At a Glance
Purpose
Curriculum planning for IB Design Technology and MYP Design teachers.
Who Uses It
Teachers, curriculum coordinators and students at IB schools worldwide.
Data Storage
Data is stored on Base44-managed cloud infrastructure. Current location and transfer details are supplied in the sub-processor schedule.
Data Protection
A school-specific DPA and transfer documentation are required before production student-data use.
What Data Is Collected
Data We Collect
- Teacher name and email address
- School name and associated school ID
- Curriculum unit and lesson content created by the teacher
- Student first name and email address (added by teacher)
- Student task submissions and assessment scores
- Basic usage and activity data for analytics
Data We Do NOT Collect
- Student home addresses or personal contact details
- Student photographs or biometric data
- Financial information (handled solely by Stripe)
- Special category data (health, religion, ethnicity etc.)
- Device location or GPS data
- Social media profiles or external account data
Data Retention Policy
We keep data only as long as necessary and give schools control over their own data.
Active school data
Retained for as long as the school account is active.
Deletion requests
Verified requests are handled in accordance with the school DPA, legal restrictions and the agreed deletion process.
Archived student data
Retained only for documented school instructions, educational continuity or applicable legal requirements.
Backups
Residual copies expire under the hosting provider's documented recovery lifecycle and are not used for normal product operation.
Data use
Personal data is not sold or used for advertising. AI data handling must follow the configured provider terms and school controls described below.
Security Measures
Encryption in Transit
The application is served over HTTPS. Transport and storage controls depend in part on the contracted hosting platform.
Protected Storage
Application data is stored on Base44-managed infrastructure. Provider security details are supplied through the procurement and sub-processor documentation.
School Data Isolation
School-scoped row-level rules and authenticated backend checks are used to restrict cross-school access.
Role-Based Access
Student, teacher and administrative actions are restricted by role and school scope.
Security Verification
Dependency scanning and automated security regression tests cover key access and assessment-integrity controls.
Breach Response
Personal-data breaches affecting school-controlled data are investigated and reported to the school without undue delay.
School Data Isolation
Project Designer uses school-scoped row-level rules and authenticated backend checks to restrict access to projects, lessons, student work and assessments. These controls are covered by automated regression tests. A live authenticated two-school boundary test remains a required release check before the platform is represented as fully security-cleared for school deployment.
User Roles & Access Levels
Admin / School Owner
- Full access to school settings
- Manage teachers and classes
- View all school data
- Billing and subscription management
Teacher
- Create and manage own projects
- Manage own classes and students
- Build lessons and assessments
- View own class data only
Student
- View lessons assigned by teacher
- Submit tasks and assessments
- View own progress only
- No access to other students' data
Safeguarding & Student Privacy
Project Designer is designed to support IB Design teaching. Student-facing features are limited to accessing lessons, submitting tasks, and viewing their own progress. Students cannot view other students' work, communicate with each other through the platform, or access any teacher or administrative data.
No student under 13 should create an account independently. Student accounts are created and managed by the teacher. We do not collect or process special category data from students.
We have a published Safeguarding Policy available at /safeguarding.
For safeguarding concerns or to report a concern about student data, contact us at hello@projectdesigner.app.
AI Usage Statement
Project Designer uses AI to power features such as curriculum gap analysis, practice exam generation, lesson design checking, and content suggestions. These features are provided to help teachers work more efficiently.
Teacher tools can send teacher-created curriculum content to configured AI providers. When a school enables AI-assisted challenge assessment, a student's submitted text or uploaded file may also be sent to the configured provider for that assessment.
Schools can disable supported AI functions through school settings. The current sub-processor schedule and DPA must identify provider data handling, retention, transfer and model-training terms before production student use.
AI output is assistive and must not be treated as the sole basis for a high-impact educational decision. Authorised staff remain responsible for review.
Sub-Processors & Third-Party Services
We use a small number of carefully selected third-party services. No student personal data is shared with advertising or marketing platforms.
| Service | Purpose | Data Location |
|---|---|---|
| Base44 | Application platform, authentication, database, storage and backend functions | See current sub-processor schedule |
| Stripe | Payment processing; curriculum and student work are not required for checkout | See Stripe's current service documentation |
| Configured AI provider(s) | Optional teacher tools and, where enabled by a school, AI-assisted assessment of submitted content | See current sub-processor schedule |
| Transactional email provider | Service and school-approval communications | See current sub-processor schedule |
Data Deletion
Schools can request return or deletion of school-controlled data by contacting us at hello@projectdesigner.app. We verify authority and scope, apply the executed DPA and legal restrictions, and record completion.
Subject Access Requests
Individuals can submit privacy-rights requests to hello@projectdesigner.app. For school-controlled student data, requests may be referred to the school as controller. Requests are handled within the applicable statutory timeframe after identity and authority checks.
Compliance Contact
For data protection, GDPR, safeguarding or procurement questions:
Send This Pack to Your IT Manager
We'll send a professional email directly to your IT manager or DPO with the full approval pack, a DPA link, and our compliance contact details.
