School Approval Pack
Everything your school needs to carry out a due diligence review of Cut Lists — including GDPR, data protection, safeguarding, security and compliance information.
Who it's for
DT teachers, technicians & school administrators
Data stored
Name, email, school, cutting requests & messages
Hosting
United Kingdom • Encrypted at rest & in transit
Data Protection Summary
What data is collected
• Full name and email address
• School affiliation and user role
• Cutting request content (dimensions, materials, files)
• In-app messages between school users
• Optional profile photo (user-uploaded)
What data is NOT collected
• Date of birth or age
• Home address or phone number
• Financial data from students
• Location data or tracking identifiers
• Student data is not used for advertising or AI training
Where data is stored
All data is stored in the United Kingdom via Base44, a managed cloud platform. The Cut Lists database is UK-based.
Data is encrypted at rest and in transit (HTTPS/TLS). File uploads are stored in isolated, access-controlled cloud storage.
Data retention
• Active school data: retained while account is active
• Cancelled accounts: data accessible 30 days, then deleted
• Deleted users: anonymised within 30 days
• Technical backups: retained for 14 days
• Data is never sold or used for advertising
Data deletion
Schools can request full data deletion by emailing hello@cut-lists.com.
Individual users can be removed by school admins from the admin panel.
Subject Access Requests are handled within 30 days.
Security measures
• HTTPS/TLS encryption on all traffic
• Token-based authentication with session management
• Role-based access control across all user types
• School data is fully isolated at the database level
• Managed hosting with regular security updates
GDPR & School Data Isolation
GDPR readiness
School data isolation
Each school's data is completely separate. No school can view, access, or interact with data from another school. This is enforced at the database level — not just through the interface.
School administrators only have access within their own school account. The super admin (app owner) manages system health only and does not access individual school content.
Safeguarding & Student Privacy Statement
Cut Lists does not expose student data publicly. All student-generated content is private to the school.
Students communicate only within their school environment — with their own technicians and teachers.
No student data is shared with other schools, third parties, or used for commercial purposes.
The platform has no social features, public profiles, or external sharing mechanisms.
Student data is never used to train public AI models or sold to third parties.
Sub-Processors & Third-Party Services
| Service | Purpose | Data shared |
|---|---|---|
| Base44 | Application hosting & database | All app data |
| OneSignal | Push notifications | Device tokens, user IDs (no content) |
| [Email provider] | Transactional emails | Email address, notification text |
| [Payment provider] | School subscription billing | School billing info (no student data) |
All sub-processors are subject to appropriate data processing agreements.
IT / DPO Approval Checklist
Compliance Contact
General & SAR enquiries
hello@cut-lists.com
Request a DPA
hello@cut-lists.com
Book a school approval call
cut-lists.com/contact
This page is provided to support school due diligence and does not replace the school's own legal, data protection or procurement review.