1. Roles
Your organisation is the controller of the personal data it uploads or generates in Raise about its staff: names, work emails, roles, organisational structure, observation and performance evidence, scores, development focuses, and any AI-generated summaries of that material.
Jigsaw Software Development Ltd is the processor. We handle that data only to provide Raise, on your organisation’s behalf and its documented instructions. Using the service is the instruction.
We are a controller in our own right only for the smaller set of account, security and correspondence data described in our privacy policy. That controller processing is not covered by this agreement.
Name, work email and role appear in both sets, and that is deliberate rather than a contradiction: the same details do two jobs. As your organisation’s record of who works there and what they teach, they are your organisation’s data and this agreement covers them. As the credentials behind a person’s login, they are ours, and the privacy policy covers those. Where the two would pull in different directions, the longer retention applies, so closing a login never removes someone from your organisation’s records while your organisation still needs them.
Raise is for teaching staff and their managers. It is designed for staff data only and has no fields for learner records. Your organisation must not include identifiable learner details in evidence notes or anywhere else in the service.
2. What we process, and why
- Account identifiers your organisation provisions: name, work email, role, curriculum area and subject area.
- Organisational structure: directorates, curriculum areas, staff lists and role assignments.
- Observation and performance evidence, scores, development focuses and review timelines.
- AI-generated summaries and category suggestions derived from the above.
We process this only to deliver Raise. No advertising, no profiling, no sale of data, and no training of AI models on your data, by us or by our providers.
Processing lasts for the life of your organisation’s contract with us, plus at most 90 days for deletion or return, unless the law requires us to keep something longer.
3. Our commitments
- Everyone who can touch personal data is bound by confidentiality.
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 in the database).
- One organisation cannot read another’s data (row-level security in Postgres), with role-based access inside the organisation.
- Production access is limited, and authenticated with SSO and multi-factor authentication.
- We help with data subject requests. If a member of your staff writes to us about service data, we pass the request to you and assist.
- If a personal data breach affects your data, we tell you without undue delay after becoming aware of it, with what we know and what we are doing about it.
- When you leave, we delete or return your organisation’s data on request, and in any case within 90 days, except where we are legally required to retain it. Backups roll off automatically.
4. Sub-processors
We use a short list of services, published on our sub-processors page, with what each one does and where it runs. You authorise that list.
If we plan to add or replace one, we email your administrators at least 30 days first. If you object and we cannot resolve it, you can end the agreement, and for a paid period we refund any unused part.
Every sub-processor is bound by terms at least as protective as these.
5. International transfers
The database is hosted in the European Union (Ireland) with Supabase, covered by the UK’s adequacy regulations for the EEA. Anthropic, Vercel, Slack and Resend host their services in the United States. Where we transfer personal data outside the UK and EEA, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, plus the provider’s own data processing terms, including, for Anthropic, that inputs are not used to train their models.
You can request copies of the relevant transfer mechanisms by emailing jamie@jigsaw.digital.
6. Showing our workings
We will answer reasonable written questions about how we protect your data and share summaries of the relevant security measures. Where the law gives you an audit right, we will cooperate with an audit on reasonable notice, run so it does not put other organisations’ data at risk.
7. Contact
Jigsaw Software Development Ltd, 42 Windsor Drive, Barnet EN4 8UD. jamie@jigsaw.digital. ICO registration ZC180043.