Data protection pack for academies
How Thwok handles your pupils' and parents' personal data, what moves onto the platform when you onboard, who is responsible for what, and the agreement that governs it. Written for academy owners, welfare officers and anyone acting as your data protection lead.
Contents
- The short version
- Who we are
- Who is responsible for what
- What data moves, and why we're allowed to
- How onboarding works, step by step
- Where the data lives and who else touches it
- How long we keep things
- How we protect it
- Children, rights requests, complaints and breaches
- Academy Data Processing Agreement
- Template: notice to parents before migration
- Template: guardian consent & medical information
- Parent FAQ
- Checklists and sign-off
1. The short version
Your academy already holds personal data about every pupil and parent — names, dates of birth, phone numbers, emergency contacts, medical notes, photo permissions. Today that lives in spreadsheets, paper forms and WhatsApp. Moving it onto Thwok does not change who is responsible for it: you remain the data controller, and Thwok becomes your data processor, acting only on your instructions under a written agreement (Section 10). That is exactly the same legal relationship you would have with a payroll provider or a hosted email service.
UK GDPR does not require you to collect fresh consent from every parent to move their data to a new supplier. What it does require is that the move is lawful, transparent, secure and minimal. This pack shows how each of those is met.
What you need to do
- Read this pack and sign the Data Processing Agreement (Section 10).
- Send parents the migration notice (Section 11) at least 7 days before we import — email, WhatsApp or a printed note in the sports hall all count.
- Export your register using the template we give you, upload it through the secure link, and delete any copies you don't need.
- Add one line to your own privacy notice naming Thwok as a processor (wording supplied in Section 11).
What Thwok commits to
- Data is stored in the UK (Google Cloud London region) and never sold or used for advertising.
- Parents claim their child's record themselves; nothing is visible to other families and no child appears in search or public pages, ever.
- Records that no parent claims within 60 days are deleted and you're told.
- We only ever contact parents about the academy — never marketing without a separate opt-in.
- We tell you about any security incident affecting your data within 24 hours of confirming it.
- You can export or delete everything at any time; leaving Thwok is one click, not a negotiation.
2. Who we are
| Legal entity | SIMPLIFY HCS LIMITED, a company registered in England and Wales, trading as Thwok (thwok.app) |
|---|---|
| Company number | 13667511 — incorporated 2021 in England and Wales |
| Registered office | 4 Henley Gardens, Pinner, HA5 2DE, England |
| ICO registration | ZB235652 — Tier 1 fee paid. Thwok is registered with the Information Commissioner's Office as a controller for its own platform data and pays the data protection fee. |
| Data protection contact | Nagini Vallamkonda, Founder and data protection lead · privacy@thwok.app Thwok is not required to appoint a statutory Data Protection Officer (it is not a public authority and its core activity is not large-scale monitoring or special category processing). A named lead with the founder's authority is the appropriate arrangement for a business of this size, and this pack has been prepared to a DPO standard. |
| Applicable law | UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025; the Privacy and Electronic Communications Regulations 2003 (PECR); the ICO Age Appropriate Design Code (the "Children's Code"). |
| Professional background | Thwok's founder holds Digital Clinical Safety Officer (DCSO) certification and has built NHS-facing compliance software. The safeguarding, data-minimisation and audit-trail patterns in this pack are carried over from that work. |
3. Who is responsible for what
Data protection law has three roles. A controller decides why and how personal data is used. A processor acts on a controller's documented instructions. Where two organisations decide together, they are joint controllers. The table below is the role map for every activity that touches academy data. It is deliberately explicit because ambiguity here is the first thing a regulator looks for.
| Activity | Academy | Thwok | Notes |
|---|---|---|---|
| Your register: pupils, guardians, emergency contacts, medical notes, attendance, term enrolments, fees owed | Controller | Processor | You decide what is collected and why. We store and process it only to run your academy on Thwok. |
| The bulk import of your existing register | Controller | Processor | You instruct the import by uploading the file. We do not add to, enrich or cross-reference it. |
| Inviting existing parents to claim their child's record | Controller | Processor | Invitations are sent in the academy's name, on your instruction. These are service messages, not marketing. |
| The parent's Thwok account (login, profile, notification settings, consent records) | — | Controller | Created when the parent accepts our terms. Governed by Thwok's Privacy Notice. |
| Payments (card details, transaction history) | — | Controller with Stripe as independent controller for card processing | Thwok never sees full card numbers. Stripe is regulated by the FCA and PCI-DSS certified. |
| Safeguarding concerns raised through the platform | Controller | Processor (academy matters) / Controller (platform matters) | Concerns about academy sessions are forwarded to your welfare officer within 4 working hours. Concerns about the platform itself are handled by Thwok. |
| Verifying your staff's credentials (DBS, safeguarding, first aid, qualifications) | Controller | Processor | Verification of staff credentials is the academy's processing, as controller. Thwok processes the uploaded certificate and the academy's check record on the academy's instruction only, and gives no verdict of its own. |
| Aggregated, anonymised platform statistics (e.g. "how many academies use waitlists") | — | Controller | Never at child level; never published below a minimum group size of 20. |
| Marketing to parents | Does not happen without a separate, unticked, revocable opt-in held by Thwok. The academy register is never used as a marketing list. | ||
4. What data moves, and why we're allowed to
Only what is needed to run the academy on Thwok moves. The import template has exactly these columns and rejects anything else. Each row below states the lawful basis you rely on as controller, which is also the basis on which Thwok processes as your processor.
| Data | Whose | Why it's needed | Lawful basis (Art. 6) and, where relevant, condition (Art. 9) |
|---|---|---|---|
| Child's first name, surname, date of birth | Pupil | Identify the pupil, place them in the right age group, apply DBS/ratio rules | Contract (6(1)(b)) — performance of the coaching contract with the guardian |
| Guardian's name, mobile number, email | Guardian | Send the invitation, confirm the place, session changes, cancellations, receipts | Contract (6(1)(b)) |
| Second guardian / emergency contact name and phone | Third party | Reach someone if the guardian can't be reached during a session | Legitimate interests (6(1)(f)) — the child's safety; balancing test recorded in Section 9 |
| Medical notes relevant to physical activity (e.g. asthma, allergies, an inhaler in the bag) | Pupil | Coaches can respond appropriately in an emergency | Contract (6(1)(b)) plus explicit consent of the guardian (9(2)(a)) — captured on the Section 12 form. In a genuine emergency, vital interests (9(2)(c)) also applies. |
| Photo/video permission (yes/no) | Pupil / guardian | Enforce your existing permissions on the platform | Consent (6(1)(a)) — imported as a flag; the underlying permission is re-confirmed by the guardian when they claim the record |
| Current group, term enrolment, session day | Pupil | Recreate your timetable so parents see the right sessions | Contract (6(1)(b)) |
| Coach or staff member's name, mobile, email, role, and the expiry date of their DBS certificate | Academy staff | Give each coach their own login, put them on the right sessions, and stop an out-of-date DBS being rostered onto a junior session | Contract (6(1)(b)) or legitimate interests (6(1)(f)) — whichever the academy relies on for that person — and, for the DBS expiry date, legal obligation and substantial public interest in safeguarding (9(2)(g), DPA 2018 Sch. 1 Pt. 2 para. 18). Thwok holds the date only; never the certificate, the certificate number or the disclosure content. |
| Outstanding balance (optional) | Guardian | Carry forward what's owed so parents aren't double-charged | Contract (6(1)(b)) |
What we ask you not to send
Free-text notes about a child or family, safeguarding case notes, previous incident reports, religion, ethnicity, benefits status, school names, or photographs. None of these are needed to onboard, and the import will reject unrecognised columns. If a medical note contains more than a coach needs to know on court, shorten it. You can always add detail later inside the platform, where it is encrypted and access-logged.
Why fresh consent is not the basis
Consent is the wrong basis for most of this data. A parent cannot meaningfully "refuse" to give their child's name to the academy that coaches them, and consent that can't be refused isn't valid consent. The coaching contract already justifies the core data; the migration is simply the academy choosing a new tool to perform that contract. What parents are entitled to is transparency — being told clearly, in advance, what is changing — which is what the Section 11 notice provides. Explicit consent is used only where the law requires it: medical information (special category data) and images of children.
Children's data and the Children's Code
Under UK law a child can consent to online services from age 13, but Thwok is designed so that this never has to be tested. Children under 13 do not have Thwok accounts at all: the pupil is a record held by a guardian, and it is the guardian who holds the account, accepts the terms and controls every setting. Pupils aged 13–17 may be given a limited account by their guardian, provisioned and controlled by the guardian, with no public profile, no messaging with strangers, and no location features. Because the service is nevertheless likely to be used by children, Thwok applies the ICO Children's Code: privacy settings default to the highest level, no nudge techniques, no profiling for advertising, no geolocation, and children never appear in search results, share cards, leaderboards or public event pages.
5. How onboarding works, step by step
The migration is designed so that the parent, not the academy or Thwok, is the one who activates their child's record. Until they do, the record is dormant, invisible and time-limited.
- Agreement signed. You sign the Data Processing Agreement (Section 10). Nothing is uploaded before this.
- Parents told. You send the Section 11 notice to all current families at least 7 days before upload, through whatever channel you normally use. Keep a copy and the date — that is your transparency evidence.
- Staff brought over. Your coaches come across the same way and at the same time, on their own template: name, mobile, email, role and DBS expiry date. They are adults, so there is no guardian step — each coach gets their own invitation, sets up their own passwordless login, and sees only the sessions you assign them. Send us the DBS expiry date, never the certificate.
- Register exported. You fill the import template (CSV or Google Sheet; we supply it). One row per pupil. The template validates dates, phone formats and rejects unknown columns before you upload.
- Secure upload. You upload through a one-time, expiring link in your Thwok academy dashboard — never by email or WhatsApp. The file goes straight to an encrypted, access-restricted bucket in the London region. The raw file is deleted automatically within 24 hours of processing.
- Pending records created. Each row becomes a pending pupil record linked to a hashed version of the guardian's phone number. Pending records are not searchable, not visible to coaches beyond name and group, and not linked to any Thwok account.
- Invitations sent in your name. Each guardian receives one message — email and/or SMS, in the academy's name — saying that Flying Shuttles has moved to Thwok and inviting them to claim their child's place. The message states where their number came from, links to the Privacy Notice, and offers a one-tap "this isn't me / remove my details" route that works without an account. This is a service message about an existing relationship, not marketing.
- Guardian claims the record. The guardian verifies their phone by one-time code, reviews the child's details, corrects anything wrong, confirms or updates medical notes and photo permission (Section 12), and accepts Thwok's Guardian Terms and Privacy Notice with an unticked checkbox. The consent record stores the document versions, timestamp and method. Only now does a Thwok account exist.
- Reminders, bounded. Unclaimed invitations get at most two reminders (day 7 and day 21). Anyone who taps "remove my details" is suppressed immediately and permanently for that academy.
- Unclaimed records deleted. Any record not claimed within 60 days is permanently deleted, and you receive a list of the pupil names (no other data) so you can follow up offline if you want to.
- Confirmation to you. You receive an import report: rows received, records claimed, records removed at the parent's request, records deleted as unclaimed. That report is your Article 30 record for the migration.
6. Where the data lives and who else touches it
Thwok is built on Google Cloud (Firebase) in the London region (europe-west2). Academy data is stored, backed up and processed in the UK. The following sub-processors are engaged under written contracts that impose the same obligations Thwok owes you. You will be given 30 days' notice of any addition, with the right to object.
| Sub-processor | What they do for us | Data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| Google Cloud / Firebase (Google Cloud EMEA Ltd) | Database, authentication, file storage, serverless functions, hosting | All platform data | UK — London (europe-west2). Authentication metadata may be processed in the EU/US per Google's regional configuration. | Google Cloud Data Processing Addendum; UK Addendum to the EU SCCs for any non-UK processing; ISO 27001, SOC 2 |
| Stripe Payments Europe Ltd / Stripe Payments UK Ltd | Card payments, payouts to the academy | Guardian name, email, card (tokenised — never held by Thwok), transaction amounts | EU/UK, with US processing under Stripe's DPA | Stripe DPA with UK Addendum; PCI-DSS Level 1; FCA-authorised |
| Anthropic (Claude) | Drafts replies to parent enquiries and summarises free text for staff review — a person approves every output before it is used | Enquiry text only; no pupil register data, no medical notes; inputs are not used to train models and are not retained beyond the request | US | Anthropic Commercial Terms and DPA with UK Addendum / IDTA; zero-retention configuration |
| Zoho Corporation B.V. | Delivers invitations, confirmations and receipts by email (SMTP) | Name, email address, message content | EU — Netherlands (smtp.zoho.eu) | Zoho Data Processing Addendum with UK Addendum to the EU SCCs; ISO 27001, SOC 2 |
| Google Cloud / Firebase Authentication | Sends the one-time codes that verify a guardian's phone | Mobile number, six-digit code | Processed by Google under its regional configuration | Covered by the Google Cloud Data Processing Addendum above |
| [Invitation SMS provider — not yet engaged] | Would send the invitation text message in the academy's name. No provider is engaged today, so invitations are sent by email only until one is. Engaging one is a change to this list and the Academy will receive 30 days' notice with a right to object (clause 6). | Mobile number, message content | To be confirmed | To be confirmed |
International transfers: where a sub-processor processes personal data outside the UK, Thwok relies on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment on file, as required following the ICO's 2026 transfer guidance and the Data (Use and Access) Act 2025 "data protection test". The current list is maintained at thwok.app/legal/sub-processors.
What never happens
- No data is sold, rented or shared with advertisers or data brokers.
- No analytics SDK receives a child's name, date of birth or medical data. Product analytics are event-level and pseudonymised.
- No child's data is used to train any machine-learning model, ours or anyone else's.
- No academy's data is visible to another academy, club or venue.
7. How long we keep things
| Data | Retention | Why |
|---|---|---|
| Raw import file | Deleted within 24 hours of processing (lifecycle rule as backstop) | Minimisation; only structured records survive |
| Pending (unclaimed) pupil records and invitations | 60 days, then deleted | No relationship established; the academy is told which names were removed |
| Suppression list ("remove my details") | Hashed phone/email, kept permanently | An objection does not expire. The record is a one-way hash with no contact details in it, so keeping it indefinitely is the least intrusive way to be certain the person is never contacted for this academy again. Deleting it after a fixed period would mean a later import could reach them a second time. |
| Active pupil record, enrolments, attendance | While enrolled, then 12 months after the last enrolment ends, then deleted or anonymised | Allows re-enrolment after a gap year; matches typical sports-body guidance |
| Medical notes | Deleted 90 days after the last enrolment ends, or immediately on guardian request | Special category data — shortest workable period |
| Consent records (terms, privacy, medical, photo) | 6 years after the relationship ends | Evidence of compliance (limitation period) |
| Payment and fee records | 6 years from end of the tax year | HMRC and accounting requirements |
| Safeguarding records | Retained per the academy's safeguarding policy and applicable statutory guidance — the academy instructs; Thwok holds | Statutory inquiries and the child's future welfare |
| Guardian account after deletion request | Deleted within 30 days; financial records retained as above in a form unlinked from the account | Right to erasure, balanced against legal obligations |
| On termination of the Academy Agreement | Full export offered; all academy data deleted within 30 days of your instruction, backups purged within a further 35 days | Section 10, clause 12 |
8. How we protect it
Technical measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256) for all data, including backups.
- Medical notes and emergency contacts are stored in a separate, more tightly controlled collection with field-level access rules.
- Every read and write goes through server-side security rules: a coach sees only the pupils in their own sessions; an academy admin sees only their academy; a parent sees only their own children.
- Guardian phone numbers are the identity anchor and are stored hashed with a secret key for matching; plaintext is held only where needed to send a message.
- All data changes are written through an audit log; medical-note access is logged by user and time.
- Passwordless sign-in (one-time code / magic link) — nothing for parents to reuse or leak.
- Automated daily backups in the London region, tested restores, 35-day point-in-time recovery.
- Dependency scanning and secret scanning on every code change; production access requires hardware-key MFA.
Organisational measures
- Production data access is limited to the founder; there are no contractors with standing access. Any future staff are DBS-checked where their role touches children's data and trained before access.
- Support is done through admin tooling with the same access rules as the product, not through raw database access.
- A written incident response procedure (Section 9) with a 24-hour notification commitment to academies.
- A Data Protection Impact Assessment covering children's data, medical data, messaging and AI-assisted features, reviewed before each major feature ships (summary in Section 9).
- Sub-processors reviewed annually; DPAs on file.
- Records of processing maintained under Article 30.
- Per-academy export and delete functions so that leaving is always possible without asking us.
Independent assurance: Thwok is an early-stage company and does not yet hold its own ISO 27001 or Cyber Essentials certification. Its infrastructure providers (Google Cloud, Stripe) are ISO 27001 and SOC 2 certified. Thwok intends to obtain Cyber Essentials within 12 months of the date of this pack and will notify academies when achieved.
9. Children, rights requests, complaints and breaches
Rights requests from parents (and older pupils)
Parents can exercise every UK GDPR right about their child's data — access, rectification, erasure, restriction, portability and objection. A pupil aged 13 or over may also exercise rights in their own name where they have the maturity to understand them; Thwok will involve the guardian unless doing so would be against the child's interests. You are responsible for responding as controller; Thwok is responsible for making that easy:
- Most requests need no request at all: guardians can view, correct, export and delete their child's data from their own account.
- A request that arrives at Thwok about academy data is forwarded to your nominated contact within 2 working days, and we do not respond on your behalf unless you ask us to.
- Where you need help — a full export, a search across attendance history, deletion with a legal-hold exception — we provide it within 5 working days so you can meet the statutory one-month deadline. Since 5 February 2026 you may pause that clock while waiting for identity confirmation or clarification from the requester, and you need only carry out a reasonable and proportionate search.
Complaints
Since 19 June 2026 every controller must have a way for people to complain about how their data is handled, acknowledge within 30 days and respond without undue delay. Thwok operates such a route for its own controller activities at privacy@thwok.app and, on request, provides academies with a simple complaints log template. Anyone unhappy with the outcome may complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113).
If something goes wrong: breach procedure
- Detect and contain. Access revoked, credentials rotated, affected systems isolated. Target: within 4 hours of detection.
- Assess. What data, whose, how many, likely consequences. Children's or medical data automatically counts as "likely to result in a risk", so assume notification is needed.
- Tell you. Written notification to your nominated contact within 24 hours of confirming a breach affecting your data, with what we know, what we've done and what we recommend — followed by updates as the picture develops. This is well inside the "without undue delay" the law requires of a processor.
- Support your ICO decision. As controller you decide whether to notify the ICO (72 hours from becoming aware) and affected parents. We give you the facts and draft wording; we do not notify parents about academy data without your instruction.
- Learn. Written post-incident review shared with you within 14 days.
Legitimate interests assessment — emergency contacts
Emergency contacts are third parties who have not signed anything. Holding their name and phone number is justified by the legitimate interest in a child's safety during a session: the purpose is real and specific; the data is the minimum needed (name, number, relationship); the contact would reasonably expect it, having been nominated by the parent for exactly this; the impact is minimal, as the number is used only in an emergency, never for messaging or marketing, and is deleted with the pupil record. The balance favours processing. The guardian is asked to confirm the person is aware they have been nominated.
Data Protection Impact Assessment — summary
A full DPIA is held by Thwok and available to academies on request. Its conclusions for the academy product are:
| Risk | Assessment | Controls |
|---|---|---|
| Children's data exposed to other users | High impact, low likelihood | Children are records, not accounts; never in search, share cards, leaderboards or public pages; per-role security rules tested on every release |
| Medical data accessed beyond need | High impact, low likelihood | Separate collection, field-level rules, access logging, 90-day post-enrolment deletion |
| Migration reaches the wrong person | Medium impact, medium likelihood (stale numbers) | Phone OTP before any record is shown; "not me" route; 60-day auto-delete of unclaimed records |
| Invitations treated as unsolicited marketing | Medium impact, low likelihood | Sent in the academy's name about an existing relationship; capped at one invite and two reminders; immediate suppression |
| AI-assisted features process pupil data | Medium impact, low likelihood | Model receives enquiry text only, never the register; human approves every output; zero-retention contract; no training on inputs |
| Automated decisions affecting a child (e.g. arrears suspension) | Medium impact | Never enforced at the door; disclosed ladder; human review on request; suspension of a child's place requires an academy admin's confirmation |
| Photos and video of children | High impact | Per-use guardian consent; guardian-only visibility by default; never indexed; withdrawable at any time with removal |
| Loss of availability (Thwok ceases trading) | Medium impact | Academy can export everything at any time; deletion on termination; no lock-in of register data |
10. Academy Data Processing Agreement
This Agreement forms part of, and is incorporated into, the Thwok Academy Agreement between the parties. It sets out the terms required by Article 28(3) UK GDPR. Defined terms have the meanings given in UK GDPR. To be reviewed by the parties' legal advisers before signature.
Parties. (1) [Flying Shuttles Badminton Academy — legal name, entity type and address] (the "Academy", the Controller) and (2) SIMPLIFY HCS LIMITED, company number 13667511, of 4 Henley Gardens, Pinner, HA5 2DE, trading as Thwok ("Thwok", the Processor).
11. Template: notice to parents before migration
Send this to every current family at least 7 days before the import, by whatever channel you normally use. Edit the amber parts; keep the substance. The final paragraph is the line to add to your own privacy notice.
Subject: Flying Shuttles is moving to Thwok — what it means for you
Dear parents and carers,
From [date] we're running Flying Shuttles on Thwok, a badminton academy platform, instead of spreadsheets and WhatsApp. You'll be able to see your child's sessions, pay for the term, update medical and emergency details, and hear about cancellations — all in one place.
What happens to your details. We'll transfer the information we already hold for your child and you — name, date of birth, your contact details, emergency contact, any medical notes you gave us, and your photo permission — to Thwok so that your child's place is ready. Thwok stores it in the UK, uses it only to run our academy, and is bound by a contract with us. Nothing about your child will ever be visible to other families or searchable online.
What you need to do. Around [date] you'll receive a message from Flying Shuttles via Thwok inviting you to confirm your child's place. It takes about a minute: verify your phone number, check the details, confirm the medical and photo permissions, and accept Thwok's terms. If you don't claim the place within 60 days, Thwok deletes the record and we'll get in touch the old way.
If you'd rather we didn't. Tell us before [date] and we'll leave your details out of the transfer and carry on with you offline. If you get a message you weren't expecting, tap "this isn't me" and it stops.
Thwok's privacy notice is at thwok.app/privacy and their data protection pack for academies — the full detail of how they look after children's data — is at thwok.app/legal/academies. Any questions, ask [name] at [academy contact].
Thanks,
[Name], Flying Shuttles Badminton Academy
Line for your own privacy notice
"We use Thwok (SIMPLIFY HCS LIMITED) to manage enrolments, registers, communications and payments. Thwok processes pupil and parent data on our behalf under a written agreement, stores it in the UK, and does not use it for any other purpose. Details: thwok.app/legal/academies."
12. Template: guardian consent & medical information
This is the screen a guardian completes when claiming a record (and the paper equivalent for anyone who prefers it). Each consent is separate, unticked, specific and withdrawable — which is what makes it valid. Thwok records the version, timestamp and method for each.
About your child — name, date of birth, group. Please check these are right.
Emergency contact — name, relationship, phone. ☐ I confirm this person knows they've been nominated.
Medical information (optional but important). Is there anything a coach should know to keep your child safe on court — for example asthma, allergies, epilepsy, a condition affecting exercise, or medication they carry?
[free text, 300 characters]
☐ I give my explicit consent for Flying Shuttles and Thwok to record this information and share it with the coaches running my child's sessions, so they can respond in an emergency. I understand I can change or remove it at any time and it will be deleted 90 days after my child's last enrolment ends.
Photos and video.
☐ Coaches may take photos or short clips of my child during sessions for my eyes only (progress and skills feedback, visible only in my account).
☐ My child may appear in academy group photos shared with other Flying Shuttles families.
☐ My child may appear in Flying Shuttles' public promotion (website, social media), never named.
Each of these is separate. Leaving all three unticked is completely fine. You can change your mind at any time and we'll take the content down.
Messages. We'll always contact you about your child's sessions, payments and safety — that's part of running the academy.
☐ Thwok may also message me about other badminton activities near me (optional; you can stop this any time).
☐ I am the parent or legal guardian of this child. I have read Thwok's Guardian Terms and Privacy Notice.
13. Parent FAQ
Do I have to use Thwok? The academy has chosen it as the way it runs bookings and communications, so it's how you'll see sessions and pay. If you have a real difficulty with it, speak to the academy — they can keep you on a manual arrangement.
Can other parents see my child? No. Only you, the academy's admin and the coaches running your child's sessions can see your child's record. Children never appear in search, on public pages or in any leaderboard.
Where is the data stored? In the UK, on Google Cloud's London region, encrypted.
Will Thwok send me marketing? Not unless you tick a separate box asking for it. Messages about your child's sessions and payments aren't marketing — they're the service.
Who can see the medical notes? You, the academy's admin and the coaches on your child's sessions. Every time someone opens them it's logged.
What if I want everything deleted? You can delete your child's record and your account from the app. Payment records that the law says must be kept are retained for six years in a form that isn't linked to your account.
Does Thwok use AI? Thwok uses an AI model to help draft replies to enquiries and to summarise text for staff, and a person checks every output. Your child's record and medical notes are never sent to it, and nothing you write is used to train it.
Who do I complain to? The academy first (they are responsible for your child's data), or Thwok at privacy@thwok.app. If you're not satisfied, the Information Commissioner's Office at ico.org.uk.
14. Checklists and sign-off
Academy — before upload
- Data Processing Agreement (Section 10) signed by both parties
- Nominated data protection contact and welfare officer given to Thwok
- Section 11 notice sent to all families; date and copy kept
- Own privacy notice updated with the Thwok line
- Families who opted out removed from the export
- Export completed in the template; medical notes trimmed to what a coach needs; no extra columns
- Upload made through the secure link only; local copies deleted or moved to your normal secure storage
Thwok — before and after import
- Signed DPA on file; academy contacts recorded
- Entity details, ICO number and sub-processor placeholders completed in this pack
- Import template validation and column rejection tested
- Raw-file 24-hour deletion and 60-day unclaimed purge verified in staging
- Invitation wording, "not me" route and reminder cap reviewed
- Guardian consent screen matches Section 12 exactly; versions recorded
- Import report delivered to the academy; Article 30 record updated
Acknowledgement
By signing below the Academy confirms it has received and reviewed this Data Protection Pack, version 1.0, and that its contents form the basis on which it instructs Thwok to migrate and process its pupil and guardian data.