SSendix
    ← Back to Sendix

    Privacy notice

    Last updated: 11 October 2026 · Version 1.3

    Sendix AI Ltd · Company number SC883770 · Registered in Scotland

    Registered office: 3F1 Third Floor, 3 Hill Street, New Town, Edinburgh, Scotland, EH2 3JP

    Registered with the Information Commissioner's Office: ZC264381. ICO registration is not certification or approval of this service.

    Data protection contact: privacy@sendix.ai. We have not appointed a statutory Data Protection Officer at this stage.

    Our role depends on the data

    Sendix supports education professionals reviewing and drafting education and support plans. We are a controller for our own business purposes, including managing customer contacts, accounts and platform security. For pupil plans and associated evidence supplied by a school, trust or other commissioning organisation, we act as a processor on that organisation's documented instructions. That organisation is responsible for determining the lawful basis and informing pupils and families.

    This notice explains our own processing and gives information about school-directed processing. It does not replace your school's privacy notice or its Data Processing Agreement (DPA) with us.

    When Sendix is the controller

    This notice covers the public website at sendix.ai and the Sendix application. We collect information you provide through waitlist and demo requests, access requests, pilot applications, invitations, your account, onboarding and feedback. Your organisation may also provide your work contact details and role.

    The website waitlist/demo form collects your contact name, school name, work email, role, request type and the framework you are interested in (England or Scotland) so we can respond and manage interest in the service. Requests are stored in our database in Azure UK South for 365 days and our team is notified by email. Sendix is the controller for this information, relying on legitimate interests in responding to business enquiries. Joining the waitlist does not authorise unrelated marketing or pupil-data processing.

    The application's pilot-application endpoint checks that your name, email, school, role and referral source are present but does not yet store them, write them to logs or send a notification; it records only that an application arrived.

    • Accounts and access requests: name, work email, organisation, role, request notes, password hash, verification and reset records, preferences and terms acceptance. We use these to evaluate requests, provide access and support users. We rely on legitimate interests in operating a secure business service (Article 6(1)(f)); where you personally contract with us, contractual necessity (Article 6(1)(b)) may apply.
    • Customer administration: billing contact details, organisation information, signatory details and agreement records. Our basis is legitimate interests in administering customer relationships, or contractual necessity where the individual is a contracting party. Legal obligations (Article 6(1)(c)) apply to records we must keep by law.
    • Feedback and pilot surveys: comments, ratings and associated account details. Our basis is legitimate interests in understanding and improving the service. Please do not include pupil information in general feedback.
    • Security and diagnostics: access events, account and organisation identifiers, IP addresses, device/browser information and error or performance telemetry. Our basis is legitimate interests in detecting misuse, diagnosing failures and protecting the service.

    Preferences can include a dyslexia-friendly display option. Choosing it does not require a diagnosis: we use it only to adjust the interface, not to infer or profile a health condition.

    When Sendix processes school data

    Plans and supporting evidence may contain pupil identifiers, educational needs, disability and health information, family details, social-care information and professional reports. Extracted plan sections, clauses, drafts, evidence, findings and review decisions are stored to support review. This includes sections beyond Section F where supplied; sensitive information can remain even after identifier removal.

    The school or commissioning controller must establish its Article 6 lawful basis and, for special category data, an Article 9 condition and any applicable Data Protection Act 2018 safeguards. We do not rely on our own legitimate interests to process pupil plans on its behalf. We assist the controller under an Article 28 DPA.

    School integration features require separate authorisation and validation. Broad MIS roster/profile ingestion is disabled in the current release; attendance is not available pending vendor arrangements. Existing pupil-profile storage structures do not mean a live integration is authorised.

    Real pupil-data processing remains paused. Use fictional documents until your organisation has a countersigned DPA and explicit release approval. Paying the ICO fee does not open this gate.

    Files, identifiers and AI

    The upload service parses PDF and DOCX files in memory; our servers do not store the original file. Extracted text and results are retained for the organisation's retention period (see below): this is not a zero-retention service.

    Before storage or AI processing, the pupil's name, NHS numbers, UPNs, postcodes and dates are removed. The upload is refused if the pupil's name cannot be reliably removed. This is minimisation, not guaranteed anonymisation. Other people's names, contextual details and sensitive needs can remain identifiable. Do not assume the resulting text is anonymous.

    AI analysis sends extracts of the minimised text, not whole plans, to an AI model run on Amazon Bedrock in AWS London (eu-west-2), in-region only. Only approved models in approved UK regions can be called; other requests are refused. Bedrock does not retain the inputs or outputs for the model we use, and they are not used for training. Earlier Microsoft Azure AI deployments are no longer used for plan text, and calls to them are blocked. Outputs require meaningful professional review and must not determine a child's provision automatically.

    Service providers and recipients

    Authorised staff and service providers receive information needed for their work. The following is a current technical inventory, not confirmation that every provider is approved for live pupil data. Provider contracts, regions and onward transfers remain part of the release review.

    • Microsoft Azure (UK South): application hosting, databases, queues, secrets, logs and monitoring, including waitlist and access requests. The Sendix application at app.sendix.ai, including its server and database, runs in UK South, and database backups stay in UK South. The public website sendix.ai is static content served through Azure Static Web Apps (resource registered in West Europe; content distributed through Microsoft's global network); its waitlist form sends requests to our UK South API.
    • Amazon Web Services, London (eu-west-2): Bedrock runs the AI model that analyses extracts of minimised plan text, and SES sends transactional email (staff names, addresses, invitation or password-reset links, and access-request notifications to our team). No pupil data is sent by email.
    • Microsoft 365: our staff email, which receives website enquiry notifications. It does not receive pupil data.
    • GitHub: source control, build pipelines and container images. Database migrations and seeding run inside Azure UK South, so GitHub does not receive database credentials or application data.
    • Groupcall Xporter: a UK school integration provider. Live pupil access requires school authorisation, a vendor agreement and release approval; current integration capability is limited as described above.
    • Cloudflare: DNS for sendix.ai. It does not receive application data.

    For school data, our DPA lists the authorised sub-processors (Microsoft Azure, AWS Bedrock and AWS SES, all processing in the UK) and gives at least 30 days' notice before any is added or replaced. Contact privacy@sendix.ai for current supplier information. We may also disclose information where required by law or to respond to a valid regulatory request.

    International transfers

    Application data, AI processing and transactional email are configured in UK regions (Azure UK South and AWS London). Website content is served through Microsoft's global network, and suppliers may provide support from outside the UK under their contractual terms.

    For school data, our DPA commits us not to transfer it outside the UK without the school's prior written consent and appropriate safeguards. For other restricted transfers, we must establish an applicable adequacy route or appropriate safeguards, such as the UK International Data Transfer Agreement or UK Addendum, and assess transfer risks where required. We have not yet verified every provider's global support, backup or onward-transfer arrangements. This is part of the live-data release review.

    Retention and deletion

    Scheduled deletion has run since 3 October 2026, under our approved DPA (version 1.0) and data protection impact assessment. A daily job deletes school records when their retention period ends. Defaults are 90 days from audit-report creation, 30 days after a draft is deleted and 365 days from evidence-record creation. A school or trust can set its own periods, and associated review records follow their parent plan's window. Fictional demonstration plans are exempt.

    Other records have set periods: website enquiries and access requests 365 days; invitations 90 days after they are accepted, revoked or expire; feedback 365 days; and security logs that do not relate to a document 730 days. Application logs contain no plan text or pupil identifiers and are kept for 30 days. When an organisation leaves, staff accounts that belong only to it are anonymised; signed contracts and DPA records are kept as the record of the agreement.

    Deleted records are removed from the live database immediately and from encrypted backups, which stay in UK South, within 35 days. At the end of a contract, under our DPA, the school chooses whether we return its data in a commonly used format, delete it, or both; we do this within 30 days and confirm deletion in writing, unless the law requires us to keep it.

    Staff users can delete their own Sendix accounts in the application. Requests about pupil records (access, correction, erasure or restriction) go to the school or commissioning controller, which instructs us under the DPA. Other account or deletion requests can be sent to privacy@sendix.ai. We assess them individually, including any need to retain records for legal obligations or disputes.

    Security

    Measures in place include encryption in transit (TLS) and at rest, secrets held in Azure Key Vault, hashed passwords with a minimum length, account lockout and rate limiting, 30-minute idle session expiry, and multi-factor authentication that is mandatory for Sendix administrators and for SENCO and SEND lead accounts. Plan text is visible only to the school's SENCOs and SEND leads and its trust's SEND lead (a plan not linked to a school stays with the person who uploaded it); IT leads, billing administrators, staff at other schools and Sendix administrators cannot see it through the application. Personal data is excluded from application logs. We will tell a school without undue delay, and within 24 hours, of becoming aware of a personal data breach affecting its data. These measures reduce risk but do not guarantee that a breach cannot occur. Cyber Essentials: we applied and paid the assessment fee on 9 October 2026; the assessment is pending and we are not yet certified. Independent application test: a scoped test will be commissioned when the first paid engagement is signed, and completed before a fourth school or any local authority goes live, and by 31 March 2027 at the latest.

    Your rights and complaints

    Depending on the processing and applicable exceptions, you may request access, correction, erasure, restriction or portability, and object to processing based on legitimate interests. Where we rely on consent, you may withdraw it without affecting earlier lawful processing.

    For information Sendix controls, contact privacy@sendix.ai. We normally respond within one calendar month; if a lawful extension or identity check is necessary, we will explain it. For pupil plans, contact your school or commissioning controller first. We assist that organisation with its requests rather than deciding them independently.

    You can complain to the Information Commissioner's Office. You do not have to contact us before doing so.

    Cookies and browser storage

    The application, not the public landing-page enquiry form, uses NextAuth authentication cookies, including session-token, csrf-token and callback-url cookies (with Secure/Host prefixes where applicable). They maintain sign-in, protect login requests and remember the sign-in destination. Session and expiry behaviour depends on the authentication configuration.

    sendix_last_activity records the last activity time for the 30-minute inactivity check, with a 30-minute maximum age refreshed during activity. These cookies support authentication and security, not advertising.

    We do not use advertising or analytics cookies or third-party trackers, and both websites serve their own fonts.

    Changes to this notice

    We publish updates with a new version and date, and draw material changes to users' attention as appropriate. New uses of school data require controller instructions and any necessary updates to the DPA and impact assessment; changing this notice alone does not authorise them.