Skip to main content
EngagedLab
Legal

Privacy Policy

Last updated: January 15, 2026Effective: February 1, 2026

Plain-Language Summary

  • • We collect only what’s necessary to provide and improve our educational services.
  • • Student learning data is used solely for educational purposes—never sold or used for advertising.
  • • We comply with FERPA (US), GDPR (EU/UK), and applicable regional privacy laws.
  • • You can access, export, or delete your data at any time.
  • • Institutional accounts retain data ownership; we are the data processor.

1. Who We Are

EngagedLab (“we”, “us”, “our”) is an educational technology platform that transforms static learning materials into interactive, gamified experiences. EngagedLab is operated by EdTechLab LTD, a company registered in England and Wales.

The official company website of EdTechLab LTD is EdTechLab.co.uk.

Data Controller: For individual user accounts, EdTechLab LTD acts as the data controller. For institutional deployments, the subscribing institution is the data controller and EngagedLab acts as the data processor under a Data Processing Agreement (DPA).

Data Protection Officer: dpo@engagedlab.co.uk

2. Data We Collect

2.1 Account Information

When you create an account, we collect:

  • • Full name and email address
  • • Password (stored as a bcrypt hash—we never store plaintext passwords)
  • • Institution name (optional)
  • • Phone number (optional, for two-factor authentication)
  • • Profile avatar (optional)
  • • Role selection (Educator, Administrator)

2.2 Learning & Interaction Data

When users interact with labs and challenges, we collect:

  • • Lab completion events and attempt timestamps
  • • Quiz and challenge responses (used for mastery tracking)
  • • Bayesian mastery probability scores per concept
  • • Time spent on activities (for learning analytics)
  • • Misconception patterns (aggregated, for content improvement)
  • • XP, achievements, and streak data (gamification)

2.3 Content Data

  • • Source materials uploaded by educators (PDFs, Word documents, text)
  • • Generated interactive lab content
  • • Comments and version history in collaborative editing
  • • Course structures and enrolment data

2.4 Technical & Usage Data

  • • IP address and approximate geolocation (country-level)
  • • Browser type, operating system, and device type
  • • Pages visited and session duration
  • • Error logs and performance metrics
  • • Referral source

3. How We Use Your Data

PurposeLegal Basis (GDPR)
Provide and operate the EngagedLab platformContract performance
Track learner mastery via Bayesian Knowledge TracingLegitimate interest (educational outcomes)
Generate interactive content from uploaded materialsContract performance
Send transactional emails (password resets, notifications)Contract performance
Provide analytics dashboards to educatorsLegitimate interest
Process subscription payments via StripeContract performance
Improve AI models and content quality (aggregated data only)Legitimate interest
Comply with legal obligations (tax records, law enforcement)Legal obligation

4. Data We Never Collect or Sell

  • • We never sell personal data to third parties.
  • • We never use student data for advertising or profiling.
  • • We never share individual learning data with employers or third parties.
  • • We do not collect biometric data, social media profiles, or browsing history outside our platform.
  • • We do not use tracking pixels or third-party advertising cookies.

5. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in transit: All connections use TLS 1.3.
  • Encryption at rest: Database storage uses AES-256 encryption.
  • Password hashing: bcrypt with salt rounds ≥ 12.
  • Access controls: Role-based access with multi-tenant isolation.
  • Infrastructure: Hosted in SOC 2 Type II certified data centres.
  • Monitoring: 24/7 intrusion detection and automated alerting.
  • Backups: Encrypted daily backups with point-in-time recovery, retained for 30 days.
  • Penetration testing: Annual third-party pen tests with remediation SLAs.

6. Data Sharing & Sub-Processors

We share data only with service providers necessary to operate the platform:

ProviderPurposeData Shared
Google Cloud (Vertex AI)AI content generationSource text (no PII)
StripePayment processingEmail, payment method
ResendTransactional emailEmail address, name
Cloud hosting providerInfrastructureAll data (encrypted)

All sub-processors are bound by Data Processing Agreements. A full list is available upon request.

7. International Data Transfers

Our primary infrastructure is located in the European Economic Area (EEA). When data is transferred outside the EEA, we rely on:

  • • EU Standard Contractual Clauses (SCCs) for US-based sub-processors
  • • UK International Data Transfer Agreement (IDTA) for UK adequacy
  • • Supplementary security measures as required by the Schrems II ruling

For institutional partners requiring data residency guarantees, we offer EU-only and UK-only hosting configurations.

8. Your Rights

Depending on your jurisdiction, you have the following rights:

Access:Request a copy of all personal data we hold about you.
Rectification:Correct inaccurate or incomplete personal data.
Erasure:Request deletion of your data ("right to be forgotten").
Portability:Export your data in a machine-readable format.
Restriction:Limit how we process your data in certain circumstances.
Objection:Object to processing based on legitimate interests.
Withdraw Consent:Where consent is the legal basis, withdraw it at any time.
Lodge Complaint:File a complaint with your local data protection authority.

To exercise any right, email privacy@engagedlab.co.uk. We respond within 30 days. For GDPR subjects, the supervisory authority is the UK Information Commissioner’s Office (ICO).

9. Data Retention

Data TypeRetention Period
Active account dataDuration of account + 90 days after deletion
Learning analyticsDuration of account (anonymised upon deletion)
Generated lab contentDuration of account + 30 days
Payment records7 years (legal requirement)
Server logs90 days
Backup data30 days (rolling)

10. Cookies & Similar Technologies

We use a minimal set of cookies:

  • Essential cookies: Session authentication, CSRF protection, locale preference. These cannot be disabled.
  • Preference cookies: Theme selection (light/dark), language preference. Stored locally.

We do not use third-party analytics cookies, advertising cookies, or cross-site tracking technologies.

11. Children’s Privacy

EngagedLab is designed for higher education and professional training. We do not knowingly collect data from children under 16 (or 13 in the US under COPPA). If an institution uses EngagedLab with students under the applicable age threshold, the institution is responsible for obtaining appropriate consent. If we learn that we have collected data from a child without proper authorisation, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes, we will:

  • • Post the updated policy on this page with a new effective date
  • • Notify registered users by email at least 30 days before changes take effect
  • • Notify institutional administrators through the admin dashboard

13. Contact Us

For privacy-related enquiries, data access requests, or complaints:

Email: privacy@engagedlab.co.uk

DPO: dpo@engagedlab.co.uk

Official company website: EdTechLab.co.uk

Post: EdTechLab LTD, Level 3, 1 Finsbury Avenue, London EC2M 2PP, United Kingdom