RefocusED
Packages
Services
Sign in
RefocusED

Behaviour and inclusion interventions, CPD, and evidence outputs for UK schools.

info@refocused.uk

Phone available on request

Product

  • Interventions
  • Reform ready pathways
  • CPD and training
  • Pricing

Company

  • About
  • Who we work with
  • Evidence and research
  • Frequently asked questions

Legal

  • Privacy Notice
  • Cookie Policy
  • Terms of Service
  • Data Protection & Security

Refocused Ltd • Company number: 16379914 • Registered address: 128 City Road, London, EC1V 2NX

© 2026 RefocusED. All rights reserved.

Made with care in the UK

Data protection in practice

Schools and trusts normally remain the data controllers for pupil and staff information entered into RefocusED. RefocusED normally acts as their data processor and handles that information under documented instructions and contractual data-processing terms.

Data minimisation

We support schools in recording information that is relevant and proportionate to the support being provided.

Controlled access

Access to platform information is limited through authorised accounts, role-based permissions and school-scoped controls.

Retention and deletion

Information is retained and deleted in line with contractual arrangements, documented instructions and applicable legal requirements.

Confidentiality

Authorised staff, technical personnel and service providers are subject to appropriate confidentiality and data-protection obligations.

Incident response

RefocusED maintains procedures for containing, investigating, documenting and responding to security incidents and personal-data breaches.

Responsible use

RefocusED does not sell pupil information, use pupil information for advertising or use school information to train artificial-intelligence models.

Our main platform and vetted service providers are selected and managed using appropriate contractual, confidentiality, security and data-protection controls.

Organisational assurance

RefocusED maintains governance, documentation and operational controls appropriate to a school-facing platform handling sensitive support information.

Current

Information Commissioner's Office registration

RefocusED Ltd is registered with the Information Commissioner's Office.

Registration numberZC147647

Additional data-processing, security and procurement information can be provided to schools and trusts during due diligence, contracting or onboarding.

Privacy and security enquiries

Schools and trusts may request further data-protection, security and procurement information during due diligence or onboarding.

For privacy, data-protection or security-assurance enquiries, contact:

privacy@refocused.uk
Contact our privacy team

No online service can eliminate every security risk. RefocusED regularly reviews and strengthens its technical and organisational safeguards as the platform, regulatory environment and threat landscape develop.

DATA PROTECTION & SECURITY

Protecting school information

RefocusED is designed to manage sensitive school support information through a secure, controlled and accountable platform. Data protection and security are built into the way the platform is hosted, accessed, monitored and maintained.

  • UK-hosted core platform
  • HTTPS / TLS
  • AES-256 database encryption
  • Role-based access
  • Multi-factor authentication
  • Audit logging

Technical security controls

RefocusED applies proportionate technical and organisational safeguards across data transmission, storage, authentication, permissions, monitoring, recovery and platform maintenance.

HTTPS / TLS

Encryption in transit

Connections to the RefocusED platform are protected using HTTPS and Transport Layer Security.

TLS encrypts information while it moves between a user's browser and the platform, helping protect it against interception, alteration and unauthorised access during transmission. Administrative and technical access to supporting cloud services also uses encrypted connections.

AES-256

Encryption at rest

The managed RefocusED PostgreSQL database is encrypted at rest using AWS-managed encryption controls.

AWS RDS encryption uses the Advanced Encryption Standard with 256-bit keys. Encryption applies to the underlying database storage, database logs, automated backups and snapshots. Other operational storage and backups are also protected using managed encryption controls.

RBAC

Role-based access control

RefocusED uses role-based access control to determine which functions and information are available to each authorised user.

Access is assigned according to the user's organisation, responsibilities and approved role. This helps ensure users can access only the functions and records relevant to their work.

Least privilege

Restricted administrative access

Administrative, technical and support permissions follow the principle of least privilege.

Accounts receive only the level of access required for an authorised task. Privileged access is restricted, reviewed and capable of being removed when it is no longer required.

MFA

Named accounts and multi-factor authentication

Protected services are accessed through individual named accounts rather than shared administrative credentials.

Multi-factor authentication is enabled across RefocusED's key administrative and business services, adding an additional security check beyond the account password.

Tenant separation

School data separation

RefocusED is a multi-school platform designed to separate each organisation's records.

School-scoped permissions operate alongside role-based controls so authorised users are associated with the correct organisation and permitted records. Records are logically separated by school.

Audit logging

Security and activity records

RefocusED records important account, security and platform activity to support accountability, troubleshooting and investigation.

This can include authentication events, account and role changes, record updates, exports, downloads, deletion activity and relevant application or security events.

Backup & recovery

Encrypted backups and recovery

RefocusED uses encrypted database backups, automated snapshots and point-in-time recovery controls.

Recovery arrangements are maintained and reviewed to support service restoration following operational failure, data corruption or a security incident.

Vulnerability management

Updates and security maintenance

The platform and its supporting components are maintained through software updates, dependency monitoring, security alerts, developer review and vulnerability-management processes.

Higher-risk issues are prioritised for faster investigation and remediation. Where an immediate permanent correction is not possible, temporary configuration or access controls may be applied to reduce exposure.

Controlled access

Authorised technical support

Technical and support access is limited to authorised personnel who need it to maintain, secure or troubleshoot the platform.

Access is protected using named accounts, multi-factor authentication, encrypted connections, restricted permissions and confidentiality requirements.