Privacy Policy
How we collect, use and protect your data.
Last updated: 30 September 2026
This privacy policy is served by SimmaSend under the websites simmasend.com and app.simmasend.com. It explains how we control, process, handle and protect personal information when you use our service. If you do not agree with this policy, you may wish to stop using the service.
Policy key definitions
- “We”, “us”, “our” refer to SimmaSend, operated by James Ward.
- “You”, “the user” refer to the person or organisation using SimmaSend.
- “School” refers to the educational establishment (school, college or university) that subscribes to SimmaSend.
- “Teacher” refers to a member of staff who records feedback.
- “Student” refers to a pupil or student who receives feedback.
- UK GDPR means the UK General Data Protection Regulation. DPA 2018 means the Data Protection Act 2018. ICO means the Information Commissioner's Office.
Who we are and how to contact us
SimmaSend is operated by James Ward. We are registered with the ICO under registration reference ZC130082. For any privacy query, or to exercise your rights, contact us at hello@simmasend.com.
Who is the data controller?
For student, teacher and feedback data, the school is the data controller and SimmaSend is the data processor, processing personal data on the school's behalf under a Data Processing Agreement. The school decides how and why this data is processed; we act only on its documented instructions.
For our marketing site (the “get notified” sign-up form) and for administering the service (e.g. school administrator accounts and billing), SimmaSend is the controller for that limited data.
Key principles of the UK GDPR
We build on the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
What personal data we collect
School administrators
- Email address (used for magic-link sign-in and account identification)
- Name (used for display within the admin dashboard)
Teachers
- Name and subject (entered once on first use, stored in a browser cookie and in our database)
- Email address (required). Provided by a school administrator. Used to send magic-link sign-in emails, to notify the teacher when a student responds to their feedback, and for school communications.
- No password is stored. Teachers sign in using a single-use magic link sent to their email address.
Students
- First name and last name (entered by a school administrator)
- Email address (required). A school administrator provides a student's school- or university-issued email address. It is used only to notify the student that new feedback is available. Students do not create accounts, do not log in, and are not asked to provide their own details.
- Students access their feedback via a unique, unguessable URL embedded in a QR code. The URL contains a random access token that is separate from the student's internal record identifier and can be reissued at any time (see “How students access feedback” below).
Feedback data
- Audio recordings, video recordings, photographs and text feedback recorded by teachers
- AI-generated transcripts, summaries, titles, subject classifications and action points produced from the above
- Student text responses to feedback
Activity/audit log
- We keep an internal activity log recording certain administrative actions — for example administrator sign-ins, and deletions of feedback, teaching sets or schools — together with who performed them and when. Entries can include the acting user's email address and the relevant student, teacher or administrator identifiers. This log covers administrative actions only; we do not record routine viewing of feedback. It is used for security, troubleshooting and accountability.
Marketing site
- Email addresses submitted via the “get notified” form on simmasend.com, stored solely to send launch updates and never shared with any third party.
How we use your data and our lawful bases
Student, teacher and feedback data (SimmaSend as processor). We process this only on the school's documented instructions, to provide the feedback service. The lawful basis is determined by the school as controller — typically the performance of a public task (UK GDPR Article 6(1)(e)) for state-funded schools, or another appropriate basis for independent schools, colleges and universities. The school is responsible for identifying and recording its lawful basis; our DPA and DPIA support this.
Specifically:
- Administrator email addresses are used to send magic-link sign-in emails and to identify the admin.
- Teacher email addresses are used for magic-link sign-in, to notify a teacher when a student replies to their feedback, and for school communications.
- Teacher names and subjects are displayed alongside feedback so students know who left it and in which subject.
- Student names are displayed on their feedback dashboard and in the admin panel.
- Student email addresses are used solely to send a notification when new feedback is available. These notification emails contain no feedback content — no title, summary, action points or transcript — they simply prompt the student to log in and view their dashboard.
- Audio and video recordings are transcribed and summarised using OpenAI's Whisper and GPT-4o-mini APIs (see sub-processors and international transfers below).
- Feedback data is stored so students and teachers can retrieve it.
Marketing sign-ups (SimmaSend as controller). We use these email addresses to send launch and product updates. Our lawful basis is consent, given when you submit the form; you can withdraw it at any time by unsubscribing or emailing us. Marketing emails are also sent in line with the Privacy and Electronic Communications Regulations (PECR).
Service administration (SimmaSend as controller). We process administrator contact details to operate and support the service and manage our contract with the school. Our lawful basis is legitimate interests / performance of a contract.
Special category data
SimmaSend does not intentionally collect special category data (such as health, or information revealing a special educational need or disability). However, free-form feedback — audio, video or text recorded by teachers — could incidentally contain such information about a student. Where it does, responsibility for identifying an appropriate Article 9 UK GDPR condition (for example the conditions for education-related processing in Schedule 1 of the DPA 2018) rests with the school as controller. We provide guidance to schools on keeping feedback proportionate and relevant, and we support the school's DPIA.
Children's data
SimmaSend is designed for use in secondary schools, colleges and universities, and will process data relating to children. We take the ICO's Age Appropriate Design Code (“Children's Code”) into account:
- We minimise the data we hold on students to a name, a school-/university-issued email address, and feedback content.
- Students do not have accounts, are not profiled, and are not tracked. We use no analytics, advertising or tracking cookies anywhere on the service.
- Notification emails carry no feedback content.
- Access to a student's feedback requires their unique QR-code URL.
- If a student's access code is lost or shared, a school administrator can revoke and reissue it, immediately disabling the old code.
- We support schools in completing a Data Protection Impact Assessment (DPIA) before deployment.
How students access feedback
Students access their feedback via a unique, unguessable URL embedded in a QR code. This URL acts as the access token: anyone who has the link can view that student's feedback, so schools should treat each student's QR code and link as confidential. The token is random and cannot be guessed or enumerated.
If a code is shared or lost, a school administrator can reissue it immediately: the old link stops working at once, and the student's feedback history is unaffected. The token is separate from the student's internal record identifier, so reissuing it changes nothing else about their record.
The underlying media files (audio, video, photos) are never public — they are served only through server-generated signed URLs, valid for one hour, and only for media belonging to that student's own feedback record.
Third-party sub-processors
We use the following sub-processors to operate SimmaSend:
| Service | Purpose | Data accessed | Location / transfer safeguard |
|---|---|---|---|
| Supabase (on AWS) | Database and file storage | All application data | AWS eu-west-1 (Ireland, EEA) — within UK adequacy |
| Vercel | Website and application hosting | Request logs, IP addresses | USA — EU-US DPF incl. UK Extension (UK-US data bridge) |
| OpenAI | Audio transcription (Whisper) and text summarisation (GPT-4o-mini) | Audio/video recordings, generated transcripts | USA — SCCs + UK Addendum (OpenAI DPA) |
| Resend | Transactional email (magic links, feedback notifications) | Administrator, teacher and student email addresses | USA — EU-US DPF incl. UK Extension (UK-US data bridge) |
| Sentry | Error monitoring | Technical error data (personal data scrubbed before sending) | USA — EU-US DPF incl. UK Extension (UK-US data bridge) |
We do not sell, rent or share personal data with any other third parties. We have a data processing agreement in place with each sub-processor.
International transfers
Application data (database records and media files) is stored in the EEA (Ireland), which is covered by the UK's adequacy regulations. Some sub-processors are based in the USA. Where personal data is transferred to the USA, it is protected by an appropriate safeguard: reliance on the UK-US data bridge (the UK Extension to the EU-US Data Privacy Framework) for Vercel, Resend and Sentry, and the UK International Data Transfer Addendum to the EU Standard Contractual Clauses for OpenAI. Audio and video sent to OpenAI is used only to generate transcripts and summaries, is not used to train OpenAI's models (API data), and is retained by OpenAI for a short period for abuse monitoring before deletion.
Data storage and security
- All application data is stored in Supabase (AWS, eu-west-1).
- Audio and media files are held in a private Supabase Storage bucket. Access requires a server-generated signed URL valid for one hour, and media is only ever served for paths belonging to the requesting student's own feedback record.
- Each student's QR link uses a random access token stored separately from their internal record identifier. If a code is lost or shared, a school administrator can reissue it — the previous code stops working immediately, the student's feedback history is preserved, and the reissue is recorded in our audit log.
- The database is locked down so that it cannot be read directly: all access goes through our application servers, which check on every request that the person asking is entitled to the specific record. Each school's data is isolated from every other school's by these checks.
- Administrator sign-in uses single-use magic links (15-minute expiry) with a 24-hour session.
- Teacher identity is stored in an HTTP-only browser cookie (365-day expiry) containing an opaque token, not personal data directly.
- All connections use HTTPS/TLS encryption in transit.
- We monitor errors using Sentry, with personal data scrubbed from error reports before they are sent.
Data retention and deletion
- Feedback data is retained for as long as the school's SimmaSend account is active. Schools may optionally set an automatic retention period after which older feedback (and its media) is permanently deleted.
- When a school administrator deletes a student, or when a school account is deleted, all associated personal data and the underlying media files are permanently deleted from both the database and file storage.
- On termination of a school's account, we permanently delete all personal data processed on the school's behalf within 30 days (unless a data export is requested first), and confirm deletion in writing on request.
- Marketing email addresses are retained until the individual unsubscribes or requests removal.
Your rights under the UK GDPR
You have the right to: be informed; access your data; rectification; erasure; restriction of processing; data portability; to object; and not to be subject to solely automated decision-making. To exercise any of these rights over student, teacher or feedback data, contact your school (the controller); the school can also contact us for assistance. For marketing data, contact us directly at hello@simmasend.com. You also have the right to complain to the ICO (www.ico.org.uk).
Cookies
We use only essential cookies. For full details, see our Cookie Policy.
Changes to this policy
We may update this policy from time to time. The “last updated” date above shows when it last changed.
Contact
Questions about this policy? Email hello@simmasend.com.