Privacy Policy

How we handle
your personal data.

Pocket Debate collects the minimum data necessary to deliver its educational platform. This policy explains what we collect, how we use it, who we share it with, and the rights you hold.

Published July 2026Next review January 2027Controller Pocket Debate Ltd.
00

Summary of Key Points.

A plain-English overview. Each row links to the relevant section for full detail.

Who we arePocket Debate Ltd. is the data controller. Contact: contact@pocketdebate.com.01
What we collectAccount data, debate transcripts, audio (transcription only), device/usage data, communications. No special category data collected by design.02
How we use itPlatform delivery, AI verdicts and feedback, school reporting, content moderation, security, legal compliance.03
Who we share withThree sub-processors and one encrypted conduit: AWS (EU infrastructure), Groq (speech-to-text, US, SCCs and Zero Data Retention), Sentry (error monitoring, EU Frankfurt), and LiveKit (real-time audio relay, US, E2EE encrypted conduit, SCCs). LiveKit cannot access audio content by design. We do not sell data.05
International transfersTwo documented transfers outside the EEA: audio to Groq for transcription (SCCs and Zero Data Retention) and live session audio via LiveKit (SCCs, E2EE, no retention). LiveKit cannot decrypt audio content and is not a processor in any substantive sense. Both transfers are covered by EU SCCs and the UK IDTA.06
RetentionAudio deleted immediately on transcription. Transcripts deleted after 7 days. Feedback retained for subscription duration.07
Your rightsAccess, rectification, erasure, restriction, portability, objection, and human review of AI decisions.08
AI & automated decisionsArbiter AI generates formative feedback and scores. No AI output is determinative without human review. No data is used to train AI models.09
AuthenticationInstitutions authenticate via single sign-on (such as Microsoft Entra ID or Google Workspace for Education) or, where no SSO provider is available, via a password stored only in salted, hashed form. Pocket Debate sets a strictly necessary session cookie on login.10
Age restrictionPlatform restricted to users aged 14 and above. Schools confirm student eligibility.12
Student data ownershipSchools own all student personal data. Pocket Debate processes it only on the school's instruction.13
Policy reviewsReviewed twice annually, January and July. Material changes communicated 30 days in advance.17
01

Who We Are.

Pocket Debate Ltd. ("Pocket Debate", "we", "us", "our") is the data controller responsible for the personal data processed through the Pocket Debate platform. We provide an online oracy platform for competitive debating with AI-powered verdicts and feedback, primarily operating in closed school and institution networks.

Pocket Debate Ltd.contact@pocketdebate.comData Protection Officer available on request via the email above.
02

What Data We Collect.

Pocket Debate collects the minimum personal data necessary to deliver its educational debate platform. Data is collected directly from users, from schools that administer accounts, and automatically through use of the service.

·

Account data

Name, school email address, year group, and role (student, teacher, or administrator).

Source: User or school administrator

·

Debate activity data

Debate transcripts, AI-generated verdicts and feedback, ELO rankings, tournament history, and motion assignments.

Source: Generated during platform use

·

Audio data

Spoken audio submitted for transcription during debate sessions. Deleted immediately on transcription completion.

Source: User submission

·

Device & usage data

IP address, browser type, session duration, feature interactions, and error logs.

Source: Collected automatically

·

Communications data

Emails, support requests, and correspondence with Pocket Debate staff.

Source: User

·

Authentication data

Name, school email address, and, depending on the authentication method the Institution uses, either an account identifier received via the Institution’s single sign-on provider or a password. Passwords are stored only in salted, hashed form and are never stored or accessible in plain text.

Source: Institution SSO provider or user (password)

We do not collect special category data (UK/EU GDPR Article 9) as part of standard platform operation. Audio is processed solely to generate a text transcript, not for voice identification or biometric recognition. No personal data processed through Pocket Debate is used to train, fine-tune, or improve any AI model.
03

How We Use Your Data.

Personal data is processed only for the purposes described below. We do not sell personal data to third parties and do not use it for advertising or behavioural profiling unrelated to the educational platform.

·

Platform delivery

Creating and managing user accounts; delivering debate sessions, AI verdicts and feedback, and ELO ranking.

Account, debate, and audio data

·

AI transcription & adjudication

Transcribing spoken debate audio via Groq Whisper and generating structured verdicts and feedback via Arbiter AI.

Audio data and debate transcripts

·

Reporting to schools

Providing teachers and administrators with individual and cohort performance summaries, progress reports, and ELO standings. These reports are not anonymised and are visible to the relevant school staff.

Debate activity data

·

Content moderation & safeguarding

Reviewing debate transcripts within the 7-day retention window to identify content that may raise safeguarding, welfare, or acceptable-use concerns.

Debate transcripts (7-day window only)

·

Platform improvement

Analysing aggregated, de-identified usage patterns to improve features and reliability. No personal data is used for AI model training.

Device & usage data (de-identified)

·

Security & integrity

Detecting fraud, abuse, or misuse; maintaining platform security and monitoring for anomalous activity.

Device & usage data, account data

·

Legal compliance

Meeting our obligations under applicable law, including responding to lawful requests from competent authorities.

Any data necessary

·

Communications

Responding to support requests, sending service notifications, and communicating material policy changes.

Communications data, account data

04

Legal Bases for Processing.

Every processing activity described in this Policy relies on at least one lawful basis under Article 6 UK/EU GDPR.

Contract (Art. 6(1)(b))
Processing necessary to perform our agreement with the user or school, including account management and platform delivery.
Legitimate interests (Art. 6(1)(f))
Platform security, fraud prevention, aggregated analytics for product improvement, and direct communications with institutional contacts. A Legitimate Interests Assessment is maintained internally.
Legal obligation (Art. 6(1)(c))
Compliance with applicable law, regulatory requirements, and lawful requests from public authorities.
Consent (Art. 6(1)(a))
Where we rely on consent for optional platform features, this is obtained separately and may be withdrawn at any time without detriment to core service access.
05

Data Sharing & Sub-processors.

Pocket Debate does not sell or rent personal data. We share data with three sub-processors and one encrypted conduit, each subject to a written data processing agreement. LiveKit is documented as an encrypted conduit rather than a sub-processor: because audio is end-to-end encrypted, LiveKit cannot access the data it relays. No personal data is used by any party to train or improve AI models.

Amazon Web Services (AWS)EU: eu-west-3 (Paris) / eu-central-1 (Frankfurt)

Cloud hosting, database, storage, and AI model inference.

Data shared: All platform data at rest and in transit. Anthropic Claude adjudication runs on AWS Bedrock EU infrastructure.

Groq Inc.United States: SCCs and UK IDTA in place (see Section 06)

Speech-to-text transcription via Whisper Large v3 for all debate modes.

Data shared: Audio data only, during debate sessions. Deleted immediately on transcription under Zero Data Retention.

Sentry (Functional Software Inc.)EU: de.sentry.io (Frankfurt, Germany)

Error monitoring and crash reporting to diagnose platform issues.

Data shared: Technical error data only (stack traces, breadcrumbs). Configured with send_default_pii: false. No student personal data is deliberately captured.

LiveKit Inc.United States — SCCs and UK IDTA in place

Real-time audio relay for live debate sessions. LiveKit is not a processor of personal data in any substantive sense — it acts as an encrypted conduit.

Data shared: Real-time audio relay for live debate sessions. Audio is end-to-end encrypted between participants; LiveKit routes encrypted packets without the ability to decrypt or access audio content. Audio is not stored or retained; relay is in-memory only.

Anthropic models accessed via AWS Bedrock do not receive identifiable user data. A pseudonymous UUID is assigned per speaker per session and reassigned after the API call completes — Anthropic's infrastructure never processes data linked to a named individual. Sentry is configured with EU data residency (Frankfurt) and with send_default_pii: false, meaning no personal identifiers are deliberately captured in error events. LiveKit routes live debate audio using end-to-end encryption, meaning LiveKit's infrastructure cannot decrypt or access audio content at any point. LiveKit is not a processor of personal data in any substantive sense; it acts as an encrypted conduit. The transfer is covered by EU SCCs (Module 2) and the UK IDTA. Full security posture at livekit.io/security.
06

International Transfers & the Groq and LiveKit Positions.

The majority of Pocket Debate's processing takes place within the European Union. AWS infrastructure is configured to EU regions (eu-west-3, Paris and eu-central-1, Frankfurt). Anthropic Claude, accessed via AWS Bedrock with an EU inference profile, processes data entirely within those EU regions. No personal data is transmitted to the United States in connection with these services.

There are two international transfers outside the EEA: audio data sent to Groq Inc. for speech-to-text transcription, and live session audio routed via LiveKit Inc. for real-time relay. Both are described in full below. In each case, the transfer is covered by the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Agreement (IDTA), and personal data is not retained by either processor after the relevant operation completes.

The Groq Transfer.

·

GDPR compliance

Groq is formally GDPR compliant and holds SOC 2 Type II certification. In fulfilment of Article 27 GDPR, Groq has appointed dedicated EU and UK representatives: DP-Dock GmbH in Hamburg and DP Data Protection Services UK Ltd in London. Full compliance posture is published at trust.groq.com.

·

Transfer mechanism

Groq's Data Processing Addendum incorporates the 2021 EU Standard Contractual Clauses (Module 2, controller-to-processor) automatically. The UK International Data Transfer Agreement (IDTA) is also incorporated for UK-scoped transfers. Both instruments are in place prior to any processing of school data.

·

Zero Data Retention

Pocket Debate operates Groq with Zero Data Retention (ZDR) enabled. Under ZDR, audio is processed transiently to produce a transcript and is not written to any storage medium by Groq. No audio, transcript, or metadata is retained after the API call completes.

·

No AI training

Groq's services agreement and DPA explicitly prohibit use of customer data to train, fine-tune, or improve any model. This prohibition applies regardless of ZDR configuration and is contractually enforceable.

·

Audio is not biometric data in this context

Audio is processed solely to generate a text transcript of spoken argument content, not for voice identification, speaker verification, or any biometric purpose. Accordingly, the audio does not constitute biometric data within the meaning of Article 9 UK/EU GDPR as processed by this platform, and Article 9 lawful bases are not required for this processing activity.

·

Residual risk assessment

The transfer is limited to audio of short duration containing no names, account identifiers, or other direct identifiers. ZDR ensures nothing is stored. SCCs with a Transfer Impact Assessment are the standard accepted mechanism for US cloud processing. Pocket Debate assesses this transfer as low residual risk.

The LiveKit Transfer.

LiveKit provides real-time audio relay for live debate sessions. Audio is routed transiently between participants via LiveKit's US infrastructure. The critical distinction from Groq is encryption architecture: audio is end-to-end encrypted, meaning LiveKit's infrastructure relays encrypted packets without the ability to decrypt or access the audio content. LiveKit is therefore not a processor of personal data in any substantive sense; it is an encrypted conduit. The transfer is nonetheless documented and covered below for completeness and in line with a conservative reading of GDPR Article 46.

·

GDPR compliance

LiveKit holds SOC 2 Type II certification and publishes its full security posture at livekit.io/security. LiveKit maintains a formal Data Processing Agreement available to all customers.

·

Transfer mechanism

LiveKit's Data Processing Agreement incorporates the 2021 EU Standard Contractual Clauses (Module 2, controller-to-processor). The UK International Data Transfer Agreement (IDTA) is also incorporated for UK-scoped transfers. Both instruments are in place prior to any processing of school data.

·

End-to-end encryption

Audio between debate participants is end-to-end encrypted. LiveKit's infrastructure relays encrypted packets without the ability to decrypt or access the audio content at any point. This means LiveKit cannot read, store, or process the substance of any conversation, regardless of jurisdiction.

·

Signalling encryption

Signalling traffic (session coordination, participant management) uses WSS (WebSocket Secure) over TLS 1.2 or higher. No signalling data is transmitted in plaintext.

·

No data retention

Audio is relayed transiently in-memory. LiveKit does not write audio to any storage medium during or after a session. The absence of retention is structural: there is no retention period because no data is ever stored.

·

No content access or AI training

Because audio is end-to-end encrypted, LiveKit cannot access audio content and therefore cannot use it for transcription, analysis, model training, or any other purpose. This prohibition is structural, not merely contractual.

·

Residual risk assessment

Pocket Debate assesses this transfer as minimal residual risk. Audio content is inaccessible to LiveKit by design. No data is retained. The only data LiveKit handles is encrypted packets and TLS-secured signalling metadata, neither of which constitutes meaningful personal data in context. This positions the LiveKit transfer as lower risk than the Groq transfer.

07

Retention Periods.

Pocket Debate retains personal data for the minimum period necessary to fulfil the purpose for which it was collected, and to comply with applicable legal, regulatory, or contractual obligations. Schools may negotiate shorter retention periods in their Data Processing Agreement.

Account dataSubscription + 12 monthsEnables post-subscription data export
Debate transcripts7 daysContent moderation and safeguarding review; permanently deleted after
AI-generated feedback & verdictsDuration of subscriptionEducational record; enables longitudinal progress tracking
ELO rankings & tournament dataDuration of subscriptionCompetitive record integrity
Audio dataDeleted immediately on transcriptionMinimum necessary; privacy by design. Not retained by Groq under ZDR.
Device & usage logs90 daysSecurity monitoring; platform diagnostics
Communications data3 years from last contactLegitimate interests; dispute resolution
SSO session dataSession duration onlyManaged by the Institution’s identity provider; Pocket Debate does not store SSO credentials
Password hashDuration of accountRequired to authenticate the account on each login where SSO is not used; stored only in salted, hashed form
08

Your Data Rights.

Every individual whose personal data is processed by Pocket Debate has the rights described below under UK GDPR and EU GDPR. To exercise any right, submit a request to contact@pocketdebate.com. We acknowledge within five working days and respond substantively within 30 calendar days.

You can also submit a request using our Data Subject Rights Request form.

·

Right to be Informed

We provide clear information about what data we collect, why, how it is used, who it is shared with, retention periods, and your rights, through this Policy and school-facing documentation.

·

Right of Access

Request a copy of the personal data we hold about you, including account information, feedback history, and ELO records, subject to identity verification.

·

Right to Rectification

Request correction of inaccurate or incomplete personal data, either directly or through your school administrator.

·

Right to Erasure

Request deletion of your personal data, subject to lawful retention requirements. User accounts and associated data can be deleted upon valid request.

·

Right to Restriction

Request that processing be restricted in certain circumstances. We can suspend or limit an account while a request is assessed.

·

Right to Data Portability

Where applicable, we can provide your personal data in a structured, machine-readable format (CSV or JSON), including account information and feedback records.

·

Right to Object

Object to processing based on legitimate interests. We will stop or limit processing where legally required.

·

Right not to be subject to Automated Decision-Making

Arbiter AI outputs are formative and educational. No automated output produces legal, disciplinary, or similarly significant effects without human review. See Section 09.

09

Automated Decision-Making & Arbiter AI.

Pocket Debate's Arbiter AI system transcribes spoken debate audio, evaluates argument structure, delivery, and rebuttals, and generates written feedback and a numerical score. These outputs are used for learning, coaching, and competitive ranking within an educational debate context.

Arbiter AI outputs do not produce legal, financial, disciplinary, or otherwise significant real-world effects without human involvement. Where a score contributes to a tournament outcome, the relevant teacher, school administrator, or tournament adjudicator retains the ability to review, query, and override the AI output before any final result is communicated. Human oversight is structurally embedded in the platform design, not offered as an optional add-on, in compliance with Article 22 UK/EU GDPR.

Nature of output
Formative feedback and indicative score for educational use. Not determinative.
Human oversight
Teachers, school staff, and tournament adjudicators can review, query, and override AI outputs before any result is finalised.
Significant effects
None without human involvement. AI outputs do not determine formal qualifications, disciplinary outcomes, or access rights.
Right to human review
Available on request via the school administrator or contact@pocketdebate.com.
AI training
No personal data processed through Pocket Debate is used to train any AI model.
Underlying model
Adjudication is performed via Anthropic Claude accessed through AWS Bedrock EU infrastructure. Processing remains within EU regions at all times.
10

Cookies & Tracking.

Pocket Debate does not use cookies, web beacons, pixel tags, device fingerprinting, or any other technology for advertising, analytics, or behavioural tracking. The only cookie Pocket Debate sets is described below.

Session cookie.

To keep a user signed in, Pocket Debate sets a single session cookie in the user's browser once they have authenticated, whether via single sign-on or a password. This cookie contains only a signed session token; it does not carry advertising or tracking identifiers and is not shared with any third party. It is strictly necessary to provide the Service the user has requested (remaining signed in) and, on that basis, does not require cookie consent under the UK/EU ePrivacy rules; no consent banner is presented for this reason. The cookie expires when the session ends and is not used for any purpose beyond authentication.

Identity provider tokens.

Where an Institution uses a single sign-on provider such as Microsoft Entra ID or Google Workspace for Education, that provider's own authentication infrastructure may set session-scoped tokens on the user's device as part of its standard OAuth 2.0 and OpenID Connect authentication flow. These tokens are set and managed entirely by the Institution's identity provider under that provider's own privacy policy (for example, Microsoft's Privacy Statement). They are used solely to maintain the authenticated session and expire on session end. Pocket Debate does not set, read, or control these tokens.

Should Pocket Debate introduce cookies or technologies for advertising, analytics, or tracking in a future version of the platform, this Policy will be updated in advance and, where required by law, consent will be obtained before any such technology is deployed.
11

Authentication Methods.

Institutions choose how their users authenticate. Where an Institution operates a supported single sign-on provider, such as Microsoft Entra ID or Google Workspace for Education, Pocket Debate uses that provider for authentication, allowing schools to manage access through their existing identity infrastructure without students or staff creating a separate Pocket Debate password. Smaller debate clubs and Institutions without a supported SSO provider can instead issue their users a Pocket Debate account secured by a password.

When a user authenticates via single sign-on, Pocket Debate receives only the user's name, school email address, and an account identifier from the Institution's identity provider. No passwords, full directory information, or data beyond what is necessary to authenticate the user's account is received or stored by Pocket Debate in this case. Where a password is used instead, Pocket Debate stores only a salted cryptographic hash of the password, generated using bcrypt; the plain-text password itself is never stored, logged, or accessible to Pocket Debate staff. In both cases, this information is used solely for account creation and authentication, not for marketing, profiling, or any other purpose. Where SSO is used, school administrators control access via their identity provider's tenant, and revoking a user's account there automatically prevents Pocket Debate login; multi-factor authentication enforcement is likewise managed at that tenant level. Where a password is used, the Institution's administrator controls the account directly through Pocket Debate. School administrators using Microsoft Entra ID should review Microsoft's Privacy Statement for information on how Microsoft processes account data.

Identity providers
Microsoft Entra ID, Google Workspace for Education, or another single sign-on provider the Institution operates, at the Institution’s choice.
Password storage
Where SSO is not used, passwords are stored only as a salted bcrypt hash. Pocket Debate never stores, logs, or has access to a plain-text password.
Data received (SSO)
Name, school email address, and account identifier only. No passwords, full directory information, or data beyond what is necessary to authenticate the user's account.
MFA / 2FA
For SSO accounts, enforced at the Institution's identity provider tenant level. For password accounts, the Institution is responsible for its own password policy.
Purpose
Account creation and authentication only. Not used for marketing, profiling, or any other purpose.
Access revocation
For SSO accounts, revoking the user's account with the identity provider immediately prevents Pocket Debate login. For password accounts, the Institution's administrator can disable the account directly.
Cookies
Pocket Debate sets one strictly necessary session cookie on login, regardless of authentication method. Where SSO is used, the identity provider may separately set its own session tokens. See Section 10.
12

Age Restrictions & School Users.

Pocket Debate is restricted to users aged 14 and above. This minimum age reflects the requirements of the EU AI Act and applicable data protection law governing the use of AI-powered services with younger children. Schools deploying Pocket Debate are required to confirm that all student users meet this age threshold prior to account creation.

·

Minimum age enforcement

The platform is restricted to users aged 14 and above. Schools are responsible for confirming student eligibility prior to account creation.

·

School as gatekeeper

All student accounts are created and managed by school administrators. Students cannot self-register. The school is responsible for communicating privacy information to students and families in an age-appropriate format.

·

No direct marketing to students

Student accounts are never used for marketing or commercial profiling. ELO rankings and performance data are used solely within the educational debate context.

·

Minimum data collection

Student accounts require only a name, school email address, year group, and role. No social media accounts, phone numbers, or home addresses are collected.

·

Audio data handling

Audio is deleted immediately upon transcription completion. It is not retained by Pocket Debate or by Groq under Zero Data Retention.

·

Parental access requests

Parents and guardians may submit data subject access requests on behalf of student users via the school administrator or directly to contact@pocketdebate.com, subject to identity verification.

13

Student Data Ownership & Commitments.

Pocket Debate is committed to the privacy and security of student personal data. The following principles govern all processing of student data through the platform and apply in addition to the general provisions of this Policy.

·

School ownership

Schools own all student personal data processed through Pocket Debate, including account information, debate records, AI-generated feedback, and ELO rankings. Pocket Debate processes this data solely on the school's instruction as data processor.

·

No commercial use

Student personal data is never used for marketing, advertising, commercial profiling, or any purpose unrelated to the delivery of educational debate services. Student data is not sold, rented, or shared with third parties for commercial purposes.

·

No AI training

No student personal data, including debate transcripts, audio, feedback, or account information, is used to train, fine-tune, or improve any AI model, whether operated by Pocket Debate or any sub-processor.

·

Educational purpose limitation

Student data is collected and used exclusively to provide debate session delivery, AI adjudication and feedback, ELO ranking, content moderation, and school reporting. It is not used for any other purpose without explicit school consent.

·

School data export

Schools may request a full export of their student data at any time in CSV or JSON format. Direct requests to contact@pocketdebate.com.

·

School data deletion

Schools may request deletion of all student data associated with their institution at any time. Pocket Debate will complete institution-wide deletion requests within 30 days, subject to any lawful retention requirements.

·

Sub-processor limitation

Student data is shared with AWS, Groq, and Sentry, each under contractual data processing agreements (see Section 05). Sentry receives only technical error data with personal identifiers disabled. LiveKit is also documented as a transfer recipient, but because audio is end-to-end encrypted, LiveKit cannot access audio content and is not a processor of personal data in any substantive sense. No other third party receives student personal data.

·

Visibility

AI-generated feedback, verdicts, ELO rankings, and performance summaries are visible to relevant teachers and school administrators, and to the student themselves. They are not anonymised at the school level, as their purpose is to support individual student development.

14

Security.

Pocket Debate applies technical and organisational security measures appropriate to the risk and nature of the data processed. Detailed security documentation is available to institutional partners on request.

·

Encryption in transit

TLS 1.2 or higher on all data transmission between users, the platform, and sub-processors.

·

Encryption at rest

AES-256 encryption applied to data stored in AWS EU infrastructure via customer-managed AWS KMS keys.

·

Access controls

Role-based access control with principle of least privilege. Administrative access governed by IAM policies. Access reviewed periodically using AWS IAM Access Analyzer.

·

Authentication

Single sign-on (e.g. Microsoft Entra ID or Google Workspace for Education) is available to every Institution, with MFA enforcement managed at the Institution's identity provider tenant level. Institutions without a supported SSO provider can use password-based accounts instead; passwords are stored only as a salted bcrypt hash.

·

Password storage

Where a password is used, it is hashed with bcrypt before storage. Pocket Debate cannot recover or view a plain-text password, including for its own support staff.

·

Network security

AWS Security Groups (stateful, scoped to eu-west-3). No port 22 exposure; server access via AWS SSM Session Manager only. No public database endpoint.

·

Threat detection

AWS GuardDuty enabled with Malware Protection and RDS Protection, providing continuous monitoring across VPC Flow Logs, CloudTrail, and DNS. ClamAV installed at instance level with daily definition updates.

·

Vulnerability scanning

GitHub Dependabot and npm audit on every code push. SAST via Snyk on every pull request. DAST via OWASP ZAP on staging. Independent security assessments conducted prior to institutional onboarding.

·

Audio data

Zero Data Retention with Groq ensures audio is not retained beyond the API call. No audio is stored anywhere on the platform.

·

Transcript deletion

Debate transcripts are permanently deleted 7 days after session completion via automated deletion routines.

·

Staff training

Access to personal data is restricted to staff who have completed data protection training, required before access is granted and renewed annually.

Pocket Debate has undergone independent security assessments prior to institutional launch. A commitment to annual independent security review is maintained, with formal third-party penetration testing planned ahead of full multi-institution rollout.
15

Security Incident Response.

Pocket Debate maintains a documented security incident response procedure. Schools and institutional partners are asked to report any suspected security incidents involving Pocket Debate data to contact@pocketdebate.com immediately.

PhaseActionTimeframe
Detection & containmentIncident identified, contained, and assessed for scope and severity. Affected systems isolated where necessary.Immediate
Internal escalationIncident escalated to senior management and Data Protection Officer. Impact on personal data assessed.Within 4 hours
School notificationAffected schools notified of the incident, data involved, likely consequences, and measures taken.Within 24 hours of confirmed breach
Regulatory notificationWhere the breach meets the threshold under Article 33 UK/EU GDPR, the relevant supervisory authority (ICO for UK; AEPD for Spain) notified.Within 72 hours
Data subject notificationWhere required under Article 34 UK/EU GDPR, affected individuals notified directly, coordinated with the relevant school.Without undue delay
Post-incident reviewRoot cause analysis conducted. Measures updated to prevent recurrence. Schools provided with a summary report on request.Within 30 days
16

Business Transfers.

In the event that Pocket Debate Ltd. is involved in a merger, acquisition, financing, reorganisation, sale of assets, or transfer of the business or part thereof, personal data held by Pocket Debate may be transferred to a successor entity as part of that transaction. Any successor entity would be required, as a condition of the transfer, to honour the commitments made in this Privacy Policy.

Where such a transaction would result in a material change to how personal data is processed, including any change to the identity of the data controller, the purposes of processing, or the applicable retention periods: Pocket Debate will notify affected schools and users at least 30 days before the change takes effect. Schools will retain the right to request deletion of their data prior to any such transfer.

Student personal data will not be transferred as part of any business transaction to an entity that would use it for commercial purposes inconsistent with the educational commitments set out in Section 13.
17

Changes to This Policy.

This Privacy Policy is reviewed twice annually, in January and July of each year, and updated as required to reflect changes in the platform, processing activities, applicable law, or regulatory guidance. The version number and date on the cover identify the current version.

Material changes, those that substantively alter how we process personal data or affect the rights of data subjects, will be communicated to institutional partners and, where appropriate, to individual users at least 30 days before they take effect. Non-material clarifications such as improved wording, corrected links, or updated sub-processor contact details may take effect immediately upon publication.

Where a school or institutional partner objects to a material change, they should contact us at contact@pocketdebate.com before the change takes effect.

18

Contact & Complaints.

For any question, concern, or request relating to this Privacy Policy or the processing of your personal data, please contact us at contact@pocketdebate.com. We aim to acknowledge all privacy-related correspondence within five working days. For student and parental requests, please contact your school's data protection lead in the first instance; they will liaise with us on your behalf.

Supervisory Authorities.

If you are not satisfied with our response, or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the relevant supervisory authority.

UK: Information Commissioner's Office (ICO) at ico.org.uk

EEA: The data protection authority in the relevant Member State.

Spain: Agencia Española de Protección de Datos (AEPD) at aepd.es

This Policy was last reviewed and approved for publication in July 2026.

Next scheduled review: January 2027.