

We will always encourage all users to contact [email protected] if they have any questions about personal data.

Cookies

Cookies are small text files that are placed onto a device when users first visit a website which monitors interactions with the site.

We use cookies to:

  • Recognise you when you return.
  • Keep you logged in.
  • Embed content hosted by third parties.
  • Provide a support chat service (coming soon).
  • Improve your experience on our websites through monitoring content and feature usage.
  • Track advertising effectiveness and user behavior through Facebook Pixel and similar technologies.

There are four categories of cookies we set:

  • Necessary cookies – these cookies are necessary for the website to function properly. Some of the following actions can be performed by using these cookies: keeping you logged in; serving video content we host on Vimeo; storing your cookie consent preferences.
  • Performance cookies – these cookies are used to gather statistical information about the use of our websites, also called analytics cookies. We use this data for performance and website optimisation.
  • Functional cookies – These cookies enable more functionality for our website visitors, and can be set by our external service providers or our own website. The following functionalities may or may not be activated when you accept this category: support live chat; social media content feeds and sharing.
  • Advertising cookies – These cookies are used to track user behavior across websites for advertising purposes. We use Facebook Pixel and similar technologies to measure the effectiveness of our advertising campaigns, understand user interactions, and provide relevant advertising experiences.

The full list of cookies we use across our sites can be viewed via the cookie information panel on our website.

Marketing and Outreach

To work towards our goals, we may reach out to other organisations and public bodies. We do this only where we see necessary and have balanced our needs with the interests of those receiving the direct communications. We may contact those we believe have closely aligned aims, and schools and other educational establishments where we believe we can support their learners and help toward our goals. Our database is reviewed regularly, and contacts are removed where necessary. We also respect the rights of our contacts to withdraw their details in accordance with our data storing processes.

Other marketing materials and updates require opt-in consent from the contact.

Subscribe for notification of changes

* indicates required

Queries

If you have any questions or queries about our data privacy, please get in touch at [email protected]