Privacy Policy

AgentChamp Privacy Policy

Version 1.0 - effective 25 August 2026


1. Who we are

AgentChamp is a reading platform for UK primary-school children, run by AgentChamp Ltd, a company registered in England and Wales (company number 17176256). Registered office: 1434 London Road, Leigh-on-Sea, Essex, England, SS9 2UL.

We are registered with the Information Commissioner's Office under reference ZC230270.

We have assessed UK GDPR Article 37 and are not required to appoint a statutory Data Protection Officer at our current scale. Instead a named Data Protection Lead is accountable for data protection at AgentChamp, and reaching them is the same for everyone:

  • Data protection questions, requests and complaints - privacy@agentchamp.co.uk
  • Anything else - support@agentchamp.co.uk
  • Reporting a security vulnerability - security@agentchamp.co.uk

If our scale or processing changes such that Article 37 requires a formal appointment, we will make one and say so here.

2. Are we the controller or the processor?

Both, depending on how an account reaches us - and it matters, because it decides who answers your requests:

ContextControllerOur role
A pupil enrolled by their schoolThe schoolProcessor, acting on the school's instructions under our Data Processing Agreement
A child registered directly by their parent, guardian or tutorAgentChamp LtdController, on the basis of the adult's consent
Adult accounts (school staff, parents, tutors) and billingAgentChamp LtdController

If your child uses AgentChamp through school, the school is the front door for questions about their data - its Data Protection Officer instructs us. If you subscribed as a family, we are the front door and this policy is the full picture.

We have assessed each thing we do with personal data separately rather than assuming one role covers everything. In particular: we do not become a controller of children's data by using it for product development, analytics, model training or anonymisation, because we do none of those things with it. See sections 8 and 15.

3. Who this policy covers
  • School staff - teachers and school administrators using AgentChamp on behalf of a school
  • Parents, guardians and tutors - adults with a family subscription, or linked to a school-enrolled child
  • Children - the readers, whose accounts are always created for them by an adult

Children never sign themselves up, never agree to anything themselves, and cannot make purchases. Every child account is created by a school or by an adult with parental responsibility.

There is a companion Privacy Notice for Children, written for the children themselves. It says the same things in language a seven-year-old can read.

4. What we collect
About children
  • First and last name, year group, and (for school pupils) class and school - provided by the school or parent, never by the child
  • A generated username, and a login code and PIN (see section 12 on how these are protected)
  • An internal email address, generated automatically from the username. It is not a real mailbox - it exists only because every account row needs a unique identifier, it cannot send or receive mail, and no message ever goes to it. Children have no email address at AgentChamp
  • Optionally, gender - a school may record it for roster purposes; it is never required and never requested from the child
  • Optionally, a marker that a child receives additional reading support. We treat this as special-category data - see section 6
  • Reading activity: which stories were opened and finished, pages read, time spent, reading speed, choices made in adventure stories, quiz answers and scores, dictionary words tapped (with the story sentence the word appeared in), points, streaks, achievements, and avatar customisation choices

Just as important is what we do not hold about children:

  • No date of birth. We collected it once, never used it, and deleted the column. Year group is enough for everything we do
  • No real email address, phone number, or home address. We hold school postcodes, never pupil ones
  • No photographs, audio or video of the child. The platform never asks for camera or microphone access, and the browser is instructed to refuse those permissions outright
  • No device location
  • No SEN diagnosis, EHCP detail, health record, ethnicity, free school meals, pupil premium status, English-as-an-additional-language flag, or Unique Pupil Number. We have never collected any of them
  • No free typing. Avatar names are chosen from a curated pool of literary names, quizzes are answered by picking options, and children cannot create stories. There is nowhere in AgentChamp for a child to type free text, so a child cannot disclose personal information to us even by accident
About adults
  • Name, email address, and role (teacher, school admin, parent, or tutor)
  • School affiliation and job title for staff; a family code for parents
  • Subscription status and payment history. Card details never touch our servers - payment is handled entirely by Stripe, and we see only that a payment happened, not your card
  • Security data: password (stored only as a one-way hash), and the IP address and browser identifier of security-relevant events such as logins and consent actions
Collected automatically
  • Security and authentication logs - IP address, browser identifier, timestamps. Identifiers in routine application logs are masked or hashed. The consent audit record (section 9) keeps exact values because it is legal evidence, and section 11 gives its retention
  • Two cookies and some browser storage, all of it necessary to run the service. There are no advertising cookies, no analytics, no tracking pixels and no third-party tracking scripts anywhere in AgentChamp. Our Cookies and Storage Policy lists every single cookie and stored value by name
5. What we do not do

Stated plainly, because these are the questions schools ask and because a policy that only describes what we *do* leaves them unanswered:

  • We do not sell personal data, share it for anyone else's marketing, or run advertising
  • We do not use children's data to train, fine-tune or evaluate any AI model - ours or anybody else's
  • We do not use children's data for product development, market research or behavioural analytics
  • We do not build commercial profiles of children, and we do not track them across other websites
  • We do not use any third-party analytics or error-reporting service. There is none in the product to remove
6. Why we collect it (lawful bases)
DataPurposeLawful basis (UK GDPR Article 6)
School pupils' dataDeliver the reading programme the school runsProcessed on the school's documented instructions; the school's own basis is 6(1)(e) public task or 6(1)(b) contract
Family-registered children's dataDeliver the reading programme at home6(1)(a) - consent of the holder of parental responsibility (UK GDPR Article 8; our readers are under 13)
Adult account dataOperate your account and subscription6(1)(b) - contract
Billing recordsTax and accounting obligations6(1)(c) - legal obligation
Security and authentication logsKeep accounts safe, detect abuse, investigate incidents6(1)(f) - legitimate interests
The additional-reading-support marker

A marker that a child receives additional reading support can reveal that the child has a special educational need or disability, so we treat it as special-category data under Article 9 even though we record no diagnosis, no condition and no EHCP detail - only a yes/no.

  • School pupils: the school is the controller and relies on its own Article 9 condition, normally Article 9(2)(g) with the substantial-public-interest condition for statutory and educational purposes in the Data Protection Act 2018, Schedule 1, Part 2. We process the marker only on the school's instruction
  • Family-registered children: we rely on Article 9(2)(a) - the explicit consent of the adult with parental responsibility, given specifically for this field

The marker does one thing: it lets the reading-level placement offer books below the usual floor for a child's year group, so a child who needs an easier book gets one. It is never used for anything else, never shown to other children, and never leaves our systems.

7. Linking a school account to a home account

AgentChamp's link codes let a parent see their child's school reading from home. Because this connects data held for a school to a private family account, here is exactly how it works:

  • Link codes are issued only by the child's school - printed on a letter sent home, or generated individually by school staff. Codes are single-use and expire automatically
  • Before anything is linked, entering a code shows you only the child's first name and school name - enough to check you have the right child, nothing more
  • Confirming the link records your acknowledgement (timestamp, policy version, IP address) in our consent audit record
  • After linking, you can see your child's reading progress, quiz results and vocabulary from both school and home. The school can see the linked guardian's name, email address and link date - so it always knows who can see its pupils' data
  • Either side can end the link at any time: you from your dashboard, the school from theirs. Ending the link immediately removes your access; it does not delete the child's school record, which remains the school's
  • The consent chain for a school pupil stays with the school - linking gives you a window into the school's programme; it does not transfer the school's responsibilities to us
  • Each parent account can link up to 3 children, and code entry is rate-limited to prevent guessing

A child registered directly by a parent (a "home child") works the other way around: you are the source of their data, we are the controller, and your consent at registration is recorded the same way.

8. Marketing
  • We send marketing emails (such as newsletters or news about reading challenges) only to adults who have opted in, and every one includes a working unsubscribe link. You can withdraw at any time, from the email or from your account settings, and you never need to sign in to unsubscribe
  • The opt-in box at registration is never pre-ticked
  • We never send marketing to children. Children have no reachable email address, so no email path can even reach one
  • We never share your details with anyone else for their marketing, and we never will
  • Competitions and reading challenges on the platform celebrate children by their avatar names (like "Emily Shakespeare"), never their real names

Service emails - verification links, password resets, purchase receipts, subscription reminders - are part of running your account and are sent regardless of marketing preferences, always to adults.

9. Who we share data with

We do not sell personal data, run adverts, or use behavioural analytics. Data is shared only with the service providers below, each bound by a data processing agreement, and only to the extent shown. The full inventory, including a per-provider statement of whether any child data is involved, is our Sub-Processor Inventory, published alongside this policy.

  • Google Cloud (London, UK region) - hosts our database, cache, file storage, application servers and logs. As our hosting provider its infrastructure holds all platform data. Its speech and AI services receive story, quiz and dictionary text only, never anything about a user
  • ElevenLabs (United States) - synthesises the spoken audio for story narration, quiz questions and dictionary words. Receives published text only, no user identifiers. Audio is generated once and reused for every reader, so nothing about an individual child is ever sent
  • Microsoft Azure Speech (UK South) - synthesises story narration with word-level timings, which is what drives word highlighting during read-aloud. Receives story text only, no user identifiers
  • Stripe - payment processing for adults. Receives the paying adult's email and our internal account reference; your card goes directly from your browser to Stripe
  • Resend (United States) - sends our service emails (verification, password reset, receipts) to adults. Receives the recipient's first name and email address

Because audio is synthesised once from published text and then served to everyone, no speech provider ever receives a request that identifies a child.

On adult checkout pages only, your browser loads Stripe's payment form directly from Stripe, including Stripe's fraud-detection component. That component examines the device to help Stripe tell a genuine payment from a stolen card. It runs only where an adult is entering card details, and never loads on any page a child can reach. We keep it on because it is what protects you and us from card fraud.

Apart from that one case, no page loads a resource from anyone but us. Fonts, scripts and every other static asset are served from our own infrastructure. Story covers and audio come from our own storage buckets, which are hosted by Google Cloud - so Google, as our hosting provider, sees the request the same way it sees every other request to our servers. It is not a separate company learning something new about your child; it is the hosting provider named at the top of this section. No advertiser, analytics company, font host or CDN sees your device, or your child's, at any point.

Beyond service providers: the child's own school sees its pupils' data (that is the service), a linked guardian sees their child's data (section 7), and we disclose data to authorities only where the law requires it.

10. International transfers

Everything we hold about you lives in the United Kingdom - Google Cloud's London region for the database, cache, files, servers and logs, and Microsoft's UK South region for narration.

Four providers involve processing outside the UK, and each is covered by a recognised transfer safeguard:

ProviderWhereWhat crosses the borderSafeguard
Google CloudUS parent companyNothing routinely - data at rest is pinned to LondonUK Extension to the EU-US Data Privacy Framework (the "UK-US Data Bridge")
StripeEU, with US processingThe paying adult's email and our account referenceUK Extension to the Data Privacy Framework, with the UK International Data Transfer Addendum incorporated as a fallback
ResendUnited StatesA recipient adult's first name and email addressStandard Contractual Clauses as amended by the UK Addendum
ElevenLabsUnited StatesStory, quiz and dictionary text only - no personal data of any kindStandard Contractual Clauses as amended by the UK Addendum

No child's personal data is transferred outside the United Kingdom.

11. How long we keep it

These retention rules are enforced by automatic daily jobs, not by promises:

DataRetention
Active accountsFor as long as the account is in use
Adult accounts that never verify their emailDeleted after 24 hours - exactly the lifetime of the verification link, so an unconfirmed registration never leaves a real person's email address sitting in our database
Pupil accounts after leaving the school's rollDeleted 365 days after the school marks them as left. A live family subscription pauses this: the account is kept while the subscription is live, and the clock is re-checked every day, so it starts the day the subscription lapses
Pupil accounts with no activityDeleted after 365 days of inactivity - an academic year, plus a summer, plus room for a genuine long absence
Adult accountsNot deleted on a timer. A teacher, school administrator or parent account is removed only when a person asks for it or a school administrator deletes it - a cron job silently deleting the account that administers a school would break the school, not protect anybody
Deleted accountsPermanently and irreversibly erased 90 days after deletion - a grace period during which an accidental deletion can be restored
Billing recordsRetained to meet accounting obligations; payment-provider detail within them is reduced after 180 days to a bare summary (amount, currency, status)
Consent and erasure audit recordThe event itself is kept as permanent legal evidence that consent was given and erasure honoured. The IP address and browser identifier attached to it are erased after 6 years - the period a regulator or a court can look back
Security and application logs30 days - the retention our hosting provider's logging applies, after which they are deleted automatically
Database backups30 days (7 days in our pre-production environment). Backups are encrypted, and a deleted account disappears from them as they roll off

When an account is erased, everything hanging off it goes too: progress, quiz history, vocabulary, points, avatar items, and family links. What survives is the minimum the law expects us to keep - the audit entry proving the erasure happened, and reduced billing records.

12. How we protect it
  • Passwords are stored as one-way hashes; password-reset and verification links are single-use and expire
  • Children's login slips work like the school reading-record systems teachers know: a pupil's simple login code and PIN can be re-shown to their teacher or parent, so a forgotten login never locks a child out. These credentials are stored encrypted, every reveal is written to an audit log naming the member of staff, and whole-class credential sheets can only be produced by staff assigned to that class. They are excluded from data exports. This is also why child accounts deliberately contain no contact details: the credentials unlock reading progress, nothing more
  • Session tokens are held in a cookie your browser will not let any script read, and the short-lived token used for each request is kept only in memory
  • All traffic is encrypted in transit; data is encrypted at rest by our hosting provider
  • Login endpoints are rate-limited against guessing, sessions are revocable server-side, and the consent audit record is append-only - enforced by the database itself, not by convention
  • The backend maintains an explicit allow-list of the external services it may talk to, so data cannot quietly start flowing somewhere new

Our full technical and organisational measures are published separately as Security Measures.

No system is perfectly secure. If a breach ever affects your data, we will notify the affected controller - you, or your school - without undue delay, in line with our legal obligations. Where we are the processor we report every personal data breach affecting a school's data to that school, not only the ones we judge significant.

13. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict, port, and object, and to withdraw consent where consent is the basis.

  • See your data: any signed-in adult can download a complete copy of their data (and, for parents, their children's data) from their account - no email required, though you can always ask us instead
  • Erasure: for a family-registered child or your own adult account, contact privacy@agentchamp.co.uk. Deletion takes effect immediately and becomes irreversible after the 90-day grace period
  • School pupils: your school is the controller - ask the school, and it instructs us. We provide schools the tools to export or delete any pupil's data on demand
  • Withdraw a link: unlink a child from your dashboard at any time
  • Withdraw marketing consent: from any marketing email, or from your account settings

We respond within one calendar month. If a request is complex we may extend that by up to two further months, and we will tell you why within the first month. We never charge for a request unless it is manifestly unfounded or excessive.

14. Complaints

If you are unhappy with how we have handled your personal data, tell us first - we would rather fix it than have you go elsewhere unsatisfied.

  • Write to privacy@agentchamp.co.uk with "Data protection complaint" in the subject line
  • We will acknowledge your complaint within 30 days, as the Data Protection Act 2018 requires
  • We will investigate and give you a substantive response, explaining what we found and what we are doing about it

You can complain to the Information Commissioner's Office at any point - you do not have to come to us first. Their details: ico.org.uk/make-a-complaint or 0303 123 1113.

If your child uses AgentChamp through school, the school is the controller of their data, so a complaint about how that data is handled should normally start with the school's Data Protection Officer. We will help the school answer it.

15. Children's privacy

AgentChamp is designed for children aged 7–11, and the ICO's Age Appropriate Design Code (the Children's Code) shapes how it is built:

  • We collect the minimum a reading programme needs, and nothing else - no birthdays, no photos, no location, no contact details
  • Children cannot talk to each other. There is no chat, no messaging, no comments, no way for one child to see another child's reading data, and no public leaderboard of real names. Shared surfaces use avatar names only
  • Children cannot type anything into AgentChamp. Avatar names come from a curated pool; quizzes are answered by choosing an option
  • No adverts, no marketing to children, no in-app purchases by children, and none of the nudges or streak pressure that exist to keep a child on a screen rather than to help them read
  • The best interests of the child come before our commercial interests where the two pull apart. Concretely: we synthesise audio once from published text rather than per-child, which costs us more and means no speech provider ever sees a child; and we self-host every font and interface graphic, so the only company a child's browser talks to is the one hosting our own servers
Automated decisions

AgentChamp recommends books at a level of challenge that suits each reader, using their reading history. This is a teacher-style judgement applied by software.

  • A teacher or parent can always see the recommendation and override it, and can pin, raise or lower a child's level directly
  • It only ever changes which books are suggested. It does not restrict access, affect assessment, or produce any legal or similarly significant effect on a child
  • It is not used for any other purpose, and we do not profile children in any other way
AI and children's data

Stories, artwork and audio on AgentChamp are produced with AI tools before a child ever sees them, by an adult choosing a theme and a reading level.

  • No child's data is ever sent to an AI model. Story generation runs offline, from parameters an adult chose. Speech synthesis receives published text
  • No child's data is used to train, fine-tune or evaluate any AI model. Not ours, and not any provider's
  • Every generated story is validated before it reaches a child, and a person can withdraw one at any time

This is set out in full in our AI and Children's Data statement.

16. Changes to this policy

Material changes prompt adults to re-accept on next sign-in, and the version accepted is recorded. Minor editorial changes update the effective date at the top of this page.

  • 1.0 (25 August 2026) - first published policy. Supersedes the 2026-04-14 and 2026-08-04 internal drafts, which were never cleared for publication and are retained unedited as the historical record
17. Contact

AgentChamp Ltd - registered in England and Wales, company number 17176256 1434 London Road, Leigh-on-Sea, Essex, England, SS9 2UL ICO registration ZC230270

  • Data protection - privacy@agentchamp.co.uk
  • General support - support@agentchamp.co.uk
  • Security disclosure - security@agentchamp.co.uk

AgentChamp keeps you signed in and remembers your reading settings using cookies and browser storage. What we store, in full.