Privacy Policy

JWE Portal · last updated 25 September 2026

1. Who we are

This portal is operated by James Wallace Education Ltd ("we", "us", "our"), a company registered in England and Wales, company number 17479328, whose registered office is 71–75 Shelton Street, Covent Garden, London WC2H 9JQ.

Our role depends on how the provision is commissioned. Where provision is commissioned by a local authority, we act as a processor on that authority's instructions and the authority is the controller. Where we provide tuition or support directly to a family or learner, we act as the controller. This notice explains how we handle personal data in both cases.

2. What data we collect and why

We collect and process the following categories of personal data:

  • Account credentials — your email address and a hashed password, to authenticate you and keep your account secure.
  • Session data — a short-lived session token stored in a browser cookie, used solely to keep you signed in during a working day. Sessions expire after 8 hours.
  • Audit log — timestamped records of key actions (login, data access, record changes) to support safeguarding compliance and security investigations.
  • Learner and case data — names, educational plans, session notes, and related records entered by authorised staff, processed under a legitimate interest and statutory education duty to provide and evidence support.
  • Special category data — health, disability, and safeguarding information about learners, processed under Article 9(2) of the UK GDPR. The specific conditions we rely on in Schedule 1 to the Data Protection Act 2018 are paragraph 18 (safeguarding of children and of individuals at risk), paragraph 6 (statutory and government purposes) and, where applicable, paragraph 2 (health or social care purposes). An appropriate policy document, explaining how we comply with the data protection principles and meet these conditions, is being prepared for qualified review. It will be available on request once adopted.
  • Staff compliance records — DBS numbers, training completion, and right-to-work documents, processed to meet statutory obligations for working with children.

3. Cookies

We use strictly necessary cookies only. Specifically, a single session cookie (portal_session) is set when you sign in. This cookie:

  • Is HttpOnly and Secure (not accessible to JavaScript)
  • Expires after 8 hours
  • Is used solely to maintain your authenticated session

No advertising, analytics, or third-party tracking cookies are used. Because we use only strictly necessary cookies, we are not required to obtain consent under PECR, but we notify you as a matter of transparency.

4. Data storage and security

  • Data is stored in an encrypted PostgreSQL database provided by Neon and hosted in Frankfurt, Germany.
  • Sensitive fields (names, health data, personal contact details) are encrypted at rest using AES-256-GCM in addition to database-level encryption.
  • Documents are stored in encrypted cloud object storage (Cloudflare R2, Western Europe) with access controlled by signed URLs.
  • All data in transit is protected by TLS 1.2 or higher.

5. Processors and recipients

We use the following processors to run the portal. Each processes personal data on our instructions:

  • Neon — the managed PostgreSQL database, hosted in Frankfurt, Germany.
  • Cloudflare R2 — encrypted document storage, hosted in Western Europe.
  • Hetzner — application hosting, in Germany.
  • Resend — transactional email delivery, for example lone-working alerts and notifications. Resend is based in the United States; this transfer is covered by Resend’s data processing agreement.

6. Data retention

We keep personal data only for as long as we need it. The periods for each type of record will be set out in a retention schedule, which is being prepared for qualified review and will be available on request once adopted. In summary:

  • Learner and case records — for the period required by education and safeguarding legislation, and no longer. Records in the portal are archived once a case has been inactive and deleted at the end of the retention window.
  • Staff compliance records — for the duration of employment plus the required statutory period.
  • Session, security and audit logs — sign-in sessions expire after 8 hours; security and audit logs are kept for as long as needed to protect the service and account for changes to records.

7. Your rights

Under UK GDPR you have the right to access, correct, or request erasure of your personal data (subject to statutory retention obligations), and to object to processing or request restriction. To exercise these rights, contact our data-protection contact at the address in section 9.

8. Data-protection complaints

If you are unhappy with how we have handled your personal data, you can make a complaint. You can:

We will acknowledge your complaint within 30 days and explain how it will be handled. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

9. Contact

Our data-protection contact is James Wallace, who can be reached at hello@jameswallace.tech. We do not have a Data Protection Officer, because one is not required.