1. Data Controller
MindStorm Coding Ltd, 167 Berrall Way, Billingshurst, RH14 9PQ, United Kingdom, is the data controller for the personal data processed through the Spark platform, except where Spark is delivered under contract to a partner school — in which case the school is the data controller and MindStorm Coding Ltd processes data on its behalf under a written data processing agreement.
MindStorm Coding Ltd is registered with the Information Commissioner's Office, registration number ZC038150.
For data protection queries, contact us directly at cjr@mindstormcoding.com. We aim to respond within one calendar month.
2. Lawful Basis for Processing
We process personal data under the following lawful bases:
- Article 6(1)(b) — Contract: Account data (username, display name, age group) is processed as necessary for the provision of the Spark educational service.
- Article 6(1)(f) — Legitimate Interests: Chat transcripts are processed in our legitimate interest of maintaining a safe learning environment and monitoring for safeguarding concerns, balanced against the privacy expectations of the child. A Legitimate Interests Assessment has been carried out and is available on request from the contact above.
- Article 8 — Conditions for Consent (Children): For all users under 18 years of age, parental consent is obtained prior to account activation (verifiable parental consent for users under 13). Consent is collected via a unique time-limited link sent to the parent or guardian's email address. The student account is blocked from login until consent is confirmed. A digital consent record is retained with timestamp. Users aged 16–17 remain children under the ICO's Children's Code and are treated accordingly. Users aged 18 or over are adults and give their own consent at signup; their accounts are likewise blocked until they confirm.
Special category data. Open-ended chat may incidentally contain special category data (for example, a student mentioning their health, religion, or ethnicity), particularly where a safeguarding concern arises. Where this occurs, it is processed under Article 9(2)(b) UK GDPR together with DPA 2018, Schedule 1, Part 2, paragraph 18 (safeguarding of children and individuals at risk). An Appropriate Policy Document covering this processing is maintained and available on request. Such data receives the same safeguards as all chat data: encryption, restricted access, safety filtering, and the retention limits in section 6.
Automated filtering.Spark applies automated content safety filters to chat messages. A filter may block an individual message from being sent or answered; it does not produce legal or similarly significant effects for the student, and all flagged content is reviewed by a human (the student's teacher).
3. Data Collected
- Username (chosen by the user, not a real name)
- Display name (chosen by the user)
- Age group (under 13, 13–15, 16–17, or 18+)
- Hashed password (irreversible cryptographic hash)
- Chat messages (student inputs and AI responses)
- Session metadata — timestamps and IP addresses, retained in our legitimate interest of securing the platform (detecting unauthorised access and abuse) and maintaining an audit trail of sensitive actions
- Consent records (reference to paper form, date, type)
- Historical AI-generated images — prompt text, revised prompt, and image URL from previously available Image Projects mode (this feature has been retired; no new images are generated)
- Prompt iteration drafts — draft prompt text and Spark feedback saved per iteration in Prompt Practice mode
Beyond the items listed above, we do not collect: students' real names, email addresses, phone numbers, postal addresses, or photographs. (A parent or guardian's email address is held for consent purposes; for adult users aged 18+, the user's own email address is held instead.) The platform actively detects and removes personally identifiable information (PII) if accidentally submitted in chat messages.
Voice input:When students use the microphone feature, audio is processed entirely within the browser using the device's native Web Speech API. No audio data is transmitted to or stored by MindStorm Coding's servers. Only the resulting text transcript is sent via the standard chat pathway.
4. Third-Party Data Processors
We use the following third-party data processors. All are engaged under appropriate data processing agreements:
- Anthropic (Claude API)— Chat messages (student inputs and Spark responses) are transmitted to Anthropic's API for AI processing. Anthropic is headquartered in the USA; transfers are made under standard contractual clauses. Anthropic does not train models on API traffic by default. See anthropic.com/privacy.
- Supabase / Neon (Database hosting) — Student account data and chat transcripts are stored on a UK/EU-region hosted PostgreSQL database.
- Vercel (Application hosting)— The platform is hosted on Vercel's edge infrastructure. Vercel processes request metadata (IP addresses, headers) as part of normal hosting operations.
- Resend (Transactional email)— Parental consent request emails and confirmation emails are sent via Resend. Only the parent or guardian's email address and the student's display name are transmitted. (For adult users aged 18+, the student's own email address is used instead.) Resend is operated under EU data processing terms.
- Upstash (Rate limiting) — Pseudonymous rate-limit counters (an internal account identifier or IP address with request counts, expiring automatically) are stored in Upstash Redis, hosted in the EU. No chat content or account details are transmitted.
- Microsoft MakeCode (block image rendering)— In Micro:bit mode, small code snippets in Spark's replies are drawn as block images by Microsoft's MakeCode rendering service (makecode.microbit.org), loaded within the page. Only the code snippet being rendered is sent to the service; as with any embedded web content, the student's IP address is visible to Microsoft. No account data or chat history is transmitted.
No student data is shared with any other third party. Teacher access to transcripts is limited to authorised MindStorm staff for safeguarding purposes only.
5. Voice Input — Local Processing
The optional microphone feature uses the browser's native Web Speech API. Audio is processed entirely on the student's device; no audio data is transmitted to or retained by MindStorm Coding servers. Only the resulting text transcript enters the standard chat pipeline (covered by section 4 above). Students may review and edit the transcript before sending. This feature requires explicit browser permission and can be declined without any impact on platform functionality.
6. Data Retention
- Routine chat data: deleted after 12 months where no safeguarding concern exists.
- AI-generated images and prompt iterations: deleted after 12 months (same schedule as chat data).
- Safeguarding-flagged data is retained on a tiered basis: flags reviewed with no genuine concern (for example blocked language or false positives) are deleted after 7 years; confirmed safeguarding concerns are retained for 18 years from account creation — reflecting the IRMS schools benchmark of retention until the young person's 25th birthday — and are then reviewed before deletion.
- Audit logs: retained for 3 years.
- Deactivated accounts with no flags: deleted after 6 months.
- All automated deletions are logged in the audit trail.
7. Data Subject Rights
Under UK GDPR, data subjects (students and their parents/guardians) have the right to:
- Access their personal data (Subject Access Request)
- Rectification of inaccurate data
- Erasure of personal data (right to be forgotten), subject to Article 17(3)(d) safeguarding exceptions
- Restriction of processing
- Data portability
- Object to processing
Requests can be made directly to cjr@mindstormcoding.com or via your MindStorm teacher. We aim to respond within one calendar month.
8. Security Measures
- All data transmitted over HTTPS (TLS encryption in transit)
- Database encryption at rest (AES-256)
- Passwords stored as irreversible bcrypt hashes
- Session tokens stored as SHA-256 hashes
- Rate limiting on authentication endpoints
- Role-based access control (students, teachers, administrators)
- Comprehensive audit logging of all sensitive actions
- Content safety filters on all chat inputs and outputs
9. Age Appropriate Design Code
This platform is designed in compliance with the ICO's Age Appropriate Design Code (Children's Code). High privacy settings are applied by default. No profiling, behavioural tracking, or nudge techniques are used. The platform does not use geolocation services.
A Data Protection Impact Assessment has been completed for the processing described in this notice. It is reviewed at least annually and on any material change to the platform, and may be made available to partner schools on request.
10. Complaints
If you are unhappy with how your data is handled, you may contact the Information Commissioner's Office (ICO) at ico.org.uk or call 0303 123 1113.