Transparency Pack
Last updated: June 2026
This page is GradeOrbit's public Transparency Pack. It is generated from a single source of truth — not a static PDF — so the information your DPO reviews is always current. It summarises how we process student work, who our sub-processors are, and the controls we have in place to protect data.
GradeOrbit is operated by George Burgess (sole trader, trading as GradeOrbit). UK ICO registration: ZC132530.
How to read this page
GradeOrbit operates two distinct tiers with different data-handling postures. Throughout the page, points are flagged with one of the badges below so you can see at a glance which tier they apply to.
DPIA summary
We have completed a Data Protection Impact Assessment for the GradeOrbit marking workflow and, for schools, the AI-detection workflow. The findings are summarised below, split by tier so you can find what applies to you.
Solo / individual teacher tier
- Lawful basis: Article 6(1)(f) legitimate interests — the teacher uses GradeOrbit on their own initiative for assistive marking, with no DPA in place.
- Client-side redaction: the teacher draws redaction boxes over student names, IDs, and signatures in the browser; a Canvas burn-in step bakes those boxes into the image before any upload.
- Anonymous students by default:students are referenced as "Student 1", "Student 2" etc. Names are never auto-detected from imagery.
- Optional custom student labels: the teacher may type a custom label for each student (for their own reference). These labels live entirely in the browser tab — they are never sent to our servers, never forwarded to AI providers, and never persisted. Closing the tab discards them.
- No persistence of outputs: transcriptions, AI feedback, and grades are returned to the teacher's device only and are not saved server-side.
- No imagery on server: redacted images are sent to the AI provider for inference and are not retained by us.
- No training: we never use solo-tier data for training, fine-tuning, or analytics. No DPA, no training.
School tier (signed DPA in place)
- Lawful basis: Article 6(1)(e) public task. The school is the controller; GradeOrbit is the processor under a signed Article 28 DPA.
- Real student names: processed because the DPA explicitly authorises it. Names are provided by the school from their own roster (manually entered or CSV imported), never auto-detected from imagery.
- No client-side redaction step: once the DPA is in place, forcing redaction on every upload is friction without legal benefit. The teacher uploads scanned work directly.
- Student imagery (marking and AI-detection): persists for the active life of the run only. Once a teacher ends the run — or after a school-configurable auto-archive window (default 90 days) — the original scanned papers are deleted from both the marking and AI-detection storage buckets. The persisted outputs (grades, feedback, transcriptions, detection results) stay.
- How AI detection works: for schools, AI detection compares a pupil’s new work against samples of that same pupil’s own prior work already held under the DPA, to flag writing that has changed markedly. It is provided as an indicator for a teacher to review, never as proof of AI use, and is not offered on the Solo or Team tiers.
- Marking outputs: persisted against a school-internal student UUID — transcriptions, AI feedback, grades, teacher notes, and rubric decisions. School-configurable retention up to 3 years.
- Pupil accounts (optional): a school may give pupils their own login to view their own marked work. Where it does, we store the pupil's email address and a login; the pupil sets their own password, held only as a salted hash — never in plain text. Pupils receive only two transactional emails (a set-password link and a "result is ready" notification), can see only their own approved results, and are never sent marketing. The login and the pupil's email are removed when the school removes the pupil, withdraws their access, or closes the account.
- Special category data: none collected by design. We do not collect biometrics, photos, safeguarding, or SEN data — schools should not enter these into nickname or note fields.
- Children's data: covered by the UK Children's Code. No profiling, no behavioural advertising, no third-party sharing for marketing, no automated decision-making (Article 22 does not apply — every grade is reviewed by the teacher).
- Residual risk: assessed as low after mitigations (time-boxed imagery retention with automatic deletion, tenanted RLS, encryption at rest and in transit, mandatory MFA for school staff, audit logging, retention controls, signed DPA).
AI safety and human-in-the-loop
GradeOrbit is an assistive tool. The teacher is always the final arbiter of any grade or piece of feedback. Some controls apply across the whole product; others differ by tier.
Universal controls
- AI output is presented as suggestions — never auto-finalised or written back to a school information system.
- Teachers review, edit, and approve before any feedback reaches a student.
- Article 22 (automated decision-making) does not apply: every grade is reviewed by a qualified teacher before it is shared.
- Our third-party AI providers (Google Gemini, Google Cloud Vision) operate under a no-training contractual stance — they do not use our customer content to train their foundation models.
Marking agent fine-tuning
Under the school tier, with a signed DPA in place, GradeOrbit may use the school's marking history to fine-tune a school-specific marking agent. This is a deliberate processing purpose authorised by the DPA — see the "Marking agent that learns with you" section on the schools page for the product context.
- What this includes: marking outputs (grades, feedback, transcriptions), teacher acceptance / override signals, and student identifiers as supplied by the school. This is the input to fine-tuning a marking agent that mirrors the school's standards.
- What this does not include: raw student work imagery (fine-tuning runs against persisted outputs, not the transient imagery), special- category data, biometrics, safeguarding or SEN flags, behavioural profiling, or any sharing of one school's data to influence another school's agent. Tenant isolation is enforced at the database and at the agent boundary.
- Right to object: a school owner may opt out of fine-tuning at any time without losing access to the rest of the product. Opt-out is reversible.
Solo tier never feeds training
We do not use any solo-tier data for training, fine-tuning, or analytics. The bright line: no DPA, no training. This is what keeps the solo flow a true PII-Free Zone.
Data residency
Storage and transfers
Primary data storage is in the EU (Supabase, Frankfurt region). Several sub-processors are US-headquartered; transfers from the UK rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, plus a Transfer Risk Assessment.
Imagery in the solo flow
The teacher redacts client-side via a Canvas burn-in step. The unredacted image never leaves the device.
Imagery in the school flow
The DPA permits unredacted uploads. Imagery is held in a private storage bucket for the active life of the assessment run so teachers can re-open a page when reviewing the AI's call. Once the teacher hits "Archive" — or after a school-configurable auto-archive window (default 90 days from completion) — the original scanned papers are deleted. Marking outputs (grades, feedback, transcriptions) stay within the school's configured retention window.
Security posture
Universal controls
- Encryption in transit: TLS 1.2+ on every endpoint.
- Encryption at rest: AES-256 across the database and object storage.
- Backups: point-in-time recovery (PITR) enabled on the production database.
- Monitoring: Sentry error monitoring runs without default PII collection and without session replay.
- Internal access control: production access is limited to the data controller and protected by MFA.
Tenant isolation and authentication
- Authorisation: row-level security (RLS) on every table holding tenant data — schools cannot read each other's records.
- User authentication: mandatory TOTP MFA for every school user (Owner, Admin, Teacher). MFA-reset is owner-only.
- Audit log: every CRUD / wipe / share / run operation is recorded in a per-school audit log per Art. 28 Clause 8.
Authentication for solo teachers
Email + password with TOTP MFA available but not mandatory for solo accounts.
Sub-processors and privacy contact
A full list of every sub-processor we use, their role, and their jurisdiction is maintained on a dedicated page. Sub-processors serve both tiers; what we send each one differs by tier and is documented on that page. For DSARs, deletion requests, or breach notifications, see our privacy contact page.
Need something more for your procurement file?
We can provide our DPA, security questionnaire, and DPIA on request. Email george@gradeorbit.co.uk and we'll respond within 48 hours.