C3NTR
Browse by discipline
Martial arts16 disciplinesDance12 disciplinesMusic11 disciplinesYoga6 disciplinesGymnastics5 disciplinesFitness7 disciplinesPerforming arts5 disciplinesAcademic7 disciplinesWellness5 disciplinesCreative6 disciplines
All disciplines Integrations Can't find your discipline?
Features Roadmap Pricing
Get started
Browse by discipline
Martial artsDanceMusicYogaGymnasticsFitnessPerforming artsAcademicWellnessCreative
All disciplines
Features Roadmap Pricing
Get started
Back to C3NTR

DPIA Summary

Version 1.0 — 10 June 2026

Source (markdown)  ·  Press ⌘P to save this page as a PDF.

This document is a redacted, public-facing summary of the Data Protection Impact Assessment (DPIA) conducted by andBeyond.digital Ltd, the company that operates C3NTR, for the C3NTR knowledge platform, in accordance with UK GDPR Article 35. The full internal DPIA is available to school leaders under NDA on written request to info@c3ntr.app.

1. Why a DPIA is required

A DPIA is required under UK GDPR Article 35(3) because C3NTR processes, on a large scale, Personal Data relating to children (school students who may be under 16). The processing falls within the indicative list maintained by the Information Commissioner’s Office (ICO) of operations likely to result in a high risk to the rights and freedoms of natural persons, specifically the use of biometric or quasi-identifying data of children in the context of educational service provision.

C3NTR has therefore conducted this DPIA before commencing large-scale Processing.

2. Description of Processing

2.1 Nature

C3NTR is a school knowledge platform: a mobile application and web portal that schools use to deliver structured curriculum content (articles, glossary terms, video, audio) to their members and to manage their roster.

2.2 Scope

Each School is the data controller for its own members’ Personal Data. C3NTR (the Processor) provides shared infrastructure. Data is segregated per school by school identifier at the Firestore-rules layer.

2.3 Context

  • Schools choose to subscribe to C3NTR; students join because their school has done so.
  • Most schools using C3NTR are martial-arts, dance, music, fitness, or academic enrichment schools.
  • A meaningful proportion of student users are under 18; some are under 16.

2.4 Purposes

Limited to: delivering curriculum content; tracking individual reading progress for the student’s own resume-where-you-left-off experience; providing aggregate engagement analytics to school leaders; sending announcements; authentication.

C3NTR does not process student data for:

  • profiling for advertising,
  • automated decision-making with legal or similarly significant effect,
  • third-party data resale or analytics syndication,
  • any purpose outside the school’s documented instructions.

3. Necessity and Proportionality

3.1 Lawful basis (the School’s responsibility as Controller)

The School relies on UK GDPR Article 6(1)(b) (performance of a contract) for its instructor and administrator members, and on Article 6(1)(f) (legitimate interests) — with explicit parental notice for students under 16 — for its students. C3NTR provides the technical means; the legal basis assessment is the School’s.

3.2 Data minimisation

C3NTR collects only the data described in the DPA Annex I. It explicitly does not collect: geolocation; payment-card details; contacts or photos outside the C3NTR app; data from anyone under 13 (account creation is gated at the eligibility check).

3.3 Retention

Reading-progress and engagement data are retained for as long as the user has an active membership in the school. Inactive memberships (no login for 18+ months) are flagged for review and deleted after a 30-day grace period. School leaders can shorten retention windows per school.

3.4 Data subject rights

The Right of Access (Art. 15), Rectification (Art. 16), Erasure (Art. 17), Portability (Art. 20), and Objection (Art. 21) are honoured. The mobile app’s Edit-Profile screen provides a self-service Delete Account flow that hard-deletes user data within minutes; export of data is available on written request to info@c3ntr.app.

4. Risks Identified

#RiskLikelihoodSeverityInherent risk
R1Unauthorised access to student data via account-takeoverLowHighMedium
R2Excessive data collection / function creep over timeMediumMediumMedium
R3Profile photo of identifiable minor disclosed unintentionallyLowHighMedium
R4Behavioural data (reading patterns) used for evaluation without consentLowMediumLow
R5Sub-processor data breach (e.g. Sub-processor compromise)LowHighMedium
R6International transfer outside UK/EEA without valid mechanismVery lowHighLow
R7Failure to deliver Data Subject Rights within statutory windowLowMediumLow
R8Personal-data breach undetected for extended periodVery lowHighLow

5. Mitigations Applied

#RiskMitigationResidual risk
R1Account-takeoverPhone-number OTP authentication; multi-factor on web portal; rate-limiting on auth attempts; immediate sign-out from active sessions on password reset.Low
R2Function creepAnnual review of data inventory by the Data Protection Lead; quarterly review of any new fields added to the user model; documented data-minimisation policy.Low
R3Photo disclosureProfile photos are optional and visible only to members of the same school; on-screen disclosure at upload time (planned, Tier B); School leader cannot extract photos in bulk.Low
R4Behavioural dataAggregated engagement only — never per-student reports for school leaders; no third-party analytics SDK; on-device semantic search runs entirely on the user’s device.Low
R5Sub-processor breachSub-processors limited to Google (Firebase / GCP) — major hyperscaler with mature security posture; SCCs / UK IDTA in place; published Sub-processor list with 30-day change notice.Low
R6International transferPrimary data residency in europe-west2 (London). Where ancillary processing routes outside the UK, the UK IDTA applies.Very low
R7DSR deliveryOne-month statutory response window tracked in the Data Protection Lead’s mailbox queue; documented internal SLA of 14 days.Low
R8Undetected breachCloud Logging alerts on anomalous patterns; immutable audit log on privileged operations; 72-hour breach SLA to school leaders documented in the DPA.Low

6. Conclusion

The DPIA concludes that the Processing of Personal Data, including that of children, by the C3NTR platform can be conducted in a manner consistent with UK GDPR after application of the mitigations described above. Residual risks have been assessed and accepted by the Data Protection Lead on behalf of andBeyond.digital Ltd.

No prior consultation with the ICO under UK GDPR Art. 36 is currently required because no residual risk remains high after mitigation.

This DPIA will be reviewed at least annually, or whenever a material change to Processing is proposed (including: a new Sub-processor, a new data category, a change in data residency, or a new purpose).

7. Sign-off

Data Protection LeadandBeyond.digital Ltd (operator of C3NTR)
Date of assessment10 June 2026
Next scheduled review2 June 2027
DPIA referenceC3NTR-DPIA-2026-01

Questions about this DPIA: info@c3ntr.app.

C3NTR
Built for the art. Built for the school.
Product
DisciplinesFeaturesIntegrationsRoadmapPricing
Legal
PrivacyTermsCookiesDisclaimer
Support
Help docsFAQsContact
Get the app
Download on theApp StoreGet it onGoogle Play
andBeyond.digital

© 2026 andBeyond.digital Ltd. All Rights Reserved

We use essential cookies to make C3NTR work, and optional analytics to improve it. See our Cookie Policy.

Claim Your Spot

Join founding schools getting early access to C3NTR. We'll reach out within 24 hours.

By submitting you agree to our Privacy Policy. Your data is handled under GDPR / UK DPA 2018.

Free to start  ·  No spam, ever

You're on the list.

Thank you, we'll be in touch within 24 hours. In the meantime, explore what C3NTR can do.

Explore the App