Skip to content
UK GDPR · DPA 2018 · ICO registered

Security at C3NTR

Your school's data is held under UK data protection law, hosted in the EU (London) on Google Cloud, and yours to delete on request. The detail below is what a school's governors or DPO can take to a procurement review.

UK GDPR + Data Protection Act 2018

C3NTR processes personal data under the UK General Data Protection Regulation and the Data Protection Act 2018. Lawful bases under Article 6 apply to every category of data we hold. We answer subject access requests within one calendar month, as required by UK GDPR Article 12. We do not use student data for automated decision-making or profiling under Article 22.

Read the full privacy policy →

What we do, in plain language

Hosted in the EU (London)

Your school's data sits on Google Cloud in the europe-west2 (London) region, within the EU and the UK. No transfer outside the UK or EEA is required for core operation. Form submissions are handled by a Firebase Cloud Function in the same region.

Encrypted in transit

All traffic between the app, the web portal and our servers uses TLS. Access to personal data is restricted to personnel with a clear business need.

Account deletion on request

A school or member can request deletion of their personal data and all content at any time, in-app or in writing. We complete deletion within 30 days and confirm in writing.

No advertising, no resale

We do not sell, share or use your data for advertising. AI search runs on-device, never on our servers. AI writing is opt-in and uses your own provider key, never ours.

Sub-processors

We use a small set of trusted providers to host and operate C3NTR. Each handles a defined slice of the service and is bound by its own data-protection terms:

  • Google LLC / Firebase, primary platform (auth, database, storage, hosting). europe-west2 (London).
  • Stripe, payment processing for subscriptions. PCI-DSS certified.
  • Pexels, stock imagery for templates (we proxy via a Cloud Function; no school data sent).
  • Cloudflare, Turnstile bot protection on web forms only.

A Data Processing Agreement (DPA) is available on request, useful if your school requires one for procurement.

Your rights under UK GDPR

You can ask to access, correct, delete, port, or object to the processing of any personal data we hold about you or your school. To exercise any right, email hello@c3ntr.app. We respond within one calendar month.

You can also lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection matters, at ico.org.uk.

For security disclosures, please email hello@c3ntr.app with the subject line Security disclosure.

Ready to give your students a knowledge home?

Free for the first 30 students. No credit card. A working library in under an hour.

Start free for your school