Privacy Notice
Version 1.0 — effective 1 September 2026
1. Controller
1.1 The controller of the personal data described in this notice is Blue Numerics Ltd, of 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ ("we", "us"), trading as Neighbourhood School. Contact: admin@neighbourhoodschool.co.uk. Our registration number with the Information Commissioner's Office is ZB623940.
2. Personal data processed
2.1 We process the following categories of personal data:
- Account data — your email address;
- Transaction and consent data — the Pass purchased, date of purchase, price paid, expiry date, a Stripe payment reference, and the record of the declarations you gave at checkout (the version of the Terms of Use and of this notice in force at that time, both declarations, the time you gave them and the IP address the request came from). That record is what evidences your consent to immediate supply, so we keep it with the transaction. Full payment card details are transmitted directly to Stripe Payments UK Ltd and are at no point received or stored by us;
- Technical and security data — sign-in records, IP addresses and server logs generated in the ordinary operation and securing of the Service.
2.2 We do not request, and you should not provide, personal data relating to your children. We do not process special category data.
3. Purposes and lawful bases
3.1 We process personal data for the following purposes, relying on the corresponding lawful bases under Article 6(1) UK GDPR:
| Purpose | Lawful basis |
|---|---|
| Creating and administering your account; supplying your Pass; sending receipts, expiry notifications and service communications | Art. 6(1)(b) — performance of a contract |
| Retention of sales, tax and accounting records, and of the checkout consent record | Art. 6(1)(c) — compliance with a legal obligation (including obligations to HMRC and under the Consumer Contracts Regulations 2013) |
| Fraud prevention, security monitoring and enforcement of our Terms of Use | Art. 6(1)(f) — legitimate interests (protecting the Service, our customers and our business) |
| Aggregate, non-identifying analysis of Service usage for improvement purposes, carried out on our behalf by Plausible Analytics without cookies and without collecting any identifier that would let us recognise you | Art. 6(1)(f) — legitimate interests |
| Direct marketing by email | Art. 6(1)(a) — consent, and regulation 22 PECR. We do not currently process personal data for direct marketing purposes. |
3.2 We do not sell personal data, and we do not carry out automated decision-making producing legal or similarly significant effects (Article 22 UK GDPR).
4. Recipients
4.1 Personal data is disclosed to the following categories of recipient, in each case limited to what is necessary:
- Clerk, Inc. — authentication and account management. Clerk holds your email address and the identity behind your account, and sets the session cookies described in section 8;
- Stripe Payments UK Ltd and its affiliates — payment processing (acting also as an independent controller for its own regulatory, fraud-prevention and compliance purposes; see Stripe's privacy policy);
- Amazon Web Services EMEA SARL — cloud hosting infrastructure and delivery of the transactional emails described in section 3, both in AWS eu-west-2 (London);
- Plausible Insights OÜ — aggregate usage analytics, hosted in the European Union. Plausible sets no cookies and collects no identifier capable of recognising an individual visitor;
- professional advisers, including our accountant and auditors, where necessary for tax, accounting or legal purposes; and
- competent authorities, where disclosure is required by law.
5. International transfers
5.1 Certain recipients — in particular Stripe and Clerk — may process personal data outside the United Kingdom, including in the United States. Any such transfer is made under safeguards recognised by UK law, namely the UK–US Data Bridge (the UK Extension to the EU–US Data Privacy Framework) or the International Data Transfer Agreement / UK Addendum, as applicable (Articles 44–49 UK GDPR).
5.2 Analytics data is processed within the European Economic Area, which is covered by UK adequacy regulations, and hosting is in the United Kingdom (AWS eu-west-2, London).
6. Retention
6.1 Personal data is retained for no longer than is necessary for the purposes described in section 3:
- transaction, consent, tax and accounting records — six years plus the current financial year, in accordance with HMRC requirements. The checkout consent record is kept for the same period, as it evidences the basis on which the Pass was supplied;
- account data — for the life of the account, with dormant accounts deleted or anonymised 24 months after the later of last sign-in and Pass expiry;
- technical and security logs — 12 months, retained beyond that only where necessary for the investigation of a specific security incident, and then only for as long as that investigation requires.
7. Your rights
7.1 Subject to the conditions and exemptions in the UK GDPR and the Data Protection Act 2018, you have the right to: access your personal data (Art. 15); rectification (Art. 16); erasure (Art. 17); restriction of processing (Art. 18); data portability (Art. 20); and to object to processing based on legitimate interests, and to direct marketing at any time (Art. 21). Where processing is based on consent, you may withdraw consent at any time without affecting prior processing.
7.2 Requests should be directed to admin@neighbourhoodschool.co.uk. We will respond within one month of receipt, subject to any lawful extension.
7.3 You have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk) (Art. 77), although we would welcome the opportunity to address any concern in the first instance.
8. Cookies and similar technologies
8.1 Nothing is stored on your device until you choose to sign in. Browsing, searching and comparing schools set no cookies at all.
8.2 Once you sign in, the following are set, all of them for authentication or security and all of them strictly necessary within the exemption in regulation 6(4) of the Privacy and Electronic Communications (EC Directive) Regulations 2003:
| Cookie | Set by | Purpose |
|---|---|---|
__session | Our domain | The session token that proves to our servers that you are signed in |
__client_uat | Our domain | Records when you last authenticated, so a page can tell a session exists before the authentication script has loaded |
__clerk_db_jwt, clerk_active_context | Our domain | Session context used by our authentication provider, Clerk |
__cf_bm, _cfuvid | Clerk's domain | Cloudflare bot management, protecting the sign-in service from abuse |
8.3 Our authentication provider also stores one configuration value, __clerk_environment, in your browser's local storage. It holds settings, not identity.
8.4 We deploy no advertising, tracking or profiling cookies. Our usage analytics (Plausible) is cookieless and stores nothing on your device. Payment pages are hosted by Stripe on Stripe's own domain under Stripe's privacy policy; we do not load any Stripe script on this site, so no Stripe cookie is set here. Accordingly no consent banner is presented.
9. Amendments
9.1 We may amend this notice from time to time. Material amendments will be notified to account holders by email. Every version remains available at its own permanent address. The effective date of the current version is stated above.