GDPR Privacy Policy for the Tacpac Assessment Tracker

Last updated: 27th October 2025

  1. Introduction

Tacpac Ltd (“we”, “our”, or “us”) operates the Tacpac Assessment Tracker (“the App”). This Privacy Policy explains how we collect, use, and protect personal data under the General Data Protection Regulation (GDPR) (EU) 2016/679 and related data protection laws.

Our App is designed for schools and educational settings to track the progress of learners (known as “Receivers”) through the Tacpac Assessment Profile, and to support educators (known as “Givers”) in managing this process.

  1. Data Controller and Contact Information

Data Controller: Tacpac Ltd
Email: office@tacpac.co.uk
Registered Address: 19 Florence Park Road, OX4 3PJ, Oxford

If you have any questions about how we handle your data, please contact us using the email above.

  1. Personal Data We Collect

We collect and process the following data through the Tacpac Assessment Tracker:

  • For Receivers (students):
    • Name or unique identifier
    • Progress data through the 30+ steps of the Tacpac Assessment Profile
  • For Givers (teachers):
    • Name
    • Email address
    • School affiliation

We do not intentionally collect any sensitive personal data (such as medical information) beyond what is necessary for the assessment tracking process. (i.e. Notes the Giver generates)

  1. Purpose and Legal Basis for Processing

We process personal data for the following purposes:

Purpose Legal Basis
To manage and record Receivers’ progress through the Tacpac Assessment Profile Steps Legitimate interest (Article 6(1)(f) GDPR) – providing the educational service
To create and manage user accounts for Givers Contractual necessity (Article 6(1)(b) GDPR)
To communicate with schools and teachers about account and system updates Legitimate interest
To maintain and improve the App and ensure data security Legitimate interest
  1. Data Storage and Security

All data is hosted securely on Knack (knack.com) servers located in Frankfurt, Germany (EU).
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction.

Knack acts as a Data Processor under GDPR, and Tacpac Ltd remains the Data Controller responsible for ensuring lawful processing.

Please refer to their strict GDPR policy by clicking here the following:

Knack Compliance Policy

  1. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes outlined above or to comply with legal obligations.
Data associated with inactive school accounts will be deleted within 12 months of account closure, unless otherwise requested by the school.

  1. Data Sharing and Third Parties

We do not sell or share personal data with third parties for marketing.
However, we may share limited data with trusted service providers who assist in operating our systems:

  • Knack.com – cloud platform and database hosting (EU data centre, Frankfurt)

All third parties are bound by GDPR-compliant Data Processing Agreements (DPAs) and act only under our instructions.

Example: If we have an issue with a data record we cannot resolve ourselves, we may contact Knack.com and refer to the record in order to resolve an issue.

  1. International Data Transfers

All data is stored within the European Union (EU).
No data is transferred outside the EU unless necessary and subject to appropriate safeguards such as Standard Contractual Clauses (SCCs).

  1. Data Subject Rights

Under GDPR, you (or your school) have the right to:

  • Access your personal data
  • Request correction or deletion of inaccurate data
  • Object to or restrict processing
  • Request data portability
  • Withdraw consent (where applicable)

Requests can be made by emailing office@tacpac.co.uk. We will respond within 30 days.

  1. Data Protection for Children

The Tacpac Assessment Tracker is designed for use by schools and educators, not directly by children. Schools act as the primary data controllers for Receivers (students) and are responsible for obtaining any necessary parental or guardian consent.

  1. Data Breach Procedure

In the event of a personal data breach, Tacpac Ltd will notify affected schools and the relevant supervisory authority (e.g., the ICO) in accordance with Articles 33–34 of the GDPR.

  1. Changes to This Policy

We may update this policy from time to time to reflect changes in legislation or operational practices.
We will notify customers of significant updates by email or via the App.

  1. Complaints

If you are not satisfied with how we handle your data, you may lodge a complaint with your local data protection authority.
For the UK, this is the Information Commissioner’s Office (ICO): https://ico.org.uk/.