Privacy Policy

Last updated: 18 December 2025

Introduction

This Privacy Policy explains how ULEARNA TECHNOLOGY LTD (Company Number: 16128306) ("we", "us", "our") collects, uses, discloses, and protects personal data when you use CLAST.io (the "Platform"), a cloud-based education ERP and AI-enabled system.

This policy is drafted in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

Data Processor / Service Provider:

ULEARNA TECHNOLOGY LTD

14 Enderby Road, Luton, Bedfordshire, LU3 2HQ, England

Email: legal@clast.io

For most data processed on the Platform, educational institutions are the Data Controller, and ULEARNA TECHNOLOGY LTD acts as a Data Processor.

2. Scope

This Privacy Policy applies to:

  • Visitors to the CLAST.io website
  • Institutional customers
  • Authorised users (administrators, staff, teachers)

Student and learner data is processed only on behalf of institutions and governed primarily by the relevant institution's privacy notices and our Data Processing Agreement (DPA).

3. Personal Data We Process

Depending on your role and use of the Platform, we may process:

3.1 Account and Identity Data

  • Name, email address, phone number
  • Job title, role, institution name
  • Login credentials (hashed)

3.2 Educational and Operational Data

  • Student records, attendance, grades, assessments
  • Timetables, communications, academic history
  • Financial and billing records (institution-level)

3.3 Technical and Usage Data

  • IP address, device information, browser type
  • Log files, usage metrics, error reports

3.4 Support and Communication Data

  • Support tickets, chat messages, emails

We do not intentionally collect biometric data or special-category data unless required by the institution and legally permitted.

4. How We Use Personal Data

We process personal data to:

  • Provide and operate the Platform
  • Authenticate users and manage accounts
  • Deliver customer support
  • Improve performance, security, and reliability
  • Comply with legal obligations

AI-powered features may process data to provide automation or assistance but do not make legally binding or autonomous decisions.

5. Lawful Bases for Processing

Under UK GDPR, we rely on the following lawful bases:

  • Contract – to deliver services to institutions
  • Legal obligation – regulatory and compliance requirements
  • Legitimate interests – security, fraud prevention, service improvement
  • Consent – where explicitly required

6. Children's Data

CLAST.io is designed for educational use. Children's data:

  • Is processed strictly on the instructions of institutions
  • Is not used for marketing or profiling
  • Is protected by technical and organisational safeguards

Parents or guardians should contact the relevant institution for rights requests.

7. Data Sharing and Disclosure

We may share data with:

  • Cloud hosting and infrastructure providers
  • Payment processors (institution-level only)
  • Analytics and monitoring providers

All third parties are contractually bound to confidentiality and data protection obligations.

We do not sell personal data.

8. International Data Transfers

Where data is transferred outside the UK:

  • Appropriate safeguards are applied (e.g. UK SCCs)
  • Transfers comply with UK GDPR requirements

9. Data Retention

  • Data is retained only as long as necessary to provide services
  • Upon contract termination, data is returned or deleted in accordance with the DPA
  • Backup retention follows industry best practices

10. Data Security

We implement appropriate safeguards, including:

  • Encryption in transit and at rest
  • Access controls and role-based permissions
  • Regular security monitoring and testing

No system is 100% secure, but we take reasonable measures to protect data.

11. Your Rights (UK GDPR)

Individuals have the right to:

  • Access personal data
  • Rectify inaccurate data
  • Erase data (where applicable)
  • Restrict or object to processing
  • Data portability
  • Lodge a complaint with the ICO

Requests should be directed to the relevant institution or to us where appropriate.

12. Cookies

CLAST.io uses essential cookies and similar technologies necessary for platform functionality. Optional analytics cookies may be used with consent.

13. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated through the Platform or website.

14. Contact Us

For privacy-related questions:

Email: legal@clast.io