Privacy Policy
How Comordo collects, uses and protects personal data across our school website compliance platform — including the accounts your staff use, the documents and website addresses you check, and the way we keep the service running.
Who we are
Comordo ("we", "us", "our") provides a compliance workspace that helps UK schools and multi-academy trusts keep their websites aligned with DfE online publication requirements. This policy explains how we handle personal data when you visit our website, create an account, and use the Comordo platform.
Comordo is operated by Comordo Ltd, a company registered in England and Wales (company no. 1729746). Our registered office details are available on request. For the personal data described here, Comordo is the data controller except where we act as a processor for your school or trust (see Controller & processor). For any privacy question, contact us at [email protected].
Data we collect
We collect the following categories of personal data:
- Account & profile data — name, work email, job role, and the school or trust you belong to, used to create and manage your account.
- Workspace content — the website addresses you scan, documents and notes you upload, tasks, comments and compliance records your team creates in the platform. This is uploaded by your school or trust and may include the names and contact details of staff.
- Usage & device data — standard technical information such as pages viewed, actions taken, approximate location (from a truncated IP address), referring site, and basic browser and device type.
- Communications — messages you send us by email, chat or our contact form, and a record of our replies.
We don't ask for special category data, and the platform is designed for staff use — it is not intended to hold information about individual pupils (see Children's data).
How we use it
We use personal data to:
- Provide the platform — set up accounts, run website scans, generate snapshots and reports, and let your team collaborate on compliance.
- Support you — respond to questions, troubleshoot issues and notify you about scans, tasks and important service updates.
- Improve the service — understand how features are used, in aggregate, so we can make Comordo more useful and reliable.
- Keep things secure — protect accounts, prevent misuse and meet our legal and regulatory obligations.
- Send relevant updates — where you've agreed, or where permitted, we may tell you about features and updates relevant to your role. Every marketing email includes an unsubscribe link.
Legal bases
Under UK GDPR we rely on the following legal bases:
- Contract — to provide the platform and support to the school or trust that subscribes, and to administer accounts.
- Legitimate interests — to secure, maintain and improve the service in aggregate, and to keep customers informed, balanced against your rights and freedoms.
- Consent — for optional marketing emails and for any non-essential analytics cookies. You can withdraw consent at any time.
- Legal obligation — where we must process data to comply with the law.
Controller & processor
For account data and our own website and analytics, Comordo is the data controller. For the workspace content your team uploads to run compliance checks, your school or trust is the controller and Comordo acts as a processor, handling that data only on your documented instructions.
Where we act as a processor, our responsibilities are set out in a Data Processing Agreement (DPA) with your school or trust, which forms part of your contract with us. The DPA covers the scope and purpose of processing, the security measures we apply, our sub-processor arrangements, and how we handle data strictly on your documented instructions.
A copy of our standard DPA is available on request — email [email protected] and we'll send it to you to review and sign.
International transfers
We aim to keep personal data within the UK or European Economic Area where we can. Where a provider processes data outside the UK, we make sure the transfer is covered by appropriate safeguards — such as the UK International Data Transfer Agreement, or the addendum to the EU Standard Contractual Clauses — so your data stays protected to UK standards.
How long we keep it
We only keep personal data for as long as we need it for the purposes set out in this policy, or for as long as the law requires. Our standard retention periods are:
| Data | How long we keep it |
|---|---|
| Account & profile data | For the life of your subscription; deleted or anonymised within 6 months of account closure. |
| Workspace content (scans, uploaded documents, reports, tasks, comments) | For the life of your subscription. After termination, available for export for 30 days, then deleted or anonymised within 90 days. |
| Billing & transaction records | 6 years, to meet UK tax and accounting law (HMRC requirements). |
| Support & enquiry messages | Up to 24 months after your last contact with us. |
| Marketing contact data | Until you unsubscribe or withdraw consent; we then keep a minimal suppression record to honour your choice. |
| Analytics & usage data | Up to 14 months, after which it is deleted or aggregated into anonymous statistics. |
| Security & access logs | Up to 12 months. |
| Backups | Held on a rolling cycle and overwritten or deleted, typically within 90 days. |
Where we act as a processor, the retention of your workspace content is governed by your instructions and your DPA. We may keep data longer where we are legally required to, or where it is needed to establish, exercise or defend legal claims.
Your rights
Under UK data protection law you have the right to access the personal data we hold about you, to correct or delete it, to restrict or object to how we use it, and to data portability. Where we rely on consent, you can withdraw it at any time.
If your data sits within a workspace controlled by your school or trust, we may direct your request to them as the controller, and help them respond. To exercise any right, email [email protected]. You can also complain to the Information Commissioner's Office (ICO), though we'd appreciate the chance to put things right first.
Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls and role-based permissions, and we work with established infrastructure providers who maintain their own security programmes. No method of transmission or storage is completely secure, but we take reasonable steps to safeguard the data we hold and to respond promptly if something goes wrong.
Children’s data
Comordo is a tool for school and trust staff, not for pupils. The platform is not directed at children and we don't intentionally collect personal data about individual pupils. If you believe pupil data has been uploaded in error, contact us at [email protected] and we'll help your school or trust remove it.
Changes & how to contact us
We may update this policy as the platform evolves or the law changes; when we make material changes we'll update the date above and, where appropriate, let you know. For anything to do with your data or this policy, get in touch.