Skip to content

Trust centre

Everything your DPO, IT security and procurement teams will ask.

We'd rather tell you what's done and what's in progress than tick boxes we haven't earned. Anything marked "in progress" or "planned" is exactly that.

Data protection

Roles

  • Institutions (universities, colleges, councils, housing associations, employers) are the controller for learners they enrol. We're their processor under an Article 28 data processing agreement.
  • People who sign up directly (free and Plus): we're the controller.
  • Research and aggregate analytics: we act as controller, on pseudonymised data only and only with separate research consent.

Documents

Download the templates below. We'll also sign your own DPA, or Jisc or consortium model clauses. A completed HECVAT is planned, not done yet.

  • Data processing agreement (Article 28) template
  • Pre-filled data protection impact assessment (DPIA)
  • Security overview and questionnaire answers
  • Accessibility conformance report (self-assessed)

Jump to downloads. For signed copies, email [email protected] or use the form below.

Processor commitments

  • We process only on your documented instructions
  • Breach notification without undue delay, and within 24 hours
  • 30 days' notice of sub-processor changes, with a right to object
  • Help with subject access requests within 10 working days
  • Deletion or return of your data within 30 days of contract end; backups age out within 35 days
  • Small numbers (under 10) suppressed in every report
  • AI coach off until you switch it on, and always off for under-18s; AI logs kept 90 days; never used for training
  • Learners can download their data and delete their account themselves, in the app
  • No profiling by default; any at-risk flags are opt-in and explainable

Download the trust pack

PDF templates and summaries for your DPO, IT security and procurement teams. The DPA and DPIA are templates, subject to review by your legal team; neither is legal advice. Everything is self-assessed: we haven't had an external audit yet.

Sub-processor register

"At launch" means the provider goes live with our public launch. "Planned" means we intend to use this provider as the feature it supports launches. Institutions get 30 days' notice before any new sub-processor processes their data.

Sub-processors, their purpose, location, transfer mechanism and status
Sub-processorPurposeLocationTransfer mechanismStatus
Hetzner Online GmbHHosting, database, object storage, backupsGermany (Nuremberg, Falkenstein)UK adequacy (EU)In use
Cloudflare, Inc.Secure tunnel, DNS, CDN, web application firewall and DDoS protection; encrypted off-site database backups in R2 (EU jurisdiction)Global edge; backups stored in the EUIDTA / UK Addendum; Data Privacy FrameworkIn use
Google LLC (Gemini API, paid tier)Ask Nana, the optional AI money coach for adults (Gemini models). Processes questions only to generate answers; paid-tier terms, so no training on customer data; names, emails and card or phone numbers are masked before sending. Switched off for under-18s and per institution. Before any institution enables the coach we move it to Google Cloud Vertex AI in London (europe-west2)United States / globalUK Extension to the EU-US Data Privacy Framework; IDTA / UK AddendumIn use (adults, optional)
Stripe Payments Europe LtdPlus subscriptions (hosted checkout, card details never reach us), refunds and institution licence invoices. Only for people who buy Plus and for institutions we invoiceIreland / United StatesUK adequacy (EU); IDTA / UK AddendumAt launch
Google Ireland Ltd (Sign in with Google)Optional "Continue with Google" sign-in: confirms your name and verified email. Google is an independent controller for your Google account; we receive no tokens we keep and send nothing about your learningIreland / United StatesUK adequacy (EU); Data Privacy FrameworkIn use (optional)
Brevo (Sendinblue SAS)Transactional email (sign-in links, receipts)FranceUK adequacy (EU)In use
Functional Software, Inc. (Sentry), EU regionError monitoring. Server errors always; browser errors only with analytics consent and never in under-18 mode. Names, emails, IP addresses, cookies, request bodies and codes in links are removed before sendingGermany (Frankfurt, de.sentry.io)UK adequacy (EU); IDTA / UK Addendum for US support accessOptional (not currently used; errors go to PostHog EU)
PostHog Inc, EU CloudProduct analytics: pages viewed, masked button taps, lesson and game events, page speed, and masked session recordings for about 1 in 4 visits (all text and typing hidden; never on settings, admin, coach or parent pages). Only with analytics consent and never in under-18 mode. No cookies, no IP addresses stored; identity is a one-way hash of the account id. Reached through our own /ingest addressGermany (Frankfurt, eu.posthog.com)UK adequacy (EU); IDTA / UK Addendum for US support accessIn use (consent only)
Google LLC (Google Analytics 4, Google Ads)Measuring our advertising on our public website pages only (never in the learning app), with Google Consent Mode v2 and only after marketing consent; never in under-18 mode. Google signals and enhanced conversions off; no names or emails sent. Google is an independent controller for its ad measurementUnited States / globalUK Extension to the EU-US Data Privacy Framework; IDTA / UK AddendumWhen ads run (marketing consent only)
LinkedIn Ireland Unlimited Company (Insight Tag)Measuring our LinkedIn adverts on our public website pages only (never in the learning app), only after marketing consent and never in under-18 mode. No names or emails sent. LinkedIn is an independent controller for its ad measurementIreland / United StatesUK adequacy (EU); UK Extension to the EU-US Data Privacy Framework (LinkedIn Corporation)When ads run (marketing consent only)

Security

Baseline controls

The controls built into the service. The security pack explains how each one is evidenced.

  • Encryption in transit (TLS 1.2+); backups and special-category data encrypted at rest. Full-disk encryption of the database server is planned with our move to a dedicated server
  • Special-category data (optional APP characteristics, only with explicit consent) encrypted separately and read only through audited aggregates
  • Row-level security in the database, so one institution's data can't leak into another's
  • Least-privilege database roles: the app runs as a role restricted by row-level security
  • Append-only audit log, isolated per institution
  • Nightly encrypted backups, kept off-site in the EU (Cloudflare R2) for 30 days and gone within 35 days, with a documented restore procedure
  • Typecheck, automated tests and row-level-security tests on every change

Certifications and assurance

What we hold today, and what's next. Certificates are available to buyers on request.

  • Cyber EssentialsCyber Essentials (IASME) is held by our parent company, Tamsar, Inc., valid to July 2027. Tamsar Global Ltd is its wholly owned UK subsidiary; certification in Tamsar Global Ltd's own name is planned. Required by PPN 014 (formerly PPN 09/23) for many public contractsGroup certified
  • Cyber Essentials PlusIndependently audited versionPlanned
  • HECVAT 4EDUCAUSE Higher Education Community Vendor Assessment Toolkit, including privacy and AI sections. Available on request when completePlanned
  • CREST penetration testBefore public launch, then annually and before major releasesPlanned
  • ISO/IEC 27001:2022Tamsar Global Ltd is certified to ISO/IEC 27001 for its information security management system. The certificate is available to buyers on requestCertified
  • NCSC Cloud Security PrinciplesA published mapping documentPlanned

Standards testing

What we've tested ourselves against official and open-source validators. Tested, not certified: we haven't applied for 1EdTech or ADL certification yet.

  • SCIM 2.0 directory syncMicrosoft Entra ID SCIM validator: "compliant", 24/24 checks passed. Open-source scim2-tester: 89 checks, 0 errors
  • LTI 1.3 AdvantageDynamic registration, launch, deep linking and grade passback tested end to end in Moodle 4.5
  • SCORM and cmi5SCORM 2004 package completed and passed on SCORM Cloud; SCORM 1.2 passed in Moodle
  • UK Access Management FederationSignature on the live federation metadata verified, and tampered metadata rejected

Found a vulnerability? Please email [email protected] with "Security report" in the subject. We won't take action against good-faith research that avoids harming users or data.

Content you can put in front of students

Accuracy review

Figures come from official UK sources (HMRC, Student Finance England, DWP, GOV.UK) and are re-checked every April when rates change. We're appointing a qualified content reviewer, such as a money adviser or someone qualified at CII, CISI or LIBF level, to sign off every item before launch.

Education, not advice

We follow the FCA's line between general guidance and regulated advice. No products, providers, funds or coins are ever named or recommended, and a content linter blocks real brand names. Crypto, trading and gambling appear only as warnings. Read the disclaimer.

Safe and kind

No chat, DMs or user-generated content. No loot boxes, gambling-style mechanics or paid streak repair. Jokes never punch down at poverty, debt, disability or mental health. Safeguarding policy.

Accessibility

We build to WCAG 2.2 AA because the Public Sector Bodies Accessibility Regulations apply to many of the institutions we're built for, and because it's right. We're currently partially compliant, and our statement lists the known issues, including how 3D missions have a classic non-3D alternative.

Accessibility statement
  • Keyboard operable throughout
  • Respects reduced-motion settings
  • Sound off by default
  • No time limits in learning
  • Colour is never the only signal
  • Self-assessed automated WCAG 2.2 AA checks (axe) on 18 key pages, phone and desktop, light and dark: no failures after fixes (8 October 2026)
  • Independent audit and audited ACR/VPAT 2.5: planned, not yet done

Ask for signed copies or anything else

Tell us which documents you need, or send your own questionnaire, and we'll reply, usually within two working days. Company details: Tamsar Global Ltd, company number 17371733, ICO registration ZC269951.

Request documents

Tell us a little about you. We'll come back with a 20-minute demo slot and a pilot outline. No sales sequence, promise.