Skip to main content

Privacy Policy — Politics Online

Last updated: 12 August 2026

This Privacy Policy explains how Politics Online Limited (“we”, “us”, “our”) collects, uses, discloses and protects your personal data on Politics Online (“the Platform”) — our website, shop, revision resources, and interactive lessons with quizzes and progress tracking. You reach the Platform at politicsonline.co.uk. The interactive lessons are hosted for us by Vercel at learn.politicsonline.co.uk and open inside a page on politicsonline.co.uk, so you stay on one site while you use them. It is all one platform, run by one company — and this one policy covers all of it.

The lessons are currently a beta (test) release. Everyone signing in reads and accepts a short beta notice on first login, and we keep a record of that acceptance (see sections 4 and 12). What beta means for the service itself, including the possibility that learning data is reset, is set out in section 10 of our Terms & Conditions.

We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and the ICO’s Age Appropriate Design Code (Children’s Code).

1. Who we are

Politics Online Limited is a company registered in England and Wales (company number 15985148).

Registered office: 3rd Floor, 86–90 Paul Street, London, England, EC2A 4NE.

ICO registration number: ZB870204.

Contact for all data protection matters: admin@politicsonline.co.uk.

We are not required to appoint a Data Protection Officer under Article 37 UK GDPR, as we are not a public authority and our core activities do not involve large-scale monitoring of individuals.

2. Controller and processor — who is responsible for your data

Who is legally responsible for your data depends on how you use the Platform, not on which page you are on:

Activity Our role Who decides why data is processed
Visiting the Platform, creating an individual account, buying a subscription, receiving our newsletter Data controller Politics Online Limited
Learning data (lessons, quizzes, progress) on accounts provided under a school or college licence Data processor Your school or college (the data controller), under a written Data Processing Agreement with us (Article 28 UK GDPR)
Learning data on accounts with an Individual Subscription Data controller Politics Online Limited

Where we act as processor, we process personal data only on the documented instructions of the school. The school is responsible for its own lawful basis (typically Article 6(1)(b) — contract, or Article 6(1)(f) — legitimate interests), for authorising student access, and for making students and parents aware of this policy.

3. Who this policy applies to

  • Visitors to the Platform.
  • Individual subscribers aged 16 and over — including students whose subscription includes the Platform’s lessons.
  • Students aged 16–18 using the Platform through a school or college licence.
  • Teachers and staff at schools/colleges administering licences and classes.

Important: users under 16 must not register directly. Access for under-16s may only be arranged by a parent, guardian, or an educational institution that has secured appropriate parental consent; responsibility for valid consent rests with them. If we become aware of an unauthorised under-16 account, we will delete it promptly.

4. What data we collect

Account, shop and browsing data

  • Identity & account data — full name, email address, school or institution (if applicable).
  • Payment data — processed by Stripe and PayPal; we never store or process full card details.
  • Technical & usage data — IP address and approximate (country/city) location, browser and device type, login activity, pages viewed.
  • Cookie data — see section 7.
  • Feedback and enquiries — anything you send via our forms or email.
  • Records of agreement: which version of our beta notice and terms you accepted, and the date and time you accepted it.
  • Subscription status: for an Individual Subscription, the date your access began and whether it is currently active.

Learning data (lessons, quizzes and progress)

In the lessons, we collect only what we need to make them work:

  • Your first name and last initial (so your teacher can identify you — we deliberately do not store students’ full surnames)
  • Your school and year group (school-provisioned accounts)
  • The sign-in email/username provided by your school, or the email you registered with if you purchased an Individual Subscription
  • A password, where your account signs in directly on the lesson pages — stored only as a secure one-way hash, never in readable form
  • Your learning progress (topics completed, scores, attempts)
  • Confidence ratings you choose to give on topics
  • Session data (when you logged in and for how long)
  • Quiz responses (which questions you answered and whether you got them right)
  • Tasks your teacher sets you and your progress against them, including any task link you open (school-provisioned accounts)
  • Which class you are in, and whether your teacher has opened a lesson for use in a live class
  • Sign-in security data: a short-lived count of failed sign-in attempts on your account and, if the limit is reached, the time until which sign-in is paused

Beyond your sign-in email, the lessons do not collect your date of birth, home address, phone number, photos, or location.

We do not collect or request special category data (e.g. political opinions or health data) anywhere on the Platform. Please do not submit such information.

5. Why we collect it, and our lawful bases

We use students’ learning data to:

  • Track your learning progress and help you improve
  • Let your teacher see how the class is doing (school-provisioned accounts)
  • Schedule spaced-repetition reviews at the right time
  • Adapt question difficulty to your level
  • Remind you to take breaks (we care about your wellbeing)
Purpose Lawful basis
Account creation and subscription management Contract (Art 6(1)(b))
Delivering educational services and content Contract (Art 6(1)(b))
Student learning data (school licences) Determined by the school as controller — typically contract or legitimate interests; we act as processor
Student learning data (Individual Subscriptions) Contract (Art 6(1)(b)) — we act as controller
Processing payments via Stripe/PayPal Contract (Art 6(1)(b))
Essential service communications Contract (Art 6(1)(b))
Security, fraud prevention and misuse monitoring (including rate limiting, counting failed sign-in attempts and temporarily pausing sign-in on an account under attack) Legitimate interests (Art 6(1)(f))
Keeping a record of the beta notice and terms you accepted, and when Legitimate interests (Art 6(1)(f)): evidence of what was agreed, and of students having been told the Platform is in beta. For school-provisioned accounts the school instructs us to show the notice and record acceptance, and we do so as processor under the Data Processing Agreement
Compliance with tax and legal obligations Legal obligation (Art 6(1)(c))
Marketing communications (newsletter) Consent (Art 6(1)(a))

We do not sell or rent personal data to anyone.

6. How we personalise learning (profiling explained in plain English)

The Platform’s lessons use algorithms to adapt each student’s experience:

  • Spaced repetition: after you complete a topic, we schedule reviews at increasing intervals (1, 3, 7, 18 and 35 days) based on how well you scored, to help you remember long-term.
  • Mastery tracking: we calculate a mastery score per topic from your quiz scores and attempts; topics are “mastered” at the threshold (usually 80%).
  • Difficulty tagging: questions are tagged by difficulty level to support personalisation of question selection as this feature develops.
  • Peer comparison: if your class has enough students, we show anonymised class statistics. This feature is off by default; only class-level averages and anonymised distributions are shown, and only when a class has at least 5 students, in line with ICO statistical-disclosure guidance. No individual student’s data is ever visible to another student.

These algorithms exist solely to support learning. They are never used for decisions outside the Platform, never for advertising or commercial profiling, and teachers cannot use them to set grades.

7. Cookies

This information is also published as a standalone Cookie Policy. Different parts of the Platform use different cookies:

Where the consent banner applies

The lessons open inside a page on politicsonline.co.uk. That surrounding page is part of our main website, so the Usercentrics consent banner belongs to it and you may see the banner before you open the lessons. On the page that holds the lessons, and inside the lessons themselves, we switch off advertising, analytics, marketing and push-notification tags: no advertising or analytics runs alongside a lesson, and the only cookies set there are the strictly necessary ones listed below.

Browsing, shop and articles

Cookie type Purpose Consent required
Essential Login, authentication, shopping cart (WooCommerce), fraud prevention, and storing your cookie-consent choices (Usercentrics) No
Analytics — Google Analytics Usage analysis and optimisation. Runs in Google Consent Mode: all analytics storage is off by default and is only enabled if you accept via the consent banner Yes
Advertising — Google AdSense Serves advertising on public website pages. Never inside the lessons, and never on the page that holds them. Runs in Google Consent Mode: ad storage and personalisation are off by default and only enabled if you accept via the consent banner Yes
Marketing — Brevo Links your visits to our newsletter so we can understand what subscribers find useful Yes
Push notifications — WonderPush Web push notifications, only if you opt in to receive them Yes
Analytics — Koko (self-hosted) Counts page views on our own server — nothing is shared with any third party. One first-party cookie (page IDs viewed that day, no personal data) prevents double-counting; expires at midnight No — anonymous and first-party
Shop attribution (WooCommerce) First-party cookies recording how you arrived at the site, attached to an order if you place one First-party; blockable in your browser

Cookie consent is managed by the Usercentrics consent banner shown on your first visit. Non-essential cookies are only set with your consent, which you can change or withdraw at any time via the banner’s privacy settings or your browser.

Inside the lessons

The lesson pages use only strictly necessary cookies: no analytics, advertising, or tracking cookies. Strictly necessary cookies do not require consent under PECR, so the lesson pages themselves show no cookie banner (the surrounding website page has its own banner, as explained above):

Cookie What it does Lifetime
pol-session Your digitally signed login session (it cannot be forged or altered). HttpOnly (cannot be read by JavaScript), Secure (HTTPS only), SameSite=Strict. 24 hours
pol-prefs A copy of your display and accessibility preferences (theme, font size, dyslexia-friendly font, reduced motion) so pages load with your settings straight away. HttpOnly, Secure. 30 days
pol-password-change Set only while you set a new password — on first login or after a password reset — to authorise that single step. Up to 15 minutes (single use)
pol-session-original Set only during a supervised support-access session (see section 11), preserving the support administrator’s own identity so the access is fully logged. Duration of the supervised session (max 15 minutes)

The lesson pages also use your browser’s local storage (a “similar technology” under PECR) for strictly necessary purposes only: remembering your position in a lesson, your audio-playback speed, your display preferences, a short-lived offline buffer of quiz progress so nothing is lost if your connection drops, and small flags such as whether you have seen the welcome tour or dismissed a notification. None of this is tracking; it stays on your device and is removed when you clear your browser’s site data.

8. How login works across the Platform

You sign in once at politicsonline.co.uk. When you open your lessons, the Platform passes a secure, single-use token to the lesson pages containing only: your user ID (a number), your role, your school ID (if any), your class code (students), the date your access began (direct subscribers only), and your first name and last initial — never your email, surname, or password. The token can be used once, expires within about ten minutes, and is verified cryptographically before it becomes your session cookie. That session expires after 24 hours (4 hours for direct subscribers). Learning records stay on the lesson platform and are never sent back to the main site. A small number of administrator and setup accounts sign in directly with a password (stored only as a secure one-way hash); this route is being phased out for students.

9. Our service providers (sub-processors)

We use the following providers to run the Platform. Each acts under our instruction and a data processing agreement:

Provider What it does Where data is processed
Krystal Hosting Hosting for the Platform’s website and shop (WordPress), which holds the single sign-in account used across the Platform, including for the lessons, and serves the page the lessons open inside United Kingdom
WordPress / WooCommerce Website and shop software United Kingdom (self-hosted on Krystal)
Stripe Card payments (PCI-DSS compliant) UK/EU; international transfers covered by Stripe’s safeguards (SCCs/IDTA)
PayPal Payments (PCI-DSS compliant) UK/EU; international transfers covered by PayPal’s safeguards
Supabase Inc Database for the Platform’s lessons (learning records, learner accounts) AWS eu-west-2 (London, UK)
Amazon Web Services (AWS) Underlying infrastructure for Supabase eu-west-2 (London, UK)
Vercel Inc Web hosting and edge compute for the lesson pages. Processes HTTP requests (including session cookies) at edge locations; no persistent storage of personal data EU/UK edge; DPA with Standard Contractual Clauses for any non-UK processing
Upstash Inc Rate limiting for the lessons’ API (abuse prevention). Processes hashed identifiers and IP-derived keys for the duration of the rate-limit window only; nothing stored beyond it AWS eu-west-2 (London, UK)
Vimeo Inc Streams the lesson videos. When you play a video, your IP address is sent to Vimeo. We embed all videos with Do-Not-Track enabled (dnt=1), which disables Vimeo’s tracking and analytics cookies USA; transfers covered by Vimeo’s SCCs/IDTA safeguards
Brevo (formerly Sendinblue) Sending our newsletter to subscribers who opted in, and — with your consent via the banner — linking your website visits to your newsletter subscription so we can understand what subscribers find useful European Union (Brevo is EU-based; UK adequacy applies)
Google (Google Analytics) Consent-gated usage analytics on the Platform’s browsing and shop pages only — runs in Consent Mode, disabled until you accept the banner. Not used inside the lessons, and switched off on the page that holds them Google Ireland / USA; transfers covered by Google’s SCCs and the UK-US Data Bridge
Google (AdSense) Serves advertising on public website pages only — never inside the lessons, and switched off on the page that holds them, so no advertising runs alongside a lesson. Runs in Consent Mode: ad storage and personalisation are disabled until you accept the banner Google Ireland / USA; transfers covered by Google’s SCCs and the UK-US Data Bridge
WonderPush Web push notifications on the website, only for visitors who expressly opt in to receive them European Union
Usercentrics The cookie-consent banner; stores your consent choices European Union

No student personal data is shared with any other third party, used for advertising, or used to train AI models. The lessons use no analytics, advertising networks, or social-media tracking of any kind, and show no advertising; nor does the page that holds them, where those tags are switched off. Elsewhere on the Platform, analytics (Google Analytics), advertising (Google AdSense on public pages), marketing (Brevo) and push notifications (WonderPush) operate only with your consent via the banner; our own self-hosted page-view counter (Koko Analytics) runs on our server and shares nothing with anyone. There are no social-media pixels anywhere. We do not sell or share your data.

10. Who can see a student’s data

  • You can see all your own data.
  • Your teacher can see your progress — but only if you are in their class.
  • Other students cannot see your individual data.
  • No one outside your school can see your data.
  • Individual Subscription accounts are not linked to any school — your data is visible only to you.
  • Platform support staff — see section 11.

11. Supervised support access

Platform support staff may access an account in a supervised session for technical support. All such access is logged, visible in the audit trail, and automatically time-limited to 15 minutes.

12. How long we keep your data

Data Retention
Individual subscriber accounts (including any learning data) Deleted after 2 years of inactivity, or within 30 days of your deletion request — whichever comes sooner
School/centre licence data Duration of licence; on expiry, student data is exported to the school within 30 days and then permanently deleted. Teachers are notified before deletion.
Student learner accounts (inactive) Name removed and account deactivated after 2 years of inactivity; all remaining data, including identifiers, permanently deleted within 30 days thereafter
Deletion requests Personal data removed within 30 days of a verified request; anonymised learning statistics may be retained for platform improvement
Lesson session logs 90 days, then automatically deleted
Audit logs 2 years, then automatically deleted
Payment records 6 years (UK tax and financial law)
Aggregate analytics (non-identifiable) Up to 24 months
Record of the beta notice and terms you accepted Kept while the account exists and for 12 months after it closes, as evidence of what was agreed
Sign-in security data (failed-attempt counts, temporary locks) A count applies to a rolling 15-minute window and any lock expires after 15 minutes. The stored value is reset on your next successful sign-in, or overwritten on the next attempt after the window has passed, and is deleted with the account

Data may be retained longer only where the law requires it (e.g. dispute resolution or fraud prevention).

During the beta: learning data may also be reset or deleted before the periods above expire, as explained in section 10 of our Terms & Conditions. Where we act as processor for a school, we will notify the school before any planned reset of its students’ data and, on request, export that data first. Please keep your own copy of anything important to you.

13. Data security

  • All data encrypted in transit (HTTPS/TLS) and at rest.
  • Row-level security on the learning database — each user can only access their own data; teachers only their own classes.
  • IP addresses used for security logging are hashed before storage and cannot be reversed.
  • Access controls and audit logging of significant actions (logins, exports, administrative access).
  • UK-based encrypted servers and encrypted backups.
  • PCI-DSS compliant payment gateways (Stripe, PayPal) — we never see full card numbers.

14. Children’s data, the Children’s Code, and safeguarding

The Platform’s lessons are designed for students aged 16–18 in England and Wales. Access is provided through your school, which verifies your age at enrolment, or through an Individual Subscription (available only to users aged 16 or over, with parental consent required for under-18 purchases); we do not knowingly collect data from anyone under 16. The Platform complies with the ICO’s Age Appropriate Design Code. In every decision about data, we treat the best interests of student users as a primary consideration:

  • We collect only what is needed to deliver the educational service (data minimisation by design — e.g. last initial instead of surname).
  • Privacy-protective settings are the default — e.g. peer comparison is off by default.
  • We never use student data for advertising or commercial profiling.
  • Personalisation algorithms are explained in plain English (section 6) and used solely to support learning.
  • Wellbeing by design: after 45 minutes in the lessons, students are reminded to take a break.

Safeguarding (KCSIE): the Platform supports the principles of Keeping Children Safe in Education. Teacher-to-student messaging (“nudges”) is limited to educational prompts — homework reminders, encouragement, review prompts. Students cannot message each other, and all nudge messages are auditable by the school. If you have a safeguarding concern about a student’s use of the Platform, contact your school’s Designated Safeguarding Lead (DSL) directly — do not use the Platform’s messaging for safeguarding communications. To report a safeguarding concern about the Platform itself, email admin@politicsonline.co.uk.

15. Parents and guardians

If a student is under 18, their parent or guardian has the same data rights as the student — to see, correct, delete, or object to the processing of the student’s data. Parents should contact the school in the first instance (school-provisioned accounts), or email us directly at admin@politicsonline.co.uk; we will verify the relationship (with the school where applicable) before acting on any request.

16. International data transfers

Personal data is stored primarily in the UK. Where a provider processes data outside the UK/EEA (see section 9), we ensure a UK adequacy decision applies, or Standard Contractual Clauses / the UK International Data Transfer Addendum are in place, or the transfer is otherwise permitted by UK GDPR. Users outside the UK/EEA acknowledge that their data is processed under UK law.

17. Your rights under UK GDPR

  • Access the personal data we hold about you (Subject Access Request).
  • Correct inaccurate or incomplete data.
  • Erasure, where no lawful basis for retention applies.
  • Restrict or object to processing (including any based on legitimate interests — Article 21).
  • Data portability — students can download their own data directly from the Platform.
  • Withdraw consent where processing is based on consent.

To exercise any right, email admin@politicsonline.co.uk — students can also simply ask their teacher, and teachers can delete a student’s account directly from their dashboard. Requests are free and answered within one calendar month. For learning data on school-provisioned accounts, your school is the data controller, so we may pass the request to the school and help them fulfil it; for Individual Subscription accounts we are the controller and handle the request directly.

You also have the right to complain to the Information Commissioner’s Office at ico.org.uk.

18. Data breach notification

If we discover a personal data breach we will notify the ICO within 72 hours where required by UK GDPR, and — where the breach is likely to result in a high risk to your rights and freedoms — notify you (and, for school-provisioned accounts, your school) directly and without undue delay. We maintain an internal breach register and documented breach procedures.

19. Data Protection Impact Assessment

We have carried out a DPIA covering the Platform’s processing of children’s data, its personalisation algorithms, and the peer-comparison feature. It is reviewed annually and on any significant change. A summary is available on request.

20. Use of AI tools in content development

We use AI-assisted tools to help create and refine educational resources. Rather than ask you to take that on trust, this section sets out plainly what those tools do and what they never touch.

No personal data, and no student data of any kind, is input into or used to train AI systems. Nothing a student types, answers, submits or scores is sent to an AI tool, for any purpose, at any time. AI tools are used solely for content development, never for profiling users.

20.1 Where we use AI

Written material. Our written content is human-led and AI-assisted. A subject specialist sets what each topic has to cover, chooses the material it is built from, and edits and approves the final text. AI tools help with drafting and rewriting along the way, always working from our own writing, the published specifications and sources we have selected.

The balance between the two varies from piece to piece. Some passages are written by hand and then tightened with AI help; others are drafted by a tool from our material and then reworked by a specialist. That holds across the textbook, slide lessons, case studies, exam-style questions and mark schemes. What stays constant is that a person decides what goes in, and a person signs it off.

Narration in lecture videos. The voice you hear in our lecture videos is synthetic speech, not a human reader. It is generated from a script we have written and checked. We mention this specifically because a synthetic voice can be mistaken for a person, and we would rather you simply knew.

Diagrams, infographics and illustrations. Photographs and archive footage on the Platform are real, licensed material, credited to their source. Some diagrams, charts and illustrations are produced with AI image tools. We do not use AI to create realistic-looking images of real people, real events or documents. Where you see a photograph or a piece of footage, it is genuine.

The software itself. The Platform is built and maintained with the help of AI coding tools. This is now ordinary practice in software development, and we mention it for completeness.

The tools in regular use at the date of this policy are:

Tool What we use it for
Claude (Anthropic) Drafting and editing written content; building and maintaining the software
Google Gemini (including NotebookLM) Diagrams, infographics and illustrations
Microsoft neural text-to-speech Narration in lecture videos

We may change tools, but not the boundaries set out below.

20.2 Where we do not use AI

These are commitments, not aspirations. If any of them changes, we will update this policy and tell subscribers and schools before the change takes effect.

  • No student data goes into AI systems. No personal data of any kind is used as input to, or for the training of, an AI model.
  • No AI marking or feedback. Quizzes and question banks are marked against answer keys we have written, by ordinary fixed rules. No AI reads a student’s work or writes comments on it.
  • No AI profiling or decision-making about people. The personalisation described in section 6, along with progress tracking, lesson unlocking and peer comparison, runs on deterministic rules we have specified, not on a model making predictions about a student. No automated decision produces a legal or similarly significant effect on anyone.
  • No AI chatbot or AI tutor. There is nothing on the Platform that generates answers to students live. If we ever build one, it will be announced, it will be optional, and this policy will be updated first.
  • No unreviewed publishing. No AI-assisted content reaches students without a human subject specialist having read and approved it.

20.3 Human review and accountability

Every piece of content we publish is read and approved by a person with subject expertise in A Level Politics before it goes live. That review covers factual accuracy, specification coverage, balance, and whether the material actually teaches the point. Responsibility for what we publish sits with us, not with a tool. Where an error reaches you, it is our error.

20.4 Accuracy, sources and quotations

AI tools can state things confidently and wrongly. We work on that assumption. Content is built from material we have written or selected and from the published specifications, rather than from a model’s recollection of the subject. We do not publish invented quotations, statistics, court judgments, Acts, division figures or sources: where we cite something, it exists and we have checked it. Named people, parties and events are checked against the record. Politics is contested and much of it is recent, so we aim for balance and for accuracy at the date of publication, and we correct things when we are told about them. If you find a factual error, please email admin@politicsonline.co.uk. We would much rather fix it than not know.

20.5 Academic integrity

Our material is a teaching resource, in the same way a textbook is. Nothing on the Platform is intended to be submitted as a student’s own work, and our exam-style answers and model paragraphs are there to be studied and taken apart, not copied. Exam boards set their own rules on the use of AI in coursework and assessed work, and those rules apply to students regardless of what they read here. Students and teachers should follow their centre’s and their board’s guidance.

20.6 Schools

For school-licensed use, these commitments are contractual as well as editorial. The Data Processing Agreement records that no personal data supplied by a school is used as input to, or for the training of, any AI system.

21. Business transfers and legal disclosure

We may disclose data to comply with legal obligations or valid court orders, or transfer it as part of a merger, acquisition or restructuring — in which case this policy would continue to apply to that data.

22. External links

The Platform may link to third-party sites. We are not responsible for their privacy practices — please review their policies.

23. Communications and marketing

Service communications (account confirmations, billing, policy updates) are necessary and not subject to opt-out. Marketing communications (e.g. our newsletter) are sent only with your prior consent, which you can withdraw at any time via the unsubscribe link or by contacting us. We never send marketing to student accounts.

24. Changes to this policy

We may update this policy periodically. Significant changes will be notified by email and on the Platform, and — for school-licensed processing — to subscribing schools.

25. Contact us

Politics Online Limited
3rd Floor, 86–90 Paul Street
London, EC2A 4NE, United Kingdom
Email: admin@politicsonline.co.uk
Company number: 15985148  |  ICO registration: ZB870204

Feedback
First
Last