Privacy
Privacy Policy
How Schedual collects, uses, and protects personal data — written for school administrators, IB coordinators, and IT teams evaluating us.
1. Introduction
Schedual is an intelligent scheduling platform designed for International Baccalaureate (IB) schools — Diploma Programme, Middle Years Programme, and Primary Years Programme. Our platform helps schools generate conflict-free timetables and manage academic data.
Schedual is committed to protecting personal data and complying with Regulation (EU) 2016/679 (GDPR), the French Loi Informatique et Libertés as amended, and all applicable European data protection laws.
This Privacy Policy explains how we collect, use, store, and protect personal data when you access or use our platform, website, or related services (the "Services").
2. Our role: controller vs processor
Schedual acts in two distinct capacities under GDPR depending on the data:
Controller for data we collect directly from school administrators, billing contacts, and visitors — account credentials, billing details, support communications, technical logs of the platform itself.
Processor for school data uploaded by Controllers — students, teachers, subjects, schedule constraints. The school remains the Controller of those records under Art. 4(7) GDPR; the terms of that processing are governed by our Data Processing Agreement.
The sections that follow describe our practices as Controller. For our practices as Processor, refer to the DPA.
3. Data controller identity
Entity
Schedual SAS (en cours d'immatriculation — SIREN/RCS published here upon registration) — co-founded and operated by Leo Bancroft and Erik Gerbst
Registered office
Montpellier, France (full address published upon registration)
Publication director
Leo Bancroft
Hosting (LCEN art. 6-III)
Self-hosted on Schedual-owned servers in the EU; warm standby: IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany
General contact
[email protected]Privacy / DSR requests
[email protected]Security incidents
[email protected]Legal / contracts
[email protected]Schedual is not legally required to appoint a Data Protection Officer (Art. 37 GDPR) at its current scale. All privacy questions, data-subject requests, and breach reports are routed through [email protected] as a single point of contact.
4. Categories of personal data we process
4.1 Account & billing data — Schedual as Controller
- Full name and professional email of school administrators
- Role (admin, super-admin)
- School name and IB Code
- Billing contact name, email, address, VAT number where applicable
- Stripe Customer ID and Subscription ID (card numbers never seen or stored by Schedual)
- Subscription tier, billing history, signed contract documents
4.2 Technical & log data — Schedual as Controller
- IP address (at the load balancer; not stored beyond access-log retention)
- Device, browser, OS user-agent string
- Authentication and session events (login, logout, password change)
- Application errors and crash reports (self-hosted error pipeline — data never leaves Schedual servers)
- Audit log of administrative actions (12 months rolling)
4.3 Communications
- Support tickets you raise, including any attached screenshots
- Emails you send to
support@,privacy@,legal@,billing@,security@ - Demo or contact form submissions on the website
4.4 School data — Schedual as Processor (see DPA for full terms)
School Controllers upload, and Schedual processes on their behalf:
- Student records: name, year/grade, IB programme, subject options, group assignments
- Teacher records: name, professional email, subjects taught, availability constraints
- Subject catalogue: name, IB group, HL/SL levels, hours per week
- Room and resource inventory
- Timetable versions and generated schedules
5. Legal bases for processing (Art. 6 GDPR)
| Processing activity | Legal basis |
|---|---|
| Providing the platform to subscribed schools | Art. 6(1)(b) — performance of contract |
| Billing & invoicing | Art. 6(1)(b) + 6(1)(c) (accounting law) |
| Audit logs, error monitoring, fraud prevention | Art. 6(1)(f) — legitimate interest in security & accountability |
| Statutory record retention (e.g. accounting) | Art. 6(1)(c) — legal obligation |
| Marketing emails or analytics requiring opt-in | Art. 6(1)(a) — consent (none deployed at the moment) |
6. Purposes of processing
- Operate the Schedual platform and generate optimized IB timetables
- Authenticate users and manage permissions
- Provide technical support and process feature requests
- Detect and prevent abuse, fraud, and security incidents
- Bill subscriptions and meet our accounting and tax obligations
- Communicate operational notices (incidents, sub-processor changes, legal updates)
- Comply with legal and regulatory obligations including data-subject requests
8. Data sharing and sub-processors
We share personal data only with sub-processors who help us deliver the Services, and only to the extent they need it for their specific function:
- Infrastructure providers (cloud hosting, network protection, backups)
- Payment processing (Stripe Payments Europe)
- Error monitoring — fully self-hosted on Schedual servers (no third-party analytics or error services).
- AI-powered bulk-import OCR (Mistral AI, Paris — zero-retention API tier)
- Legal authorities, but only where compelled by a binding legal order
Each sub-processor is bound by a written contract with data-protection obligations no less protective than this Privacy Policy and our DPA. The complete, dated list is published at /SubProcessors with 30 days' prior notice before any change.
9. International data transfers
Personal data is primarily hosted and processed in the European Union, on Schedual-owned hardware physically located in the EU, with a warm-standby replica at IONOS (Germany). AI-powered bulk imports are processed by Mistral AI in Paris — fully EU.
Some sub-processors operate outside the EEA, notably Backblaze (encrypted backups, United States), Stripe Payments (Ireland with US fallback), Tailscale (control plane in Canada, never sees in-tunnel traffic). Error monitoring and analytics are self-hosted on our own EU servers — no third-party error or analytics service since June 2026.
For each transfer outside the EEA, Schedual relies on the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914), supplemented where required by additional safeguards consistent with EDPB Recommendations 01/2020 — including end-to-end encryption, IP scrubbing, and limiting transferred data to what each sub-processor strictly needs.
10. Data retention
We retain personal data only as long as we have a clear purpose. The schedule below applies unless a longer period is required by law (e.g. French commercial-code retention for accounting — up to 10 years).
| Data category | Retention | After termination |
|---|---|---|
| Account data (name, email, role) | Duration of contract | Deleted within 30 days |
| School data (students, teachers, subjects, timetables) | Duration of contract | Exported on request, then deleted within 30 days |
| Audit logs | 12 months rolling | Anonymised or deleted within 30 days |
| Backups (Backblaze B2 Object Lock) | 30 days (immutable) | Ages out automatically |
| Support tickets & communications | 24 months | Deleted at retention end |
| Billing / invoicing records | 10 years (French commercial code) | Retained as required by law |
| Error reports (self-hosted _system_errors) | 90 days rolling | Purged by retention job on our own servers |
| Product analytics (PostHog) | 365 days | Identified profile deleted within 30 days |
| Bulk-import uploads (Supabase Storage) | Deleted after extraction; orphans 7 days | N/A (transient) |
| Mistral AI bulk-import processing | Zero retention (no model training) | N/A (transient) |
11. Student / children's data
Schedual is used by schools to schedule teaching activity. As part of this, schools upload information about students who, in many cases, are minors. In that context the school is the data Controller (Art. 4(7) GDPR) and Schedual is its Processor (Art. 28).
The school is responsible for the lawful basis for processing student data (typically performance of a public-interest educational mission, Art. 6(1)(e), or the school's contractual relationship with parents) and for any age-appropriate notice to parents or guardians as required by the school's home jurisdiction.
Schedual collects only what's needed to schedule (name, year/grade, programme, subject options, group assignments). We do not knowingly collect special-category data about students. Student records inherit the same security and retention treatment as all other Controller data.
12. Data security
Schedual implements technical and organizational measures appropriate to the risk presented by the processing (Art. 32 GDPR). These include:
- Encryption: TLS 1.2+ for all data in transit; encrypted host volumes for data at rest; AES-256 server-side encryption for off-site backups
- Access control: zero-trust mesh VPN (Tailscale) for admin access; SSH key-only authentication; Row-Level Security at the database layer with adversarial cross-tenant tests in CI; mandatory MFA on all administrative accounts
- Network protection: Cloudflare WAF + rate limiting; origin firewall restricts ingress to Cloudflare IPs only;
fail2banagainst brute-force attempts - Backups & recovery: continuous WAL archiving (RPO ≈ 1 minute) with Object Lock immutability for 30 days; weekly automated restore drills
- Monitoring & audit: 8-check health endpoint, off-site uptime probes, application audit log of every privileged action with actor identification
- Vulnerability management: continuous dependency scanning (Snyk), deploy gate blocks critical CVEs
- Vendor governance: sub-processors selected for GDPR alignment and contractually bound to equivalent obligations
The full technical and organizational measures appear in Annex A of the Data Processing Agreement. A public summary is at /Security.
13. Personal data breach notification
If we become aware of a personal data breach affecting your data, we will notify the relevant school (Controller) without undue delay and at the latest within 72 hours, per Article 33 GDPR. The notification will describe the nature of the breach, the categories and approximate volumes affected, the likely consequences, and the measures taken or proposed to address it. For details, see § 8 of the Data Processing Agreement.
14. Your rights under GDPR
Under GDPR, you have the right to:
- Access your personal data and obtain a copy (Art. 15)
- Rectify inaccurate or incomplete data (Art. 16)
- Erase your personal data, subject to retention obligations (Art. 17)
- Restrict processing in certain circumstances (Art. 18)
- Object to processing based on legitimate interest (Art. 21)
- Receive your data in a portable, structured, machine-readable format (Art. 20)
- Withdraw consent at any time where consent is the legal basis (Art. 7)
- Not be subject to solely automated decisions with legal effect (Art. 22) — Schedual does not perform such decisions
Requests should be sent to [email protected]. We will respond within one month (Art. 12(3)). If the request is complex or numerous, this period can be extended by up to two further months; we will inform you of any extension within the initial month.
15. Lodging a complaint
You have the right to lodge a complaint with a data protection authority. Schedual's lead supervisory authority is the French Commission Nationale de l'Informatique et des Libertés (CNIL) — cnil.fr. You may also complain to your local EU data protection authority.
16. Changes to this Privacy Policy
We may update this Privacy Policy periodically. Material changes will be notified by email to the school's primary contact at least 30 days before they take effect. The current version is always available at this URL with the "Last updated" date at the top.