Privacy Policy

  1. ABOUT THIS NOTICE
    1. If you are a student, parent/carer, or member of staff at a school that uses MiniTest, this notice applies when we process your personal data as an independent Data Controller. This includes data in server and application logs, business correspondence, and online safety reports. For School Data, we normally act as the school's Data Processor. You should contact your school (the Data Controller) for privacy information.
    2. We collect, use, and are responsible for certain personal information about school contacts, people who enquire about or discuss MiniTest with us, people involved in online safety reports, and visitors to minitest.co.uk (the "Site"). In doing so, we act as an independent Data Controller, and this Privacy Policy applies.
    3. Please also read our Website Terms of Use, Online Safety Notice, and Cookie Policy.
    4. This version is effective from 28 July 2026.
  2. WHO WE ARE
    1. The Site is operated by Mr J. Gurung, trading as MiniTest ("we", "us"). Our trading office is at 70 Burnfoot Avenue, Fulham, London SW6 5EA.
    2. Mr J. Gurung is our privacy lead. You can contact him with data protection queries at [email protected].
  3. THE DATA WE COLLECT
    1. School account, contract, and billing data: School name and address; primary contact's title, name, work email address, and login provider; contract acceptance records, including the accepted terms version, signatory, and date; and billing details
      1. Source: You or your School
      2. Purpose: Managing customers and contracts; providing support; and billing
      3. Legal basis: Article 6(1)(f) Legitimate interests in administering School accounts, supporting customers, and maintaining business records; Article 6(1)(c) Legal obligation for tax and accounting records
      4. Retention: 6 years after the end of the School's subscription term, or longer where UK law requires
      5. Requirement: To enter into the School contract, we require the School's name and address, and the primary contact's title, name, work email address, and login provider. We cannot create the School account without this information. We require billing details only to invoice or take payment. Without them, we may be unable to provide or renew a paid subscription.
      6. Card payments: Braintree's hosted fields collect card details. MiniTest receives a single-use payment token, amount, outcome, and limited transaction metadata; it neither receives nor stores the full card number or security code.
    2. Business correspondence sent to us, along with any attachments and metadata (such as timestamps and email headers), but excluding School Data sent for support
      1. Purpose: Providing requested support, information, or marketing updates
      2. Legal basis: Article 6(1)(a) Consent (marketing); Article 6(1)(f) Legitimate interests in responding to enquiries, administering School accounts, and maintaining business records
      3. Retention: 2 years
    3. Server logs (which may include IP addresses, user-agent strings, pages or features accessed, actions taken, timestamps, and user IDs)
      1. Purpose: Security, fraud prevention, and service diagnostics
      2. Legal basis: Article 6(1)(f) Legitimate interests in keeping our service secure
      3. Retention: 30 days from collection
    4. Online safety and child sexual exploitation and abuse (CSEA) reports (which may include reporter details, reported content, account and user identifiers, IP addresses and port numbers, timestamps, metadata, location data, related communications and evidence, and disclosure records)
      1. Source: Reporters, Schools, content and activity on the Service, server and application logs, and the NCA, police, Ofcom, or other regulators or safeguarding bodies
      2. Purpose: Handling reports; restricting content or access; preserving evidence; safeguarding children; preventing and detecting unlawful acts; making required reports; and cooperating with the NCA, police, Ofcom, and other regulators or safeguarding bodies
      3. Legal basis: Article 6(1)(c) Legal obligation; Article 6(1)(f) Legitimate interests in safeguarding users and preventing unlawful use; where applicable, Article 9(2)(g) and Article 10 UK GDPR with paragraphs 10 and 18 of Schedule 1 to the Data Protection Act 2018
      4. Retention: For a CSEA report to the NCA, we keep the NCA reference number for 5 years. We keep the detected content, report and assessment information, and relevant associated user data for 1 year from the report. We retain this data longer only where required or permitted by law. We retain other report data only as long as needed for these purposes.
    5. We do not request or intentionally collect special category or criminal offence data for ordinary controller purposes. Online safety and CSEA reports may contain such data, which we process only where necessary as described above. We do not sell personal data.
  4. WHO WE SHARE DATA WITH
    1. We use trusted processors to run MiniTest:
      1. Microsoft Azure – UK data centre for hosting
      2. Cloudflare – global DNS and security
      3. Zoho Mail – email provider
      4. Postmark – transactional email
    2. We use other sub-processors listed in our subscription agreement with schools. We use them only in our capacity as a Data Processor, so they fall outside the scope of this notice.
    3. We use only processors that provide sufficient guarantees under Article 28 of the UK GDPR, and we have Article 28-compliant data processing agreements with each.
    4. Braintree, a PayPal service, receives card and purchaser details as an independent controller. MiniTest receives only the limited payment information described above.
    5. We may share online safety and CSEA report data with the NCA, police, Ofcom, the relevant School, and other regulators or safeguarding bodies where required or permitted by law. We will disclose other data if legally compelled (for example, by court order).
  5. INTERNATIONAL TRANSFERS
    1. For a restricted transfer of personal data, we rely on either (a) UK adequacy regulations or (b) an appropriate safeguard, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. We also complete any required data protection test.
    2. You may request a copy of the relevant safeguard by emailing us.
  6. YOUR RIGHTS
    1. Depending on the circumstances and lawful basis, you may have rights of access, rectification, erasure, restriction of processing, and data portability. You may also withdraw consent where we rely on it.
    2. Where we rely on legitimate interests, you may object to our processing based on your particular situation. You may object to direct marketing at any time.
    3. To exercise any of these rights, email [email protected]. Where necessary, we may ask for proportionate evidence to confirm your identity.
  7. DATA PROTECTION COMPLAINTS
    1. You may complain directly to MiniTest about our handling of personal data for which we act as Data Controller. This includes server and application logs, business correspondence that does not contain School Data, customer and billing records, and online safety reports. Email [email protected] with the subject "Data protection complaint".
    2. For complaints about School Data, the School is normally the Data Controller and MiniTest acts as its Data Processor. You should contact the School. If you send such a complaint to us, we will promptly refer it to the School and assist the School in handling it.
    3. We will acknowledge your complaint within 30 days of receiving it. We will make appropriate enquiries without undue delay, keep you informed of our progress, and tell you the outcome.
    4. You may complain to the Information Commissioner's Office at any time. Contact the ICO at ico.org.uk or on 0303 123 1113.
  8. SECURITY
    1. All traffic to the Site is encrypted using TLS. Data at rest is encrypted on Microsoft Azure. Access to production systems is limited to authorised personnel and protected by MFA.
    2. We will notify the ICO of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals' rights and freedoms. If the breach is likely to create a high risk to those rights and freedoms, we will inform affected individuals without undue delay.
  9. AUTOMATED DECISION-MAKING

    We do not carry out automated decision-making or profiling that has legal or similarly significant effects.

  10. CHANGES TO THIS NOTICE

    We may update this notice. We will post the new version at minitest.co.uk/Privacy.