Privacy Policy (UK GDPR)
Last updated: May 2026
1. Introduction
Primary Solutions is committed to protecting personal data and respecting privacy. This Privacy Policy explains how we collect, use, share and protect personal data when you use our websites, ordering pages and educational platform (the “Services”).
We process personal data in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
2. Who we are (Contact Details)
Organisation: Primary Solutions
Address: Kimberley House, Church Road, Copthorne, RH10 3RA
Email: contact@primarysolutions.info
If you have questions about this Privacy Policy or how we use personal data, please contact us using the details above.
3. Key definitions
“Personal data” means any information relating to an identified or identifiable person.
“Controller” means the organisation that decides why and how personal data is processed.
“Processor” means an organisation that processes personal data on a Controller’s behalf.
4. Controller / Processor roles when used by schools
Where our educational platform is used by a school, the school will generally be the Data Controller for student personal data and Primary Solutions will act as a Data Processor on the school’s behalf (UK GDPR Article 28).
For teacher-initiated purchases and billing administration, Primary Solutions may act as an independent Data Controller for order and billing data.
5. Data hosting and system separation
Our Services are designed with strict separation between (a) student educational platform data and (b) ordering/payment data.
Student account data (educational platform): All student account data (including names/identifiers, usernames and platform activity) is hosted exclusively on secure servers located in Germany. This environment is provided by Hetzner Online GmbH. Encrypted backup copies of platform data are also stored off-site using an encrypted backup system. These backups are encrypted before transfer and no unencrypted personal data is stored outside the primary hosting environment.
Ordering and payment data: Ordering functionality is provided via Wix. Payments may be processed via Wix and PayPal. The ordering system is used for teacher purchases and billing only. Student platform accounts are not processed or stored within the ordering system.
6. The personal data we collect
Depending on how you use the Services, we may collect the following categories of personal data:
A) Teachers / School Staff
-
Name
-
School email address
-
School name and organisation details
-
Account credentials (e.g., hashed passwords)
-
Support communications
-
Order and billing information (teacher purchases)
B) Students (accounts created by teachers)
-
Student name or school identifier (as entered by the school/teacher)
-
Username / login identifier
-
Platform usage/activity data (e.g., progress, interactions, timestamps)
C) Technical and usage data
-
IP address (typically captured temporarily for security and fraud prevention)
-
Device and browser information
-
Log data (date/time of access, pages viewed, error logs)
We do not intentionally collect special category data (such as health data, ethnicity, religion) and ask schools not to enter such data into the platform unless expressly agreed.
7. Purposes of processing and lawful bases (UK GDPR Article 6)
We process personal data for the following purposes and on the following lawful bases:
-
To provide and operate the educational platform (Article 6(1)(b) contract / and school’s instructions where we are Processor).
-
To create and manage teacher and student accounts (Article 6(1)(b) / Article 6(1)(f) legitimate interests in providing a secure service).
-
To provide customer support and respond to enquiries (Article 6(1)(b) and/or Article 6(1)(f)).
-
To process orders and manage billing for teacher purchases (Article 6(1)(b) contract; Article 6(1)(c) legal obligation for record-keeping where applicable).
-
To secure and maintain the Services, prevent misuse and investigate incidents (Article 6(1)(f) legitimate interests).
-
To use analytics cookies on certain parts of our websites (such as ordering or marketing pages) where you consent (Article 6(1)(a) consent; and PECR where applicable). For student data processed on behalf of a school, the school determines the relevant lawful basis as Controller.
8. Google Analytics
We may use Google Analytics to understand how certain parts of our websites (such as ordering or marketing pages) are used and to improve user experience. The educational platform itself does not use Google Analytics or any tracking technologies.
Analytics cookies are used only where consent has been given via our cookie banner. Where analytics are enabled on some parts of our domain but not others, this Privacy Policy applies to any areas where Google Analytics is active.
Google may process data outside the UK. Where this occurs, appropriate safeguards are used in accordance with UK GDPR (see International Transfers section).
9. Cookies and similar technologies
The educational platform uses only strictly necessary cookies required for authentication, security and core functionality.
Analytics cookies (e.g., Google Analytics) may be used on certain parts of our websites (such as ordering or marketing pages), and only where you provide consent via a cookie banner.
You can manage cookie preferences via our cookie banner and your browser settings. A separate Cookie Policy may be provided on our website.
10. Sharing of personal data (Recipients)
We do not sell personal data.
We may share personal data with trusted service providers (“sub-processors”/processors) only as needed to deliver the Services, such as:
-
Hetzner Online GmbH (Germany) – hosting of the educational platform and student data
-
Wix – teacher ordering/checkout pages (ordering/billing data only)
-
PayPal – payment processing (payment transaction data)
-
Encrypted cloud storage providers (e.g. Google Drive) – used solely for storing encrypted backup data. These providers do not have access to unencrypted personal data.
We may also share information with professional advisers and with authorities where required by law.
11. International transfers
Student educational platform data is hosted in Germany (EU) for platform operation.
Ordering, payment and analytics providers may process certain data internationally. Encrypted backup data may also be stored using cloud storage providers outside the UK/EU. All backup data is encrypted prior to transfer and remains inaccessible without the encryption key, which is retained solely by Primary Solutions. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as UK adequacy regulations and/or approved contractual protections (e.g., Standard Contractual Clauses/UK Addendum) where applicable.
12. Data retention
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, including legal, accounting, or reporting obligations.
Typical retention approach:
-
Teacher accounts: for the duration of the school’s use of the Services, then deleted or anonymised on request or termination (subject to legal obligations).
-
Student accounts: retained under school control and deleted on request or on contract termination (typically within 30 days), unless otherwise instructed by the school.
-
Order and billing records: retained as required for financial record-keeping and tax purposes.
-
Security logs: retained for limited periods for security monitoring and incident investigation.
13. Security
We implement appropriate technical and organisational measures designed to protect personal data, including:
-
HTTPS/TLS encryption in transit
-
Role-based access controls and least-privilege administration
-
Secure EU-based hosting for student platform data
-
Regular updates and monitoring
-
Separation of student platform systems from ordering systems
-
Encrypted off-site backups with client-side encryption (data encrypted before leaving the server)
14. Data subject rights
Under UK GDPR, individuals have rights including: access, rectification, erasure, restriction, objection, data portability, and the right to withdraw consent (where consent is the lawful basis).
Where we act as a Processor for student data, we will support the school (Controller) to respond to rights requests and may direct requests to the relevant school.
15. Complaints
You have the right to lodge a complaint with the UK supervisory authority: the Information Commissioner’s Office (ICO).
ICO website: https://ico.org.uk (provided for convenience).
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version will be published on our website and the ‘Last updated’ date will be amended.