EDF Quest โ Version 1.0 ยท Last updated 10 June 2026
[Company Name โ set in Control Panel โ Legal & GDPR]
[Registered Address]
Data Protection Contact: dpo@edfquest.org
We collect: account data (name, email, hashed password); usage data (quiz attempts, progress, session timestamps); communications you send us; technical data (IP address, browser type, session identifiers).
We do not collect payment card data, government IDs, or sensitive health data.
| Purpose | Lawful Basis |
|---|---|
| Providing your account and the platform | Contract (Art. 6(1)(b)) |
| Service emails (password resets, notifications) | Contract / Legitimate Interest |
| Analytics to improve the platform | Consent (Art. 6(1)(a)) โ optional |
| Security monitoring and fraud prevention | Legitimate Interest (Art. 6(1)(f)) |
| Legal compliance | Legal Obligation (Art. 6(1)(c)) |
We retain personal data for up to 2 years from your last activity. After this, inactive accounts are flagged for deletion. Backup copies may persist up to 90 days in encrypted storage before permanent deletion.
We do not sell or rent your data. We may share with: hosting/infrastructure providers (under DPAs); email service providers; law enforcement where required; and your linked school or tutorial centre (name, email, progress).
Essential session cookies are always set. Analytics and preference cookies require your explicit consent via the cookie banner. Withdraw consent at any time by clearing cookies for this site.
Email dpo@edfquest.org to exercise your rights. We respond within 30 days. You may also complain to the ICO.
We use TLS encryption, bcrypt password hashing, session token rotation, IP-based rate limiting, and ongoing security monitoring.
Where data is transferred outside the UK or EEA, we ensure appropriate safeguards (Standard Contractual Clauses or equivalent) in accordance with UK GDPR + EU GDPR.
We do not knowingly collect data directly from children under 13 without school or parental involvement. Schools using EDF Quest are responsible for obtaining appropriate parental consents.
Significant changes will be communicated by email and/or in-app notice. The version and date at the top reflects the current version.
[Company Name โ set in Control Panel โ Legal & GDPR]
[Registered Address]
Email: dpo@edfquest.org