School documents · Pack 2026-08-29

Privacy notice

What personal data the platform processes and why, including roster, SEND, and optional AI features.

Who it is for
Staff, DPOs, and (via the school’s own notice) parents
How to access it
Public. Schools should still issue their own parent/pupil privacy notice naming Five Wells as a processor.

This pack describes how Five Wells Education designs and operates the platform so schools can complete their own due diligence. It is not legal advice. The school remains the data controller for pupil and staff data it places in the product. A solicitor or DPO should review processing before go-live.

Who we are

Five Wells Education provides a school recognition, analytics, and optional SEND Progress Tracker platform. For pupil and staff data in a school tenant, the school is typically the controller and Five Wells is the processor.

What we process

Categories depend on which modules the school enables:

  • Identity and account: names, emails, roles, school, class labels, login events.
  • Recognition: credits, notes staff choose to record, certificates, optional wellbeing pulse, peer nominations, Journey activity, and making-proof photos or “show the teacher” records when the pupil submits them.
  • Optional demographics the school supplies: pupil premium, FSM, EAL, SEND/EHCP flags — used for school-scoped equity analytics, not for public marketing.
  • Optional SEND Tracker: IEP/ISP targets, progress notes, provision sessions, pupil-voice check-ins, staff voice-note transcripts if used, and EHCP excerpts while staff are drafting (see the SEND Tracker data note).
  • Optional photos (Photo Memories and Journey making-proof) stored in school-scoped storage.
  • Optional AI: staff lesson/SEND drafts, and — if the school turns it on — the labelled pupil Well helper (see AI processing and the pupil Well helper note).

Roster and demographic data

Schools choose how roster data enters Five Wells.

  • CSV upload: only columns in the file. Typical fields are role, email, name, class, and optional PP/SEND/EAL/FSM flags. CSV does not accept date of birth, ethnicity, UPN, safeguarding, medical records, or photos.
  • Wonde MIS sync (if enabled): pupil and teacher names, class membership, staff work emails, and impact flags (PP, FSM, EAL, SEND/EHCP). Safeguarding, medical, ethnicity, and photos are not imported. Wonde identifiers used only to keep sync stable are stored for matching, not shown as a demographics table.

The field-level inventory is in the school roster data notice. Staff must accept that notice in the product before first bulk upload or Wonde connect.

Who can access what

  • Teachers: pupils and classes in their school, according to product roles.
  • School administrators: school-wide roster, settings, and exports for their tenant only.
  • Pupils and parents: only what the school’s product configuration exposes.
  • Platform operators: cross-school access only for operating the service, under operator allowlisting and MFA policy.

Lawful basis (school’s responsibility)

The school determines lawful basis (typically public task / official authority for maintained schools, and appropriate bases for academies). SEND status and EHCP content can be special category data. The school must ensure Article 6 and, where needed, Article 9 conditions are documented in its own DPIA and privacy notices.

We do not sell personal data

Five Wells does not sell pupil or staff data. Anonymous product analytics on public marketing pages (if enabled) do not include school roster data.

Contact

Parents and pupils should contact the school first. School staff can use in-app Support when signed in. Five Wells will not change a pupil record on a parent’s email without the school’s instruction.

Related: All school documents · Roster field inventory

All school documents ·