GDPR & Your Privacy Rights

Last updated: 15 January 2026

Your Data, Your Rights

At Lessonly, we are committed to protecting your personal data and respecting your privacy rights. This page explains your rights under the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR), and how you can exercise them.

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that gives individuals control over their personal data. Whether you are based in the United Kingdom or the European Economic Area (EEA), you have specific rights regarding how your personal data is collected, used, and stored.

This page should be read in conjunction with our Privacy Policy, which provides full details about how we process your personal data.

1. Data Controller Information

Under GDPR, the "data controller" is the organisation that determines the purposes and means of processing personal data. For Lessonly, the data controller is:

Lessonly Ltd

Company Registration Number:

Registered Address:

Website: https://lessonly.co.uk

Data Protection Officer (DPO)

We have appointed a Data Protection Officer to oversee our data protection strategy and ensure compliance with GDPR. You can contact our DPO for any data protection queries:

Data Protection Officer

Email: contact@lessonly.co.uk

Address:

2. Legal Bases for Processing

Under Article 6 of the GDPR, we must have a valid legal basis to process your personal data. We rely on the following legal bases:

A

Contract Performance (Article 6(1)(b))

Processing necessary to perform our contract with you or to take steps at your request before entering into a contract.

Examples: Creating your account, providing the Lessonly service, processing payments, customer support.

B

Legitimate Interests (Article 6(1)(f))

Processing necessary for our legitimate interests or those of a third party, provided your rights don't override those interests.

Examples: Improving our services, analytics, fraud prevention, security monitoring, business administration.

C

Consent (Article 6(1)(a))

Processing based on your specific, informed, and unambiguous consent. You can withdraw consent at any time.

Examples: Marketing communications, optional analytics cookies, newsletter subscriptions.

D

Legal Obligation (Article 6(1)(c))

Processing necessary to comply with a legal obligation to which we are subject.

Examples: Tax and accounting requirements, responding to lawful requests from authorities, regulatory compliance.

Legitimate Interests Assessment

Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment (LIA) to balance our interests against your rights and freedoms. You can request a copy of our LIA by contacting our DPO.

E

AI Processing (Article 6(1)(b) and 6(1)(a))

Processing of your prompts and inputs by AI systems to provide the lesson generation service you have requested.

Legal basis: Contract performance (providing the service you requested) and, where applicable, consent for optional AI features.

[X]. AI Processing and Automated Decision-Making

Lessonly uses artificial intelligence to generate educational content. This section explains how AI processing relates to your GDPR rights.

[X].1 Nature of AI Processing

When you use our AI-powered lesson generation features:

  • Your prompts and inputs are processed by AI systems to generate content
  • This processing is automated but does not constitute "automated decision-making" under Article 22 of the GDPR
  • AI outputs are suggestions and tools – no decisions with legal or similarly significant effects are made solely by AI
  • You maintain full control over whether to use, modify, or discard AI-generated content

[X].2 Article 22 - Automated Decision-Making

Article 22 of the GDPR gives you the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you.

Our AI features do not fall under Article 22 because:

  • AI-generated lesson content does not produce legal effects on you
  • AI suggestions do not similarly significantly affect you – they are tools to assist your work
  • You have full human oversight and control over all AI outputs
  • No automated decisions are made about your account, access, or rights

[X].3 Data Sent to AI Providers

When you use AI features, the following data is processed:

Data TypePurposeLegal BasisRetention
Lesson promptsGenerate contentContractTransient (up to 30 days by provider)
Subject/topicContext for generationContractTransient
Year group/key stageAge-appropriate contentContractTransient
Curriculum preferencesAligned contentContractTransient

[X].4 AI Providers and International Transfers

Our AI features are powered by third-party providers. Data transfers to these providers are protected by:

ProviderLocationTransfer SafeguardTraining Data Policy
[e.g., OpenAI][e.g., USA][e.g., SCCs + UK Addendum]Data not used for training
[e.g., Anthropic][e.g., USA][e.g., SCCs + UK Addendum]Data not used for training

[X].5 Your Rights Regarding AI Processing

In relation to AI processing, you have the right to:

  • Information: Know when AI is being used to process your data (this page)
  • Access: Request information about AI processing of your data
  • Choice: Use Lessonly without AI features if you prefer
  • Deletion: Request deletion of AI-generated content and associated data
  • Object: Object to AI processing based on legitimate interests
  • Human review: Request human review of any concerns about AI outputs

[X].6 AI Training and Your Data

Important: Your Data Is Not Used to Train AI Models

We have contractual agreements with our AI providers ensuring that:

  • Your prompts and inputs are not used to train or improve AI models
  • AI-generated outputs are not used to train AI models
  • Your data is processed only to provide the requested service
  • Data is handled in accordance with our Data Processing Agreements

[X].7 Data Protection Impact Assessment (DPIA)

In accordance with Article 35 of the GDPR, we have conducted a Data Protection Impact Assessment for our AI features. This assessment evaluates the risks to your rights and freedoms and the measures we have implemented to mitigate those risks. You may request a summary of our DPIA by contacting our Data Protection Officer.

3. Your Data Protection Rights

Under UK GDPR and EU GDPR, you have the following rights regarding your personal data. These rights are not absolute and may be subject to certain conditions and exemptions.

πŸ” Right of Access (Article 15)

You have the right to obtain confirmation as to whether we process your personal data and, if so, to request access to that data. This is commonly known as a "Subject Access Request" (SAR).

What you can request:

  • Confirmation that we process your data
  • A copy of your personal data
  • Information about processing purposes
  • Categories of data we hold
  • Recipients of your data
  • Retention periods
  • Source of the data (if not collected from you)
  • Information about automated decision-making

✏️ Right to Rectification (Article 16)

You have the right to request correction of inaccurate personal data and to have incomplete data completed.

How to rectify your data:

  • Update your profile directly in your Lessonly account settings
  • Contact us to request corrections to data you cannot edit yourself
  • We will respond within one month

πŸ—‘οΈ Right to Erasure / "Right to be Forgotten" (Article 17)

You have the right to request deletion of your personal data in certain circumstances.

When you can request erasure:

  • The data is no longer necessary for its original purpose
  • You withdraw consent (where consent was the legal basis)
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • Legal obligation requires erasure

Note: We may not be able to delete your data if we need to keep it for legal compliance, legal claims, or other lawful purposes. We will inform you if this is the case.

⏸️ Right to Restriction of Processing (Article 18)

You have the right to request that we restrict processing of your personal data in certain circumstances.

When you can request restriction:

  • You contest the accuracy of the data (while we verify it)
  • Processing is unlawful but you prefer restriction over erasure
  • We no longer need the data but you need it for legal claims
  • You have objected to processing (pending verification)

When processing is restricted, we will only store your data and not process it further without your consent (unless for legal claims, protecting others' rights, or important public interest).

πŸ“¦ Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.

This right applies when:

  • Processing is based on consent or contract
  • Processing is carried out by automated means

Data formats we provide: JSON, CSV

You can export your data directly from your Lessonly account settings, or contact us for assistance.

βœ‹ Right to Object (Article 21)

You have the right to object to processing of your personal data in certain circumstances.

You can object to:

  • Direct marketing: You have an absolute right to object to processing for direct marketing purposes. We will stop immediately.
  • Legitimate interests: You can object to processing based on legitimate interests. We must stop unless we have compelling legitimate grounds.
  • Research/statistics: You can object to processing for scientific, historical research, or statistical purposes (unless in the public interest).

How to object: Email contact@lessonly.co.uk with details of your objection, or use the unsubscribe link in marketing emails.

πŸ€– Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.

Our approach:

Lessonly does not currently make any solely automated decisions that have legal or similarly significant effects on users. If this changes, we will update this policy and ensure you have the right to obtain human intervention, express your point of view, and contest the decision.

↩️ Right to Withdraw Consent (Article 7)

Where we process your data based on consent, you have the right to withdraw that consent at any time.

How to withdraw consent:

  • Update your preferences in account settings
  • Click "unsubscribe" in marketing emails
  • Update cookie preferences via our cookie banner
  • Contact us at contact@lessonly.co.uk

Note: Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

4. How to Exercise Your Rights

Submit a Data Subject Request

You can exercise any of your rights by contacting us using the methods below:

πŸ“ Post

Data Protection Officer
Lessonly Ltd

What to Include in Your Request

To help us process your request efficiently, please include:

  • Your full name and email address associated with your Lessonly account
  • The specific right(s) you wish to exercise
  • Any relevant details to help us identify the data concerned
  • Preferred format for receiving data (for access/portability requests)

Identity Verification

To protect your data, we may need to verify your identity before processing your request. This may include:

  • Confirming information we already hold about you
  • Requesting a copy of identification documents
  • Verifying via your registered email address

Response Times

StageTimeframe
Acknowledgement of requestWithin 5 working days
Standard responseWithin 1 month
Complex requests (extension)Up to 3 months total

If we need to extend the response time, we will inform you within one month of receiving your request, explaining why the extension is necessary.

Fees

In most cases, you will not have to pay a fee to exercise your rights. However, we may charge a reasonable fee if your request is:

  • Manifestly unfounded or excessive
  • Repetitive

Alternatively, we may refuse to comply with the request in such circumstances. If we charge a fee or refuse your request, we will inform you and explain our reasons.

5. Personal Data We Process

For full details about the personal data we collect, please see our Privacy Policy. Below is a summary:

CategoryExamplesLegal Basis
Identity DataName, username, titleContract
Contact DataEmail address, phone numberContract
Professional DataSchool name, job title, subjects taughtContract
Account DataUsername, password (encrypted)Contract
Technical DataIP address, browser type, device infoLegitimate Interests
Usage DataPages visited, features usedLegitimate Interests
Content DataLesson plans, resources, documentsContract
Marketing DataPreferences, subscriptionsConsent

Special Category Data

We do not intentionally collect special category data (e.g., racial or ethnic origin, political opinions, religious beliefs, health data, biometric data). If you include such data in your content, you do so at your own discretion.

6. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, in accordance with Article 5(1)(e) of the GDPR (storage limitation principle).

Data TypeRetention PeriodReason
Account dataDuration of account + 30 daysService provision
User contentUntil deleted or account closure + 30 daysService provision
Transaction records7 yearsLegal obligation (tax/accounting)
Analytics data26 monthsLegitimate interests
Marketing consentUntil withdrawn + 3 yearsLegal compliance
Support tickets3 years after resolutionLegitimate interests
Security logs12 monthsSecurity/legitimate interests

After the retention period expires, your data will be securely deleted or anonymised.

7. International Data Transfers

Your personal data may be transferred to, stored, and processed in countries outside the United Kingdom and European Economic Area (EEA). When we transfer your data internationally, we ensure appropriate safeguards are in place as required by Articles 44-49 of the GDPR.

Transfer Mechanisms We Use

βœ… Adequacy Decisions

Transfers to countries recognised by the UK Government or European Commission as providing adequate protection for personal data.

βœ… Standard Contractual Clauses (SCCs)

EU Commission-approved standard contractual clauses that provide appropriate safeguards for data transfers.

βœ… International Data Transfer Agreement (IDTA)

UK-specific transfer agreement approved by the ICO for transfers from the UK.

βœ… UK Addendum to EU SCCs

The UK Addendum used alongside EU SCCs to cover UK data transfers.

Our Data Sub-Processors

ProviderPurposeLocationSafeguard
SupabaseDatabase & authenticationEU (Frankfurt) / USASCCs
VercelHostingGlobal CDNSCCs
[Payment Provider]Payment processing[Location][Safeguard]
[Email Provider]Transactional emails[Location][Safeguard]

You may request a copy of the safeguards we have put in place for international transfers by contacting our DPO at contact@lessonly.co.uk.

8. Data Security Measures

In accordance with Article 32 of the GDPR, we have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

πŸ” Technical Measures

  • β€’ TLS/SSL encryption in transit
  • β€’ AES-256 encryption at rest
  • β€’ Secure password hashing (bcrypt)
  • β€’ Row-level security policies
  • β€’ Regular security patching
  • β€’ Intrusion detection systems
  • β€’ Regular penetration testing
  • β€’ Automated vulnerability scanning

πŸ“‹ Organisational Measures

  • β€’ Data protection policies
  • β€’ Staff training on GDPR
  • β€’ Access controls (need-to-know basis)
  • β€’ Confidentiality agreements
  • β€’ Vendor due diligence
  • β€’ Incident response procedures
  • β€’ Regular policy reviews
  • β€’ Data protection impact assessments

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by Article 33). If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly (Article 34).

9. Complaints & Supervisory Authorities

If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with a supervisory authority.

πŸ‡¬πŸ‡§ UK Users

Information Commissioner's Office (ICO)

Website: ico.org.uk

Telephone: 0303 123 1113

Live chat: ico.org.uk/live-chat

Address:
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF

πŸ‡ͺπŸ‡Ί EU/EEA Users

You may lodge a complaint with your local data protection authority. A list of EU/EEA supervisory authorities can be found at:

European Data Protection Board - Members

Common supervisory authorities:

  • β€’ Ireland: Data Protection Commission
  • β€’ Germany: State data protection authorities
  • β€’ France: CNIL
  • β€’ Netherlands: Autoriteit Persoonsgegevens

Before contacting a supervisory authority: We would appreciate the opportunity to address your concerns directly. Please contact our Data Protection Officer at contact@lessonly.co.uk first, and we will do our best to resolve your issue.

10. Changes to This GDPR Information

We may update this GDPR information page from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:

  • Posting the updated information on this page
  • Updating the "Last updated" date
  • Sending an email notification for significant changes
  • Displaying a notice when you log in to Lessonly

11. Contact Our Data Protection Team

If you have any questions about this GDPR information, your rights, or our data practices, please contact us:

Data Protection Officer

Data Protection Officer

Email: contact@lessonly.co.uk

Lessonly Ltd

General Enquiries

Email: contact@lessonly.co.uk

Website: https://lessonly.co.uk

Related Pages

GDPR Articles Referenced

This page references the following GDPR articles:

Art. 5

Principles

Art. 6

Lawfulness

Art. 7

Consent

Art. 12-14

Transparency

Art. 15

Right of Access

Art. 16

Rectification

Art. 17

Erasure

Art. 18

Restriction

Art. 20

Portability

Art. 21

Right to Object

Art. 22

Automated Decisions

Art. 32-34

Security & Breach

Art. 44-49

Int'l Transfers

Art. 77

Right to Complain