← Back to Home

Privacy Policy

Last updated: 1 September 2026

School Compliance Documents

For Principals, DPOs, and school procurement reviews, the following supporting documents are available:

Where this page summarises those documents, the documents themselves govern.

1. Who We Are

SENScribe Limited is a company registered in Ireland that develops and operates the SENScribe service.

Legal EntitySENScribe Limited (CRO 813862)
Registered AddressARKINS & COMPANY LIMITED, BLOCK 15, Galway Technology Park, Parkmore, Galway, GALWAY, Ireland, H91 AY0Y
Data Protection Contacthello@senscribe.ie

Our role depends on the data involved:

  • Student personal data: When a school, ETB, or board of management uses SENScribe, that educational body is the data controller for student personal data, and SENScribe Limited acts as its data processor. This allocation is set out in Clause 2.4 of our Data Processing Agreement.
  • Teacher accounts, teacher-access applications, school licence enquiries, subscription payments, and consent-based marketing and analytics: SENScribe Limited is the data controller.

2. Data We Collect

We collect the following categories of personal data:

2.1 Account Information

  • Email address: used for authentication and communication
  • Name: for personalisation (if provided)
  • School affiliation: to review your application for teacher access

2.2 Teacher Access Applications

When you apply for teacher access, we collect your full name, school or work email, role, and selected school (or manual school name if unlisted). Application details are stored by SENScribe and shared with Zoho CRM to support manual application review. Please do not include pupil or student information in an application.

2.3 School Enquiry Information

If you enquire about a school licence, we collect your name, school or work email, optional phone number, role, selected school details (including directory-derived roll number, county, and type when listed) or manual school name/type, estimated staff requiring access, optional referral code, and optional message. Please do not include pupil or student information in an enquiry.

2.4 Usage Data

  • Session tokens: to keep you logged in
  • Usage count: to enforce fair use limits
  • Timestamps: when you access the service

2.5 Student Support Data

When using SENScribe, you may input information about students and save Student Support Files. This data is encrypted on your device before being stored on our servers. Saved files use keys held by the teacher. For secure review links, the decryption key is split: the SENScribe application stores one half and a separate, database-free email service receives the other half only long enough to place it in the link. Neither service alone can decrypt the shared file. Our servers hold ciphertext and wrapped keys only; during normal operation we have no technical means to decrypt stored files, and decryption depends on teacher-held credentials such as the data password or recovery key. Details and exceptions are described in our Privacy Whitepaper. See Section 5: AI Processing & Data Storage for details.

3. How We Use Your Data

We use your personal data for the following specific purposes:

PurposeData Used
Account creation & authenticationEmail, name, hashed password
Sending password reset and account-related service emailsEmail
Reviewing and processing teacher access applicationsTeacher access application information listed in Section 2.2
Generating Student Support Plan draftsRedacted and generalised AI text (see the automated-detection limitation below)
Enforcing fair use limitsUsage count
Responding to and managing school licence enquiriesSchool enquiry information listed in Section 2.3
Service and account-related email (password reset, security, account support)Email
Product updatesEmail - where we hold your valid marketing consent, or on the soft opt-in basis available to existing customers for similar products under the ePrivacy Regulations (with a clear unsubscribe in every message)
Website analytics & improvementPseudonymous usage data via Google Analytics (consent required)

5. AI Processing & Student Data

✓ Encryption for Student Support Files

SENScribe encrypts all Student Support Files on your device. Your data is encrypted on your device before being stored on our Azure-hosted servers in the EU, which hold ciphertext and wrapped encryption keys only. During normal operation we have no technical means to decrypt stored files: decryption depends on teacher-held credentials such as your data password or recovery key. Documented exceptions are described in our Privacy Whitepaper. This claim covers Student Support Files; account information such as your email address is handled as described in this policy. For AI generation, a final browser-side check redacts likely names and common direct identifiers and generalises recognised diagnoses before transmission. Every official AI request is blocked if that privacy check cannot complete; automated detection is not infallible.

Read our Privacy Whitepaper for Principals & DPOs →

How AI Processing Works

  1. You enter student information into SENScribe
  2. Your browser detects and replaces likely names and common direct identifiers with anonymous placeholders (e.g., "Seán" → [PERSON_1])
  3. Your browser generalises specific diagnoses to functional descriptions (e.g., "ADHD" → "attention regulation needs")
  4. The complete request is checked again immediately before sending; if redaction cannot complete, nothing is sent
  5. The resulting redacted and generalised text is sent to our server and Azure OpenAI within the European Union data zone
  6. The AI generates a draft using the anonymous placeholders and generalised needs
  7. Your browser restores the real names when displaying the result

How Data Storage Works

  1. You set a data password (separate from your login password) when you first save a student
  2. A unique encryption key is generated on your device and wrapped using your data password
  3. All Student Support Files (plans, reviews, logs, checklists) are encrypted on your device using AES-256-GCM before being sent to our servers
  4. Our servers hold only ciphertext and wrapped keys - during normal operation we have no technical means to decrypt stored files
  5. When you log in on a new device, you enter your data password to unlock your data
  6. A recovery key is provided at setup in case you forget your data password

GDPR & Special Category Data

Educational data linked to identifiable students may be considered Special Category Dataunder GDPR Article 9. SENScribe addresses this through two layers of protection:

  • AI generation: Likely student names, diagnoses, and common direct identifiers are redacted or generalised in your browser before transmission; automated detection reduces risk but cannot guarantee that every identifier in free text will be recognised
  • Data storage: All stored data is encrypted on the teacher's device with AES-256-GCM - our servers hold only ciphertext and wrapped keys, with no technical means to decrypt during normal operation
  • These measures satisfy GDPR Article 32 security requirements; breach notification obligations under Articles 33 and 34 apply without prejudice
  • Customer database hosting is in an Azure EU/EEA region. AI processing uses an Azure OpenAI EU Data Zone deployment.
  • These controls support GDPR Article 5(1)(c) data minimisation

Your Responsibilities as a Teacher

As the user entering student data, you are responsible for ensuring you have appropriate authorisation from your school to use SENScribe for this purpose. We recommend:

  • Obtaining approval from your school's Data Protection Lead
  • Using only the minimum necessary student information
  • Not sharing generated drafts inappropriately

6. Who We Share Data With

We use the following service providers. Depending on the service, they act as our processor or as an independent controller under their own terms:

ProviderPurposeData Shared
Microsoft Azure (Cosmos DB)Database hostingAccount data, sessions, encrypted Student Support Files (encrypted on the teacher's device)
Microsoft Azure OpenAIAI generationRedacted and generalised prompts (likely names and common direct identifiers replaced with placeholders in your browser before transmission)
Microsoft Azure Communication ServicesEmail delivery (primary)Recipient, subject, HTML and plain-text message content, optional reply-to address, and for secure review invitations only, the email-link half of the split decryption key
ResendEmail delivery (fallback)Recipient, subject, HTML and plain-text message content, and optional reply-to address for supported fallback emails
RevolutPayment processing for subscriptionsBilling contact and payment details (no Student Support File content)
Zoho CRM (Zoho Corporation B.V.)Managing teacher access applications and school licence enquiriesTeacher access application details and school enquiry information listed in Section 2.2 and Section 2.3; no pupil or student information is requested
Zoho (Zoho Corporation B.V.)InvoicingBilling contact details needed to issue invoices; no Student Support File content
Google AnalyticsWebsite analyticsPseudonymous usage data (consent required)

We do not sell your personal data to third parties.

Our current provider register, including regions and transfer safeguards, is published on our Providers & Sub-processors page.

Record of processing (GDPR Article 30 summary)

To help your school complete its own record of processing activities, this table shows how our role maps to each category of data. Full detail is in the Data Processing Agreement (Annexes) and the Trust Center.

Data CategorySENScribe RolePurposeLawful BasisRetention (general terms)
Encrypted Student Support FilesProcessor for the schoolSecure storage, sync, and sharing of student support recordsDetermined by the school as controllerUntil deleted by the school or handled per offboarding instructions (DPA Clause 12)
Browser-redacted AI promptsProcessor for the schoolGenerating draft support-plan text from teacher inputDetermined by the school as controllerNot stored by SENScribe (in-memory processing); flagged prompts may be retained by Microsoft under Azure abuse-monitoring terms
Account and service emailController (Microsoft primary; Resend fallback)Delivering password reset and account service emailsContract (Art. 6(1)(b))Kept only as long as needed to deliver and troubleshoot email
School-related email (secure review invitations)Processor for the schoolDelivering secure review invitations on documented school instructionsDetermined by the school as controllerDeleted or returned under Clause 12 of the DPA; invitation key split so neither service holds both halves
Teacher account dataControllerAccount creation, authentication, fair-use limitsContract (Art. 6(1)(b))Personal accounts deleted after 12 months of inactivity; school-controlled records excluded
Teacher access applicationsControllerManaging and reviewing teacher access applicationsSteps toward a contract / legitimate interests (Art. 6(1)(b)/(f))Kept while needed to review and manage the application, then reviewed or deleted unless an approved user account is created or a longer period is required by law
School licence enquiriesControllerManaging prospective school relationshipsLegitimate interests / steps toward a contractKept while needed to manage the enquiry, then reviewed or deleted
Subscription paymentsController (billing via Revolut under its own terms)Processing subscription paymentsContract (Art. 6(1)(b))Retained for the life of the subscription and as needed for billing records
Product updates & service emailControllerAccount-related service email; product updates to existing customers (soft opt-in) or with affirmative consentContract / legitimate interests (Art. 6(1)(b)/(f)); consent where given (Art. 6(1)(a)); ePrivacy soft opt-in for existing customersMarketing contact data held while consent stands or the soft-opt-in conditions are met; service email records kept as needed for service
Consent-dated analyticsControllerSite analytics cookiesConsent (Art. 6(1)(a) / ePrivacy)Until consent is withdrawn

7. International Data Transfers

We use EU-region hosting for the following services:

  • Azure Cosmos DB: Azure EU/EEA region
  • Azure OpenAI: European Union data zone deployment
  • Azure Communication Services: Europe (primary email provider)
  • Zoho CRM: EU data centre for application and enquiry records

Some providers may process data outside the EEA for support or through their sub-processors. Google and Resend may process data in the United States; Resend is used only as a fallback email provider if our primary provider (Azure Communication Services) is temporarily unavailable. Zoho may allow limited support access or use approved sub-processors outside the EEA. Where restricted transfers occur, safeguards include:

  • EU-US Data Privacy Framework (for certified companies)
  • Standard Contractual Clauses (SCCs)

8. Data Retention

We retain your data for the following periods:

Data TypeRetention Period
User account dataEligible personal accounts and their personal data are automatically deleted after 12 months of inactivity. Organisation-controlled school and student records are excluded and follow the school's offboarding or deletion instructions.
Teacher access application informationKept while needed to review and manage access requests, then reviewed or deleted when no longer needed, unless an approved user account is created or a longer period is required by law
Session tokens7 days of inactivity (expiry refreshed every 24 hours while you remain active), then automatically expire
School enquiry informationKept while needed to respond to and manage the prospective school relationship, then reviewed or deleted when no longer needed, unless a longer period is required for a customer relationship or by law
Encrypted Student Support FilesPersonal files are stored until manually deleted, deletion is requested, or the eligible personal account is automatically deleted after 12 months of inactivity. Organisation-controlled school and student records are excluded and follow the school's offboarding or deletion instructions. Encrypted on the teacher's device - decryption depends on teacher-held credentials such as the data password or recovery key.
Student names (during AI generation)Redacted in your browser immediately before sending to AI; the request is blocked if that check cannot complete
Redacted and generalised AI promptsNot stored by SENScribe (processed in-memory only)
Redacted and generalised prompts (Azure abuse monitoring)Flagged content may be stored by Microsoft for human abuse-monitoring review under the applicable Azure terms (see Azure documentation)

Note:Microsoft states that prompts flagged for potential abuse may enter additional review. Automated review does not store prompts, while content selected for human review may be stored within the Azure service boundary. For European deployments, authorised human reviewers are based in the EEA. Microsoft states that prompts are not used to train foundation models without customer permission or instruction; SENScribe has given neither. SENScribe's automated redaction reduces risk but cannot guarantee recognition of every identifier in free text.

9. Your Rights

Under GDPR, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure:Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Request we limit how we use your data
  • Right to Object: Object to processing based on legitimate interests
  • Right to Data Portability: Receive your data in a portable format
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent

To exercise any of these rights, email us at hello@senscribe.ie. We will respond within one month as required by GDPR.

10. Cookies & Analytics

We use the following cookies:

Cookie TypePurposeConsent Required
Strictly NecessaryAuthentication, session managementNo (essential)
Analytics (Google Analytics)Understanding how visitors use our siteYes

For more details, see our Cookie Policy.

11. Security Measures

We protect your data using industry-standard security measures:

  • Encryption in transit: All data is transmitted over HTTPS/TLS
  • Encryption at rest: Database encryption provided by Azure (AES-256)
  • Secure password storage: Passwords are hashed using an industry-standard password hashing approach and are never stored in plaintext
  • Access controls: Limited access to production systems
  • EU data residency: Customer database hosting is in an Azure EU/EEA region and AI processing uses the European Union data zone

12. Children's Data

SENScribe is designed for use by teachers aged 18 and over only. We do not knowingly collect personal data directly from children.

When teachers use SENScribe to generate Student Support Plan drafts, they may enter information about students. As described in Section 5, this information is encrypted on the teacher's device before being stored on our servers. During normal operation we have no technical means to decrypt this data; decryption depends on teacher-held credentials such as the data password or recovery key.

Teachers are responsible for ensuring they have appropriate authorisation to process student data through SENScribe.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify registered users by email for significant changes

We encourage you to review this page periodically for the latest information.

14. Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

SENScribe Limited

Email: hello@senscribe.ie

Address: ARKINS & COMPANY LIMITED, BLOCK 15, Galway Technology Park, Parkmore, Galway, GALWAY, Ireland, H91 AY0Y

15. Complaints

If you are not satisfied with our response to a data protection concern, you have the right to lodge a complaint with the Irish Data Protection Commission:

Data Protection Commission

21 Fitzwilliam Square South

Dublin 2, D02 RD28

Ireland

Website: www.dataprotection.ie

Email: info@dataprotection.ie

Tutorials