Legal
Privacy notice
How personal data is handled in the Aspire & Thrive platform — the web application and the Aspire & Thrive staff app for Android and iOS. Last updated 25 August 2026.
Who is responsible for your data
Aspire & Thrive provides this platform to youth and education providers. Each provider organisation is the data controller for the records its staff enter — they decide what is recorded and why. Aspire & Thrive acts as a data processor, handling that data only on the organisation's documented instructions.
If you are a parent, carer or young person asking about records held about you, contact the organisation working with you first — they hold the relationship and the legal duty to answer. You can also write to privacy@aspireandthrive.co.uk and we will route your request to them.
Aspire & Thrive is registered with the Information Commissioner's Office, registration reference ZC173760. Data protection enquiries: privacy@aspireandthrive.co.uk.
What the platform stores
- Staff accounts — name, work email, role, and the organisation and areas you are assigned to. Used to sign you in and to decide what you are permitted to see.
- Young people's records — name, preferred name, date of birth, reference code, school year, pronouns, ethnicity and first language where recorded; placement details; allergies, medical, dietary and pick-up notes; and the contacts associated with them (parents, carers, social workers, school safeguarding leads).
- Session records — dates, venues, attendance, write-ups, the young person's own voice where captured, and ratings of engagement and progress.
- Safeguarding records — concerns raised, their level, the actions taken and by whom, and the closure narrative. These are special category data and are treated accordingly.
- Plans and reviews — individual learning plans, goals, risk assessments, half-term reviews, consents and questionnaire responses.
- Audit history — who changed what and when. This exists so safeguarding decisions can be accounted for after the fact.
The mobile app specifically
The app shows the same records as the web application, subject to the same permissions. It does not collect anything additional about you or your device. Specifically:
- No advertising, no analytics SDKs, no tracking. The app contains no third-party advertising or behavioural analytics libraries.
- Biometrics stay on the device. The app can be locked with your fingerprint, face or device PIN. That check is performed by Android or iOS; the app is only told whether it passed. No biometric data is transmitted or stored by us.
- Sign-in details are held in the operating system's protected credential storage so you are not asked to sign in repeatedly.
- Notifications — if you allow them, alerts about safeguarding activity are delivered through Apple's and Google's push services. Alerts about safeguarding concerns are deliberately content-free: they say an alert exists, never its details.
- Location — the app does not request or record your location. Venue addresses open your existing maps application; we are not told where you are.
Who else processes the data
The platform relies on a small number of sub-processors, each bound by a data processing agreement. Every organisation's data passes through these four:
- Supabase — the database, sign-in service and file storage that hold the records. Data is held in Supabase's Europe (Ireland) region. Ireland is part of the European Economic Area, which the UK recognises as providing an adequate level of data protection, so no additional transfer safeguards are required.
- Vercel — serves the web application and the app's API endpoints.
- Resend — sends the platform's emails, including attendance confirmations to schools and local authorities, questionnaire invitations and staff notifications.
- Apple and Google — deliver push notifications to the app, where enabled.
A few more only process data when your organisation switches on the feature that uses them — for example SMS reminders, AI drafting assistance, or syncing your own Google or Microsoft calendar. The sub-processors page lists every one of them, what each is used for, and whether it applies to your organisation by default or only once you turn it on.
Data is not sold, and is not shared with anyone else except where the organisation instructs it (for example, an attendance email to a school) or where the law requires it.
How long it is kept
Records are retained for as long as the organisation needs them for the care of the young person, and then according to its own retention policy. The platform additionally applies automatic housekeeping:
- Archived audit records are swept after 90 days.
- Uploaded evidence files are purged after two years.
- Consents expire on their recorded expiry date and are flagged for renewal rather than silently lapsing.
Organisation-specific retention periods, where agreed: [to confirm].
How it is protected
- Every record is protected by database-level access rules, so a member of staff can only read records their role and assignments permit — the restriction is enforced by the database itself, not merely hidden in the interface.
- Organisations are isolated from one another: data from one provider is never reachable from another's session.
- Data is encrypted in transit, and at rest by the hosting platform.
- The app can be locked behind a biometric or device credential, and hides its contents in the app switcher.
Your rights
Under UK GDPR you may request access to the personal data held about you, ask for corrections, object to processing, or ask for erasure where it applies. Because the provider organisation is the controller, address these requests to them; they can action them in the platform, and we support them in doing so. If you are unhappy with the response, you may complain to the Information Commissioner's Office.
Children's data
This platform exists to support work with children and young people, so most of the records it holds are about them. The app itself is a professional tool for staff — it is not directed at children and is not intended for them to use. Where a young person's own words or self-completed questionnaire responses are recorded, that is done by, or with, the staff working with them, under the consent arrangements the organisation holds.
Changes
Material changes to this notice will be communicated to customer organisations, who are responsible for informing the people they work with. The date at the top always reflects the current version.
Questions about this notice: privacy@aspireandthrive.co.uk