Home › Privacy Policy
Privacy Policy
Last updated: May 2026
This privacy policy explains how PMM Digital Ventures Ltd collects, uses, and protects personal data when you use 11+ Prep at 11plusapp.co.uk. We take privacy seriously, especially because this service is used by children. Please read this carefully.
Short version: Parents register accounts and consent on behalf of their children. We collect only what is needed to deliver the service. We do not sell your data, show advertising, or use your child's data for profiling.
1. Who we are
Data controller: PMM Digital Ventures Ltd
8 Watford Road, Croxley Green, WD3 3BJ, United Kingdom
Contact: paulmaciocia@gmail.com
We are the data controller responsible for your personal data under UK GDPR. If you have any questions about how we handle your data, please contact us at the email above.
2. What data we collect and why
Parent account data
- Email address — used to create and manage your account, send transactional emails (account confirmation, password reset), and contact you about your subscription.
- Password — stored as a secure hash; we cannot see your password.
- Name — used to personalise communications.
- Subscription status and payment history — we record whether you are on a free trial or paid plan. Payment card details are handled entirely by Stripe and never pass through our systems.
Child profile data
- Character name — the in-app display name for the child. This does not need to be the child's real name.
- Year group — used to tailor question difficulty and exam timelines.
- Target school — used to select the appropriate exam board format (GL Assessment, CEM, CSSE, etc.).
- Question attempt history — which questions were answered, whether correct or incorrect, time taken, and XP/progress earned. Used to personalise practice sessions and populate the parent dashboard.
Technical data
- Session tokens — a JWT stored in your browser's localStorage to keep you logged in. This is a functional necessity, not tracking.
- Server logs — standard web server logs including IP address and browser type, retained for up to 30 days for security and debugging purposes.
We do not collect real names for children, home addresses, school names beyond target school, or any sensitive personal data as defined under UK GDPR Article 9.
3. Children's data and the UK Children's Code
This app is designed for children aged approximately 9 to 11 who are preparing for the 11+ examination. We comply with the ICO's Age Appropriate Design Code (UK Children's Code).
The key principles we follow:
- Parent-controlled accounts: Only adults may register an account. Parents set up child profiles and consent to data processing on behalf of their child.
- Data minimisation: We collect the minimum data needed to deliver a personalised practice service. Character names do not have to be real names.
- No tracking or profiling for commercial purposes: We do not build profiles of children for advertising or share children's data with third parties for marketing.
- No nudge techniques: Progress indicators and XP are designed to support learning, not to encourage excessive or harmful use.
- Default high privacy settings: All defaults are set to maximum privacy. There are no optional data-sharing features.
4. Lawful basis for processing
- Performance of contract (UK GDPR Article 6(1)(b)) — processing your email, name, and subscription data to provide the service you signed up for.
- Parental consent (UK GDPR Article 6(1)(a)) — by registering a parent account and creating a child profile, the parent provides consent for processing of the child's profile and performance data. You may withdraw this consent at any time by deleting your account.
- Legitimate interests (UK GDPR Article 6(1)(f)) — server security logging to protect the service and its users, balanced against your privacy rights.
5. Who we share data with
We use a small number of trusted third-party data processors. We do not sell your data to anyone.
Supabase (database)
Our database is hosted on Supabase, Inc. (USA). Data is stored on servers in the European Union (eu-west-1 region). The transfer of data to Supabase's US parent company is governed by Standard Contractual Clauses (SCCs) as permitted under UK GDPR Article 46. Supabase's privacy policy: supabase.com/privacy.
Stripe (payments)
Subscription payments are processed by Stripe, Inc. Stripe is an independent data controller for payment card data. We receive only a payment status and customer reference from Stripe; we never see or store card numbers. Stripe's privacy policy: stripe.com/gb/privacy.
Resend (transactional email)
Account confirmation and password reset emails are sent via Resend, Inc. Resend receives your email address to deliver these messages. Resend's privacy policy: resend.com/legal/privacy-policy.
No other third parties have access to your personal data.
6. International data transfers
Supabase and Resend are US-based companies. Transfers of personal data to these processors are protected by Standard Contractual Clauses approved by the UK Information Commissioner under the UK GDPR international transfer framework.
7. How long we keep your data
- Account data (email, name, subscription) — kept for as long as your account is active, plus 30 days after a deletion request to allow for error recovery.
- Child profile data (character name, year group, target school) — deleted when the parent account is deleted.
- Question attempt history — anonymised (all identifiers removed) after 2 years. Anonymised aggregate data may be retained indefinitely to improve question quality.
- Server logs — deleted after 30 days.
- Payment records — retained for 7 years as required by UK financial regulations.
8. Your rights
Under UK GDPR, you have the following rights. To exercise any of them, email paulmaciocia@gmail.com. We will respond within one calendar month.
- Right of access — you can request a copy of the personal data we hold about you and your child.
- Right to rectification — you can ask us to correct inaccurate data.
- Right to erasure — you can ask us to delete your account and associated data. We will do so within 30 days, subject to any legal retention obligations.
- Right to restrict processing — you can ask us to pause processing while a complaint is resolved.
- Right to data portability — you can request your data in a structured, machine-readable format.
- Right to object — you can object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent (child profile data), you may withdraw consent at any time by contacting us or deleting your account.
9. Cookies and local storage
We do not use advertising cookies, analytics cookies, or any third-party tracking cookies. The only data stored in your browser is a session token (JWT) in localStorage, which keeps you logged in. This is essential for the service to function. See our Cookies Policy for details.
10. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects. The personalisation of practice questions is a functional feature of the educational service, not profiling for commercial purposes.
11. Data security
We use industry-standard security measures including encrypted connections (HTTPS), hashed passwords, and access controls on our database. No system is perfectly secure, but we take reasonable steps to protect your data. If we become aware of a data breach affecting your rights, we will notify you and the ICO as required by law.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email at least 14 days before the changes take effect. The current version is always available at 11plusapp.co.uk/privacy.html.
13. How to complain
If you are unhappy with how we have handled your data, please contact us first at paulmaciocia@gmail.com and we will do our best to resolve the issue.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
← Back to 11+ Prep