PathWaySign in

Privacy Policy

Last updated: 28 May 2026 · Pathway Edu Ltd (Company No. 17246607)

Pathway Edu Ltd (“we”, “us”, “our”) is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights under UK GDPR and the Data Protection Act 2018.

1. Who We Are

Pathway Edu Ltd is the data controller for personal data processed through the PathWay platform. Our Data Protection contact is privacy@pathwayedu.co.uk.

2. Data We Collect

2.1 Information you provide

  • Profile data: first name, age, year group, school name, predicted/achieved grades
  • Interests: subject preferences and career areas of interest
  • Account data: email address and password (hashed — we never store passwords in plain text)
  • School code: if you link your account to a school institution
  • Pilot request data: name, email, school, role, and message (for school pilot enquiries)

2.2 Data we collect automatically

  • Usage data: pages visited, features used, session duration
  • Device data: browser type, operating system, screen resolution
  • IP address: used for security and to determine approximate region

2.3 Data we do NOT collect

We do not collect ethnicity, special educational needs status, free school meals eligibility, or other sensitive protected characteristics unless you voluntarily provide them as part of a future feature with explicit consent.

3. How We Use Your Data

3.1 To provide the Service

  • Generate personalised career pathway recommendations
  • Save and retrieve your pathway results across sessions
  • Allow school advisors to view and support students linked to their institution

3.2 To improve PathWay

  • Analyse aggregate (anonymised) usage to improve pathway accuracy
  • Identify which career areas and pathways are most popular by region and year group

3.3 To communicate with you

  • Send transactional emails (account confirmation, password reset)
  • Respond to pilot enquiries and support requests
  • Send service updates where you have opted in to receive them

4. Legal Basis for Processing

We process your personal data on the following legal bases:

  • Contract: to deliver the Service you have signed up for
  • Legitimate interests: to improve PathWay, prevent fraud, and ensure security
  • Consent: for marketing communications and, where required, for processing data relating to users under 13
  • Legal obligation: where required by law

5. Children's Data

PathWay is designed for use by young people aged 11 and above. We take the protection of children's data seriously.

  • Users under 13 require verifiable parental or guardian consent before creating an account
  • We do not use data from users under 13 for any marketing purposes
  • We do not sell or share children's data with third parties for commercial purposes
  • Schools deploying PathWay to students under 13 must obtain appropriate consents under their own safeguarding policies

6. Sharing Your Data

6.1 With your school (if linked)

If you enter a school code during onboarding, your name, year group, grades, subjects, career areas, and pathway activity will be visible to authorised school advisors and administrators at that institution. This enables them to provide personal guidance and meet Gatsby Careers Benchmark requirements.

6.2 Service providers

We use the following third-party processors:

  • Supabase (database and authentication) — data held in EU data centres
  • Vercel (hosting and edge delivery) — data processed in EU/UK regions
  • Groq (AI narrative generation) — only anonymised pathway context is sent, no personal identifiers

6.3 Public data sources

Pathway recommendations are generated using publicly available datasets: ONS Annual Survey of Hours and Earnings, HESA Graduate Outcomes, DfE LEO, and Adzuna job postings. No personal data is sent to these sources.

6.4 We do not sell your data

PathWay does not sell, rent, or otherwise trade personal data with third parties for their own marketing purposes.

7. Data Retention

  • Guest profiles (no account): retained for 90 days, then permanently deleted
  • Student accounts: retained for the duration of the account plus 12 months after deletion request
  • School admin data: retained for the duration of the school licence plus 24 months
  • Pilot request data: retained for 24 months

8. Security

We implement appropriate technical and organisational measures to protect your data, including:

  • All data transmitted over HTTPS/TLS encryption
  • Passwords hashed using bcrypt (we never store plain-text passwords)
  • Database access restricted by Row Level Security policies
  • Regular security reviews and dependency updates

No system is completely secure. If you suspect a security issue, please report it to security@pathwayedu.co.uk.

9. Your Rights

Under UK GDPR you have the right to:

  • Access: request a copy of the personal data we hold about you
  • Rectification: ask us to correct inaccurate data
  • Erasure: ask us to delete your data (“right to be forgotten”)
  • Restriction: ask us to restrict processing in certain circumstances
  • Portability: receive your data in a machine-readable format
  • Object: object to processing based on legitimate interests
  • Withdraw consent: where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, email privacy@pathwayedu.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

10. Cookies

PathWay uses essential cookies for session management and authentication. We do not currently use tracking or advertising cookies. If this changes, we will update this policy and seek your consent before setting any non-essential cookies.

11. International Transfers

We process data primarily within the UK and EEA. Where data is transferred outside these regions (e.g., certain Vercel edge nodes), we ensure appropriate safeguards are in place including Standard Contractual Clauses or adequacy decisions.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified by email (for registered users) or by a prominent notice on the platform. Continued use of PathWay after changes constitutes acceptance of the updated policy.

Data Protection Contact

For any privacy questions or to exercise your rights:

privacy@pathwayedu.co.uk

Pathway Edu Ltd
c/o hello@pathwayedu.co.uk
London, England, United Kingdom