Privacy practices designed for school procurement review.
Your school is the data controller and decides why and how student data is used. Outleap acts as a processor under the signed school agreement and Data Processing Agreement. This page is a procurement summary and should be read alongside the trust pack and the agreed contract.
Last updated: 25 July 2026.
What we process today
The processing below is live in the current product. Each item runs only for the cohorts and modules your school has activated:
- Evidence Bank entries that students build and own.
- The UCAS three-question personal statement workflow, including AI feedback on drafts.
- CVs, cover letters, competency answers and non-university applications.
- Cohort visibility for staff, including progress, exception flags and logged interventions where a workflow involves submission or staff review.
Reference workflows and Opportunity Radar are coming in September 2026. They are not part of the live product and Outleap does not process data for either feature today. They are out of scope for this notice until they ship.
UK GDPR alignment
Lawful basis
The school, as data controller, decides and documents the lawful basis for processing in its own records and DPIA. Schools typically rely on a public task or legitimate interests basis for structured educational support, or contractual necessity where Outleap is engaged as part of the post-18 programme. We support that assessment; we do not make it for the school.
Data minimisation
We collect only what the platform needs to operate: student name, email, school affiliation, Evidence Bank entries, UCAS statement drafts and feedback, CVs, cover letters, competency answers, non-university application records, and the cohort metadata staff need to track progress. We do not profile students for marketing and do not share data beyond what is needed for service delivery, support, security and the agreed subprocessors.
Purpose limitation
Student data is processed only to run the modules your school has activated: evidence capture, the UCAS statement workflow, CV and application support, and cohort visibility. It is not used to train AI models, for advertising, or for any purpose outside the school's application workflow.
Children's data
Outleap is used by an under-18 cohort, so we design to the ICO's Age Appropriate Design Code: high privacy by default, data minimisation, and the best interests of the child as a primary consideration. There are no nudges that weaken a student's privacy.
Data residency and security
UK/EU hosting
The platform runs on Google Cloud and Firebase. The API is hosted in Google Cloud europe-west2 (London), and core platform records remain stored in UK/EU-oriented Google Cloud services. AI processing uses approved providers, including Google Vertex AI and Amazon Bedrock, in UK/EU regions.
Encryption
Data is encrypted in transit with modern TLS and at rest with AES-256 via Google Cloud's default encryption. Database access is authenticated and role-scoped.
Environment isolation
Staging and production are fully separated: different Firebase and GCP projects, and different data stores. The Firestore database is locked to the backend only; client applications cannot read or write it directly.
Retention and access
Retention
Student data is retained according to the retention schedule agreed with your school, with different windows for account metadata, evidence, submissions, feedback, application records and audit events. The template schedule is in the trust pack and requires school and legal review before adoption.
Access controls
Role-based access is enforced at both the application and infrastructure level. Students see only their own data, teachers see only their assigned students, and school admins see only their own school. Cross-school access is prevented by design.
Data subject rights
Rights are exercised through your school as the controller. We support schools with access, rectification, erasure, portability and related requests, subject to identity checks, school instructions, safeguarding duties and any lawful retention obligations.
AI data handling
No training on pupil data
Student content and AI outputs are not used to train Outleap models. AI processing uses the student's own evidence, drafts and relevant workflow context only to provide the authorised service. Provider retention and transfer terms are documented through the DPA and subprocessor schedule.
Advisory, bounded AI
AI feedback is advisory and bounded to the student's own work. Staff can see the feedback each student receives through the normal product views, so school support and safeguarding processes remain owned by the school. Automated safeguarding alert delivery, routing and hold workflows are not active in the launch product. AI is a tool inside the workflow, not an autonomous decision-maker, and it makes no admissions, safeguarding, academic or school decisions.
Subprocessors
Google Cloud and Firebase
Hosting, database, authentication (email-link sign-in) and the task queue. Hosted in Google Cloud, primarily in UK/EU regions as set out above.
Google Vertex AI
AI-assisted feedback and drafting support where enabled. Processing takes place in UK/EU Google Cloud regions.
Amazon Web Services (Amazon Bedrock)
AI-assisted feedback and drafting support where enabled. Processing takes place in supported EU AWS regions.
Postmark
Transactional email. Postmark is US-based, so this involves a transfer outside the UK; appropriate safeguards are set out in the contract schedule.
International transfers
Core platform records are hosted in the UK and EU where possible. Some service providers may process personal data in EU regions outside the UK. Where personal data leaves the UK, including transactional email through Postmark, we document the applicable UK adequacy basis or other appropriate safeguard in the contract schedule.
Your rights and complaints
Students, parents and staff can exercise their data protection rights by contacting their school as the data controller, or by emailing info@outleap.io and we will route the request to the school. If you are not satisfied with how a concern is handled, you have the right to complain to the Information Commissioner's Office at ico.org.uk.
Controller and contact
Outleap Limited (Company No. 14277395), 3rd Floor, 86-90 Paul Street, London EC2A 4NE. ICO registration ZB393894. For privacy and data-rights enquiries, contact info@outleap.io. We have not appointed a Data Protection Officer, which is not required under UK GDPR Article 37; the company director is our data-protection contact.
For a plain-language summary written for students, see the student privacy notice.
The full trust pack
For procurement, the trust pack includes a DPA template, DPIA starter, subprocessor list, data-flow description, retention policy and AI-safety policy. To review them with your team, book a trust review.