Policies

Children's Privacy Policy

A companion document to the QGen Privacy Policy (Version 2.0). Read the two together.

Last Reviewed September 2026 | Version 1.0 · Operating in the United Kingdom and Zimbabwe

1. Introduction and Purpose (UK & Zimbabwe)

QGen is an educational platform built for learners. A significant proportion of our users are children and young people under the age of 18. This Children's Privacy Policy explains, in one place, how QGen collects, uses, protects, and shares the personal data of children — and what rights children, their parents and guardians, and their schools have over that data.

This Policy sits alongside, and does not replace, the QGen Privacy Policy (Version 2.0). Where the general Privacy Policy describes our processing for all users, this Policy sets out the additional and enhanced protections that apply specifically because the user is a child. Where this Policy is more protective of a child than the general Privacy Policy, this Policy prevails.

It should also be read together with:

  • The QGen Cookie Policy
  • The QGen Terms of Service
  • The QGen Privacy Policy

The governing principle of this Policy is that the best interests of the child are a primary consideration in every decision we take about how children's data is collected and used — as required by Standard 1 of the ICO's Age Appropriate Design Code in the United Kingdom, by section 81 of the Constitution of Zimbabwe, and by Article 3 of the United Nations Convention on the Rights of the Child, to which both the United Kingdom and Zimbabwe are parties.

2. Scope and Application (UK & Zimbabwe)

2.1 Who this Policy applies to

This Policy applies to:

  • Any registered Student on QGen who is under the age of 18
  • Any child whose personal data is processed through a School Account, a linked Parent/Guardian account, or a Tutor's account
  • Any child who uses a Free Sample of the Question Generator without creating an account
  • Parents, guardians, teachers, school personnel, and tutors, insofar as it describes their responsibilities and the controls available to them

2.2 Services covered

This Policy covers the whole of the QGen platform, including the Question Generator, the Question Bank, the tutoring marketplace, the feedback a tutor, teacher, or parent gives a child on their work, and the QGen website and applications. QGen does not provide general messaging between users.

2.3 Likely to be accessed by children (UK)

QGen accepts that it is an information society service likely to be accessed by children within the meaning of section 123 of the Data Protection Act 2018 and the ICO Age Appropriate Design Code. We do not treat the Code as optional or as applying only to parts of the Service: we apply it across the platform by design and by default.

The Data (Use and Access) Act 2025 further requires controllers providing such services to have regard to children's higher protection needs — including that children merit specific protection and may be less aware of the risks and consequences of data processing — when deciding what technical and organisational measures to put in place. Our design decisions are documented against that duty.

3. Definitions (UK & Zimbabwe)

Terms defined in the QGen Privacy Policy (Version 2.0) carry the same meaning here. The following additional or clarified definitions apply:

  • Child: Any individual under the age of 18. This is the definition used throughout this Policy, in both jurisdictions, and is consistent with section 81 of the Constitution of Zimbabwe, the Children's Act [Chapter 5:06], the Marriages Act [Chapter 5:17] (2022), and the safeguarding definition used in Keeping Children Safe in Education (UK).
  • Age of digital consent: The age at which a child may give their own consent to the processing of their personal data in connection with an information society service. This is 13 in the United Kingdom (section 9, Data Protection Act 2018). See Section 5 for the position in Zimbabwe.
  • Parent / Guardian: A person with parental responsibility for a child (UK) or custody or guardianship of a child (Zimbabwe), including a person exercising that responsibility under a court order or under the Children's Act [Chapter 5:06].
  • Age assurance: Any technical or procedural measure used to establish or estimate a user's age or age band with a level of certainty appropriate to the risks arising from the processing.
  • Best interests of the child: The standard under Article 3 UNCRC — the child's rights to development, health, safety, privacy, family life, freedom of expression, freedom from economic and commercial exploitation, and access to information, taken as a whole.
  • Detrimental use: Use of a child's personal data in a way that is demonstrably against their wellbeing, or that is contrary to industry codes of practice, other regulatory provisions, or Government advice.
  • Profiling: Any automated processing of personal data to evaluate, analyse, or predict aspects of a child's performance, preferences, interests, behaviour, or location.

4. Legal Framework

4.1 United Kingdom (UK)

InstrumentRelevance to children's data on QGen
UK GDPR (Retained Regulation (EU) 2016/679), as amended by the Data (Use and Access) Act 2025Core data protection obligations. Recital 38 (children merit specific protection); Article 6 (lawfulness); Article 8 (child's consent for information society services); Article 12 (transparency in clear, plain language a child can understand); Article 22 (automated decision-making); Article 35 (data protection impact assessments).
Data Protection Act 2018Section 9 sets the UK age of digital consent at 13. Section 123 requires the Commissioner to produce the Age Appropriate Design Code. Schedule 1 governs special category and criminal offence data, including safeguarding conditions.
Data (Use and Access) Act 2025Reforms applied throughout this Policy: the duty to have regard to children's higher protection needs; recognised legitimate interests, which include safeguarding children and vulnerable individuals; reformed rules on solely automated decision-making; the new controller complaints-handling duty; the revised “data protection test” for international transfers; and the restructured Information Commission.
ICO Age Appropriate Design Code (Children's Code)The fifteen standards of age-appropriate design, applied in Section 12 of this Policy.
Privacy and Electronic Communications Regulations 2003 (PECR), as amendedCookies, local storage, and electronic marketing. No marketing cookies or advertising trackers are used on any part of QGen.
Online Safety Act 2023Children's safety duties, age assurance expectations, and content risk assessment duties for user-to-user and search services, as they apply to the QGen tutoring marketplace and to feedback given to a child on their work.
Keeping Children Safe in Education (KCSIE)Statutory safeguarding guidance applying to schools and colleges using QGen, and informing our own safeguarding disclosure practice.
Children Act 1989 and Children Act 2004Welfare of the child; information sharing for safeguarding purposes.
UN Convention on the Rights of the ChildArticle 3 (best interests), Article 12 (the child's voice), Article 16 (privacy), Article 13 (access to information).

4.2 Zimbabwe (Zimbabwe)

InstrumentRelevance to children's data on QGen
Constitution of Zimbabwe (Amendment No. 20) Act 2013Section 57 (right to privacy); section 81 (rights of children, including the best interests of the child as paramount in every matter concerning the child); section 75 (right to education).
Cyber and Data Protection Act [Chapter 12:07]Core data protection obligations, including lawful basis and consent, heightened protection for data subjects who are minors, and the rights of access, rectification, erasure, and objection. Section numbers cited in this Policy require independent verification — see the Verification Note.
Statutory Instrument 155 of 2024Licensing of data controllers and the appointment of Data Protection Officers. QGen's registration and DPO appointment status under this instrument is recorded at Section 22.
Children's Act [Chapter 5:06]Protection of children from harm, neglect, and exploitation; duties of persons having custody or guardianship; reporting obligations.
Marriages Act [Chapter 5:17] (2022)Confirms 18 as the age of majority for the purposes of the protections relied on in this Policy.
Education Act [Chapter 25:04]Rights of learners and duties of educational institutions, relevant to School Accounts in Zimbabwe.
Postal and Telecommunications Act [Chapter 12:05]Establishes POTRAZ, which administers the Data Protection Authority function under the Cyber and Data Protection Act.

This Policy is scoped exclusively to the law of the United Kingdom and the law of Zimbabwe. No other jurisdiction's requirements are addressed, and no other jurisdiction's law is relied upon.

5. Age Thresholds and Who Can Consent

The two jurisdictions in which QGen operates take different positions on the age at which a child can consent to their own data being processed. We apply the more protective position wherever a user's jurisdiction is uncertain.

5.1 United Kingdom (UK)

Section 9 of the Data Protection Act 2018 sets the age of digital consent at 13. This means:

  • A child aged 13 or over may give their own consent to processing offered directly to them in connection with an information society service, where we rely on consent as the legal basis
  • A child under 13 cannot give that consent; it must be given or authorised by a person holding parental responsibility, and we must make reasonable efforts to verify that it has been
  • QGen does not directly offer Student accounts to children under 13. Where a child under 13 is to use the platform, this must be through a School Account or a supervised Parent/Guardian account, with the appropriate consent recorded.

Consent is not the only lawful basis we use. Where we rely on performance of a contract, legal obligation, or legitimate interests, the age of digital consent does not determine lawfulness — but it continues to inform how we communicate with the child and what protections we apply.

5.2 Zimbabwe (Zimbabwe)

Zimbabwean law does not set a separate, lower age of digital consent equivalent to section 9 of the UK's Data Protection Act 2018. A person under 18 is a child for the purposes of the Constitution, the Children's Act [Chapter 5:06], and the Marriages Act [Chapter 5:17] (2022), and the Cyber and Data Protection Act [Chapter 12:07] affords heightened protection to data subjects who are minors.

QGen therefore applies the following rule in Zimbabwe:

  • Every Student in Zimbabwe under the age of 18 must have the consent of a parent or guardian, or of their school acting under a properly documented institutional arrangement, before an account is created and before any processing that relies on consent takes place.

5.3 Summary of thresholds (UK & Zimbabwe)

PositionRequirement
Under 13 — UKNo self-registration. Access only via a School Account or a supervised Parent/Guardian account, with verified parental or institutional consent.
13 to 17 — UKMay register as a Student and may give their own consent where consent is the basis. Parental awareness is strongly encouraged and parental linking is offered at registration.
Under 18 — ZimbabweParent, guardian, or documented school consent required in all cases before an account is created. Students must confirm that parents or guardians have consented.
Jurisdiction unclearThe Zimbabwean rule applies by default until the position is established.

6. Age Assurance (UK & Zimbabwe)

Standard 3 of the Age Appropriate Design Code requires us to establish age with a level of certainty appropriate to the risks of our processing, or else to apply the Code's standards to all users. Our approach is as follows:

  • At registration, users are asked to provide a date of birth or age band. This self-declaration determines the default protections applied to the account.
  • Where an account is created by a school or teacher under a School Account, the institution confirms the age band of the learners it is registering, and warrants that it holds the necessary consents.
  • Where a Parent/Guardian account is linked to a Student account, the linkage itself operates as a confirmation that the Student is a child.
  • Because QGen is an education platform and the majority of Student users are children, we apply child-appropriate default settings to all Student accounts regardless of declared age, unless and until an account is confirmed as belonging to an adult learner.
  • We do not use biometric age estimation, facial analysis, or identity document scanning on child users. We consider these disproportionate to the risk profile of an education platform that carries no advertising, no public profiles, and no open social networking.
  • Where the declared age is materially inconsistent with other information available to us, we may ask for confirmation and may restrict the account pending it.

Age assurance measures are reviewed at least annually, and after any material change to the platform's features or risk profile.

7. Information We Collect About Children (UK & Zimbabwe)

We collect the minimum information needed to deliver the educational service (Standard 8 of the Age Appropriate Design Code; Article 5(1)(c) UK GDPR; the corresponding minimisation principle under the Cyber and Data Protection Act [Chapter 12:07]). Specifically:

7.1 Registration and account data

  • First name and last name, or a display name
  • Email address — a school-issued address where the account is created under a School Account
  • Date of birth or age band
  • Year group, education level, subjects, and curriculum or exam board
  • School name, where applicable
  • Username and password
  • The linked Parent/Guardian or School Account, where one exists

7.2 Learning and progress data

  • Assessment activities started or completed, and the results achieved
  • Subject preferences, and topics studied
  • Homework and assignments set by a teacher or tutor, and submissions against them
  • Session history with tutors and teachers, and feedback or ratings given or received

7.3 Communications

  • Support enquiries and correspondence with QGen staff
  • Reports made under the Reporting and Complaints Procedure

7.4 Technical and device data

  • Device type, operating system, browser type and version
  • Pages and features used, and time spent
  • IP address and the approximate country and region derived from it
  • Unique device identifiers and diagnostic data

7.5 What we do not collect from children

  • Precise or real-time GPS location. We derive country and region only to serve the correct curriculum (for example, ZIMSEC or a UK exam board) and to apply the correct legal protections (Standard 10, geolocation)
  • Contact lists, address books, photographs, or camera and microphone access, other than where a tutoring session is delivered through a video service, and the child or their parent has separately consented
  • Special category data about a child, unless a school or parent provides it for a specific accessibility or safeguarding purpose and a lawful condition under Schedule 1 of the Data Protection Act 2018 applies
  • Payment card details from a child. Payment is made by a parent, guardian, or institution, and is processed by a PCI-DSS compliant provider
  • Any data for advertising, commercial profiling, or resale. QGen carries no third-party advertising

8. Question Generator and the Question Bank (UK & Zimbabwe)

Because the Question Generator and the Question Bank are the features children use, we set out separately what is collected and how it is treated. This section should be read with Sections 4.8, 4.9 and 15 of the Privacy Policy (Version 2.0).

8.1 What is collected when a child uses these features

  • The selections the child makes: resource type, subject, topic, curriculum or exam board, and level
  • The content generated for the child, and any resources saved to their Question Bank
  • The child's answers, attempts, and hint requests
  • Whether a resource is downloaded or printed
  • Timestamps, session duration, and which feature was used

8.2 Free Sample use without an account

A child may try the Question Generator without registering. When this happens, the data described above is processed on a temporary basis only, for the duration of the session, solely to generate and display the resource. It is not linked to an account, is not saved to a Question Bank, and is deleted shortly after the session ends.

8.3 Protections applied to children's AI interactions

  • Children are told, in language appropriate to their age, not to type their own or anyone else's personal information into the Question Generator. Prompts are designed to discourage it.
  • Our contracts with AI model providers prohibit them from using any child's inputs or outputs to train their models. They act as our processors under Article 28 UK GDPR and on equivalent contractual terms for Zimbabwean users.
  • Interactions may be monitored and logged for safeguarding and quality assurance. Where monitoring identifies a possible safeguarding concern, it is handled under the safeguarding provisions of the QGen Terms of Service, not as an ordinary data processing matter.
  • AI-generated content may contain errors. Exam-style material is aligned to a syllabus but is not an official past paper and is not produced or endorsed by any exam board.
  • No decision producing a legal or similarly significant effect concerning a child is made solely by automated means. See Section 14.

8.4 Visibility to parents, schools, and tutors

Where a child's account is linked to a Parent/Guardian account, a School Account, or a Tutor, the subjects, topics, and resources the child has generated, and their progress against them, are visible to those adults. This is so that learning can be supported and supervised. Children are told at the point of use who can see their activity — we do not give a child the impression of privacy that does not exist.

QGen does not provide general messaging. The only messages a child receives on the platform are the feedback a tutor, teacher, or parent gives on work the child has generated or completed. That feedback is not private from QGen: it may be reviewed by authorised staff where there is a safeguarding or misuse concern. This is stated plainly to children where the feedback appears, not only in this Policy.

9. How We Use Children's Information (UK & Zimbabwe)

We use children's personal data only for the following purposes:

  • To create and operate the child's account and authenticate them
  • To deliver the educational service, including generating curriculum-aligned resources and saving them to the child's Question Bank
  • To allow teachers, schools, tutors, parents, and guardians to set work and monitor learning and progress
  • To allow a verified tutor, teacher, or parent to give the child feedback on their work, and for the child to receive it
  • To keep children safe on the platform by monitoring for safeguarding risk, grooming behaviour, misuse, and harmful content
  • To provide support when a child, parent, or school contacts us
  • To meet our legal obligations in the United Kingdom and Zimbabwe, including safeguarding and record-keeping duties
  • To maintain the security and integrity of the platform and investigate misuse
  • To improve the Service, using de-identified or aggregated data that cannot be linked back to an individual child

9.1 Detrimental use (Standard 5, UK)

We do not use children's personal data in ways that are demonstrably against their wellbeing. In particular, we do not use children's data to:

  • Serve advertising of any kind, or to build advertising or commercial profiles
  • Extend session length, encourage compulsive use, or maximise time on the platform
  • Apply streaks, pressure mechanics, loss-aversion prompts, or similar techniques that exploit a child's developmental stage
  • Rank, publicly compare, or expose one child's performance to other children outside a class context controlled by their teacher
  • Make automated judgements about a child's ability, character, or prospects that are presented as authoritative
  • Train third-party AI models

We do not sell children's personal data. There are no circumstances in which we will.

10. Legal Basis for Processing Children's Data

10.1 United Kingdom (UK)

Our lawful bases under Article 6(1) UK GDPR, as they apply to children, are:

  • Performance of a contract (Article 6(1)(b)): delivering the educational service the child, their parent, or their school has signed up for, including generating the resources requested.
  • Consent (Article 6(1)(a), read with Article 8 and section 9 DPA 2018): for optional features such as personalisation, and for any non-essential communications. A child aged 13 or over may consent for themselves; below 13, consent must be given or authorised by a parent.
  • Legal obligation (Article 6(1)(c)): where UK law requires us to process or retain data, including in connection with safeguarding referrals and record-keeping.
  • Legitimate interests (Article 6(1)(f)): platform security, fraud prevention, and service improvement, subject to a balancing test in which a child's interests are given particular weight, as required by Recital 38.
  • Recognised legitimate interests (as introduced by the Data (Use and Access) Act 2025) safeguarding the welfare of children and other vulnerable individuals. Where we rely on this basis, for example to review the feedback given to a child on their work for the safety of that child, the usual balancing test is not required, but we continue to document the reliance and will identify it on request.

Where we process special category data about a child, for example health or disability information provided for accessibility, or data processed in the course of a safeguarding concern, we identify an additional condition under Article 9 UK GDPR and, where required, a Schedule 1 Data Protection Act 2018 condition, and maintain an appropriate policy document.

10.2 Zimbabwe

For children in Zimbabwe, we process personal data in compliance with the Cyber and Data Protection Act [Chapter 12:07], relying on:

  • Parental or guardian consent: obtained before an account is created for any user under 18, and before any processing that depends on consent. Consent may be withdrawn at any time without penalty.
  • Contractual necessity: to perform the service the parent, guardian, or institution has contracted for on the child's behalf.
  • Legal obligation: including duties arising under the Children's Act [Chapter 5:06] and the Cyber and Data Protection Act.
  • Legitimate interests: platform security, fraud prevention, and service improvement, provided this does not unjustifiably infringe the rights of the child.

The Cyber and Data Protection Act affords heightened protection to data subjects who are minors, and section 81 of the Constitution requires that the best interests of a child be paramount in every matter concerning the child. We treat both as overriding constraints on what we may do with a Zimbabwean child's data, not merely as factors to be weighed.

11. Best Interests of the Child and Data Protection Impact Assessments (UK & Zimbabwe)

Standard 1 of the Age Appropriate Design Code and Article 3 UNCRC require the best interests of the child to be a primary consideration in the design of our processing. Standard 2 and Article 35 UK GDPR require a data protection impact assessment for processing likely to result in a high risk to individuals, which processing children's data at scale is presumed to be.

Accordingly:

  • QGen maintains a standing Data Protection Impact Assessment covering the processing of children's personal data across the platform.
  • A DPIA is completed or reviewed before any new feature that processes children's data is released, before any change to the AI models or providers used by the Question Generator, and before any new category of data is collected from children.
  • Each DPIA records the risks to children's rights and freedoms specifically, including risks to development, safety, and freedom from commercial exploitation not only risks of unauthorised access.
  • Where a DPIA identifies a residual high risk that cannot be mitigated, the processing does not proceed without prior consultation with the relevant supervisory authority.
  • Where practicable, the views of children and their parents are sought and recorded as part of the assessment, consistent with Article 12 UNCRC.

12. Age Appropriate Design Code Standards (UK)

The following table records how QGen applies each of the fifteen standards of the ICO Age Appropriate Design Code. Standard numbering should be checked against the current published Code before circulation.

StandardHow QGen applies it
1. Best interests of the childPrimary consideration in all design and processing decisions. See Section 11.
2. Data protection impact assessmentsStanding DPIA for children's processing, reviewed before each material change. See Section 11.
3. Age-appropriate applicationAge band established at registration or confirmed by the school; child-appropriate defaults applied to all Student accounts by default. See Section 6.
4. TransparencyAge-banded, plain-language privacy information, with just-in-time notices at the point of collection. See Sections 13 and 20.
5. Detrimental use of dataNo advertising, no engagement-maximising design, no commercial profiling of children. See Section 9.1.
6. Policies and community standardsWe uphold our own published standards safeguarding, AI use, tutor conduct, and complaints and enforce them.
7. Default settingsAll privacy settings on a child's account are set to high privacy by default. Any change is an active, informed choice, and is explained at the point it is offered.
8. Data minimisationOnly data necessary for the educational service is collected. Optional fields are clearly marked as optional. See Section 7.
9. Data sharingChildren's data is shared only with linked parents, schools, tutors, and processors under contract, or where safeguarding or law requires. See Section 16.
10. GeolocationCountry and region only, derived from IP address, used to serve the correct curriculum and legal protections. No precise location. Never shared with other users.
11. Parental controlsParental oversight tools are provided, and the child is told clearly when a parent can see their activity. See Section 15.
12. ProfilingProfiling is limited to educational personalisation, is off by default, and never determines opportunities or outcomes for the child by itself. See Section 14.
13. Nudge techniquesNo nudges toward lower privacy settings, extended use, or unnecessary data sharing. Pro-privacy nudges only.
14. Connected toys and devicesQGen does not provide or connect to connected toys or Internet-of-Things devices. Recorded as not applicable, and reviewed if that changes.
15. Online toolsChildren can exercise their data rights through prominent, easy-to-use in-platform tools, and receive a response in plain language. See Section 20.

13. Transparency and Talking to Children About Their Data (UK & Zimbabwe)

Article 12 UK GDPR requires information addressed to a child to be given in clear and plain language the child can understand. Standard 4 of the Children's Code requires it to be age-appropriate and delivered at the point it matters. We do this by:

  • Publishing age-banded versions of our privacy information, written for the age groups who use the platform rather than for lawyers
  • Giving just-in-time notices at the point of collection; for example, when a child first uses the Question Generator, they are told what happens to what they type and who can see it
  • Using icons, short videos, and examples rather than dense text for younger age bands
  • Making it clear, in the child's own interface, which adults can see their work, their feedback, and their progress
  • Providing Shona and Ndebele summaries alongside English for Zimbabwean users, and accessible formats as set out in the QGen Accessibility Statement

See Section 23 for the plain-language summary included with this Policy.

14. Automated Decisions and Marketing (UK & Zimbabwe)

14.1 Automated decision-making

QGen does not make decisions about a child based solely on automated processing that produce legal effects concerning them or similarly significantly affect them. The Question Generator generates learning content; it does not grade formally, determine progression, allocate places, or make judgements about a child's character or prospects.

The rules on solely automated decision-making in Article 22 UK GDPR have been reformed by the Data (Use and Access) Act 2025. Our position is unchanged by that reform: meaningful human involvement is retained wherever an automated output could materially affect a child, and a child, parent, or school may request human review of any output they consider unfair or incorrect.

14.2 Marketing

  • We do not send marketing communications to children.
  • Marketing about QGen is directed to parents, guardians, schools, and adult users only, and requires consent under PECR where applicable.
  • No behavioural advertising, retargeting, or advertising cookies operate anywhere on the platform.
  • Service messages — session reminders, homework notifications, security alerts — are not marketing and cannot be switched off without affecting the service, but they are kept to what is necessary.

15. Parental and Guardian Rights and Controls (UK & Zimbabwe)

Parents and guardians can:

  • Link their account to their child's account and see the subjects, topics, resources, and progress recorded for the child
  • Give, review, and withdraw consent for processing that depends on consent, including for the Question Generator
  • Review and adjust the child's privacy and personalisation settings
  • Request access to, correction of, or deletion of their child's personal data
  • Request that a child's account be closed and its contents removed
  • Raise a concern or complaint under the Reporting and Complaints Procedure

15.1 Balancing parental oversight with the child's own rights

Parental controls are not unlimited. A child has their own rights to privacy and to be heard, and these grow as the child matures. Accordingly:

  • Where a parent activates monitoring of a child's activity, the child is given an age-appropriate notification that they are being monitored. We do not provide covert monitoring.
  • QGen does not carry private messaging between a child and a tutor. Where a tutor or teacher leaves feedback on a child's work, a linked parent or guardian can see that feedback, and the child is told at the point of use that they can.
  • Where a child aged 13 or over in the UK has given their own consent, a parent cannot unilaterally override the child's withdrawal of that consent in respect of optional features.
  • Where a parental request conflicts with a child's safety, for example, where a safeguarding concern involves a person with parental responsibility, we follow the safeguarding provisions of the QGen Terms of Service, and the child's safety takes precedence over the parental request.
  • Where a competent child objects to a parental access request, we consider the child's views before responding, consistent with Article 12 UNCRC and section 81 of the Constitution of Zimbabwe.

16. Schools, Tutors and Sharing Children's Data (UK & Zimbabwe)

16.1 School Accounts

Where a child uses QGen through a School Account, the school or institution is generally the data controller for the learner's educational record, and QGen acts as processor for that data, under the terms of the School and Institutional Terms of Use. The school is responsible for obtaining any parental consent required and for providing privacy information to parents. QGen remains controller for account security, platform integrity, and its own safeguarding obligations.

16.2 Who a child's data is shared with

  • Linked parents and guardians, for learning oversight
  • The child's school and teachers, where the child is enrolled under a School Account
  • Verified tutors engaged to work with the child, limited to what is needed to deliver the session
  • Processors acting on our instructions under written contract, hosting, authentication, payment processing, and the AI providers that power the Question Generator
  • Statutory safeguarding partners, the police, or a local authority, where a child protection duty or a legal obligation requires it (see Section 17)

We do not share a child's personal data with any other party, and we do not disclose one child's data to another user. Children cannot make their profile or work publicly visible, and there are no open social features on the platform.

16.3 Tutor access

Tutors receive the minimum information necessary to deliver tutoring: the learner's first name or display name, year group or level, subject and topic, and the work assigned or generated. Tutors do not receive a child's contact details, home address, date of birth, or payment information. Tutor obligations are set out in the QGen Terms of Service.

17. Safeguarding Disclosures (UK & Zimbabwe)

Data protection law does not prevent, and is not a reason to delay, sharing information to safeguard a child. Where we identify a concern that a child is at risk of harm, we will share the information necessary with the appropriate person or body, whether or not consent has been given, and whether or not the child or parent has been informed in advance.

In the United Kingdom, such sharing is supported by the recognised legitimate interest in safeguarding children and vulnerable individuals introduced by the Data (Use and Access) Act 2025, by the substantial public interest and safeguarding conditions in Schedule 1 of the Data Protection Act 2018, and by the information-sharing expectations in Keeping Children Safe in Education.

In Zimbabwe, such sharing is supported by the duties arising under the Children's Act [Chapter 5:06], by section 81 of the Constitution, and by the legal obligation basis under the Cyber and Data Protection Act [Chapter 12:07].

Disclosures of this kind are made by, or with the authority of, the Designated Safeguarding Lead, are recorded, and follow the process set out in the QGen Terms of Service. QGen does not maintain a separate Safeguarding and Child Protection Policy: the safeguarding commitments and reporting routes that apply to QGen are those in the Terms of Service. We will not inform a person about a disclosure where doing so would place a child at greater risk.

18. Retention of Children's Data (UK & Zimbabwe)

We keep children's personal data only for as long as we need it:

  • Account data: for as long as the account is active, and for two years after the account is closed, to allow recovery and to meet legal obligations.
  • Question Bank and generation history: until the child, parent, or school deletes it, and in any event for no more than one year after the account is closed.
  • Free Sample data: deleted shortly after the session ends; never retained against an identifiable child.
  • Learning and progress records: retained while the child is an active learner and for one year after the account is closed, and thereafter in line with the retaining school's own record-retention schedule where a School Account applies.
  • Feedback on a child's work: retained for one year from the date the feedback is given, for safeguarding and dispute resolution.
  • Safeguarding records: retained for three years from the date of the record, in line with statutory safeguarding retention expectations, which are longer than ordinary account retention, and are held separately and access-restricted.
  • Consent records: parental, guardian, or school consent records are retained for the duration of the child's account and for five years thereafter, so that we can demonstrate that consent was lawfully obtained.
  • Payment records: held against the paying adult or institution, not the child, and retained for the period required by financial and tax law.

Specific retention periods: the periods set out above apply to each category, and mirror the retention schedule in the QGen Privacy Policy, so that a child's data is not held for longer under one document than under another. Standard 8 of the Children's Code expects defined periods rather than open-ended retention.

When a retention period ends, data is deleted or irreversibly anonymised. Anonymised, aggregated data that cannot be linked back to a child may be retained for research and for demonstrating educational impact, and aggregated analytics are retained for up to 26 months.

19. Security and International Transfers

19.1 Security (UK & Zimbabwe)

We apply the security measures described in the Privacy Policy (Version 2.0) to all users, and the following additional measures to children's data:

  • Access to children's data within QGen is restricted on a need-to-know basis and logged
  • Staff and contractors with access to children's data receive safeguarding and data protection training appropriate to the role
  • Children are encouraged to use display names that do not reveal their full name
  • Child accounts cannot publish or expose personal information publicly
  • Suspected unauthorised access to children's data is escalated immediately to the Designated Safeguarding Lead as well as to the privacy function

19.2 International transfers (UK)

Where children's personal data is transferred outside the United Kingdom, we rely on adequacy regulations made under the data protection test introduced by the Data (Use and Access) Act 2025, or on an International Data Transfer Agreement or the Addendum to the Standard Contractual Clauses, supported by a transfer risk assessment that considers the additional sensitivity of children's data.

19.3 International transfers (Zimbabwe)

Personal data originating from a child in Zimbabwe may only be transferred to another country where that country provides an adequate level of protection, or where appropriate safeguards recognised by the Data Protection Authority are in place, in accordance with the Cyber and Data Protection Act [Chapter 12:07].

19.4 Breach notification involving children (UK & Zimbabwe)

A personal data breach affecting children is treated as inherently higher risk. We apply a lower threshold for direct notification than we would for adult users, and we will:

  • Notify the Information Commissioner without undue delay and, where feasible, within 72 hours where the breach is likely to result in a risk to individuals (UK)
  • Notify the Data Protection Authority administered by POTRAZ in accordance with the Cyber and Data Protection Act [Chapter 12:07] where the breach affects users in Zimbabwe
  • Notify affected children, their parents or guardians, and their schools directly, in age-appropriate language, where the breach is likely to result in a high risk to them
  • Involve the Designated Safeguarding Lead in assessing whether a breach creates a safeguarding as well as a privacy risk

20. Children's Rights and How to Use Them

Children have data protection rights of their own. They do not need to wait for an adult to exercise them, and we will not refuse a request simply because it comes from a child.

20.1 United Kingdom (UK)

  • Right of access: to ask for a copy of the data we hold about them, including their Question Bank and generation history
  • Right to rectification: to have inaccurate or incomplete information corrected
  • Right to erasure: to have their data deleted. This right carries particular weight for data a child provided when younger, and we apply it generously
  • Right to restriction: to ask us to pause our use of their data while a concern is resolved
  • Right to data portability: to receive their data in a machine-readable format
  • Right to object: to processing based on legitimate interests
  • Right to withdraw consent: at any time, where consent was the basis
  • Right not to be subject to solely automated decisions: producing legal or similarly significant effects, as reformed by the Data (Use and Access) Act 2025

20.2 Zimbabwe (Zimbabwe)

Children in Zimbabwe, and their parents or guardians acting for them, have the rights of access, rectification, erasure, and objection, and the right to withdraw consent, under the Cyber and Data Protection Act [Chapter 12:07], read with section 57 and section 81 of the Constitution.

20.3 Exercising rights (UK & Zimbabwe)

A child can exercise rights directly in their account settings, or by contacting us at the address in Section 22. When a child makes a request, we will:

  • Respond in plain, age-appropriate language, not in legal terms
  • Not require the child to go through a parent first, unless we cannot satisfy ourselves of their identity or they are too young to understand the request
  • Take account of the child's own views where a parent's wishes and the child's differ
  • Respond within one month in the UK, and within the timeframe required by Zimbabwean law, and tell the child if we need longer and why
  • Explain clearly if we cannot do what has been asked, and how to complain

Following the Data (Use and Access) Act 2025, we operate a formal complaints-handling process. A child, parent, or school may complain to us directly at complaints@gostudious.uk. We will acknowledge within 30 days and respond substantively as soon as we can. If you remain dissatisfied, you may complain to the Information Commissioner in the United Kingdom, or to the Data Protection Authority administered by POTRAZ in Zimbabwe. Details are in the Reporting and Complaints Procedure.

21. Governance and Accountability (UK & Zimbabwe)

  • Designated Safeguarding Lead: responsible for safeguarding decisions and for disclosures under Section 17.
  • Data Protection Officer / Privacy Lead: responsible for this Policy, for the DPIA, and for handling children's rights requests.
  • Registration with the Information Commissioner (UK): QGen is registered as a data controller.
  • Licensing and DPO appointment under Statutory Instrument 155 of 2024 (Zimbabwe): QGen's registration as a data controller with POTRAZ and its appointment of a Data Protection Officer under that instrument.
  • Review: this Policy is reviewed at least annually, and after any material change to the platform, to the law of either jurisdiction, or following any breach or significant safeguarding incident.
  • Staff training: all QGen staff who handle children's data complete children's data protection and safeguarding training on joining and at defined intervals thereafter. Tutors and teachers are not employed by QGen. They remain responsible for their own safeguarding and data protection training, and for meeting the requirements of their school, employer, or professional body. QGen does not provide, verify, or accept responsibility for that training. Their obligations are set out in the QGen Terms of Service.

22. Contact (UK & Zimbabwe)

  • QGen Privacy Team
  • Privacy and data rights: privacy@gostudious.co.uk
  • Complaints: complaints@gostudious.uk
  • Supervisory authority (UK): The Information Commissioner — www.ico.org.uk
  • Supervisory authority (Zimbabwe): The Data Protection Authority, administered by the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ). Contact details are set out in the Reporting and Complaints Procedure.

23. Plain-Language Summary for Children (UK & Zimbabwe)

This summary is part of the Policy, not a substitute for it. It is written for children, and is offered here as a drafting basis for the age-banded versions referred to at Section 13.

23.1 For learners aged 13 to 17

We collect the things we need to help you learn: your name, your email, your year group, the subjects and topics you pick, the questions you generate, your answers, and the feedback your tutor, teacher, or parent writes on your work.

Your parent or guardian, your school, and your tutor can see what you are studying and how you are getting on. There is no chat or messaging on QGen. The only messages here are the feedback a tutor, teacher, or parent gives you on your work, and that feedback is not private from us: we can read it if there is a safety concern. We will always tell you who can see your work.

We never sell your information. We never show you adverts. We never use your work to train an AI company's models.

Do not type your full name, address, phone number, or anything private into the Question Generator. You do not need to, and it is safer not to.

You can ask us what we hold about you, ask us to fix it, or ask us to delete it: and you can ask us yourself. You do not have to go through an adult. Email privacy@gostudious.co.uk and we will write back in normal English.

If something on QGen makes you uncomfortable, or someone asks you for personal information, tell us or tell an adult you trust straight away.

23.2 For learners under 13

QGen keeps a record of the work you do so your teacher, your tutor, and your grown-up at home can help you.

Keep private things private. Do not type your address, your phone number, or your full name into the question box.

There is no chat on QGen. Your teacher, tutor, or grown-up at home can leave you feedback about your work, and grown-ups at QGen can read that feedback too. That is to keep you safe.

If you want to know what we know about you, or you want us to delete it, ask your parent, guardian, or teacher to email us and we will sort it out.

If anything worries you, tell a grown-up you trust.

24. Changes to This Policy (UK & Zimbabwe)

We may update this Policy to reflect changes to our practices, to the platform, or to the law of the United Kingdom or Zimbabwe. Where a change materially affects how children's data is used, we will:

  • Publish the updated Policy with a revised review date and version number
  • Notify parents, guardians, and schools in advance, and give them the opportunity to review the change before it takes effect
  • Tell affected children directly, in age-appropriate language
  • Where the change relies on consent, obtain fresh consent rather than treating continued use as agreement

Verification Note

This Children's Privacy Policy has been drafted as a companion to the QGen Privacy Policy (Version 2.0) and is scoped exclusively to the law of the United Kingdom and the law of Zimbabwe. No other jurisdiction is addressed.

United Kingdom: the Policy reflects the Data (Use and Access) Act 2025 reforms relied on elsewhere in this suite — the duty to have regard to children's higher protection needs, recognised legitimate interests including safeguarding of children and vulnerable individuals, the reformed rules on solely automated decision-making, the controller complaints-handling duty, the revised international transfer "data protection test", and the restructured Information Commission. Because individual DUAA provisions have been commenced on a phased basis by secondary legislation, QGen must confirm the commencement status of each provision cited before this Policy is circulated.

The numbering and wording of the fifteen ICO Age Appropriate Design Code standards set out in Section 12 must be checked against the current published Code, consistent with the flag already applied to the QGen Accessibility Statement.

References to the Online Safety Act 2023 in Section 4.1 are included because the tutoring marketplace and the feedback features may bring parts of the Service within scope. Whether, and to what extent, QGen is a regulated user-to-user service under that Act has not been determined here and requires a separate assessment.

Zimbabwe: section numbers under the Cyber and Data Protection Act [Chapter 12:07], and the description of Statutory Instrument 155 of 2024, require independent legal verification before circulation. This Policy deliberately describes the substance of the obligations rather than citing specific subsections for children's consent, because the precise provision governing the processing of a minor's data could not be verified from source. It has not been invented. The same applies to the assertion in Section 5.2 that Zimbabwean law sets no separate age of digital consent — this reflects the position as understood, but should be confirmed by Zimbabwean counsel.

All items marked [TBC] must be resolved before publication: the DPIA reference and review date (Section 11); the status and location of the age-banded privacy notices (Section 13); the Designated Safeguarding Lead, Data Protection Officer, ICO registration reference, POTRAZ licence reference and DPO appointment date (Sections 21 and 22); and the safeguarding reporting address and postal addresses (Section 22).