Privacy Policy

This privacy policy underpins the policies, promises and contracts we make with customers relating to the education data that Alps processes. 

This Privacy Policy with our Site Terms and Conditions sets out the basis on which any personal information we collect from you, or that you provide to Alps, will be processed by us and applies to personal data collected through our Site (at https://alps.education/and through the Connect, Summit or Ascent web applications accessed through the Site (together the “Services” or Site“). 

We are committed to protecting personal data and handling it responsibly, transparently and securely. We encourage you to read this privacy policy carefully so that you understand how and why we use your personal data and the rights available to you. If you have any questions about this Privacy Policy or how we handle personal data, please contact us at [email protected]  

Our Role

Alps may act as either a data controller or a data processor, depending on how personal data is used. 

In most cases, we act as a data processor on behalf of schools, colleges or other educational organisations that use our Services. Those organisations are the data controllers. They decide what personal data is collected, what is shared with us and the purposes for which it is processed. We process that personal data only in accordance with their instructions.  

We act as a data controller in certain circumstances, including where we process personal data: 

  • to create and manage your account; 
  • to monitor and analyse use of our Services; 
  • to support internal operations such as quality assurance, training and documentation; 
  • to improve, test and develop our Services, including artificial intelligence features; and 
  • in relation to our own business administration, including information relating to our employees. 

Our Data Protection Principles 

We:

  • Adhere strictly to the terms of the Data Protection Act 2018, the UK GDPR, and any future amendments or applicable legislation 
  • Process the data received from schools or colleges for the purposes of education and school improvement only, and only for those purposes necessary to provide the service explicitly offered to schools or colleges 
  • Collect data only for purposes that we have clearly explained to you and limited only to those purposes 
  • Only store and process the minimum data required to provide our services, and to inform you in advance of using any of our services what data that service requires. 
  • Transport and store all personal data originating from schools or colleges using modern and best practice encryption technologies. This includes Secure Socket Layers (SSL/TLS) for encrypted data transfer over the internet, encryption of all data at rest, field-level encryption for personally identifiable data and password-protected identities for all end users 
  • Report all requests made by individuals under data protection legislation including Subject Access Requests relating to the data we store to the data controller, or where we are the data controller, comply with all requests made by individuals under data protection legislation. 
  • Only retain data for as long as required, and delete all your data if you ask us to do so, or if your account becomes inactive for a certain period of time 
  • Ensure that all data is held securely by taking steps so that data is not corrupted or lost 
  • Ensure data is accurate and kept up to date 
  • Always maintain adequate liability insurance 
  • Maintain ISO 27001 and Cyber Essentials Security Compliance 
  • Audit our services against this policy every 12 months and provide evidence of compliance to the other party whenever requested 
  • Report any breaches of security to the data controller, the Information Commissioner’s Office (ICO) and other authorities if required by law, and, in co-operation with the data controller, to data subjects 
  • Only share your data with third parties who are bound by contractual provisions and process your data in accordance with this Privacy Policy 
  • Make the Site Terms and Conditions and this Privacy Policy clearly and publicly available on our website. 

Information we may collect

We collect and process the following types of personal information: 

a. Account information 

Information you provide by registering to use our Services. This may include your name, email address, postal address, payment details and other identification information.  

b. Interaction Data:

Records of communications and interactions with us, including support requests, emails, meeting or training session recordings, transcripts, summaries, feedback, and inputs submitted through AI features. 

c. Survey and Feedback Data: 

Information you provide when completing surveys or providing feedback, which may be used for statistical and service improvement purposes. 

d. Usage and Technical Data: 

Details of your use of our Services, including cookies, traffic data, location data, weblogs and other communication data, as well as information about the resources you access.  

e. Customer Data: 

Information provided by our customers (such as schools or colleges) through our applications and Services. This may include pupil data and related educational data used to measure educational attainment and progress, including prior attainment data and qualification outcomes (such as GCSE’s, A levels and L3 vocational qualifications) 

f. Marketing and Communications Data: 

Includes your preferences in receiving marketing from us and our third parties and your communication preferences. 

g. AI Input and Output Data:

Information submitted or generated by AI Features, including prompts, queries, uploaded content, analysis requests, summaries, recommendations, outputs and related metadata. This may include pupil data where such information is provided through the use of the Site 

How we collect information

We collect personal information through different methods including: 

  • Direct interactions: where you contact us by telephone, e-mail, through our Site, or otherwise; 
  • Use of our Services: when you access and use our applications; 
  • Automated technologies: when you interact with our Site or applications, we may automatically collect technical information about your equipment, browsing actions and patterns.  We collect this personal information by using cookies, server logs and other similar technologies. 

How we use personal information

We will only use your personal information where the law allows us to do so.  Most commonly, we will use personal information in the following circumstances: 

  • Where processing is necessary to perform a contract with you or to take steps at your request before entering into a contract  
  • Where processing is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests; or 
  • Where we are required to process your personal information to comply with a legal or regulatory obligation. 
  • Where we have obtained your active agreement to use your personal data for a specific purpose, for example if you consent to receiving marketing communications. 

We may process your information for more than one lawful ground depending on the specific purpose for which we are using your information. 

We use personal information for the following purposes: 

  • provide and manage our Services; 
  • to ensure that content is presented in the most effective manner for you and for your device; 
  • where you agree, provide you with information, products or Services that you request from us or which we feel may interest you; 
  • to carry out our obligations arising from any contracts entered into between us and you; 
  • to allow you to participate in interactive features of our service, when you choose to do so; 
  • to notify you about changes to our Services which may affect you; and 
  • to operate, maintain and improve the Site. 

We will only use personal information for the purposes for which we collect it. 

Use of Artificial Intelligence

We may use artificial intelligence, machine learning and related technologies (“AI Features”) in connection with our Services and our internal operations.  

AI Features may process information provided by users through queries, prompts, uploaded content, documents, analysis requests or other inputs submitted through the use of our Site. This may include pupil data and related educational data where that information is provided by a school or college.  

AI Features may be used to: 

  • generate analysis, summaries, insights and recommendations; 
  • support user queries and customer support; 
  • identify patterns, trends and areas for improvement; 
  • assist with documentation, classification and reporting; 
  • improve the performance and usability of the Services; and 
  • support internal processes such as quality assurance, training and operational efficiency. 

We may use third party AI service providers, including Anthropic, to provide or support AI Features. Where personal data is processed through AI Features, we apply appropriate safeguards in accordance with Data Protection Legislation. These safeguards may include data minimisation, access controls, human oversight and where appropriate, anonymisation.  

We do not use your personal data to train any general purpose or publicly available artificial intelligence models for use outside our Services. Where we use third party AI providers, we configure and use those Services so that customer data is not used to train or improve their models, unless a customer has expressly agreed otherwise. 

AI Features are intended to support analysis, summarisation, reporting and service improvement. They are not intended to make solely automated decisions about individuals that have legal or similarly significant effects. Users should review AI generated outputs before relying on them.  

Sharing Personal Information

We may share personal data with: 

  • our customers, in accordance with their instructions; 
  • trusted third party service providers (such as hosting, infrastructure and support providers); 
  • public bodies (such as local authorities or education bodies); 
  • our legal advisers and insurers; 
  • government bodies and law enforcement agencies; and 
  • third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy policy.  

Examples of third party providers we may share your information with include: 

  • Amplitude — We use Amplitude to understand how our applications are used, helping us to improve your experience over time. 
  • Microsoft Azure — Some of our systems and infrastructure are hosted securely on Microsoft’s Azure cloud platform. 
  • Zoho — Zoho provides a suite of business tools that support our internal operations, including HR, finance, customer relationship management and reporting. 
  • Anthropic — Anthropic is our AI service provider, whose technology supports areas such as code generation, data analysis and internal tooling. 

Any third parties will be bound by contractual provisions with us and only have access to personal data to perform the described purposes, and may not use it for other purposes.  

We require all third party providers to implement appropriate technical and organisational measures to protect your personal data and to process it in compliance with applicable data protection legislation.  

How we store personal information

We implement appropriate technical and organisational measures to protect personal information we collect from unauthorised access, loss or misuse. These measures include: 

  • encryption of data in transit (including Secure Socket Layers (SSL/TLS)) 
  • secure hosting environments; 
  • access controls and confidentiality obligations; and 
  • regular review of security practices. 

Our information security practices are supported by our ISO27001 accreditation. 

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.  

International Transfers

We may transfer your personal data to service providers that carry out certain functions on our behalf. This may involve transferring personal data outside the UK to countries which have laws that do not provide the same level of data protection as the UK law.  

Whenever we transfer your personal data outside of the UK, we ensure a similar degree of protection is afforded to it by ensuring that the following safeguards are in place: 

  • We will only transfer your personal data to countries that have been deemed by the UK to provide an adequate level of protection for personal data including countries within the European Economic Area (EEA); 
  • We may use specific standard contractual terms approved for use in the UK which give the transferred personal data the same protection as it has in the UK 

Data Retention

We will only retain your personal information for as long as is necessary to fulfil the purposes for which we collected, including for the purposes of satisfying any legal, accounting or reporting requirements. 

To determine the appropriate retention period for personal information, we consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through any other means, and the applicable legal requirements. 

Details of retention periods for different aspects of personal information: 

  • Analysis records derived from personal data will be deleted automatically after 8 years. Our online service will keep a record of your analysis for 8 years and our analysis tables show four-year trends. 
  • Personal information will be deleted within 28 days of a confirmed request for deletion from the school or college. 
  • Personal information will be deleted within 28 days if a school or college does not confirm a contract renewal within 18 months of the start of the academic year which shall be deemed to be 1 September each year. 
  • Anonymised data will be held for 6 academic years and automatically deleted afterwards. 

Where personal information is no longer required, we will ensure it is disposed of in a secure manner.  

If you request to stop receiving marketing communications from us, we will keep your details on a suppression list to ensure that no further marketing communications are sent.  

Our marketing communications

We may send you updates about Services and/or events we believe might be of interest to you via email. We call this marketing communications.   

We will only send you marketing communications where you have given us your consent.  

You can ask us to stop sending you marketing communications by following the unsubscribe links on any marketing communications sent to you or by contacting us at any time. 

Where you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes.   

Cookies

A cookie is a small file of letters and numbers that we put on your device when you visit our Site.  

We use cookies to help us understand how our Site is used and to improve user experience.  

For more information about the cookies, we use and how to change your cookie preference, please see our Cookie Policy. 

Third Party Links

We may link to and embed content from a variety of other Sites.   

We do not control these third party Sites and are not responsible for their content or privacy policies, nor for the way in which information about their users is treated. 

In particular, unless expressly stated, we are not agents for these Sites, nor are we authorised to make representations on their behalf. 

When you leave our Site, we encourage you to read the privacy policy of every Site you visit.  

Your Rights

Where we act as a data controller, under UK GDPR and the Data Protection Act 2018, you have the right to: 

  • Request access to your personal data (commonly known as a “subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it. 
  • Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us. 
  • Request erasure of your personal data in certain circumstances. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request. 
  • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) as the legal basis for that particular use of your data (including carrying out profiling based on our legitimate interests). In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your right to object. 
  • You also have the absolute right to object any time to the processing of your personal data for direct marketing purposes  
  • Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you. 
  • Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or Services to you. We will advise you if this is the case at the time you withdraw your consent. 
  • Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in one of the following scenarios: 
      • If you want us to establish the data’s accuracy; 
      • Where our use of the data is unlawful but you do not want us to erase it; 
      • Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or 
      • You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it. 

Where a school or college acts as the data controller for the personal data to which your request relates, we may refer your request to them, as they are responsible for handling and responding to such requests.  

How to contact us

If you have any questions, concerns or requests regarding this privacy policy or about the use of your personal data, please contact us in the following ways: 

  • Or by post: Mary Ahern, Chief Executive Officer, Alkemygold Limited, The Media Centre, 7 Northumberland Street, Huddersfield, HD1 1RL. 

Complaints

We take any complaints we receive about the collection and use of personal information very seriously.  We would encourage you to bring it to our attention if you think that our collection or use of information is unfair, misleading or inappropriate.  You can make a complaint at any time by contacting us on the contact details above.  

You also have the right to make a complaint to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues. You can contact the ICO at the following address: Information Commissioner’s Office; Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF 

However, before contacting the ICO, please first raise your complaint with us or ask for clarification if there is something you do not understand. The ICO will expect you to have done this before reviewing your complaint. 

DATA PROTECTION COMPLAINTS PROCESS

Changes to this privacy policy

This privacy policy was last updated in May 2026. 

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements and other factors.  

We encourage you to review this privacy policy periodically to stay informed about how we protect your data.  

 

July 2026