GDPR

Our policy

1. GDPR Summary

Reading Plus® is owned and provisioned by Taylor Associates/Communications, Inc. (“Taylor Associates”). Taylor Associates (Reading Plus Publishers) is based in the U.S. Reading Solutions UK Limited is the sole UK representative/reseller for Taylor Associates.

All user personal data collected through the use of Reading Plus® is processed by Reading Plus to provide and deliver the software. This includes applications hosting and client support, through data centres and systems that are outside the United Kingdom and the European Union, including in the U.S. Data is stored on AWS (Amazon Web Services) Servers in the U.S.

For individuals located in the European Union and the United Kingdom, Reading Plus participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework.

We are aware that following the decision made in the Schrems II case, Privacy shield was deemed invalid for data transfers to the U.S. and we are currently in the process of refining our processes to implement Standard Contractual Clauses as advised by the ICO (this will be done imminently). In the interim, we continue to use the current Software as a Service (SaaS) document so that there is still a contract in place between ourselves, Reading Plus (Taylor Associates) and the school.

Our assessments regarding the transfer of data (pupil’s first name, last name and year group) deem the data low risk.

(To go into further detail regarding our assessment of data, Reading Plus LLC is not the type of company that can be required to disclose data under Section 702 of FISA. There are technical safeguards and encryption standards Reading Plus LLC has put in place to prevent data be intercepted during transfer under the powers set out in EO 12333. All data is encrypted in transit and remains protected within current processes.)

We will work with any school to assist in anonymising data on the system which removes any issues of data transfer.

2. Do I need to sign the Software as a Service (SaaS) document?

Yes. The document protects your rights, shows acceptance of our terms of service and forms the contract for your school to use the software.
But I’m only piloting the software?

A signed agreement should still be in place to show acceptance of our terms of service and forms the contract for your school to use the software.
You can view a sample agreement here. Add link or doc

3. Is my data transferred out of the UK?

Yes. All user personal data collected through the use of Reading Plus® is processed by Reading Plus to provide and deliver the software, including applications hosting and client support, through data centres and systems that are outside the United Kingdom and the European Union, including in the U.S. (Data is stored on AWS (Amazon Web Services) Servers in the U.S.)

We are currently in the process of refining our processes to implement Standard Contractual Clauses as advised by the ICO.

We will also work with any school to assist in anonymising data on the system which removes any issues of data transfer.

4. How do you collect data?

We use different methods to collect data from and about you including through:

  • Direct interactions. You may give us your Identity, Contact and Financial Data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
  • Enter into a discussion with us to purchase a subscription for Reading Plus
  • Enter a competition, promotion or survey; including providing feedback
  • Automated technologies or interactions. As you interact with our website, we may
    automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, and other similar technologies. Please see our cookie policy within the privacy policy here https://readingsolutionsuk.co.uk/privacy-policy/ for further
    details. (update link)
  • Third parties or publicly available sources. We may receive personal data about you from various third parties and public sources.
  • Identity and Contact Data from publicly available sources such as Companies House and the Electoral Register.

5. How do you process my data and what is the lawful basis?

1.  Processing by the supplier

1.2 Scope

The processing of Customer Personal Data as required under the terms of the SaaS agreement

1.3 Nature

The storage of Customer Personal Data processed by the Customer using the Services together with such retrieval, amendment, transmission, structuring, restriction or erasure of Customer Personal Data as may be required in the course of the provision of support services to the Customer.

1.4 Purpose of processing:

To enable and facilitate the Customer’s use of the Services.

1.5 Duration of the processing

The processing shall continue for the duration of the SaaS agreement

2. Types of personal data

Names (first name, surname, title)

Status (student, teacher, administrator)

Contact details – (email address, telephone number)

Technical data – (IP address, login date and times, domain and web browser information, technical information about a user’s workstation or local area network, simultaneous login attempts, lesson dates and times, account creation date and time, account modification date and time, and information collected through cookies and other tracking technologies)

Profile data – username, passwords, student number (if provided by the school), school year, race(if provided by the school), lunch status(if provided by the school), first language (if provided by the school), special educational status(if provided by the school)

Usage data – (tasks performed, assessments undertaken, progress and development, skills deficiencies/areas of weakness)

3. Categories of data subject

Students, teachers and administrators attending or employed at the school run by the Customer.

 

6. Are you registered with the ICO?

Reading Solutions UK Ltd are registered to the ICO you can view the certificate of registration by clicking here.