FrogSystems Group

Privacy

How we respect your privacy.

FrogSystems Group is a UK-based data controller and processor. We take our responsibilities under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), the Privacy and Electronic Communications Regulations (PECR) and all other applicable UK legislation extremely seriously.

Lawful, fair and transparent

We only process personal data where we have a lawful basis and we tell you clearly what we do with it.

Purpose limitation

Personal data is collected for specified, explicit and legitimate purposes and never used in ways incompatible with them.

Data minimisation

We only collect the personal data we actually need to deliver our services.

Security by design

Encryption in transit and at rest, access controls, auditing, and secure UK/EU hosting.

Your rights

Access, rectification, erasure, restriction, portability and objection — always available on request.

Contactable DPO

A named point of contact for every data protection question or request.

What we collect and why

We collect only the personal data required to deliver, secure and improve our services — for example, account details for staff using our products, contact details for customer schools and organisations, and product telemetry needed to keep services stable and safe. Where our products process personal data on behalf of our customers (for example pupil records within Unify MIS), we act as a data processor under a written Data Processing Agreement (DPA) with the customer as data controller.

Legal bases

We rely on the lawful bases set out in Article 6 of the UK GDPR — most commonly performance of a contract, legal obligation, legitimate interests (balanced against your rights) and, where required, consent. For special category data, we rely on the additional conditions in Article 9 UK GDPR and Schedule 1 of the DPA 2018 — including safeguarding of children where relevant.

Safeguarding

Where our products are used in schools, we support statutory safeguarding obligations, including Keeping Children Safe in Education (KCSIE) and the DfE guidance on data protection in schools. Safeguarding records are treated as the most sensitive data we handle.

Retention

Personal data is retained only for as long as necessary for the purposes for which it was collected, or as required by law. Retention schedules are documented per product and reviewed regularly.

International transfers

We primarily host data in the United Kingdom and European Economic Area. Where a transfer outside the UK is required, we rely on approved safeguards such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.

Your rights

You have the right to access, rectify, erase, restrict, port or object to the processing of your personal data, and to complain to the Information Commissioner's Office (ICO) at any time. Requests can be sent to our data protection contact.

Contact

Data protection enquiries: dpo@efrog.co.uk

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time — ico.org.uk.