Security & compliance
Everything IT managers, data protection officers and school leadership need to onboard Cut Lists with confidence.
GDPR compliant
Cut Lists is built to meet UK and EU GDPR requirements. We only collect the information needed to run the service for your school, and we never sell or share data for advertising.
Secure authentication
All logins are encrypted. We support password and Google sign-in, and passwords are never stored in plain text. Students, teachers and technicians each get their own secure account.
Role-based permissions
Students, teachers, technicians, admins and super admins each see only the data and tools relevant to their role. Access is controlled at every level.
Data protection & school isolation
Every school's data is kept completely separate. A user at School A can never see the requests, messages, files or users belonging to School B — enforced at the technical level.
Safeguarding first
School isolation and controlled, role-based communication support child protection and safeguarding responsibilities. Students only communicate with staff in their own school.
Secure cloud infrastructure
All data is encrypted in transit (TLS/HTTPS) and at rest on enterprise-grade cloud infrastructure. We perform regular security reviews and fix vulnerabilities as they are discovered.
School-ready implementation
We provide a ready-made School Approval Pack covering GDPR, data retention, security and safeguarding — so IT managers and DPOs can onboard Cut Lists with confidence.
UK-based data hosting
The Cut Lists database is hosted in the United Kingdom. Your school's data stays on secure UK infrastructure, encrypted in transit and at rest — with no unnecessary international transfers.
Need documentation for your IT team?
Our School Approval Pack covers GDPR, data retention, security and safeguarding in one ready-to-share document.
View the School Approval Pack