Trust centre

Trust, security & privacy

This page is maintained by School Summit to answer common security and privacy questions about School Summit Connect. It describes practices and controls currently in place. It is editable project content — not an independent certification.

Access & authentication

Sign-in is available via email/password and Google. Sessions are managed by our hosting provider's authentication service, with secure token storage in the user's browser.

Administrative actions are gated by role-based access control (platform admin, hub admin, university admin, school user). Sensitive commercial fields on organisations are only readable by platform administrators via a server-side authorisation check.

Data protection & storage

Customer data is stored in a managed Postgres database with row-level security policies enabled on user-data tables. Data in transit is encrypted via HTTPS/TLS. Data at rest is encrypted by our managed database provider.

Database backups and platform-level encryption are managed by our hosting provider. We do not store payment card data.

What we collect

School Summit Connect collects the information school staff, students and partner organisations submit through the platform — for example school name, teacher name and email when registering for an event, or contact details submitted via an enquiry form.

We also collect basic engagement signals such as page views, resource downloads and event registrations to help partner organisations understand how their hub is being used.

Hosting & subprocessors

The platform is hosted on managed serverless infrastructure. Authentication, database, file storage and email delivery are provided by trusted infrastructure partners. A current list of subprocessors is available on request from the contact below.

Shared responsibility

Platform features (authentication, encryption-in-transit, RLS, infrastructure patching) are provided by School Summit and our hosting partners. Organisation-specific content, the accuracy of pathway and event information, and management of users and roles within each hub are the responsibility of the licensed organisation.

Customers are responsible for protecting their own login credentials and for ensuring their use of the platform complies with applicable law and their own internal policies.

Cookies & analytics

The platform uses cookies that are strictly necessary for sign-in and session management, plus a small number of cookies used for product analytics. A cookie notice is presented on first visit. Analytics data is aggregated and used to improve the product and report engagement to partner organisations.

Retention & deletion

Account and engagement data is retained for as long as an organisation maintains an active licence with School Summit. Deletion or export requests are handled in line with applicable data-protection law.

Specific retention periods and contractual data-handling terms can be confirmed in writing as part of a licence agreement.

Privacy requests & contact

For privacy requests (access, correction, deletion), security questions, or to report a suspected vulnerability, please contact us at hello@schoolsummit.co.uk.

We aim to acknowledge security reports within two business days.

For procurement teams

Procurement Information Pack

A consolidated reference document covering company information, GDPR & data processing, safeguarding, accessibility, platform governance and the support model. Designed for procurement, IT, data-protection and legal teams. Not a legal certification — definitive terms sit in the Master Licence Agreement and DPA.

Download Procurement Pack (PDF)
Voices

What organisations say

Approved stories and testimonials from the organisations we work with. Filter by sector.

This page describes current practices and is maintained by School Summit. It is not an independent audit, certification or legal warranty. For contractual commitments, refer to your licence agreement. Return home.