B Squared Software Privacy Policy

This privacy policy relates to the use of B Squared Software Products; Evisense, Connecting Steps, the B Squared Analytics platform and My BSquared admin portal

If you are looking for the privacy policy that relates to this website click here. 

Version 3.4  |  Last Updated: 12th May 2026

Introduction

This policy describes how B Squared Ltd collects, processes, stores, and protects personal data in the course of its business operations. It applies to all personal data processed by B Squared Ltd, whether as a data controller (for our own business data) or as a data processor (for customer data processed through our products).

This policy supports the Information Security Policy, Section 14 (Compliance) and the Data Protection Policy.

Scope

This policy applies to:

  • All personal data processed by B Squared Ltd
  • All staff, contractors, and third parties who access personal data on behalf of B Squared Ltd
  • All B Squared Ltd products and services: Connecting Steps, Evisense, B Squared Analytics, and My BSquared
  • Processing activities in both the United Kingdom and Australia

Regulatory Framework

B Squared Ltd complies with:

  • UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 — our primary data protection framework
  • Australian Privacy Act 1988 and the Australian Privacy Principles (APPs) — applicable to personal data of Australian customers and their pupils
  • Notifiable Data Breaches (NDB) scheme — Australia’s mandatory breach notification regime
  • ICO guidance — as our lead supervisory authority

Where requirements differ between jurisdictions, B Squared Ltd applies the higher standard of protection.

Categories of Personal Data

Data We Process as Controller

B Squared Ltd is the data controller for:

Category Data Types Classification Lawful Basis
Staff data Names, addresses, bank details, emergency contacts, performance records CONFIDENTIAL Contract, legal obligation
Business contacts Names, email addresses, phone numbers of school administrators and LA contacts CONFIDENTIAL Legitimate interest, contract
Website visitors IP addresses, browser type, cookies, page visits INTERNAL Consent (cookies), legitimate interest
Job applicants CVs, application forms, references CONFIDENTIAL Legitimate interest, consent

Data We Process as Processor

B Squared Ltd is the data processor for customer data entered into our products. The school or local authority is the data controller.

Category Data Types Classification Our basis for processing
Pupil data Names, dates of birth, UPN, year group, assessment records RESTRICTED Contract (with the school as controller)
SEN data EHCP details, SEN status, support categories RESTRICTED Contract (with the school as controller). Processed as special category data under the controller’s Article 9(2)(g) condition.
Pupil media Photographs, videos (Evisense) RESTRICTED Contract (with the school as controller)
School staff data Names, email addresses, roles (as Authorised Users) CONFIDENTIAL Contract (with the school as controller)

Classification levels are defined in the Data Classification Standard.

Controller and Processor Responsibilities

When B Squared Is the Controller

B Squared Ltd determines the purposes and means of processing for staff data, business contacts, and website visitor data. We are directly responsible for:

  • Ensuring a lawful basis for processing
  • Responding to data subject access requests (SARs) within 30 calendar days
  • Notifying the ICO of personal data breaches within 72 hours where required
  • Conducting Data Protection Impact Assessments (DPIAs) for high-risk processing
  • Maintaining records of processing activities

When B Squared Is the Processor

For pupil and school data entered into Connecting Steps, Evisense, B Squared Analytics, and My BSquared:

  • The school or local authority is the controller — they decide what data to enter and why
  • B Squared processes data only on the controller’s instructions, as defined in our Terms and Conditions (Schedule 4)
  • We do not access, use, or share customer data for our own purposes
  • We notify the controller without undue delay if we become aware of a data breach affecting their data (see T&Cs clause 4.8)
  • We provide reasonable assistance with SARs, DPIAs, and breach notification per T&Cs clause 4.10

Data Subject Rights

B Squared Ltd respects and facilitates the following rights under UK GDPR:

Right Description How to Exercise
Access Request a copy of your personal data Contact dpo@bsquared.co.uk
Rectification Request correction of inaccurate data Contact dpo@bsquared.co.uk
Erasure Request deletion of your data (where applicable) Contact dpo@bsquared.co.uk
Restriction Request limitation of processing Contact dpo@bsquared.co.uk
Portability Where applicable under Article 20 of the UK GDPR (consent or contract bases only), receive personal data you have provided in a structured, machine-readable format. The right does not extend to data inferred or derived by B Squared (calculated progression metrics, framework-aligned summaries) or to data that cannot be provided without adversely affecting the rights and freedoms of others, including third-party intellectual property under Article 20(4). Contact dpo@bsquared.co.uk
Objection Object to processing based on legitimate interest Contact dpo@bsquared.co.uk

Response time: 30 calendar days from receipt of a valid request (UK GDPR Article 12(3)).

For pupil data: Parents, guardians, or pupils should contact their school in the first instance. The school is the data controller and is responsible for handling rights requests. B Squared will assist the school as required under our contract.

Australian Privacy Principles

For individuals covered by the Australian Privacy Act 1988, B Squared Ltd also respects:

  • APP 12: Right of access to personal information
  • APP 13: Right to correction of personal information
  • Right to complain to the Office of the Australian Information Commissioner (OAIC)

International Data Transfers

Pupil and school records processed through Connecting Steps, Evisense, B Squared Analytics and My BSquared are stored exclusively in the UK (for UK customers) or Australia (for Australian customers) and do not leave those regions. Microsoft Azure is our sole sub-processor for this data.

B Squared Ltd operates separate Azure environments by region:

  • UK customers, and customers outside the UK and Australia (including Canadian customers by default): Hosted on Microsoft Azure UK South (primary) and UK West (failover). All such customer records processed through our platforms are stored in the United Kingdom.
  • Australian customers: Hosted on Microsoft Azure Australia regions. All Australian customer records processed through our platforms are stored in Australia, meeting Australian data residency requirements.

We do not currently operate Canadian, US, or EU Azure regions. Customers requiring residency in a region we do not currently operate would need to agree this separately and is not part of our default deployment.

Internal business systems (Microsoft 365, Entra ID) are hosted in Microsoft UK/EU datacentres.

Cross-border transfers: Some operational data (e.g., support correspondence, school or LA contact details, marketing emails, account administration) may be transferred outside the UK in the course of providing the service. These transfers do not include pupil data. They are protected by:

  • B Squared Ltd’s contractual obligations under the relevant Terms and Conditions;
  • Appropriate safeguards required by UK GDPR Chapter V — typically the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework where the sub-processor is certified;
  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256).

Sub-processors

B Squared Ltd uses sub-processors in two clearly separated categories: those that process customer records (pupil and school data) under our Terms and Conditions, and those that process other categories of data such as business contacts, support tickets or marketing emails. Pupil data is only ever processed by the sub-processor in the first table.

Sub-processors for customer records (pupil and school data)

Sub-processor Purpose Data Processed Location
Microsoft Azure Cloud hosting, compute, databases, blob storage, key management, identity, networking for Connecting Steps, Evisense, B Squared Analytics, My BSquared Pupil personal data, assessment records, Evisense media, school administrator and Authorised User accounts UK South + UK West (UK customers); Azure Australia regions (Australian customers). Data does not leave these regions.
Microsoft Azure OpenAI Service AI inference for Advanced Features in Connecting Steps (assessment summarising, next-steps summarising, lesson plan drafting) Pupil first name (last name not sent), age, framework names and assignments, group names and membership, attainment levels and percentages, form-fill inputs within the workflow. No sex/gender, date of birth, UPN, address, SEN status, EHCP, medical data, or media. UK South (region-pinned). Microsoft retains prompts and completions for 30 days for abuse-monitoring purposes only, in UK South; not used to train Microsoft’s general-purpose AI models.

No other sub-processor has access to pupil data. This is a contractual commitment under clauses 4.4, 4.7(d) and 4.14 of our Terms and Conditions.

Sub-processors for business administration (no pupil data)

The sub-processors below support our business operations (support, marketing, invoicing, identity, document signing). None of them process pupil data.

Sub-processor Purpose Data Processed Location Safeguard for transfers outside UK
Microsoft 365 / Entra ID Email, collaboration, identity for B Squared staff B Squared staff data, business contacts UK/EU N/A (within UK/EU)
Capsule CRM Customer relationship management School/LA contact details UK N/A
Transpond.io Marketing email campaigns Email addresses, marketing preferences UK N/A
CircleLoop Business telephony Phone numbers, call records UK N/A
Xero Accounting and invoicing Financial records, business contacts UK/AU N/A
Cloudflare CDN, DNS, web security for bsquared.co.uk IP addresses, web traffic metadata Global edge network UK IDTA
Mandrill (Mailchimp) Transactional email delivery (account invites, password resets, notifications) Email addresses, notification content (no pupil data) US UK IDTA / UK Extension to EU-US DPF
HelpScout Customer support ticketing School/LA contact details, support correspondence US UK IDTA / UK Extension to EU-US DPF
Dropbox Sign Electronic contract signing Names, email addresses, signed documents US UK IDTA / UK Extension to EU-US DPF
WordPress.com (Automattic) Hosting for SENDcast training platform (thesendcast.com) Teacher/professional names, email addresses, account data. No pupil data. US/Global UK IDTA / UK Extension to EU-US DPF
Stripe Payment processing for SENDcast training purchases (via WooCommerce) Payment card details, billing information. B Squared does not store card data. US/Global UK IDTA / UK Extension to EU-US DPF

Social media channels (Facebook, Instagram) are used for marketing and customer engagement. Personal data shared via these channels is processed by the respective platform under their own privacy policies. No pupil data is shared via social media.

SENDcast (thesendcast.com) is a separate training and CPD platform operated by B Squared Ltd. It stores only teacher/professional account data (name, email, purchase history). No pupil or student data is processed through SENDcast. It has its own privacy policy at thesendcast.com/privacy-policy/.

Customers are notified of any new sub-processors in accordance with our Terms and Conditions (clause 4.15). We will not engage a new sub-processor for customer data without the customer’s written consent.

Encryption in Practice

In transit: TLS 1.2 minimum, with TLS 1.3 in use across the platform. One legacy My B Squared endpoint operates at TLS 1.2 and is scheduled for retirement alongside the next authentication-focused My B Squared release. All web, API, and mobile traffic to and from B Squared services uses TLS.

At rest: AES-256 throughout. Azure SQL databases use Transparent Data Encryption (TDE). Azure Blob Storage (including Evisense media) uses Storage Service Encryption (SSE). All cryptographic keys are Azure-managed, held within the same Azure tenant as the customer data they protect.

Per-School Licensing Model

B Squared products are licensed per school. Each school operates its own independent tenant within the platform, with its own pupil records, user accounts, and configuration. Multi-school customers (school divisions, multi-academy trusts, local authorities) hold one Connecting Steps licence per school in their estate.

Within a school’s tenant, all Authorised Users see all pupils registered to that school. Sub-school scoping by sub-group is not currently supported.

AI Features (Advanced Features)

Products in scope. The Advanced Features capability — AI-assisted content generation — is part of Connecting Steps. Evisense does not include AI features (Explorer or paid).

Architecture. AI features are delivered via Microsoft Azure OpenAI Service, deployed as a resource within B Squared’s own Azure tenant in UK South (region-pinned). The B Squared platform is not connected to the public OpenAI API or to consumer ChatGPT.

What is sent to Azure OpenAI when a user invokes an AI feature. Pupil first name (last name is not sent), pupil age, framework names and assignments, group names and membership, subject attainment levels and percentages, and the form-fill inputs the teacher provides for the chosen workflow (summarise this pupil’s recorded assessments, summarise suggested next steps, or draft a lesson plan).

What is not sent. Sex/gender, date of birth, UPN, address, SEN status, EHCP details, medical data, photographs or any other media.

Retention.

  • B Squared side. Prompts and AI responses are persisted as workflow records in our database in UK South. Retention follows the same lifecycle as other customer data — life of contract or school-configured retention threshold, soft-deletable, deleted at contract end alongside other customer data.
  • Microsoft Azure OpenAI side. Microsoft retains prompts and completions for 30 days for abuse-monitoring purposes only, in UK South. Processed by automated systems and (in cases flagged as abusive) human reviewers, then deleted by Microsoft. Within the Azure DPA and Microsoft’s ISO 27001 / SOC 2 / SOC 3 compliance certifications.

No training use of customer data, by either party.

  • B Squared does not use customer data — including prompts, completions, conversation history, pupil records, assessment data, or any other category — for the training, fine-tuning or development of any artificial intelligence or machine-learning models. This is a contractual commitment under clause 4.4 of our Terms and Conditions.
  • Microsoft does not use Azure OpenAI prompts or completions to train its general-purpose foundation models (Azure OpenAI service terms).

Access scope. Advanced Features is enabled or disabled at the school-tenant level. When enabled by a school’s administrator, the AI capability is available to all Authorised Users of that school. Sub-school role-based gating is not currently supported.

Human-in-the-loop. All AI-generated text is presented to the user (typically a member of teaching staff) for review and adjustment before it reaches a pupil’s record. The human reviewer remains the final author of any text used; the AI feature is a decision-support tool, not an autonomous decision-maker. This is reinforced contractually under clause 4.19 of our Terms and Conditions.

Data Integrity and Audit

The B Squared platform retains a full history of changes to audit-relevant records, with every change attributed to the user who made it and timestamped. The platform applies a soft-replace pattern: when a record is updated, the previous version is preserved alongside the new version rather than overwritten, so the historical state of any record can be reconstructed.

This applies to pupil records, assessments, evidence, user accounts, role assignments, group memberships, and configuration. Login events (successful and failed authentication, captured with user identifier, email, IP address, device, product, school, success flag, and timestamp) and school synchronisation operations are captured in dedicated event logs.

Audit data is retained for the duration of the customer contract or the school’s configured retention period, whichever is shorter, and is available on request through B Squared support. The platform does not currently surface a self-service log query or export interface, nor does it expose audit data via webhook or API for customer-side SIEM ingestion.

Data Flow Overview

A high-level data flow description, including a Mermaid architecture diagram and explanation of trust boundaries, sub-processor relationships, and data categories, is published as a separate redistributable artefact: Data Flow Diagram. This diagram is intended for sharing with regulators, prospective customers, and procurement teams in response to Privacy or Data Protection Impact Assessments.

Data Protection Impact Assessments

B Squared Ltd will conduct a DPIA before commencing any processing that is likely to result in a high risk to the rights and freedoms of individuals. This includes:

  • Introduction of new products or features that process personal data
  • Changes to the way pupil data is processed
  • New categories of data collection
  • Processing involving children’s data at scale

DPIAs will be conducted by the CTO/ISM in consultation with the DPO and approved by the Directors.

Retention and Disposal

Personal data is retained only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Specific retention periods are defined in the Data Retention Policy. Disposal methods are defined in the Media Destruction Policy.

Breach Notification

Personal data breaches are handled in accordance with:

  • The Incident Response Plan
  • The Data Breach Response Plan

UK GDPR: Notifiable breaches reported to the ICO within 72 hours. Australian NDB scheme: Notifiable breaches reported to the OAIC and affected individuals as soon as practicable.

Data Protection Officer

B Squared Ltd’s Data Protection Officer can be contacted at:

  • Email: dpo@bsquared.co.uk
  • Post: Data Protection Officer, B Squared Ltd, 6 Lakeside Business Park, Swan Lane, Sandhurst, GU47 9DN

Complaints

B Squared Ltd operates a formal complaint handling procedure in accordance with section 103 of the Data (Use and Access) Act 2025. The full procedure is documented in the Data Protection Policy.

If you are unhappy with how B Squared Ltd handles your personal data:

  1. Submit a complaint via the electronic complaint form at https://bsquared.co.uk/data-protection-complaint/ (recommended), or contact the DPO at dpo@bsquared.co.uk
  2. B Squared will acknowledge your complaint within 30 calendar days and investigate without undue delay
  3. If not resolved, you may complain to the ICO (ico.org.uk, helpline 0303 123 1113)
  4. Australian individuals may also complain to the OAIC (oaic.gov.au)

For complaints about pupil data, data subjects should contact their school first — schools are the data controller and B Squared processes data on their instructions.