Security and data protection
How the platform protects the young people who use it
Brightwire is deliberately built so that it never holds a student’s name or date of birth. All personal data is hosted in the European Union, and accounts cannot be self-created.
- Document version
- 1.1 — 5 August 2026
- Applies to
- The Brightwire platform
- Audience
- School IT, data protection and safeguarding leads
- Applicable law
- UK GDPR and Data Protection Act 2018
The short version
Research records carry an anonymous identifier, an exact age and an age band, and nothing else that identifies the person. A student’s email address exists only in the authentication system, so that a sign-in link can be sent. A student exists only because a named administrator invited them. Information about neurodivergence is collected only where the young person has given explicit consent — and that rule is enforced by the database itself, not only by the application.
Never collected, at any point
- Full name or surname
- Date of birth
- Address or telephone number
- School roll or UPN number
- Photographs
- Free text about other people
- Payment information
- Anything joining an email to an answer in a research export
Where the data lives
Every system that stores or processes personal data is hosted in the European Union. This is the live production configuration.
| Service | Provider | Region | Purpose |
|---|---|---|---|
| Database, authentication, storage | Supabase (PostgreSQL 17) | Frankfurt, Germany | All student data and accounts |
| Application hosting | Vercel | Frankfurt, Germany | Web application and server-side processing |
| Transactional email | Resend | Ireland | Sign-in links and invitations, with open and click tracking disabled |
| AI narrative generation | Anthropic (Claude API) | United States | Generates the written profile from banded results only |
| Website analytics | Google Analytics 4 | United States | Public pages only, and only after the visitor accepts |
On the two non-EU services. Neither receives anything that identifies a student. The AI provider receives banded results and an age band, with no identifier attached. Analytics runs only on the public pages a member of staff might browse, never on a page a student is signed in to.
Who gets in, and who sees what
Students sign in with a one-time link
Sent to their email. There is no password to be guessed, reused, or shared.
Staff passwords are checked against breach data
At least 12 characters, rejected if the password appears in a database of known breached credentials.
Accounts cannot be self-created
A student account exists only because a named administrator issued an invitation. There is no public sign-up route.
A student sees only their own
Their own session, answers, scores, and profile — nothing belonging to any other student. A school administrator sees only their own school.
Declared openly: what is not in place yet
Brightwire is in its first school deployment. The following are genuinely outstanding, and are listed here rather than omitted so that a school’s due diligence finds no surprises.
- Data Processing Agreement
- Template prepared; to be executed with each school before any student account is created.
- ICO registration and data protection contact
- To be confirmed and published in the privacy notice before the pilot begins.
- Defined retention period
- Being confirmed with the university ethics team. Data is held for the duration of the pilot and deleted on request at any time.
- Parental consent for under-16s
- Currently handled offline by the school. The in-platform process is being confirmed with the ethics team.
- Independent penetration test
- Not yet carried out.
- Cyber Essentials, ISO 27001, formal WCAG 2.1 AA certification
- Not held. Accessibility requirements are built in and tested, but no formal certification has been sought.
The full factsheet
This page is a summary. The complete document covers consent and special category data, encryption and platform hardening, exactly what is and is not sent to the AI provider, data subject rights, and operational resilience.
Platform built and operated by NLACE. Research direction: Pablo Muñoz, PhD. Questions about anything on this page can go to the Brightwire team via your coordinator.