Privacy Policy
Last updated: 16 September 2026
Ibdaa Ltd ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share personal data when you use the Tawaasal platform — including the tawaasal.com website, the customer portal, the Tawaasal web application at tawaasal.app, including each school's own subdomain, and the Tawaasal mobile applications for iOS and Android (together, "the Service").
1. Data Controller
The way personal data is controlled depends on which part of the Service you are using.
-
Ibdaa Ltd is the data controller for personal data we process directly — including the public website (tawaasal.com), the billing and customer portal, sales and marketing communications, and our own staff and contractor records.
-
Schools are the data controller for personal data processed within their own Tawaasal environment — including student, guardian, teacher, and staff records, attendance, grades, messages, homework submissions, and any other content created or stored within the school's tenant. In this context, Ibdaa Ltd acts as a data processor under a Data Processing Agreement with the school.
This Privacy Policy describes both sets of processing activities. Where we act as a processor on behalf of a school, you may also wish to consult that school's own privacy notice.
2. Data We Collect
Account Data (website and portal)
- Full name, email address, phone number
- Organisation name and country
- Language and theme preferences
- Profile photo (optional)
Billing Data (portal)
- Subscription plan, billing period, and renewal status
- Payment history (card numbers are processed by Stripe — we do not store them)
- School registrations and provisioning status
- Tax identifiers where required by law
Mobile App Data
- Authentication tokens stored securely on the device
- Push notification token (provided by Apple Push Notification service or Firebase Cloud Messaging) so we can deliver notifications to your device
- Crash and diagnostic data captured by Firebase Crashlytics (stack traces, device model, OS version, language)
- Anonymous error and performance events
- Biometric authentication preferences — the biometric template itself never leaves your device; iOS or Android returns only a "match / no match" result
- Content you choose to submit, including messages, comments, photographs, files, and homework submissions
- Profile photographs you choose to upload
- App settings such as language, theme, and notification preferences
Usage Data
- Login timestamps and IP addresses
- Browser type, device model, and operating system
- Pages or screens visited and features used
Consent Records
- Records of your acceptance of our Terms of Service, including version, timestamp, and IP address
- Records of your marketing email choices — each opt-in and opt-out per topic, with its source (which form or page), language, timestamp, and IP address
Marketing Email Data (optional)
If you opt in to our product update or company news emails — via the website, at checkout, or in the customer portal — we collect your email address, preferred language, and per-topic subscription choices. Subscribing is always optional, is never pre-selected, and is separate from the transactional emails we send about your account and orders.
School Tenant Data (where Ibdaa acts as processor)
Within each school's Tawaasal environment, the school instructs us to process personal data including, depending on configuration: student records (names, dates of birth, contact details, enrolment information), guardian records, teacher and staff records, attendance and behaviour records, grades and assessment data, homework and submissions, calendar and timetable data, messages and announcements, photographs and files uploaded by users, and audit and access logs. Where a school enables AI connectors, this also includes records of which AI assistants its users have connected and what those assistants asked (as record identifiers and outcomes, never the text of a question).
The categories, retention, and sharing of school tenant data are defined by the Data Processing Agreement between Ibdaa Ltd and the school. The school is the controller for this data and is responsible for the lawful basis on which it is collected.
3. How We Use Your Data
We use data we control to:
- Provide and maintain the Service
- Process payments and manage subscriptions
- Communicate with you about your account and the Service
- Send push notifications and emails you have asked to receive
- Send optional marketing emails (product updates and company news) to subscribers who opted in — every such email includes an unsubscribe link and a link to a preference page where you can manage topics or leave entirely
- Detect and prevent fraud, abuse, and security incidents
- Investigate crashes and improve the reliability of our applications
- Comply with legal and regulatory obligations
- Improve the Service using aggregated, anonymised data
We process school tenant data only on the documented instructions of the school, as set out in the Data Processing Agreement.
4. Legal Basis for Processing
We process personal data under UK GDPR on the following legal bases:
- Contract: Processing necessary to provide the Service you have subscribed to.
- Consent: Where you have given explicit consent (for example, marketing communications, cookie preferences, optional notifications).
- Legitimate Interest: For fraud prevention, security, service improvement, and maintaining the integrity of the Service.
- Legal Obligation: To comply with applicable laws and regulations.
For school tenant data, the lawful basis is determined by the school as data controller. The school is responsible for obtaining any necessary consents — including parental consent for minors — before that data is provided to the Service.
5. Data Sharing and Third-Party Processors
We do not sell your personal data and we do not share it for advertising purposes. We share data only with the following categories of recipients.
Within a school
Users within a school's Tawaasal environment will see data relevant to their role. School administrators have visibility across the school; teachers see data for the classes and students they are assigned to; guardians see data for their own children; students see their own data. Access is controlled by the school's configuration and by our role-based permission system.
Service providers (sub-processors)
We use the following sub-processors to deliver the Service:
| Provider | Purpose | Region | |---|---|---| | Stripe | Payment processing | United States, with UK and EU representatives | | Google LLC (Firebase Cloud Messaging) | Mobile push notifications | Global Google infrastructure | | Google LLC (Firebase Crashlytics) | Crash and diagnostic reporting for the mobile app | Global Google infrastructure | | Google LLC (Sign in with Google) | Optional social sign-in | Global Google infrastructure | | Apple Inc. (Apple Push Notification service, Sign in with Apple) | iOS push notifications and optional social sign-in | United States | | Cloud infrastructure providers | Hosting, storage, and content delivery | United Kingdom and European Economic Area | | Email and messaging providers | Transactional email and SMS | United Kingdom and European Economic Area | | Resend, Inc. | Marketing email delivery and subscription list management for opted-in recipients | United States |
All sub-processors are bound by data processing agreements and process personal data only on our documented instructions. An up-to-date list of sub-processors is available on request from [email protected].
AI assistants connected by a school (not sub-processors)
A school may choose to let some of its users connect an AI assistant to Tawaasal and ask it questions about the school's data in plain language: who was absent today, how a class did in its last assessment, what is on tomorrow's timetable. When a user does this, Tawaasal sends the assistant's provider the data that user is already allowed to see, and only in answer to that user's questions. The connector provides no operation that creates, changes or deletes data in Tawaasal.
The assistant's provider is chosen by the school and its user, not by us, and the connection is made through the user's own account with that provider. We have no contract with the provider covering this data, and we do not treat the provider as our sub-processor. The question you type, the data returned and the answer the assistant writes are all held by the provider under its own privacy policy and terms; we store neither the question nor the answer, and we cannot control how long the provider keeps them or how it uses them. The school must make sure its users connect only accounts whose terms do not allow the provider to use this data to train its models; personal consumer accounts on some of these services do not meet that requirement. Removing a connection stops further requests but does not delete what the provider already holds; the provider's own deletion controls are the way to do that.
| Provider | Assistant | Region | |---|---|---| | OpenAI, L.L.C. | ChatGPT | United States | | Anthropic, PBC | Claude | United States | | Google LLC | Gemini | United States and global Google infrastructure |
Nothing is connectable until a school administrator turns the feature on, accepts a plain-language notice, and chooses which roles may connect. Connections are switched off for pupil and guardian accounts by default; a school that switches them on is responsible for the safeguards the law requires. An assistant can be given attendance, grades, merit points, timetables and the reports the school has marked as reachable, and nothing else: safeguarding concerns, wellbeing records, private messages, leave requests, parents' evening notes, financial records, and uploaded files, images, audio and video are not available to an assistant on any plan or setting. Every user can see and remove their own connections from their profile; a school administrator can see and remove every connection in the school; and all connections expire after 90 days.
Law enforcement and legal compliance
We may disclose personal data where we are required to do so by law, court order, or other lawful request from a competent authority.
6. Data Retention
- Account data: Retained for the duration of your account plus 6 years.
- Billing records: Retained for 7 years as required by financial regulations.
- Consent records: Retained for the duration of the customer relationship plus 6 years.
- Marketing email data: Your subscription preferences are kept until you unsubscribe or ask us to delete them. The underlying opt-in and opt-out records are retained for 6 years as evidence of consent.
- Usage logs: Retained for 90 days, then anonymised. Demo visit records are kept for up to 365 days — see section 10.
- Crash and diagnostic data: Retained for 90 days.
- AI connector records: Connection history (which assistant, when and from where consent was given) is part of the school's tenant data and follows the school tenant retention below. Routine per-question activity records are deleted after 90 days.
- School tenant data: Retained for as long as the school's subscription is active. Following cancellation or termination, the school is given a 30-day window to export its data, after which the school's data is permanently deleted from our production systems within a further 30 days. Backups containing school data are retained for up to 90 days and are then deleted in the normal course of our backup rotation.
7. Your Rights
Under UK GDPR you have the right to:
- Access: Request a copy of your personal data.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your data ("right to be forgotten").
- Portability: Receive your data in a machine-readable format.
- Restriction: Request that we limit processing of your data.
- Objection: Object to processing based on legitimate interest.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time. For marketing emails, use the unsubscribe or preference link in any email, or the Preferences page in the customer portal — withdrawal takes effect immediately.
To exercise these rights against data we control, visit our Data Rights page or email [email protected].
For data held within a school's Tawaasal environment, please contact your school directly — the school is the controller and decides how to respond. We will support the school in fulfilling your request.
8. Children's Data
Tawaasal is used by schools and may be used by pupils under the age of 18, including in some cases pupils under the age of 13.
We process children's data only on the documented instructions of the school. The school is the data controller and is responsible for:
- Determining the lawful basis for processing children's personal data
- Obtaining any consents required by law from a parent or guardian
- Ensuring that any data shared with Tawaasal is necessary and proportionate to its educational purpose
We do not knowingly collect personal data directly from children outside of the school environment. We do not use children's data for advertising, marketing, profiling, or any purpose other than providing the Service as instructed by the school. An AI assistant provider that a school has chosen to connect processes data under its own terms, not ours; see section 5.
We design the Service to be safe for children:
- No third-party advertising of any kind, anywhere in the Service
- No behavioural profiling or targeted content
- No cross-app or cross-site tracking
- Access to a child's data is limited to authorised users within their own school. Where a school has chosen to enable AI connectors, a user may ask a connected assistant about data they already have access to, and the school controls which roles may do so; see "AI assistants connected by a school" in section 5. Connections are switched off for pupil and guardian accounts by default
- Strong account security, including multi-factor authentication for staff accounts
We design our practices to align with UK GDPR (age of consent: 13), the EU GDPR-K framework (with the relevant member-state age threshold, between 13 and 16), the US Children's Online Privacy Protection Act (COPPA) where applicable, the Saudi Personal Data Protection Law (PDPL), and the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).
If you believe we hold personal data about your child that we should not, please contact [email protected] and we will work with you and your school to investigate.
9. Mobile App Permissions
Our mobile applications may request the following device permissions. You can deny or revoke each one at any time from your device settings; if you do, some features may not work as expected.
- Notifications: to deliver push notifications about messages, attendance, homework, and other school activity.
- Camera: to take photographs for profile pictures and homework submissions.
- Photos / Media: to attach files and images to messages and homework.
- Biometrics (Face ID, Touch ID, Android biometric): to sign you in securely without typing your password. The biometric template never leaves your device.
- Microphone: only if you choose to record voice or video.
We do not collect device location, contacts, calendar entries, or health data.
10. Demo Environment
We publish a demonstration of the Tawaasal school app so that anyone can try it before buying. It is a single shared environment, not a school's real system — every visitor signs in with the same published demo accounts. If you have come here looking for your own school's records, they are not here.
Because it is shared, anything you type into it can be seen by the next person who tries it. Everything in the demonstration is erased and rebuilt each night. Please do not enter real information about yourself, your child, or anyone else.
We keep a short record of each visit: when you signed in, the IP address you connected from and the country we work out from it, your browser, operating system and device type, which demo account was used, and how many records were created while you were there. We use it to keep the demonstration running, to protect it from abuse, and to understand how it is used. We keep that record for up to 365 days.
The demonstration is not covered by our Data Processing Agreement. That agreement is between a school and Ibdaa Solutions and applies to that school's own environment. A demo visitor is not a customer, so your use of the demonstration is covered by this Privacy Policy alone.
11. Tracking and Advertising
We do not display advertising in the Service and we do not use your data for advertising on or off the Service. We do not engage in cross-app or cross-site tracking. On Apple devices, our app does not request the IDFA (Identifier for Advertisers) and does not present the App Tracking Transparency prompt.
We use cookies and similar technologies on our website to provide essential functionality and, with your consent, for analytics. See our Cookie Policy for details.
12. Security
We implement industry-standard security measures, including:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Multi-factor authentication for administrator accounts
- Role-based access control with the principle of least privilege
- Audit logging for security-sensitive events
- Regular security assessments and penetration testing
- Automated daily backups with geo-redundancy
- Read-only, reduced-scope credentials for AI connectors that cannot write data, cannot reach safeguarding, wellbeing or messaging data, expire after 90 days, and are revoked together with the user's other sessions
No system is perfectly secure. If you become aware of a security issue, please report it to [email protected].
13. International Transfers
Your personal data is primarily processed in the United Kingdom and the European Economic Area. Some of our sub-processors (notably Stripe and Google) operate global infrastructure and may process data outside these regions. Where we transfer personal data outside the UK and EEA, we rely on appropriate safeguards — including the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, and the EU Standard Contractual Clauses — supported by transfer risk assessments where required. Where a school enables AI connectors, data sent to a connected assistant is transferred to that assistant's provider in the United States (and, for Google, its global infrastructure) on the school's instruction; the school, as controller, is responsible for the lawful basis of that transfer.
14. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated by email and, where appropriate, by an in-app or in-portal notice.
15. Contact Us
| | | |---|---| | Data protection enquiries | [email protected] | | General enquiries | [email protected] | | Registered office | Ibdaa Ltd, 128 City Road, London, EC1V 2NX, United Kingdom | | Company number | 11658668 |
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data protection rights have been violated. Customers in other jurisdictions may also contact their local supervisory authority.