Privacy, Terms & Data Protection

How we handle your school's data, your rights under UK GDPR, and our commitments to you.

Last updated: April 2026

Contents

  1. Who we are
  2. Data controller vs data processor
  3. What data we collect
  4. Legal basis for processing
  5. How we use your data
  6. Storage and security
  7. Data retention
  8. Your rights
  9. Sub-processors and third parties
  10. Children's data
  11. Terms of service
  12. Contact and data requests

1. Who we are

Sencohaven is a web-based SEND review management platform designed for UK primary school SENCOs (Special Educational Needs Co-ordinators). It is operated by Mark Stevenson, trading as Sencohaven, based in the United Kingdom.

For data protection purposes, our contact is:

Data Protection Contact
Mark Stevenson, Sencohaven
Email: privacy@sencohaven.co.uk
ICO Registration: We are currently completing our registration with the Information Commissioner's Office (ICO) as a data processor. ICO registration details will be published here once complete. Schools wishing to verify this status may contact us directly.

2. Data controller vs data processor

Under UK GDPR, it is important to be clear about who holds what responsibility for pupil data:

Your school is the Data Controller. Your school decides why pupil data is collected and how it is used. Your school must have its own lawful basis for processing SEND data — typically a legal obligation under the SEND Code of Practice (2015) and the Children and Families Act 2014.
Sencohaven is the Data Processor. We process pupil data only on your school's instruction, solely to provide the Sencohaven service. We do not use pupil data for any other purpose, do not sell it, and do not share it with third parties except as described in this policy.

By using Sencohaven, your school agrees to act as data controller for all pupil records entered into the system, and to our processing that data on your behalf. We are in the process of publishing a formal Data Processing Agreement (DPA) — please contact us if you require one for your records before it is published.

3. What data we collect

Pupil data (entered by your school)

Data typeExamplesSensitivity
Pupil identity First name, last name, year group, date of birth Personal data
SEND status & needs SEN support level, EHCP status, primary need category Special category
Reviews Review dates, outcomes, chair, notes Special category
Provisions Interventions, strategies, outcomes Special category
Notes & actions Free-text case notes, action items Special category
Agency referrals External agency names, referral details Personal data

SEND data is special category data under Article 9 of UK GDPR because it relates to a child's health, disability, and educational needs. This is the highest protection tier and we treat it accordingly.

School staff account data

Data typePurpose
Name, work email addressAccount identity, login, notifications
Job roleDisplay within the system
Session cookiesKeeping you logged in (PHP session, not tracking)
Audit log entriesRecord of who made changes to pupil records

What we do NOT collect

5. How we use your data

We use the data we hold only for the following purposes:

We will never:

6. Storage and security

Where data is stored

All data is stored on servers physically located in the United Kingdom. We do not transfer personal data outside the UK or the European Economic Area.

Transmission security

All data in transit between your browser and our servers is encrypted using TLS 1.2 / 1.3 (HTTPS). HTTP connections are automatically redirected to HTTPS. Our SSL certificates are managed by Cloudflare.

Access controls

Infrastructure security

Encryption at rest: We are currently implementing database-level encryption at rest and application-level encryption for the most sensitive free-text fields (notes, provision details). We will update this policy when that work is complete. Data in transit is already fully encrypted.

Breach notification

In the event of a personal data breach that is likely to result in a risk to individuals, we will notify affected schools within 72 hours of becoming aware of it, in line with our obligations under UK GDPR Article 33. We will also notify the ICO where required.

7. Data retention

We retain data for as long as your school has an active Sencohaven subscription, plus a short period to allow for account recovery.

Data typeRetention period
Pupil records (while school is active)Held until deleted by the school or account closed
Pupil records (after account closure)Permanently deleted within 30 days of account closure
Staff account dataDeleted within 30 days of account removal or school closure
Audit logsRetained for 1 year from creation, then deleted
Email logs (SES)Retained by AWS for up to 30 days, then auto-deleted
Server access logsRetained for 90 days, then deleted

Schools are responsible for their own retention schedules under the DfE's Records Management and Retention Schedule. Sencohaven provides tools to delete pupil records at any time — contact us or use the admin panel.

8. Your rights under UK GDPR

Under UK GDPR, individuals (including parents/carers acting on behalf of children) have the following rights. Because schools are the data controller for pupil data, subject access requests from parents should be directed to the school in the first instance. Schools can then contact us to assist with the response.

RightWhat it meansHow to exercise it
Right of access Request a copy of the personal data held about you or your child Contact your school (data controller), who will contact us if needed
Right to rectification Request correction of inaccurate data School staff can edit records directly, or contact us
Right to erasure Request deletion of personal data ("right to be forgotten") School can delete pupil records directly; full account deletion via privacy@sencohaven.co.uk
Right to restriction Request we restrict processing while a dispute is resolved Contact privacy@sencohaven.co.uk
Right to portability Receive your data in a machine-readable format Contact us — we can export school data as CSV/PDF on request
Right to object Object to processing in certain circumstances Contact privacy@sencohaven.co.uk

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk/concerns or by calling 0303 123 1113.

9. Sub-processors and third parties

We use a small number of carefully selected sub-processors to operate the service. All sub-processors are contractually bound to handle data in compliance with UK GDPR.

Sub-processorPurposeData location
Cloudflare DDoS protection, SSL termination, CDN UK/EEA edge nodes; no personal data stored
Amazon Web Services (SES) Transactional email delivery (review reminders, account emails) EU (Ireland) region — covered by AWS Data Processing Addendum
Hosting provider Physical server infrastructure United Kingdom

We do not use Google Analytics, Facebook Pixel, or any third-party advertising or behavioural tracking on the Sencohaven platform.

10. Children's data

Sencohaven processes data about children as part of its core function — supporting schools in managing SEND reviews. We take the following additional steps to protect children's data:

Sencohaven does not offer services directly to children. Only authenticated school staff may access pupil records.

11. Terms of service

Acceptance

By creating a Sencohaven account, the school owner agrees to these terms on behalf of their school. Schools may not use the service if they do not accept these terms.

Permitted use

Subscription and payment

Sencohaven is offered on an annual subscription basis (currently £249/year, paid by BACS bank transfer) with a monthly option at £29/month. Pricing may change with 30 days' notice to active subscribers. No refunds are offered for partial subscription periods unless required by law.

Trial period

New schools receive a 30-day free trial. No payment details are required to start a trial. At the end of the trial, access will be restricted unless a subscription is set up.

School responsibilities

Availability and support

We aim to maintain service availability of 99.5% on a monthly basis, excluding scheduled maintenance. We provide support by email at hello@sencohaven.co.uk. We do not guarantee response times but aim to reply to all enquiries within two working days.

Termination

Either party may terminate the subscription with 30 days' written notice. We reserve the right to suspend access immediately in cases of misuse, non-payment, or breach of these terms. On termination, all school data will be permanently deleted within 30 days.

Limitation of liability

Sencohaven is provided "as is". To the fullest extent permitted by law, we exclude liability for indirect or consequential losses. Our total liability in any 12-month period shall not exceed the subscription fees paid in that period. Nothing in these terms limits liability for death or personal injury caused by negligence, or for fraud.

Governing law

These terms are governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

Changes to these terms

We may update these terms and this privacy policy from time to time. We will notify active school accounts by email at least 14 days before any material changes take effect. Continued use of the service after that date constitutes acceptance of the updated terms.

12. Contact and data requests

For any data protection queries, subject access requests, or data deletion requests, please contact us:

Data protection contact

Email: privacy@sencohaven.co.uk
We aim to respond to all data protection enquiries within 5 working days.
For formal Subject Access Requests, we will respond within the statutory 30-day period.

If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO):