Privacy

Privacy Policy

How Schedual collects, uses, and protects personal data — written for school administrators, IB coordinators, and IT teams evaluating us.

Last updated · June 12, 2026GDPR-compliantEU-hostedNo data selling

1. Introduction

Schedual is an intelligent scheduling platform designed for International Baccalaureate (IB) schools — Diploma Programme, Middle Years Programme, and Primary Years Programme. Our platform helps schools generate conflict-free timetables and manage academic data.

Schedual is committed to protecting personal data and complying with Regulation (EU) 2016/679 (GDPR), the French Loi Informatique et Libertés as amended, and all applicable European data protection laws.

This Privacy Policy explains how we collect, use, store, and protect personal data when you access or use our platform, website, or related services (the "Services").

2. Our role: controller vs processor

Schedual acts in two distinct capacities under GDPR depending on the data:

Controller for data we collect directly from school administrators, billing contacts, and visitors — account credentials, billing details, support communications, technical logs of the platform itself.

Processor for school data uploaded by Controllers — students, teachers, subjects, schedule constraints. The school remains the Controller of those records under Art. 4(7) GDPR; the terms of that processing are governed by our Data Processing Agreement.

The sections that follow describe our practices as Controller. For our practices as Processor, refer to the DPA.

3. Data controller identity

Entity

Schedual SAS (en cours d'immatriculation — SIREN/RCS published here upon registration) — co-founded and operated by Leo Bancroft and Erik Gerbst

Registered office

Montpellier, France (full address published upon registration)

Publication director

Leo Bancroft

Hosting (LCEN art. 6-III)

Self-hosted on Schedual-owned servers in the EU; warm standby: IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany

General contact

[email protected]

Privacy / DSR requests

[email protected]

Security incidents

[email protected]

Legal / contracts

[email protected]

Schedual is not legally required to appoint a Data Protection Officer (Art. 37 GDPR) at its current scale. All privacy questions, data-subject requests, and breach reports are routed through [email protected] as a single point of contact.

4. Categories of personal data we process

4.1 Account & billing data — Schedual as Controller

  • Full name and professional email of school administrators
  • Role (admin, super-admin)
  • School name and IB Code
  • Billing contact name, email, address, VAT number where applicable
  • Stripe Customer ID and Subscription ID (card numbers never seen or stored by Schedual)
  • Subscription tier, billing history, signed contract documents

4.2 Technical & log data — Schedual as Controller

  • IP address (at the load balancer; not stored beyond access-log retention)
  • Device, browser, OS user-agent string
  • Authentication and session events (login, logout, password change)
  • Application errors and crash reports (self-hosted error pipeline — data never leaves Schedual servers)
  • Audit log of administrative actions (12 months rolling)

4.3 Communications

  • Support tickets you raise, including any attached screenshots
  • Emails you send to support@, privacy@, legal@, billing@, security@
  • Demo or contact form submissions on the website

4.4 School data — Schedual as Processor (see DPA for full terms)

School Controllers upload, and Schedual processes on their behalf:

  • Student records: name, year/grade, IB programme, subject options, group assignments
  • Teacher records: name, professional email, subjects taught, availability constraints
  • Subject catalogue: name, IB group, HL/SL levels, hours per week
  • Room and resource inventory
  • Timetable versions and generated schedules
Schedual does not knowingly process special-category data (Art. 9 GDPR) about students. Controllers must not upload health, religious, biometric, or other special-category data without a written variation.

6. Purposes of processing

  • Operate the Schedual platform and generate optimized IB timetables
  • Authenticate users and manage permissions
  • Provide technical support and process feature requests
  • Detect and prevent abuse, fraud, and security incidents
  • Bill subscriptions and meet our accounting and tax obligations
  • Communicate operational notices (incidents, sub-processor changes, legal updates)
  • Comply with legal and regulatory obligations including data-subject requests

7. Cookies and tracking technologies

Schedual uses only strictly necessary cookies and local-storage entries — those required for authentication, anti-fraud, and basic functionality. We do not use analytics, marketing cookies, cross-site tracking pixels, or advertising tools (product analytics was removed entirely in June 2026). Because our cookies are strictly necessary, no opt-in consent banner is required under EU ePrivacy law and CNIL guidance; see the Cookies Policy for the full inventory.

For the full inventory of cookies and their purposes, see our Cookies Policy.

8. Data sharing and sub-processors

Schedual does not sell personal data. Ever.

We share personal data only with sub-processors who help us deliver the Services, and only to the extent they need it for their specific function:

  • Infrastructure providers (cloud hosting, network protection, backups)
  • Payment processing (Stripe Payments Europe)
  • Error monitoring — fully self-hosted on Schedual servers (no third-party analytics or error services).
  • AI-powered bulk-import OCR (Mistral AI, Paris — zero-retention API tier)
  • Legal authorities, but only where compelled by a binding legal order

Each sub-processor is bound by a written contract with data-protection obligations no less protective than this Privacy Policy and our DPA. The complete, dated list is published at /SubProcessors with 30 days' prior notice before any change.

9. International data transfers

Personal data is primarily hosted and processed in the European Union, on Schedual-owned hardware physically located in the EU, with a warm-standby replica at IONOS (Germany). AI-powered bulk imports are processed by Mistral AI in Paris — fully EU.

Some sub-processors operate outside the EEA, notably Backblaze (encrypted backups, United States), Stripe Payments (Ireland with US fallback), Tailscale (control plane in Canada, never sees in-tunnel traffic). Error monitoring and analytics are self-hosted on our own EU servers — no third-party error or analytics service since June 2026.

For each transfer outside the EEA, Schedual relies on the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914), supplemented where required by additional safeguards consistent with EDPB Recommendations 01/2020 — including end-to-end encryption, IP scrubbing, and limiting transferred data to what each sub-processor strictly needs.

10. Data retention

We retain personal data only as long as we have a clear purpose. The schedule below applies unless a longer period is required by law (e.g. French commercial-code retention for accounting — up to 10 years).

Data categoryRetentionAfter termination
Account data (name, email, role)Duration of contractDeleted within 30 days
School data (students, teachers, subjects, timetables)Duration of contractExported on request, then deleted within 30 days
Audit logs12 months rollingAnonymised or deleted within 30 days
Backups (Backblaze B2 Object Lock)30 days (immutable)Ages out automatically
Support tickets & communications24 monthsDeleted at retention end
Billing / invoicing records10 years (French commercial code)Retained as required by law
Error reports (self-hosted _system_errors)90 days rollingPurged by retention job on our own servers
Product analytics (PostHog)365 daysIdentified profile deleted within 30 days
Bulk-import uploads (Supabase Storage)Deleted after extraction; orphans 7 daysN/A (transient)
Mistral AI bulk-import processingZero retention (no model training)N/A (transient)

11. Student / children's data

Schedual is used by schools to schedule teaching activity. As part of this, schools upload information about students who, in many cases, are minors. In that context the school is the data Controller (Art. 4(7) GDPR) and Schedual is its Processor (Art. 28).

The school is responsible for the lawful basis for processing student data (typically performance of a public-interest educational mission, Art. 6(1)(e), or the school's contractual relationship with parents) and for any age-appropriate notice to parents or guardians as required by the school's home jurisdiction.

Schedual collects only what's needed to schedule (name, year/grade, programme, subject options, group assignments). We do not knowingly collect special-category data about students. Student records inherit the same security and retention treatment as all other Controller data.

12. Data security

Schedual implements technical and organizational measures appropriate to the risk presented by the processing (Art. 32 GDPR). These include:

  • Encryption: TLS 1.2+ for all data in transit; encrypted host volumes for data at rest; AES-256 server-side encryption for off-site backups
  • Access control: zero-trust mesh VPN (Tailscale) for admin access; SSH key-only authentication; Row-Level Security at the database layer with adversarial cross-tenant tests in CI; mandatory MFA on all administrative accounts
  • Network protection: Cloudflare WAF + rate limiting; origin firewall restricts ingress to Cloudflare IPs only; fail2ban against brute-force attempts
  • Backups & recovery: continuous WAL archiving (RPO ≈ 1 minute) with Object Lock immutability for 30 days; weekly automated restore drills
  • Monitoring & audit: 8-check health endpoint, off-site uptime probes, application audit log of every privileged action with actor identification
  • Vulnerability management: continuous dependency scanning (Snyk), deploy gate blocks critical CVEs
  • Vendor governance: sub-processors selected for GDPR alignment and contractually bound to equivalent obligations

The full technical and organizational measures appear in Annex A of the Data Processing Agreement. A public summary is at /Security.

13. Personal data breach notification

If we become aware of a personal data breach affecting your data, we will notify the relevant school (Controller) without undue delay and at the latest within 72 hours, per Article 33 GDPR. The notification will describe the nature of the breach, the categories and approximate volumes affected, the likely consequences, and the measures taken or proposed to address it. For details, see § 8 of the Data Processing Agreement.

14. Your rights under GDPR

Under GDPR, you have the right to:

  • Access your personal data and obtain a copy (Art. 15)
  • Rectify inaccurate or incomplete data (Art. 16)
  • Erase your personal data, subject to retention obligations (Art. 17)
  • Restrict processing in certain circumstances (Art. 18)
  • Object to processing based on legitimate interest (Art. 21)
  • Receive your data in a portable, structured, machine-readable format (Art. 20)
  • Withdraw consent at any time where consent is the legal basis (Art. 7)
  • Not be subject to solely automated decisions with legal effect (Art. 22) — Schedual does not perform such decisions

Requests should be sent to [email protected]. We will respond within one month (Art. 12(3)). If the request is complex or numerous, this period can be extended by up to two further months; we will inform you of any extension within the initial month.

If you are an end-user of a school using Schedual (teacher, student, parent), please address your request to your school first — they are the Controller of student/teacher records. Schedual will support the school in fulfilling the request as required by the DPA.

15. Lodging a complaint

You have the right to lodge a complaint with a data protection authority. Schedual's lead supervisory authority is the French Commission Nationale de l'Informatique et des Libertés (CNIL)cnil.fr. You may also complain to your local EU data protection authority.

16. Changes to this Privacy Policy

We may update this Privacy Policy periodically. Material changes will be notified by email to the school's primary contact at least 30 days before they take effect. The current version is always available at this URL with the "Last updated" date at the top.