Updated 4th November 2019
At Sumdog, we take your privacy and online safety very seriously.
It is important that you read this policy, together with any other privacy notice we may provide on specific occasions when we are collecting or processing personal information about or provided by you, so that you are aware of how and why we are using such information.
Information you give us
We only ask teacher and parent users to provide us with their child’s name, date of birth, school and grade. This constitutes “directory information” as defined in FERPA (US). This is personal data as defined in the GDPR(EEA).
We do not ask student users to enter any personal information.
Information we collect automatically
When you use Sumdog, we collect some information automatically. For example, we collect educational progress data as you answer questions.
If you’re a Student User, this information may be accessed by Parent Users in your Sumdog Family, or the Teacher Users linked to your Sumdog School.
To help us improve Sumdog, we also use analytics software to collect usage information.
We don’t allow children to set up their own Student logins directly. Sumdog’s Student accounts must be created by a Teacher User or a Parent User (this includes guardians).
Teacher and parent accounts need to be confirmed by email, in keeping with good practice and the requirements of COPPA (for US users).
Encryption, and keeping your information safe
We encrypt your information using SSL while it’s being transferred between your computer and our servers.
On your web browser, you’ll see a padlock beside the Sumdog web address. Clicking the padlock gives you the details of our security certification.
Storing and processing your information
Depending on your location, we may need to transfer it http://www.sumdog.com/en/Privacy_Policy/#SumdogPrivacyPolicyembed-Howwestoreandprocessyourinformationto these places.
Transfers from the EU to the USA will be done under the terms of Article 46 of the GDPR: “when the controller or processor provides appropriate safeguards, or on the basis of an adequacy decision”.
Sumdog currently has no social features that allow students to communicate freely.
What we do with your information
With the exception of our service providers, we do not allow anyone else to access your information, unless required to do so, for example by law.
We only use your information to provide, evaluate and improve the Sumdog service.
We only use service providers that we are confident are compliant with all relevant laws and regulations.
Sumdog does not carry paid advertisements for anyone else.
Your rights over your information
Teacher Users and Parent Users can view and amend information they’ve given us. This is in keeping with regulations such as FERPA and the GDPR.
We’ll store your information as long as you keep your login to Sumdog, but you can ask us to delete your account.
Below, you’ll find more information on the rights you have.
The legal basis for processing your information
The provision of the Sumdog service is intended to help children and parents or guardians with their child’s education and development. It is in our legitimate business interests to collect and process your personal information so that we can continue to provide the Sumdog service.
Information users give us
Student Users: Children and under 18s.
If you are under 18,
- you are only permitted to log in to Sumdog as a Student User;
- before you can log in as a Student User, a parent, guardian or teacher must create an account for you. They do this by first creating a parent or teacher account for themselves.
We will not ask student users to enter information that, by itself, is considered personal information.
If we’re informed that we have collected personal information from anyone under 18 without permission from someone with the authority to give permission, we will delete that information as quickly as possible. If you believe that this has happened, please contact us at firstname.lastname@example.org.
Any personal information is provided by the parent, guardian or teacher who created the student account.
In some of Sumdog’s writing games, students may be asked to input text as an answer. Their access to these games is controlled by the Parent Users and Teacher Users linked to their account.
When they play these writing games, students may see what other players have written. For that reason, we remind them not to enter any personal information. Sumdog does its best to enforce this rule automatically. To help provide the safest possible environment, we may permit Teacher Users to view what their students have written and Parent Users to view what their child has written.
We collect the following personal information from Parent Users.
On sign-up, Parents Users enter their:
- first and last name
- email address and password
Parent Users then enter information about each of their children:
- first and last name
- date of birth
- school login details
Parent Users may also send an email invite to other parents or guardians by entering their names and email addresses.
If Parent Users choose to subscribe to premium services, they enter:
- a postal address
- payment method details
The following personal information is collected from Teacher Users.
On sign-up, Teacher Users enter their:
- first and last name
- email address and password
- school name and address
Teacher Users may then enter information about their students:
- first and last name
- grade level or school year
Teachers are responsible for inviting and accepting other Teacher Users who wish to join a school. It is their responsibility to identify that the invited or requesting teacher is allowed to access the personal information of students and teachers stored in the Sumdog school.
All users can choose the gender and visual appearance of their on-screen avatar. They can also specify profile details, such as their favorite Sumdog game.
In order to provide the best possible service, we may extend the types of information we ask users to give us. If we do this, we will tell you what extra information we would like to collect from you, and why we are doing it.
If you don’t provide personal information
You can choose not to give us your information. However, this may prevent you from using most parts of Sumdog. If we are unable to provide you with the Sumdog service because you fail to provide us with the personal information requested by us, we may have to cancel all or part of the Sumdog service. We may also be prevented from complying with our legal obligations. We will tell you if this is the case at the time.
Information we collect automatically from users
When you use Sumdog, we will collect the following information automatically:
For Student Users
- educational data from your activity on Sumdog, for example accuracy and speed of answers to Sumdog’s questions;
- text written in Sumdog’s writing games.
For all Users
- data on your use of Sumdog, for example the last time you logged in;
- communications you have made with other Sumdog users;
- technical information, for example the device you use, your operating system and your IP address.
The data we collect automatically may be linked to your account and to the personal information that you or your parent, guardian or teacher have given us.
Some of the information that we collect from Student Users may be accessed by the Parent Users in their Sumdog Family, or the Teacher Users linked to their Sumdog School.
We also use analytics software to help us understand how Sumdog is used. For example, to help us optimise our email communication, we may use customised links, or small images called web beacons. These allow us to understand how our messages are received by our users.
In order to provide the best possible service, we may decide to extend the types of information we automatically collect from users. If we do we will tell you first.
How we use your information
The situations in which we will process your personal information are listed below. We have indicated the purpose or purposes for which we are processing or will process your personal information, as well as indicating which categories of data are involved. Here is a reminder of the legal bases under which we collect and process your data:
We will only use your personal information when the law allows us to. Most commonly, we will use your personal information in the following circumstances:
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests (Condition 1).
- Sumdog is intended to help students with their education and development, and to help their educators, parents and guardians support this.
- Where we need to comply with a legal obligation (Condition 2).
- Where we have your consent or are otherwise permitted to provide you with electronic marketing information (Condition 3).
We use information held about you in the following ways:
Information you give to us
We may use this information:
- to provide you with the information, products and services that you request from us (Condition 1 and Condition 4);
Your information is used during the normal functioning of the Sumdog service. This may include:
- personalising Sumdog for you;
- informing you about our services, or to help you to use them, such as telling you about a new Sumdog game, or notifying you of the end of a trial period;
- identifying and, where necessary, acting against improper or illegal use of Sumdog. This helps keep Sumdog safe for all of our users;
- analysing usage patterns, requesting feedback from you or conducting research on the educational impact of our services so that we may improve them;
- to provide you with information about our services. We will contact you for marketing purposes by electronic means only if you have consented to this or we are otherwise permitted by law to contact you (Condition 3);
- to notify you about changes to our service (Condition 1 and Condition 4);
- to ensure that content from our site is presented in the most effective manner for you and for your computer (Condition 1);
- If you have given us your email address, we may send you messages via email. This may include information about new features or services, or about your usage of the site, or the usage of others in your Sumdog School or Sumdog Family. To change your mind about which types of email you receive from us, please go to www.sumdog.com/emails. Please note that there are certain emails that you can’t opt out of receiving, unless you delete your account entirely, as these are concerned with the administration of your account (Condition 1 and Condition 3).
Information we collect about you.
We will use this information:
- to administer our site and for internal operations, including troubleshooting, data analysis, testing, statistical and survey purposes (Condition 1);
- to improve our site to ensure that content is presented in the most effective manner for you and for your computer (Condition 1);
- to allow you to participate in interactive features of our service, when you choose to do so (Condition 1);
- as part of our efforts to keep our site safe and secure (Condition 1);
- to measure or understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you (Condition 1);
- to make suggestions and recommendations to you and other users of our site about services that may interest you or them (Condition 1).
Some of the above grounds for processing will overlap and there may be several grounds which justify our use of your personal information.
The data that we collect from you is used to make some automated decisions about your experience on Sumdog. For example, our algorithms to help automatically decide the level of questions that you are asked to answer. This enhances your experience of Sumdog as a learning tool by tailoring the service to your exact learning needs. Student Users may also see messages encouraging them to play Sumdog for longer. We do not anticipate that the automated decisions we make would impact our users in a legal, or similarly significant, manner.
Change of purpose
We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is related to the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law (Condition 2).
How we store and process your information
Your information is stored and processed on our servers and those of our service providers. For security reasons, payment card details are not held by us and are stored instead by our payment service provider.
While your information is being transferred to our servers, it is encrypted using SSL. This helps to protect it in transit.
Information we collect will only be stored and processed in the United States of America or the European Union. Depending on your location, we may need to transfer it to these places. However, to ensure that your personal information does receive an adequate level of protection appropriate measures are put in place to ensure that your personal information is treated by those third parties in a way that is consistent with and which respects the EU and UK laws on data protection. Therefore, transfers of this information from the European Union to the USA are done in such a way as to ensure an adequate level of protection such as by using the EU-US privacy shield or another appropriate safeguard, such as the model contract clauses approved by the European Commission.
We also collect information from Teacher Users and Parent Users that doesn’t relate to individual students – for example, in our online accounting systems. We may transfer this information to other countries. If you are from the European Union, and we need to transfer this information to countries outside the EU, transfers will be done in such a way as to ensure an adequate level of protection such as by using the EU-US privacy shield or another appropriate safeguard, such as the model contract clauses approved by the European Commission.
Suppliers of support services to Sumdog – for example, the provider of our data storage – may process any of the information we collect on our behalf.
We will take all steps reasonably necessary to ensure that this information is treated securely.
We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
With that in mind, we will keep your personal information as long as your Sumdog account exists. We may also need to keep your information to comply with our legal obligations, or to resolve disputes or enforce our agreements.
Parent Users or Teacher Users may ask us to delete personal information held in a Sumdog Family or Sumdog School linked to their account by contacting us as described below. We will do this within 30 days of your request except where we need to keep your information to comply with our legal obligations, or to resolve disputes or enforce our agreements.
If you sign up as a Teacher User or a Parent User, and you do not confirm your email address within 30 days of signing up, we will automatically delete your information.
The following information will not be deleted:
- after a request to delete a Sumdog Family, the Student User accounts will not be deleted if they are also linked with a Sumdog School.
- after a request to delete a Sumdog School, the Student User accounts will not be deleted if they are also linked with a Sumdog Family.
- any information required to protect the safety of other Sumdog Users will not be deleted; for example, we keep the conversations held in writing games in case we need to investigate claims of abuse.
Inactive accounts may be deleted. We will make reasonable efforts to contact you using either Parent User or Teacher User email addresses before we do so. If as a teacher or parent, you do not confirm your account, this will be deleted automatically one week after creating it.
We may also use aggregated data that has been derived from your information after you have deleted it. However, this will not be in any way that might identify you personally.
We may have to share your data with third parties, including third-party service providers and other entities in the group.
We require third parties to respect the security of your data and to treat it in accordance with the law.
If you are based in the EU, we may transfer your data outside of the EU.
Why might you share my personal information with third parties?
We will share your personal information with third parties where required by law, where it is necessary to administer the working relationship with you or where we have another legitimate interest in doing so.
We will disclose your information:
- where we believe in good faith that disclosure is required by law;
- to protect the rights or safety of Sumdog’s users;
- to protect the property or rights of Sumdog or its employees;
- where there has been a clear breach of our licensing terms. In this case we may share information with our partners, lawyers and/or law enforcement agencies in the relevant country;
- if you are a Student User, and your login is linked to a Sumdog School; in this case, any Teacher Users who are members of that Sumdog School will be able to access your information;
- if you are a Student User, and your login is linked to a Sumdog Family; in this case, any Parent Users who are members of that family will be able to access your information;
- when you have made a sales or support enquiry from a country in which we work with a partner, in which case we may forward your information to them;
- where the information you have given us is used on a profile that can be accessed by other users, or in an activity where it is shared with other users, such as one of Sumdog’s writing games;
- where we have engaged a third party to provide us with services to help us provide Sumdog, and that third party requires us to share your information with them. Examples of this include research on the effectiveness of the Sumdog service, sending you messages by email, storing or processing data, and processing payment. We will ensure that we only do this for the purposes of providing you with and improving the Sumdog service, and that these third parties have no right to use your information except as required to provide the services we engage them for;
- when you have given explicit permission to pass your information to a third party.
Which third-party service providers process my personal information?
“Third parties” means third-party service providers and other entities within our group. The following activities are carried out by third-party service providers: system administration, processing of subscription payments, data storage and data hosting and the provision of professional advisory services (including lawyers, auditors and insurers providing legal, accounting and insurance services).
How secure is my information with third-party service providers and other entities in our group?
All our third-party service providers and other entities in the group are required to take appropriate security measures to protect your personal information in line with our policies and the law. We do not allow our third-party service providers to use your personal data for their own purposes. We only permit them to process your personal data for specified purposes and in accordance with our instructions.
When might you share my personal information with other entities in the group?
We will share your personal information with other entities in our group as part of our regular reporting activities on company performance, in the context of a business reorganisation or group restructuring exercise, for system administration, data storage and data hosting.
What about other third parties?
We may share your personal information with other third parties, for example in the context of the possible sale or restructuring of the business. We may also need to share your personal information with a regulator or to otherwise comply with the law.
Transferring information outside the EU
We will transfer the personal information we collect about you outside the EU to the United States of America in order to provide the Sumdog service. However, to ensure that your personal information does receive an adequate level of protection appropriate measures are put in place to ensure that your personal information is treated by those third parties in a way that is consistent with and which respects the EU and UK laws on data protection. Therefore, transfers of your personal information from the European Union to the USA are done in such a way as to ensure an adequate level of protection such as by using the EU-US privacy shield or another appropriate safeguard, such as the model contract clauses approved by the European Commission. If you require further information about these protective measures, you can request it from our Data Protection Officer.
Content you enter on our website
If you enter offensive, inappropriate or objectionable content on our websites, we may use the information you have given us to stop such behavior.
Where we believe in good faith that you are or may be in breach of any law, or that your safety is at risk, we may use the information you have given us to inform relevant third parties such as your employer, school, e-mail/internet provider or law enforcement agencies.
If we permit you to add information to create a public profile on Sumdog, this information may be displayed to other users. You should bear in mind that whenever you disclose information online, for example as part of a public profile, or in written communications on the site, it may be available to other users, who may be able to collect and use it without either us or you knowing.
Third party advertisements
We do not carry any paid advertising on Sumdog.
Keeping your information safe
We have put in place measures to protect the security of your information.
Third parties will only process your personal information on our instructions and where they have agreed to treat the information confidentially and to keep it secure.
Your information is protected by your password. We also take all reasonable steps to prevent attack on Sumdog.
Parent Users and Teacher Users are responsible for using their best efforts to select and protect their login details, including restricting access to your Sumdog account, and logging off after using Sumdog.
We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
Rights of access, correction, erasure, and restriction
Your duty to inform us of changes
It is important that the personal information we hold about you is accurate and current. Please keep us informed if your personal information changes during your relationship with us.
Your rights in connection with personal information
Under certain circumstances (where the GDPR applies), by law you have the right to:
- Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
- Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
- Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
- Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
- Request the transfer of your personal information to another party.
If you want to review, verify, correct or request erasure of your personal information, object to the processing of your personal data, or request that we transfer a copy of your personal information to another party, please contact the Sumdog Data Protection Officer in writing.
No fee usually required
You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.
Right to withdraw consent
In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal information for a specific purpose (such as electronic marketing), you have the right to withdraw your consent for that specific processing at any time. To withdraw your consent, please contact our Data Protection Officer. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.
Data protection officer
Data Protection Supervisory Authority / The Information Commissioner’s Office
If you are an EU citizen or our use of your personal information is subject to the GDPR, you also have the right to lodge a complaint about how we handle your personal information with an EU data protection supervisory authority.
In the UK, the supervisory authority is the Information Commissioner’s Office / the ICO. You can call the ICO’s helpline on +44 (0)303 123 1113. See also https://ico.org.uk/global/contact-us/.
How to contact us
For the purposes of the EU General Data Protection Regulation, Sumdog Inc’s representative in the EU is Sumdog Ltd, 43 Queensferry Street Lane, Edinburgh, EH2 4PF, UK.