Privacy Policy
Last reviewed: 29 May 2026
This Privacy Policy explains how SB Marketing Limited ("we") collects, uses, and protects your personal data through the Transfera platform. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data controller
SB Marketing Limited, registered in Northern Ireland, is the data controller. Contact our data protection point of contact at hello@transfera.co.uk. We are registered with the Information Commissioner's Office (ICO).
2. What we collect
- Parent/guardian account data: full name, email address, role, registration date, consent timestamp and IP address. This is the only email address we hold — a child never has their own login, email address or account.
- Child data: first name only. We do not collect a surname, date of birth, year group, email address, or any other identifying detail about a child.
- Usage data: exam attempts, scores, topic performance, login timestamps, recorded against the parent/guardian account and the linked child profile
- Payment data: processed by Stripe; we never store card numbers
- Technical data: browser, device type, country-level location (with consent)
3. Lawful basis
- Contract performance (Art 6(1)(b)) — delivering the service
- Legitimate interests (Art 6(1)(f)) — security, fraud prevention
- Explicit consent (Art 6(1)(a) / Art 8) — analytics, children's data
- Legal obligation (Art 6(1)(c)) — financial records
4. Children's information and the ICO Children's Code
Transfera is designed so that parents do not need to provide extensive personal information about their child. When a parent or guardian creates a child profile, we only ever ask for the child's first name. We do not require a child's email address, date of birth, home address, telephone number or school.
We associate that first name with the child's practice activity, answers, scores and progress, so the parent can monitor preparation and performance from their own account. Children do not create independent Transfera accounts; every child profile is created and managed by a parent or guardian, and a child never has their own login or way to access the platform directly.
The ICO's Children's Code applies to online services likely to be accessed by children, including educational platforms like Transfera, whether or not a child is the paying customer. We have built Transfera with this in mind: we collect the minimum data necessary (data minimisation); analytics and non-essential cookies stay off unless a parent actively consents (high-privacy defaults); we never build profiles of children or use their data for marketing (no profiling); we share data with a small, named list of processors and never sell it (limited sharing); we hold data only for the periods set out below (defined retention); and every part of the service is mediated through a parent or guardian account, with no independent child access to change (parental involvement). No photographs are collected — avatars use initials only.
5. Sharing
We use these processors under written Data Processing Agreements: Supabase (Dublin) for database hosting; Vercel (Frankfurt) for application hosting; Stripe for payments; OpenAI for AI explanations (anonymised); Resend for transactional email; Posthog (EU) for opt-in analytics. We never sell data.
6. Retention
- Account data: retained while active; erased within 30 days of deletion request
- Exam attempts: 2 years
- Billing records: 7 years (HMRC requirement)
- Parental consent records: life of child account + 3 years
7. Your rights
Under UK GDPR you have rights of access, rectification, erasure, data portability, restriction, objection, and to withdraw consent. Email hello@transfera.co.uk. We respond within one calendar month. You may also complain to the ICO at ico.org.uk.
8. Security
AES-256 encryption at rest, TLS 1.3 in transit, role-based access controls, password hashing with bcrypt, all data in EU data centres. Breach notification to the ICO within 72 hours where required.