Data Inventory (ROPA Annex)
How to use this document: Copy the relevant rows into your school's ROPA and DPIA.
The lawful basis for pupil data is determined by the school as data controller.
iAntz acts as processor for pupil data and controller for certain school billing and parent account data (see Controller / Processor Overview).
Processing activities via Payments by iAntz
| Processing activity | Data subjects | Personal data categories | Purpose | Typical lawful basis (Controller) | Processor / location | Retention (indicative) |
|---|---|---|---|---|---|---|
| School staff accounts | Staff, governors, volunteers with admin access | Name, email, phone, role, permissions, auth data, audit logs | Platform administration, safeguarding access controls | Contract; legal obligation; legitimate interests (security) | iAntz / AWS UK (London) | Duration of account + up to 24 months after deactivation; logs 30-180 days |
| Parent / guardian accounts | Parents, carers, guardians | Name, email, phone, address (if provided), auth data, linked children | Account management, wallet access, communications | Contract; legitimate interests | iAntz / AWS UK | Until account deleted (anonymised on self-service deletion); see privacy policy |
| Pupil records (MIS sync) | Pupils | Name, year group, class, MIS ID, photo (if synced), group memberships | Linking parents to children, payments, clubs, meals | Public task / legitimate interests / contract (school to determine) | iAntz + Wonde / UK | While enrolled at school using iAntz; per school offboarding terms |
| Payments and wallets | Parents, pupils (indirect) | Transaction amounts, items purchased, wallet balances, payment metadata | Collect school payments, refunds, reporting | Contract; legal obligation (financial records) | iAntz + Stripe / UK-EU | Financial records 7 years; anonymised where account deleted |
| In-app messaging | Staff, parents | Message content, recipients, timestamps | School-parent communications | Contract; legitimate interests | iAntz / AWS UK | Per school policy; typically up to 2 years after resolution for support-related |
| SMS / WhatsApp | Parents, staff (where enabled) | Phone number, message content | Service notifications, payment reminders | Contract; consent (where marketing-style) | Twilio / UK-EU | Per messaging retention policy; typically up to 2 years |
| Push notifications | App users who enable notifications | Device token, notification content | Service alerts (messages, payments) | Contract; consent (device permission) | Google Firebase (FCM) / provider-dependent | While token active; revoked on uninstall or opt-out |
| Dietary / safeguarding / care profiles | Pupils | Allergies, dietary requirements, medical notes, club registration answers | Meals, clubs, pupil safety | Legal obligation; vital interests; legitimate interests (school to determine) | iAntz / AWS UK | While relevant to active services; per school retention policy |
| Collection / pickup passes | Pupils, authorised collectors | Collector name, verification data, pass status | Safeguarding at collection | Legal obligation; legitimate interests | iAntz / AWS UK | Per event/session; audit logs per retention policy |
| AI-assisted features | Staff (primarily) | Minimised operational context; prompts avoid pupil PII by design | Reporting assistance, content drafting, insights | Legitimate interests; contract | AWS / UK-EU | Not used to train public models; logs per platform policy |
| Support and CRM | School contacts, parents (if they contact support) | Name, email, phone, enquiry content | Customer support, onboarding | Contract; legitimate interests; consent (marketing) | HubSpot / EU | Typically 2 years after resolution |
Special category data
The platform may process special category data (for example dietary, allergy, or medical information) only where the school enters it for safeguarding or meals/clubs purposes. Schools must ensure an appropriate Article 9 UK GDPR condition applies (for example, explicit consent, vital interests, or substantial public interest under Schedule 1 DPA 2018).
Children's data
- iAntz does not collect data directly from children.
- Pupil data is provided by the school (or via authorised MIS integration).
- Pupil data is not used for marketing or to train public AI models.
Full details: iantz.com/privacy