Privacy Policy
Effective Date: 6 July 2026
Everybodycounts Ltd, trading as Everybody Counts ("we," "us," "our"), is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Primary/KS1-KS2 maths learning platform (the "Platform"), including our AI-personalised learning features.
Registered Office: 5–7 Montgomery Lane, Edinburgh, Scotland, EH7 5JT.
1. Information We Collect
We collect the following types of information:
1.1 Personal Data
1.2 Usage Data
1.3 Learning Interaction Data (AI-Personalised Learning)
To power our AI-personalised learning features, the Platform records detailed interaction data as a student completes activities, including response accuracy, response timing, answer-revision patterns, navigation behaviour, and error types. This data is used to adapt content difficulty, pacing, and presentation to each student's learning needs.
A subset of this interaction data is analysed by our personalisation models to identify patterns that may be associated with neurodivergent learning traits (for example, patterns commonly associated with dyslexia or dyscalculia). We refer to this as "Inferred Learning Trait Data." This data reflects statistical patterns in how a student interacts with the Platform, not a clinical or medical assessment, and it is never presented to teachers, parents, or students as a diagnosis. This is a core governance principle of our platform: inferred is never treated as diagnosed.
2. How We Use Your Information
2.1 Provision of Services
2.2 AI-Personalised Learning
Our personalisation features are subject to a "fairness firewall": Inferred Learning Trait Data is used only to adapt the learning experience within the Platform, is logically and technically separated from a student's core academic record, and is never used to restrict a student's access to content, lower expectations of a student, or make any decision with a legal or similarly significant effect on a student.
2.3 Communication
2.4 Compliance and Protection
3. Legal Basis for Processing
We process personal data based on:
3.1 Special Category Data
Inferred Learning Trait Data, because it relates to indicators that may be associated with neurodiversity, is treated by us as data concerning health for the purposes of UK GDPR. We only generate and use this data where the student's school has enabled the relevant AI personalisation features on the school's behalf under its data protection agreement with us, and, where required by applicable law or the school's own policies, parental/guardian consent has also been obtained. This dual consent gating ensures Inferred Learning Trait Data is never processed without an appropriate lawful basis under Article 9 UK GDPR, which in this context is explicit consent.
4. Automated Processing and Profiling
Our AI-personalisation features involve automated analysis of a student's interaction data. We do not use this analysis to make any decision about a student that produces legal effects or similarly significant effects without meaningful human involvement. Specifically:
5. Data Sharing and Disclosure
We may share your information with:
We do not sell personal data, and we do not share Inferred Learning Trait Data with any third party for marketing, advertising, or profiling purposes unrelated to the delivery of the Platform.
6. Data Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal or reporting requirements. Once data is no longer needed, we securely delete or anonymise it. Inferred Learning Trait Data is retained only for as long as the relevant AI personalisation features remain active for a student, and is deleted or anonymised on a rolling basis as it is superseded by more recent interaction data, or on request from the school or parent/guardian.
8. Children's Privacy
Protecting the privacy of children is especially important. We collect personal data from children aged 5 to 11 only with the consent of their school and, where applicable, their parents or guardians. We design our Platform in line with the principles of the ICO's Age Appropriate Design Code, including high privacy-by-default settings, data minimisation, and no use of children's data for advertising or marketing. We encourage parents and schools to monitor children's use of our services.
9. Your Data Protection Rights
You have the following rights regarding your personal data:
10. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
Email: privacy@everybodycounts.org.uk
Address: 5–7 Montgomery Lane, Edinburgh, Scotland, EH7 5JT
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. We encourage you to review this Privacy Policy periodically for any updates.
By using our services, you agree to the collection and use of information in accordance with this Privacy Policy.