Security & data protection
Your pupils’ data, handled properly
You’re trusting us with information about children. Here’s exactly how PupilDB looks after it today, and what we’re adding next. No vague promises.
In place today
How PupilDB protects your data
-
Hosted in the EU
PupilDB runs on Amazon Web Services (AWS) in the EU, in Ireland.
-
Role-based access
Administrators manage the system. Teachers see only the timetable and registers they need.
-
Passwords never stored in plain text
Passwords are stored as salted hashes, so nobody can read them, including us.
-
Sign-ins expire
Sign-in tokens expire and have to be renewed, and administrators can remove a user’s access at any time.
-
Archive, don’t delete
Pupils and staff who leave are archived, not deleted, so records stay intact.
-
Email delivery tracking
Every email PupilDB sends is logged with its delivery status.
Coming next
These are on our public roadmap. They’re not available yet.
- PlannedTwo-factor sign-in
- PlannedChange history on every record
- PlannedFiner-grained user permissions
Questions from your data protection officer?
Schools and local authorities often need details for their own checks. Get in touch and we’ll answer your questions about how PupilDB stores and protects data.
Where is our data stored?
PupilDB is hosted on Amazon Web Services (AWS) in the EU, in Ireland. The UK recognises the EU as providing adequate data protection, so no extra transfer paperwork is needed under UK GDPR.
See PupilDB with your own eyes
Book a friendly, no-pressure demo. We’ll show you registers, timetables and pupil records, and answer your questions in plain English.