Skip to content

Privacy Policy

Last updated 21 June 2026

This policy explains what personal data Ceidwad handles, why, and the rights you have. It is written to meet UK GDPR and the Data Protection Act 2018. Plain-English summaries sit alongside the detail.

Who we are

Ceidwad ("we", "us", "our") provides a cyber-security and compliance platform for schools, colleges and multi-academy trusts. The data controller is Ceidwad Limited, a private company limited by shares registered in England and Wales with company number 17373758. Our registered office is 279 Highbury Grove, Portsmouth, England, PO6 2RW. You can reach us about privacy at security@ceidwad.co.uk.

Controller or processor — which applies

This matters for schools. There are two different relationships:

  • We are the controller for personal data about visitors to this website, people who request an assessment or sign up, and the named contacts at a school or trust. This policy governs that data.
  • We are a processor for the pupil and staff data inside a school's or trust's own systems (e.g. Microsoft 365). The school or trust remains the controller and decides how that data is used. Our handling of it is governed by the Data Processing Agreement that forms part of your contract — not by this website policy.

What we collect and why

  • Account & contact details (name, work email, school/trust, role) — to create and run your account. Lawful basis: contract.
  • School identity (URN, establishment type, trust membership) looked up in the DfE's public Get Information about Schools register — to assign the correct plan. Lawful basis: legitimate interests (accurate, fair pricing).
  • Assessment answers you provide in the free security assessment — to generate your indicative score and recommendations. Lawful basis: consent.
  • Microsoft 365 security posture data (configuration and security signals, read-only) where you connect a tenant — to assess and report your posture. We handle this as your processor. We do not read message content or files.
  • Usage & technical data (e.g. pages viewed, device/browser, IP) — to keep the service secure and working. Lawful basis: legitimate interests.

We do not sell personal data, and we do not use it for third-party advertising.

Who we share data with

Service providers (sub-processors) that help us run Ceidwad:

  • Microsoft — Microsoft 365 / Graph security signals you choose to connect, and Microsoft Azure (UK South region) for hosting.
  • Azure OpenAI — AI advisor and inference processing for Ask Ceidwad, where enabled. The Azure resource is configured in UK South, but chat inference may be processed using an Azure OpenAI GlobalStandard deployment and may involve processing outside the UK under Microsoft's data protection terms and UK-approved transfer safeguards. Azure OpenAI is not used to train Microsoft or third-party models on customer data.
  • Email delivery — to send service messages and reports.
  • AI processing — where the "Ask Ceidwad" advisor is enabled, Ceidwad uses Azure OpenAI to help generate plain-English explanations and guidance. The Azure resource is configured in UK South and core platform data at rest is hosted in the UK. The chat model currently uses an Azure OpenAI GlobalStandarddeployment, which means inference processing may be routed to Microsoft datacentres outside the UK. Our embeddings model is UK-region pinned; the international transfer risk relates to the chat model.

    Before relevant text is sent to Azure OpenAI, Ceidwad applies redaction and tokenisation controls designed to reduce direct identifiers, including email addresses, phone numbers, postcodes, IP addresses and user principal names. The original values are restored only in the answer shown back to the authorised user. Free-text personal names may not always be detected or masked.

    Azure OpenAI is not used to train Microsoft or third-party models on customer data. Microsoft acts as our sub-processor under its data protection terms. Where AI processing involves an international transfer, we rely on appropriate contractual safeguards, including Microsoft's data protection terms and UK-approved transfer safeguards where required.

    We have chosen to leave Microsoft's standard abuse-monitoring controls switched on, as an additional safety and misuse-detection measure for a service used by schools. This means Microsoft may retain prompts and responses for up to 30 days for abuse-monitoring purposes, and content that is flagged may be reviewed by Microsoft. We treat this as sub-processor processing, record it in our data protection records, and keep the decision under review.
  • Email-security reporting (Mail check) — DMARC aggregate reports are received and processed entirely within our own UK Azure tenancy; no third party handles them. These reports contain only sending-server IP addresses and pass/fail counts — never message content, documents or pupil data.

A current sub-processor list is available on request at security@ceidwad.co.uk.

Where your data is held

Core platform data at rest is hosted in the UK using Microsoft Azure UK South where applicable. Some services may involve processing outside the UK. In particular, where the Ask Ceidwad AI advisor is enabled, chat inference may be routed through an Azure OpenAI GlobalStandard deployment to Microsoft datacentres outside the UK. Where any international transfer is involved, we rely on UK-approved safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or other applicable safeguards.

How long we keep it

We keep account and customer administration data for the life of the customer relationship and for up to 6 years afterwards where needed for contract, tax, accounting or legal record purposes. Enquiry and assessment data is normally kept for up to 24 months unless a longer period is needed for an active customer relationship, legal requirement, security investigation or dispute. Customer personal data processed as processor is retained and deleted in accordance with the Data Processing Agreement and the applicable Order Form.

Your rights

Under UK GDPR you can ask us to:

  • give you a copy of your data (access)
  • correct inaccurate data (rectification)
  • delete data in certain circumstances (erasure)
  • restrict or object to processing
  • port data you gave us, where it's based on consent or contract
  • withdraw consent at any time, without affecting earlier processing

Email security@ceidwad.co.uk and we'll respond within one month. If you're a pupil, parent or staff member asking about data your school holds, contact the school — they are the controller and we'll support them.

Automated decisions

Your readiness score and recommendations are generated automatically, but they support human decisions — they do not produce legal or similarly significant effects on any individual, so Article 22 does not apply.

Ask Ceidwad does not make decisions about individuals. It provides explanations and guidance. Security scores are calculated in code from measured security facts — the AI model does not determine the score, and it does not make legal or similarly significant decisions about individuals.

Children's data

Ceidwad is sold to and used by school staff, not children. Any pupil data is handled only as a processor on a school's instructions under the Data Processing Agreement.

Complaints

We hope to resolve any concern directly. You also have the right to complain to the Information Commissioner's Office — ico.org.uk, 0303 123 1113.

Changes

We'll update this policy as the service evolves and post the new date above. Material changes will be highlighted to account holders.