Status at a glance
What students share with the product
Sub-processors
| Processor | Role | Region | Data |
|---|---|---|---|
| Netlify | Website + edge functions | EU (Frankfurt) | HTTP logs (IP, user-agent, URL). No personal student data. |
| Neon | Postgres database | EU (Frankfurt, eu-central-1) | Session state, teacher email, student nickname only. |
| Anthropic | AI-report generation (Claude API) | EU endpoint | Aggregated game decisions per student (no identifying info) for report text. |
Documents
Four PDFs your data-protection officer will review. The one-page summary unblocks most DPO approvals without deeper reading.
Data Protection Summary (2026)
What we collect, where it's stored, retention, contact. Written for busy DPOs.
Download PDFPrivacy Policy (2026)
Full privacy policy — data subject rights, lawful basis, retention, transfers.
Download PDFData Processing Agreement (2026)
Controller/processor DPA ready for schools to sign. Sub-processors listed.
Download PDFInternal Data Policies (2026)
Access controls, incident response, staff training, retention.
Download PDFAccessibility statement
We aim for WCAG 2.2 AA conformance across both the marketing site and the live classroom simulation. Current known gaps (being addressed in Wave 3, May 2026):
- SEND-friendly options in the student view: quiz timer 15 / 30 / 45 / 60 seconds (currently fixed at 15s).
- Dyslexia-friendly font toggle in the student view.
- ARIA labels on emoji-only buttons in the teacher dashboard.
- High-contrast colour mode.
If a specific adjustment is needed for a pupil or pilot, email sakari.laajoki@gmail.com and we will prioritise it.
Security
HTTPS is enforced site-wide. For a security issue, email security@thebusiness.school or see security.txt.
Safeguarding and AI safety
AI-generated feedback reports run through Anthropic's Claude API with the teacher's session data only. No chat or free-text input from students reaches the model. No personal identifiers are sent. Output is shown only to the teacher and the individual student. This aligns with KCSIE 2024/25 §143 and the DfE Generative AI Product Safety Expectations.
Data-protection enquiries
Controller: TBS Education Ltd Oy · Business ID 3614159-3 · Helsinki, Finland
UK ICO Registration: ZC133810 · verify on the ICO public register
Email: sakari.laajoki@gmail.com
We aim to respond within 72 hours. For subject access requests, data-deletion requests, or DPA-signing requests, please reference your school name in the subject line.