Who is responsible
Education Host Ltd, 15 Penrice Road, Droitwich, WR9 8NS, United Kingdom, provides Cover Manager for Education. Contact nick@educationhost.co.uk for privacy enquiries.
Your school is the data controller for its staff records, absence requests and cover decisions. Education Host processes that information on the school's behalf under its service agreement. Ask your school for its staff privacy notice, lawful basis and any applicable conditions for handling health information.
Information used and why
The school code identifies the school installation. Microsoft sign-in provides tenant and user identifiers, name and email to match an existing school staff account. The app does not receive your Microsoft password.
The app displays your name, department, role, school branding, absence dates and sessions, reasons, optional notes, approval status, decisions, decline reasons, cover allocations and suggestions including candidate names and workload facts. It sends the requests and decisions you make to your school's installation.
Absence reasons and optional notes may contain health or other sensitive information. Medical detail is not required; include only information your school needs and follow its staff privacy guidance.
App version, request identifiers and operational outcome information support troubleshooting and security. These are distinct from advertising or behavioural analytics.
Device storage and security
Sign-in credentials are stored in the iOS Keychain with device-only protection and no iCloud Keychain synchronisation. The school code is saved as a convenience preference. Staff and absence screens and drafts are held in memory rather than saved as an offline content cache.
Signing out clears local sign-in credentials and attempts to revoke the server session. The school code may remain saved for your next sign-in. Signing out or removing the app does not delete the school's records. Sign out before removing the app; do not rely on uninstalling it to revoke a session.
Retention
Access tokens are short-lived and refresh tokens expire within 30 days; local credentials are cleared on sign-out. Temporary sign-in state is removed when the sign-in finishes or is abandoned.
Central sign-in audit records are retained for 7 years. School absence, approval, allocation and associated school-server records follow the school's retention policy and contractual arrangements. Contact your school for the periods applying to its records.
Your rights and privacy choices
Contact your school office or data protection contact to request access, correction, deletion, restriction or to raise an objection concerning your staff records. Where applicable, you may also have a right to data portability. Your school assesses requests against its legal obligations; some employment records may need to be retained.
For enquiries about central sign-in records or Education Host's handling of data, contact us using the email below. We can help route school-record requests to the school. You may complain to the UK Information Commissioner's Office.
Accounts are managed by the school. The app has no account-creation feature; removing access or deleting school records must be arranged with the school.
Permissions, tracking and children
The current app has no advertising, cross-app tracking or third-party analytics SDKs. It does not request access to your camera, microphone, photos, location or contacts, or send push notifications.
The app is intended for school staff, not children. This policy concerns the app; the Studio website's cookies and analytics are covered separately.
Changes to this policy
We will update this page and its last-updated date when the app's data practices change.
