Last updated 22 July 2026
The Ready Room is the data controller for the personal data described here. Contact: hello@thereadyroom.co.uk. We are a UK service for UK schools, and we handle personal data in line with UK GDPR and the Data Protection Act 2018.
The demonstration uses an entirely fictional school and stores nothing about you. The IDSR analytics tool in the Ofsted preparation pack runs wholly in your browser — the IDSR file you load is never uploaded to us or anyone else.
We send only service emails — invitations, invoices, reminders, guidance digests and replies. We do not send marketing emails, and we never sell or share personal data for advertising.
Policy generation and import review are performed by Anthropic’s Claude models. The wizard answers or imported document for the policy in question are sent to Anthropic’s API for processing and the draft is returned to your account. Under Anthropic’s commercial API terms, data sent to the API is not used to train their models. Demo sessions never send anything to the AI provider.
We use essential cookies only: a session cookie so you stay signed in (8 hours, or 30 days if you tick Remember me). There are no analytics, advertising or tracking cookies, which is why you don’t see a cookie banner.
Account and policy data are kept while your school holds a licence and for a reasonable period afterwards (so a lapsed school can renew and pick up where it left off). If your school asks us to delete its account, we do so promptly — except invoices and order records, which we must keep for 6 years for tax purposes. You can also remove individual users yourselves at any time via Manage users.
We use a small number of service providers as processors:
Some of these providers process data in the United States. Where they do, transfers are protected by UK GDPR safeguards — the UK Extension to the EU–US Data Privacy Framework or the UK International Data Transfer Agreement / Addendum, as applicable to each provider.
Passwords are stored only as salted scrypt hashes. All traffic is encrypted in transit (HTTPS), data is encrypted at rest by our database provider, sessions are signed tokens that expire, and each school’s data is accessible only to its own signed-in users. Access revocation takes effect immediately.
Individuals whose data we hold — school staff and governors with accounts, and billing contacts — have the usual UK GDPR rights: to access their data, correct it, have it erased, restrict or object to processing, and data portability. Email hello@thereadyroom.co.uk and we will respond within a month. If you are unhappy with how we handle data you can complain to the Information Commissioner’s Office (ico.org.uk), though we would welcome the chance to put things right first.
If we change this policy materially we will email school administrators before the change takes effect. The current version always lives at this address. See also our terms of service.