Legal

Privacy Policy

Mr G Education Ltd · Effective 26 July 2026 · Version 1.0

In short

Moodly Surveys is anonymous by default: survey answers are stored without your name, email or account identifier unless a survey clearly asks for identity. This policy explains what we do collect — rosters, sign-in details, billing and website analytics — why, and the rights you have over it.

1. Who we are

Moodly Surveys is operated by Mr G Education Ltd (trading as "Moodly"), a company registered in England and Wales (company number 14557194). We are registered with the Information Commissioner's Office (ICO) under registration number ZB526873. You can contact us about anything in this policy at info@moodly.education.

This policy covers the Moodly Surveys product: this website (moodlysurveys.com), the Moodly Surveys web portal (portal.moodlysurveys.com), the web answering pages and the Moodly Surveys mobile app. The Moodly wellbeing platform for younger learners (portal.moodly.education) has its own privacy policy.

We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).

2. Controller or processor — who is responsible for what

Moodly Surveys is used by organisations — schools and colleges, workplaces, care providers, charities and clubs. Who is legally responsible for your data depends on how it got to us:

  • Your organisation is the data controller for the data it manages in Moodly Surveys: its participant roster (names, email addresses, roles, groups) and the survey responses it collects. We process that data on the organisation's behalf as its data processor, under our Data Processing Agreement.
  • We are the data controller for the rest: data about visitors to this website, the account and billing relationship with the people who sign up and administer an organisation, and our own correspondence with you.

If you are a participant (for example a student or employee answering surveys), your organisation decides why and how your data is used, and its own privacy information applies alongside this policy. Questions about why you were added to a roster, or requests about survey data, are usually best directed to your organisation first — we explain why in section 9.

3. The data we collect

Website visitors

When you browse this website we collect limited analytics data (see section 6 for cookies): pages viewed, approximate location derived from your IP address, device and browser type, and how you found us. If you book a demo, the scheduling service you land on will tell you what it collects.

Organisation admins and portal users

  • Your name and email address, your organisation's name and type, and your portal access level (viewer, editor, admin or owner).
  • Sign-in records. If you sign in by magic link, we generate a single-use link that expires after 30 minutes; we store only a cryptographic hash of the link's token, never the token itself. If you sign in with Google or Microsoft, we receive your name and email address from that provider — we never see your password.
  • Billing details for paid plans: the billing contact's name and email, your plan, and payment records. Payments are handled by Stripe — card numbers never touch our systems.
  • Support correspondence — emails you send us and our replies.

Participants added by an organisation

Organisation admins add participants to their roster, by hand or by importing a spreadsheet. For each participant the roster holds: name, email address, role (for example student or staff), an optional group such as a year group or team, and a portal access level. The organisation is responsible for having a lawful basis to share this with us.

Survey responses

This is the heart of the product, so here is exactly how it works:

  • Anonymous surveys (the default). Your answers are stored with no name, no email address and no account identifier. This is enforced by database security rules on our servers, not just hidden in the interface — a response that tries to include identity is rejected before it is stored. Your role (for example student or staff) and group (for example year group or team) are stored with your answers as demographic buckets so results can be filtered, but they never identify you individually.
  • Surveys that ask who you are. An organisation can publish a survey where giving your name is optional (you choose, with an unticked checkbox) or required (the survey says so before you start). Only then are your name and participant record stored with your answers, and the survey is clearly labelled before you answer.
  • Completion records. For roster surveys, we record separately *that* you finished a survey — deliberately disconnected from *what* you answered. Your organisation can see who has completed a survey, but not which response is yours (unless you chose, or the survey required, to attach your name).
  • Small-group protection. Organisations can set a minimum group size below which group-filtered charts are hidden, so that results for a group of one or two people cannot be read as individuals.

Public link respondents

Some surveys are opened to anyone holding a share link. Answering one requires no account and is always anonymous — there is no roster record, no sign-in, and no identity of any kind stored with the response. Your IP address is used transiently to rate-limit abuse and, where the organisation has bot protection enabled, is processed by Cloudflare Turnstile; it is not stored with your answers.

AI authoring assistant

Editors can draft surveys with an optional AI assistant. When used, the text the editor types and the survey draft being worked on are sent to our AI provider (Anthropic by default; alternatively OpenAI on Microsoft Azure, where configured), together with limited context: the organisation's name, its display terminology, and the names of its groups (for example "Year 10" or "Sales team"). Survey responses and the participant roster are never sent to AI providers, and our providers do not use these requests to train their models.

On your device

The answering apps keep your draft answers on your own device (so you can resume a half-finished survey) and the portal remembers preferences such as your theme and organisation name. These stay local until you submit.

4. How we use data, and why we are allowed to

Where we act as processor, we use data only to provide the service to your organisation, on its instructions. Where we act as controller, we rely on the following lawful bases:

What we doDataLawful basis
Provide accounts, sign-in and the portalAccount details, sign-in recordsContract (our Terms with you and your organisation)
Take payment and keep billing recordsBilling contact, plan and payment recordsContract, and legal obligation (tax and accounting law)
Send service emails — sign-in links, receipts, important product and legal noticesEmail addressContract and legitimate interests (running the service)
Understand how the website performs and improve itAnalytics data (section 6)Legitimate interests, and consent where required
Keep the service secure — rate limiting, abuse and fraud preventionIP addresses, security logsLegitimate interests (protecting the service and its users)
Answer your questions and provide supportCorrespondenceLegitimate interests
Tell existing customers about relevant product changesAdmin contact detailsLegitimate interests, with an opt-out in every message

We do not sell personal data, we do not use it for third-party advertising, and we do not make automated decisions with legal or similarly significant effects about anyone.

5. Who we share data with

We use a small number of service providers (sub-processors) to run Moodly Surveys. Each is bound by a contract that meets UK GDPR requirements:

ProviderWhat they do for usWhere
Google Cloud / FirebaseHosting, database and authentication. Survey data is stored in Google's London region (europe-west2); some supporting services run elsewhere in the EU/USUK / EU / US
StripeSubscription billing and card paymentsEU / US
ResendSending transactional email — sign-in links and service noticesUS
AnthropicAI drafting assistant (only when an editor uses it — see section 3)US
OpenAI / Microsoft AzureAlternative AI drafting provider (only where configured for your organisation)EU / US
CloudflareTurnstile bot protection on public survey links (only where enabled)Global

If you sign in with Google or Microsoft, those providers act as your identity provider under their own privacy policies — that is your relationship with them, and they are not our sub-processor.

Beyond service providers, we share personal data only: with our professional advisers under confidentiality; where the law requires it (for example a court order); or as part of a sale or restructuring of our business, in which case this policy would continue to apply. We never share survey data with anyone other than the organisation that collected it.

6. Cookies and analytics

On this website we use:

CookiePurposeLifetime
mdly_ab_landingRemembers which version of our landing page you were shown, so it stays consistent between visits180 days
Google Analytics (_ga and similar)Anonymous usage statistics — which pages are visited and which buttons are clicked — so we can improve the siteUp to 2 years

You can block or delete cookies in your browser settings without breaking this website. Google also offers a browser opt-out for Google Analytics.

In the portal and apps we do not use any advertising or third-party analytics cookies. We use only the storage needed to keep you signed in (Firebase Authentication) and local functional storage such as draft answers and your theme preference.

7. Where data lives and international transfers

Survey data — rosters, surveys, responses — is stored in Google Cloud's London (europe-west2) region.

Some of the providers in section 5 process data in the United States or other countries outside the UK. Where that happens, we rely on UK-approved safeguards: the UK's adequacy regulations, the UK Extension to the EU–US Data Privacy Framework for certified providers, or the ICO's International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses. You can ask us at info@moodly.education for details of the safeguard used for any provider.

8. How long we keep data

  • Roster and survey data is kept for as long as your organisation's account exists, because it belongs to the organisation. When an organisation owner deletes the organisation, its roster, surveys, responses and completion records are permanently deleted immediately — there is no recycle bin.
  • Individual participants removed from a roster are deleted from it immediately, and their sign-in stops working. Their anonymous survey responses remain, because they contain nothing that identifies them.
  • Magic sign-in links expire after 30 minutes and can only be used once; we store only a hash of each token.
  • Billing records are kept for 6 years after the transaction, as UK tax and accounting law requires.
  • Support correspondence is kept for up to 2 years after the conversation ends.
  • Website analytics is retained by Google Analytics for up to 14 months.
  • Deleted data may persist briefly in encrypted backups operated by our hosting provider before those backups are cycled out.

9. Children and students

In schools and colleges, Moodly Surveys is designed for older students — typically Years 9 to 13 (ages 13 and up) — as well as staff. The school is the data controller for its students' data and is responsible for telling students and, where appropriate, parents how Moodly Surveys is used, and for the lawful basis of that use.

We design with young people in mind, in line with the ICO's Age Appropriate Design Code: surveys are anonymous by default; surveys that ask for identity say so up front, in plain language, before any question is answered; there is no advertising, no profiling and no selling of data; and we collect the minimum needed to run the service.

A note on anonymity and safeguarding. Because anonymous answers genuinely cannot be traced back to a person — by the organisation or by us — a concerning answer on an anonymous survey cannot be followed up with that individual. Organisations should tell respondents where to get help directly (a safeguarding lead, a helpline) alongside any wellbeing survey.

10. Your rights

Under the UK GDPR you have the right to access a copy of your personal data, to have it corrected or erased, to restrict or object to its processing, and to data portability. You will never be penalised for exercising a right.

Two practical notes on how those rights work here:

  • For roster and survey data, contact your organisation first. It is the controller of that data, and we support it in responding — our Data Processing Agreement commits us to help. If you contact us directly we may need to refer the request to your organisation, though you are always welcome to write to us.
  • Anonymous responses cannot be found, corrected or deleted individually — by design. Once submitted, an anonymous answer is not linked to you in any way, which means neither we nor your organisation can identify which responses are yours. This is a deliberate privacy protection, and it is why we cannot fulfil subject access requests for anonymous survey answers.

To exercise a right against us as controller (account, billing, website data), email info@moodly.education. We respond within one month. If you are unhappy with our answer you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113 — though we would appreciate the chance to put things right first.

11. How we protect data

  • All data is encrypted in transit (TLS) and at rest.
  • Anonymity is enforced server-side: database security rules reject any attempt to attach identity to a response on an anonymous survey.
  • Completion records are stored separately from answers, so "who finished" can never be joined to "what they said".
  • Sign-in tokens are single-use, expire in 30 minutes, and are stored only as cryptographic hashes.
  • Access inside an organisation is role-based — viewers, editors, admins and owners see only what their level allows — and our own staff access production data only when needed to run or support the service.
  • Card payments are processed by Stripe, a certified PCI DSS Level 1 provider; card numbers never reach our systems.

No internet service can promise perfect security, but if a breach ever puts your rights at risk we will notify affected organisations without undue delay and the ICO where required.

12. Changes to this policy

When we make material changes to this policy we will notify organisation admins by email or via the portal before the changes take effect, and update the effective date at the top of this page. Minor clarifications may be made without notice.

Questions, concerns or requests: info@moodly.education.

Mr G Education Ltd (trading as Moodly) · Registered in England and Wales, company number 14557194 · ICO registration ZB526873 · info@moodly.education