Skip to content
PupilDB PupilDB

Security & data protection

Your pupils’ data, handled properly

You’re trusting us with information about children. Here’s exactly how PupilDB looks after it today, and what we’re adding next. No vague promises.

In place today

How PupilDB protects your data

  • Hosted in the EU

    PupilDB runs on Amazon Web Services (AWS) in the EU, in Ireland.

  • Role-based access

    Administrators manage the system. Teachers see only the timetable and registers they need.

  • Passwords never stored in plain text

    Passwords are stored as salted hashes, so nobody can read them, including us.

  • Sign-ins expire

    Sign-in tokens expire and have to be renewed, and administrators can remove a user’s access at any time.

  • Archive, don’t delete

    Pupils and staff who leave are archived, not deleted, so records stay intact.

  • Email delivery tracking

    Every email PupilDB sends is logged with its delivery status.

Coming next

These are on our public roadmap. They’re not available yet.

  • PlannedTwo-factor sign-in
  • PlannedChange history on every record
  • PlannedFiner-grained user permissions

Questions from your data protection officer?

Schools and local authorities often need details for their own checks. Get in touch and we’ll answer your questions about how PupilDB stores and protects data.

Where is our data stored?

PupilDB is hosted on Amazon Web Services (AWS) in the EU, in Ireland. The UK recognises the EU as providing adequate data protection, so no extra transfer paperwork is needed under UK GDPR.

See PupilDB with your own eyes

Book a friendly, no-pressure demo. We’ll show you registers, timetables and pupil records, and answer your questions in plain English.