Skip to main content
Back to home
Legal

Privacy Policy

How NAfSA collects, uses, and protects personal data when you use the platform, buy services, book commissioned training, or take part in our community.

Last updated: 6 September 2026

Legal entity

National Alliance for School Attendance Ltd (NAfSA). Registered in England and Wales. Company Registration Number: 10252699. Registered Office: Cleveland, Hayscastle, Haverfordwest, Wales, SA62 5NY.

Who we are

National Alliance for School Attendance Ltd (NAfSA). Registered in England and Wales. Company Registration Number: 10252699. Registered Office: Cleveland, Hayscastle, Haverfordwest, Wales, SA62 5NY.

For the purposes of UK data protection law (the UK General Data Protection Regulation, or UK GDPR), National Alliance for School Attendance Ltd is the data controller for personal data processed through the NAfSA platform, unless we tell you otherwise for a specific service. We are registered as a data controller with the UK Information Commissioner's Office (ICO). Our ICO registration reference is ZA217586.

Registered entity details shown on this page are maintained centrally in our admin settings and may be updated when our corporate structure changes (for example, when NAfSA is registered as a separate limited company).

Personal data we collect

We collect and process personal data depending on how you use the platform, including:

  • Account and profile data: name, email, organisation, job title, phone (optional), school or local authority identifiers, and preferences you provide when registering or editing your profile.
  • Membership and billing data: membership tier, payment status, invoice or purchase order references, and transaction records processed via Stripe or recorded manually for invoice customers.
  • Event and ticket data: bookings, attendance-related event selections, discount codes applied, and payment confirmations.
  • Commissioned training data: delegate names, roles, organisation, contact details, and related booking correspondence provided by the commissioning organisation.
  • Commercial activity data: partner directory and event listing submissions, tier selections, listing fees paid, and correspondence relating to approval or rejection.
  • Community content: forum posts, replies, resource uploads, expert questions, and related metadata.
  • Communications: messages sent through contact forms, support mailboxes, and email delivery and engagement logs (including whether an email was delivered, opened, or a link was clicked, where measurement is enabled).
  • Professional mailing list: work email, name, organisation, organisation type, and subscription status for people who are not (or not yet) platform members, collected via a contact import under legitimate interests or via the public Keep in touch form under consent.
  • Technical data: IP address, browser type, device information, and usage analytics where enabled.

How we use your data

We use personal data to provide, secure, and improve the platform, including:

  • Creating and managing member accounts and access to portal features.
  • Processing membership, event tickets, commissioned training bookings, partner directory listings, and event calendar listing fees.
  • Arranging and delivering commissioned training, including communicating with nominated contacts and delegates.
  • Sending transactional and service emails (for example, the Monday weekly platform digest, 7-day free evaluation alerts, booking confirmations, submission updates, and account notifications). The weekly digest is a membership service email about platform activity (including NAfSA News); it is not marketing and can be paused from your profile.
  • Sending optional marketing and sector updates to members who have opted in via their profile preferences (consent).
  • Sending occasional professional updates to a separate mailing list of work contacts (local authority, school, and related roles) who are not mailed as members — see “Professional mailing list” below.
  • Measuring whether emails we send were delivered, opened, or had links clicked (via our email provider) so we can improve whether sector and professional updates are useful. Open rates can be imperfect because some mail clients prefetch images; we do not sell this data.
  • Moderating community content, preserving the professional integrity of our forums, and enforcing our terms.
  • Complying with statutory legal obligations and responding to lawful requests.
  • Understanding platform usage to improve system reliability, speed, and security.

Professional mailing list

We hold a professional mailing list that is separate from NAfSA membership accounts. It is used only for occasional role-relevant updates about school attendance practice and related sector news — not for selling products to the general public.

Where we add a work contact from a prior professional relationship (for example a curated contact list), we rely on legitimate interests for B2B electronic mail under UK PECR, balanced against your right to object. The first message explains why you are hearing from NAfSA and how to stop.

Where you subscribe via the public Keep in touch form (/updates), we rely on your consent. We use a confirmation email (double opt-in) before activating the subscription.

You can object or unsubscribe at any time using the link in every mailing-list email, or by contacting us. After you unsubscribe we keep a suppression record so a later contact import does not silently re-add you. If you later become a member, marketing preferences move to your member profile and the prospect row is suppressed so you are not emailed twice.

Mailing-list and marketing emails may include delivery and engagement measurement (opens and link clicks) operated by our email sub-processor. This helps us understand whether role-relevant updates are useful. You can stop messages at any time via unsubscribe; engagement measurement follows the same retention approach as our email delivery logs.

Lawful bases

This is the legal reason we may use your data. We rely on one or more of the following lawful bases under UK GDPR, depending on the specific activity:

  • Contract — to fulfil or prepare for a membership, evaluation access, ticketing, commissioned training, or commercial listing service you request.
  • Legitimate interests — to operate, secure, and improve the platform, manage collective industry insight, prevent fraud, support our members, and (for the professional mailing list) send role-relevant B2B updates to work contacts where PECR permits, balanced fairly against your individual privacy rights.
  • Consent — where explicitly required for optional member marketing preferences, public mailing-list subscribe, or non-essential cookies (see Cookie Policy).
  • Legal obligation — where we must retain or disclose information to comply with UK statutory law.

Sub-processors

We use other organisations (sub-processors) to run the platform. They handle personal data strictly under our instruction. The same register is in procurement pack. Cookies and similar technologies are explained in Cookie Policy.

  • Clerk — Authentication, single sign-on (SSO), and account security.
  • Stripe — Payment Card Industry (PCI) compliant card payments and checkout.
  • Neon (PostgreSQL) — Managed database — core member data.
  • Vercel — Application hosting and deployment.
  • Resend — Email delivery and engagement measurement (opens and link clicks where enabled).
  • Supabase — Cloud file storage for uploads and attachments.
  • Vercel Analytics — Aggregated, privacy-respecting usage analytics.

International data transfers

Some of our service providers are headquartered or operate infrastructure outside the United Kingdom and the European Economic Area (EEA), mainly in the United States.

Whenever your personal data is transferred internationally, we ensure a similar degree of protection is afforded to it by ensuring that appropriate legal safeguards are implemented, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to standard contractual clauses approved by the European Commission.

Sharing personal data

We do not sell, rent, or trade your personal data.

We only share data with the infrastructure processors listed above, with other members where you explicitly choose to make information public (such as setting your profile to visible in the community directory), or where we are legally compelled to do so by law enforcement or regulatory authorities.

Event organisers using the NAfSA platform for ticketing receive the necessary purchaser information required to fulfil and manage the specific event they host, in line with our terms.

For commissioned training, we use delegate details only to deliver that booking. We do not share delegate lists with third parties except processors needed to host the session (for example an online meeting provider), or where the commissioning organisation asks us to, or where we are legally compelled to do so.

How long we keep data

We do not keep personal data longer than we need it.

We retain personal data only for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To comply with UK tax law and statutory limitation periods, membership financial transactions and billing records are securely retained for 6 years following the end of the financial year in which the transaction occurred. Unconverted 7-day evaluation account profiles are routinely reviewed and cleared of identifying personal data if inactive.

Professional mailing-list contacts are retained while subscribed. After unsubscribe or suppression we retain a limited record (including the email address or an anonymised placeholder) so we do not re-import or re-mail you by mistake.

Your rights

You have legal rights over your personal data.

Under UK data protection law, you have distinct rights regarding your personal data, including the right to access, rectify, erase, restrict, or object to the processing of your data, as well as the right to data portability. Where our processing relies entirely on your consent, you have the right to withdraw that consent at any time.

To exercise any of your statutory rights, contact us via our contact form on the contact page. To protect your privacy and security, we will take reasonable steps to verify your identity before granting access or making corrections.

You also have the right to lodge a formal complaint at any time with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us first.

Security

We implement strict technical and organisational security measures to prevent your personal data from being accidentally lost, used, altered, disclosed, or accessed in an unauthorised way. This includes encrypted connections (HTTPS), strict database access controls, and fully outsourced, Payment Card Industry (PCI) compliant payment handling via Stripe. While we work to protect your information, no digital platform or internet transmission can ever be guaranteed as 100% secure.

Contact

For privacy and data protection questions, use our contact form on the contact page.