Privacy Policy

Last updated: January 2026

1. Who We Are

Novi provides focus mode management software for secondary schools. We are the data processor acting on behalf of schools (the data controllers) under UK GDPR.

2. What Data We Collect

We collect the following data about students:

Data TypePurposeLegal BasisName & EmailAccount identificationPublic task / Legitimate interestsSchool & Year GroupClass organisationPublic taskFocus session recordsTrack focus timePublic taskTimetableSchedule focus sessionsPublic taskAttendance recordsSchool administrationPublic task

We do NOT collect:

  • Location data (timetable/attendance are NOT location tracking)

  • Biometric data

  • Health data

  • Social media accounts

  • Photos or videos

3. Legal Basis for Processing

We process student data under:

  • Article 6(1)(e) - Public task (schools' educational function)

  • Article 6(1)(f) - Legitimate interests (school administration)

We do NOT rely on consent from children. Schools authorise data processing as part of their educational duties.

4. How We Use Your Data

  • Managing focus mode sessions during school hours

  • Providing teachers with class focus metrics

  • Generating focus statistics for students

  • School administration

5. Data Sharing

We share data with:

  • Firebase/Google Cloud (sub-processor) - Data stored in UK (europe-west2)

  • Your school - Teachers and administrators

We do NOT:

  • Sell your data

  • Share with advertisers

  • Use data for marketing

  • Transfer data outside the UK/EEA

6. Data Security

  • All data encrypted at rest (AES-256)

  • All data encrypted in transit (TLS 1.3)

  • Data stored in UK data centres only

  • Access controls and audit logging

  • Annual security reviews

7. Data Retention

  • Active student data: Retained while enrolled

  • After leaving school: Deleted within 30 days of school request

  • Audit logs: Retained for 7 years (legal requirement)

8. Your Rights (UK GDPR)

You have the right to:

  • Access your data (via your school)

  • Rectify incorrect data

  • Erase your data ("right to be forgotten")

  • Restrict processing

  • Data portability (receive your data)

  • Object to processing

To exercise these rights, contact your school. Schools can use the Novi admin panel to export or delete your data.

9. Children's Privacy

We comply with the UK Children's Code (Age Appropriate Design Code):

  • Minimal data collection

  • High privacy by default

  • No profiling for marketing

  • No nudge techniques

  • Clear, age-appropriate information

10. Complaints

If you're unhappy with how we handle your data:

  1. Contact us at privacy@getnovi.co.uk

  2. Contact your school's Data Protection Officer

  3. Contact the ICO: ico.org.uk

11. Changes to This Policy

We may update this policy. Schools will be notified of material changes.