written in plain english, built against UK & EU GDPR (articles 13 and 14) and the ICO’s own guidance. this is our master notice; the ISP assessment has a short scoped version that links back here.
the short version
- we are a small uk consultancy. one person and a therapy dog
- we collect the least we can get away with
- we never sell your data, and we never will
- we work to UK and EU GDPR standards, and where your local law gives you extra rights, we honour those too
- when we work inside a school, pupil data stays with the school. we do not take it away
- you can ask us what we hold, ask us to correct it, or ask us to delete it. email us and we will do it within one month
detail below.
1 · who we are
- Unbarrier Education Ltd, a company registered in England and Wales, company number 16603630, trading as unbarrier.me
- registered office: 45–47 The Triangle, Malmesbury, Wiltshire, SN16 0AH
- we are the data controller for the information described in this notice
- registered with the Information Commissioner’s Office, reference ZC038215
- contact for anything in this notice: privacy@unbarrier.me
- we are not required to appoint a data protection officer, and we have not appointed one. Nici Foote is accountable for data protection
2 · when this notice does not apply
when we deliver an audit or engagement inside a school, the school decides what data is collected and why. in that work we act as a data processor for the school, under a written agreement.
- pupil and staff data in that context is covered by your school’s privacy notice, not ours
- our standing design position is that identifiable pupil data stays inside the school’s own systems. we work from anonymised or aggregated information wherever possible
- if you are a parent or pupil with a question about that data, your school is the right first contact
3 · what we collect, and why
if you visit unbarrier.me
- what: anonymised page views and referrers via Plausible Analytics
- why: to understand which pages are useful
- lawful basis: legitimate interests · understanding site use
- note: Plausible does not use cookies and does not track individuals across sites
if you enquire or fill in a form
- what: name, email, organisation, and whatever you tell us
- why: to answer you
- lawful basis: legitimate interests · responding to an enquiry you started
if you become a client or partner
- what: name, work contact details, organisation, engagement notes, invoicing details
- why: to deliver the work and get paid
- lawful basis: contract, and legal obligation for accounting records
if you complete an assessment or survey we run for a client project (for example the ISP Learning & Device Compass)
- what: your name, email, role, organisation or region, and your answers
- why: to deliver that project for the client who commissioned it, and to send you your own results
- lawful basis: legitimate interests · delivering the client engagement
- note: these are professional responses from staff and leaders — we do not collect pupil data through these tools, and please don’t enter special-category data in the free-text boxes
if you join loopbreakers coaching or the community
- what: name, contact details, session notes, anything you choose to share in a session
- why: to coach you well and keep continuity between sessions
- lawful basis: contract
- coaching notes may include information about health, neurodivergence, or wellbeing. that is special category data. we rely on your explicit consent (article 9(2)(a)) and you can withdraw it at any time
if you subscribe to the newsletter
- what: name and email
- why: to send you writing you asked for
- lawful basis: consent · withdrawable in one click from any email
if you book a session
- what: name, email, chosen time, anything in the booking notes
- why: to hold the appointment
- lawful basis: contract or legitimate interests
if you are a supplier or contact
- what: business contact details
- why: to work with you
- lawful basis: legitimate interests
4 · where we get it
almost always directly from you. occasionally from:
- a colleague or partner organisation who introduces us
- a school or client that books us on your behalf
- publicly available business sources such as a school website
5 · who else sees it
we use these services to run the business. each one is contracted, and each acts only on our instructions:
- Google Workspace · email, calendar, files
- Notion · notes and project records
- Xero · invoicing and accounts
- Stripe · payments · we never see your full card details
- MailerLite · newsletter
- TidyCal · bookings
- Vercel · website hosting, and the database behind our assessment tools
- Resend · transactional email
- Plausible · anonymised analytics
- Plaud (uk.plaud.ai) · meeting recording and transcription, where a meeting is recorded with everyone’s agreement
- WhatsApp · optional messaging and community groups · you join voluntarily
we also share with our accountant, and with HMRC or other authorities where the law requires it.
we do not sell your data, and we do not share it for anyone else’s marketing.
6 · international transfers, and which law applies
we work to UK and EU GDPR standards. some of the services above store data outside the uk. where that happens we rely on:
- uk adequacy regulations, where the country has them, or
- the uk International Data Transfer Agreement, or the uk addendum to the eu standard contractual clauses
if you’re in a country with its own data protection law — for example the EU, Brazil, the UAE or India — that law may give you additional rights. contact us and we’ll honour them.
for work with international schools, our position is that data stays in the country it was collected in unless there is a written agreement saying otherwise.
7 · how long we keep it
- enquiries that go nowhere: 12 months
- client and engagement records (including responses to client assessment/survey tools): 6 years after the engagement ends, to match accounting and insurance requirements
- coaching notes: kept for the length of the coaching relationship plus 3 years after the last session, then securely deleted
- accounting records: 6 years plus the current year · legal requirement
- newsletter: until you unsubscribe
- analytics: anonymised, so not tied to you at all
8 · how we keep it safe
- multi-factor authentication on every business account
- encrypted devices, kept up to date
- access limited to the one person who runs the business
- suppliers chosen partly on their own security position
- a written breach procedure, and a duty to tell the ICO within 72 hours where there is a risk to you
9 · your rights
you can ask us to:
- tell you what we hold about you
- correct anything wrong
- delete it
- restrict what we do with it
- hand it over in a portable format
- stop processing it, where we rely on legitimate interests
- withdraw consent, where we rely on consent · this does not undo what we did before you withdrew it
email privacy@unbarrier.me. we will respond within one month. it is free.
10 · automated decisions
we do not make automated decisions about you, and we do not profile you. where a tool of ours shows a score or a recommendation, that is a guide for a human conversation — not a decision made about you by a machine.
11 · cookies
this site sets no non-essential cookies. we use Plausible for analytics, which is cookie-free and does not identify you — so there is no cookie banner, because there is nothing to consent to.
when you click “book” or “pay” and are taken to Stripe’s checkout, Stripe sets its own cookies for payment security on stripe.com — not on unbarrier.me. you can block, clear or manage cookies in your browser settings.
12 · children
our services are sold to adults and to organisations. we do not knowingly collect data directly from children through this website. where we encounter pupil data, we do so as a processor for a school, as described in section 2.
13 · complaints
come to us first — we’d rather fix it. but you have the right to complain directly to the regulator:
- Information Commissioner’s Office
- Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- 0303 123 1113 · ico.org.uk/make-a-complaint
if you are in the EU or another country, you can also complain to your local data protection authority.
14 · changes
we will update this notice when what we do changes. the version and date at the top always tell you which one you are reading.