Legal
Privacy Policy
How We Starter Ltd (iTeach) collects, uses, shares, and protects personal data across the iTeach platform, websites, and related services.
Last updated: 3 July 2026 · Effective date: 1 July 2024
This Privacy Policy explains how We Starter Ltd (trading as “WeStarter”) collects, uses, shares, and protects personal data when you use the iTeach platform available at https://iteach.westarter.com (the “Platform”), our websites, and related services (together, the “Services”). “iTeach”, “we”, “us”, and “our” in this policy refer to We Starter Ltd.
We are committed to protecting personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
1. Who we are
We Starter Ltd is a company registered in England and Wales.
| Company name | We Starter Ltd |
|---|---|
| Company registration number | 15821772 |
| Registered office | 52-54 Stourbridge Road, Stourbridge, England, DY9 7DL |
| Trading name | WeStarter |
| ICO registration number | ZB906896 |
| Data protection contact | privacy@westarter.com |
iTeach is a product of We Starter Ltd (trading as WeStarter). References to “iTeach” in this policy mean the iTeach platform and Services provided by We Starter Ltd.
If you have any questions about this policy or how we handle personal data, contact us using the details in Section 16.
2. Our role: Controller and Processor
iTeach is a business-to-business (B2B) Software-as-a-Service platform used by schools, academies, training centres, and other institutes (“Customers”). Because of this, our role under data protection law depends on the data involved.
2.1 Where we are a Data Controller
We act as a Controller (we decide why and how data is processed) for personal data relating to:
- Account holders, administrators, and authorised users who register for or manage an iTeach account
- Billing and finance contacts
- People who submit enquiries, request a demo, or are captured as leads through our own website and sales channels
- Visitors to our websites
- People who contact our support or communicate with us directly
This Privacy Policy governs that processing.
2.2 Where we are a Data Processor
We act as a Processor for personal data that a Customer uploads, enters, or generates within the Platform about their own students, leads, and staff — for example student names, contact details, class/subject enrolment, attendance, and academic progress records; admissions/leads enquiries; and employee/HR and payroll records (“Customer Data”).
For Customer Data, the Customer is the Controller and decides how that data is used. We only process Customer Data on the Customer’s documented instructions, under a Data Processing Agreement (DPA) that forms part of our Terms of Service. If you are a student, parent, or staff member of an institute, please direct privacy requests to that institute in the first instance; we will support them in responding.
3. Personal data we collect
Depending on how you interact with the Services, we may collect the following categories of personal data.
3.1 Account and identity data
Name, job title, employer/institute name, username, password (stored in hashed form), and account preferences.
3.2 Contact data
Email address, telephone number(s), postal/business address.
3.3 Billing and payment data
Billing name and address, subscription plan, invoices, and transaction history. Card and bank details are collected and processed directly by our payment processor, Stripe — we do not store full card numbers on our systems. See Section 7.
3.4 Communications data
Records of communications you send or receive through the Platform or with us, including support tickets, in-app chat, emails, phone and SMS communications, and WhatsApp messages (via the WhatsApp Business Platform). This may include message content, metadata, sender/recipient numbers, and timestamps.
Chat and phone communications handled through your connected WhatsApp Business API and phone numbers are encrypted and stored so that they are accessible only to your own authorised users. We Starter does not access the content of these communications for its own purposes (see Section 6 and Section 11).
3.5 Usage and technical data
IP address, device and browser type, operating system, login records, pages and features used, time zone, and diagnostic/log data. Some of this is collected via cookies and similar technologies — see our Cookie Policy.
3.6 Marketing and preferences data
Your preferences for receiving marketing from us and your communication preferences.
3.7 Customer Data (processed on behalf of Customers)
Where you are a Customer, the Platform allows you to store and process data about your students, leads, and staff, which may include: student records, class and subject enrolment, attendance, academic progress, and uploaded academic documents/files (stored via Amazon S3); admissions/leads enquiries; and HR and employee records, including payroll information.
We do not collect or process health, medical, or safeguarding data as part of the Services — the Platform has no database fields or tables for this category of data. You are responsible for ensuring you have a lawful basis and appropriate notices/consents to process this data and to put it into iTeach.
3.8 Children’s data
The Platform is used by Customers to store academic and enrolment-related records about their students (children), such as class/subject enrolment, attendance, and progress data. The Customer (institute) is the Controller of this student data and is responsible for the lawful basis and any required parental/guardian consent for processing it. iTeach does not collect health, safeguarding, or other special category data as part of the Services, and does not use student data for its own purposes. Security measures applied to this data are set out in Section 11.
4. How we collect personal data
We collect personal data:
- Directly from you — when you register, request a demo, subscribe, contact us, or use the Services
- Automatically — through cookies, server logs, and similar technologies when you use the Platform or websites
- From your institute/Customer — if your institute creates an account or user profile for you
- From third parties — such as our payment processor (Stripe), authentication/single sign-on providers, and integrated services you choose to connect (e.g. Google, Microsoft, Zoom, Meta/WhatsApp)
5. Why we use personal data and our lawful bases
Under the UK GDPR we must have a lawful basis for processing. We rely on the following.
| Purpose | Lawful basis |
|---|---|
| To create and administer your account and provide the Services | Performance of a contract |
| To process subscriptions, billing, invoicing, and payments | Performance of a contract; Legal obligation |
| To provide support and respond to your enquiries | Performance of a contract; Legitimate interests |
| To send service, security, and transactional messages (e.g. billing updates, account notices) | Performance of a contract; Legitimate interests |
| To secure the Platform, prevent fraud, and ensure network/information security | Legitimate interests; Legal obligation |
| To maintain and improve the Services and develop new features | Legitimate interests |
| To send marketing communications and newsletters to individuals | Consent (you may withdraw at any time); Legitimate interests (for existing business customers, where permitted) |
| To use non-essential cookies and analytics | Consent |
| To comply with tax, accounting, and other legal obligations | Legal obligation |
| To establish, exercise, or defend legal claims | Legitimate interests |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may ask us about this balancing assessment using the contact details below.
Where we rely on consent (for example, for marketing or non-essential cookies), you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
6. Communication channels (SMS, phone, WhatsApp, email)
The Platform provides tools that connect — through their APIs — to third-party services that you set up using your own provider accounts. Where enabled, these include:
- Telephone and SMS — where enabled, Customers can connect their own phone numbers to make calls and send SMS to their end users.
- WhatsApp Business Platform (Meta) — Customers may connect their own Meta WhatsApp Business Account (WABA) and phone numbers to send and receive messages with their end users. To make this connection quick and secure, iTeach is registered with Meta as a Tech Provider and uses Meta’s official Embedded Signup flow to let Customers link their WhatsApp Business Account to the Platform. Through this flow, the WhatsApp Business Account, phone number, and associated Meta Business Portfolio remain owned and controlled by the Customer at all times; iTeach is only granted access to send and receive messages on the Customer’s behalf, and this access can be revoked by the Customer at any time from their own Meta Business Suite. Messages routed through WhatsApp are also processed by Meta Platforms in accordance with Meta’s and WhatsApp’s terms and privacy policies. Use of the WhatsApp Business Platform is subject to Meta’s Business Messaging policies, including rules on user opt-in, message templates, and permitted message categories.
- Email (Amazon SES) — Customers connect their own Amazon SES configuration to send outbound email to their end users (for example, sign-up, billing, newsletter, and custom emails).
When these channels are used, communication content and metadata are processed to deliver the messages. Customers acting as Controllers must ensure they have obtained any required opt-ins/consents from recipients (particularly for WhatsApp and marketing messages) and must comply with applicable laws including PECR and the platform rules of Meta and Amazon.
Your own provider accounts. The integrations above — email (Amazon SES), WhatsApp (the Meta WhatsApp Business Platform), and phone/SMS — are connected by you using your own accounts with those providers through their APIs. You contract with each provider directly and are billed by them directly for any usage; iTeach supplies the tool that connects to the service, including facilitating the connection as a registered Meta Tech Provider for WhatsApp, and does not itself charge you for, or control, those third-party usage fees. For the data you process through these integrations, you act as the Controller and the relevant provider acts as your processor or independent controller under its own terms.
Encryption and access to your communications data. Chat and phone data handled through your connected WhatsApp Business Account and phone numbers is encrypted in transit and at rest within the Platform, and is accessible only to your authorised users. We Starter does not read, monitor, or use the content of these communications for its own purposes. Please note that messages sent through the WhatsApp Business Platform are still transmitted through and processed by Meta in accordance with Meta’s terms and privacy policies.
7. Payments (Stripe)
Subscription payments are processed by Stripe Payments Europe, Ltd. and its affiliates (“Stripe”). When you make a payment, your card/bank details are provided directly to Stripe and processed under Stripe’s Privacy Policy. We receive limited information such as confirmation of payment, the last four digits of your card, card type, and billing details — we do not receive or store your full card number. Stripe acts as an independent Controller for the payment data it processes for fraud-prevention and regulatory purposes.
8. Sharing personal data and sub-processors
We do not sell personal data. We share personal data only as described below.
8.1 Service providers / sub-processors
We use trusted third parties to operate the Services. Each is bound by contract to process data only for the purposes we specify and to apply appropriate security. Our key sub-processors include:
| Provider | Purpose |
|---|---|
| Amazon Web Services (AWS) | Cloud hosting and file storage (Amazon S3) |
| Stripe | Payment processing and billing |
| Meta Platforms (WhatsApp Business Platform) | Business messaging via WhatsApp; iTeach acts as a Meta-registered Tech Provider to facilitate Customer onboarding |
| Video conferencing (Google Meet) and related APIs you connect | |
| Zoom | Video conferencing |
| Microsoft | Video conferencing (Microsoft Teams) |
A current list of sub-processors is available on request and, where applicable, in our DPA.
Note that some services are connected by you using your own provider accounts (see Section 6) — for example email (Amazon SES), WhatsApp (the Meta WhatsApp Business Platform), and phone/SMS. For those, the relevant provider processes data under your own agreement with that provider, and bills you directly.
Google API note: Where the Services use Google APIs (for example, to create or manage Google Meet classroom links), our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, and we do not transfer or sell it.
8.2 Other disclosures
We may also disclose personal data:
- To our professional advisers (lawyers, accountants, auditors, insurers)
- To Customers (institutes) in relation to their authorised users and Customer Data
- In connection with a merger, acquisition, financing, or sale of assets (subject to appropriate confidentiality)
- Where required by law, regulation, court order, or a lawful request from a public authority
- To establish, exercise, or defend legal rights, or to protect the safety and security of our users and Services
9. International data transfers
Some of our providers process data outside the United Kingdom (for example, in the European Economic Area or the United States). Where we transfer personal data outside the UK, we ensure an appropriate safeguard is in place, such as:
- Transfers to countries covered by UK adequacy regulations; or
- The International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus any additional measures required.
You can request more information about the specific safeguards we apply using the contact details in Section 16.
10. How long we keep personal data
We keep personal data only for as long as necessary for the purposes set out in this policy, including to satisfy legal, accounting, tax, or reporting requirements.
- Account and Customer Data: retained for the duration of the subscription and, after termination, for a limited period to allow export/retrieval, after which it is deleted or anonymised in line with our DPA and Customer instructions.
- Billing and transaction records: retained for the period required by UK tax and company law (generally 6 years).
- Marketing data: retained until you unsubscribe or withdraw consent, plus a short suppression period.
- Logs and security data: retained for a limited period appropriate to the purpose.
Specific retention periods are set out in our internal retention schedule and, for Customer Data, in our DPA. When data is no longer needed, we securely delete or anonymise it.
11. How we protect personal data
We implement appropriate technical and organisational measures to protect personal data, including:
- Encryption of data in transit (TLS) and encryption of stored files at rest
- Encryption of chat and telephony communications data, configured so that it is accessible only to the relevant Customer’s authorised users
- Role-based access controls and the principle of least privilege
- Authentication controls and audit logging
- Network and application security measures, regular updates, and monitoring
- Use of reputable, security-certified infrastructure providers
- Staff confidentiality obligations and data protection training
No method of transmission or storage is completely secure, but we work to protect personal data and to maintain procedures for handling any suspected data breach, including notifying the ICO and affected individuals where required by law.
12. Your data protection rights
Subject to certain conditions and exemptions, you have the following rights under the UK GDPR:
- Right to be informed — about how we use your data (via this policy)
- Right of access — to a copy of the personal data we hold about you
- Right to rectification — to correct inaccurate or incomplete data
- Right to erasure — to have your data deleted in certain circumstances
- Right to restrict processing — in certain circumstances
- Right to data portability — to receive certain data in a portable format
- Right to object — to processing based on legitimate interests and to direct marketing at any time
- Rights related to automated decision-making and profiling — we do not make decisions producing legal or similarly significant effects based solely on automated processing
- Right to withdraw consent — where we rely on consent
To exercise any right, contact us using the details in Section 16. We will respond within one month (extendable by two further months for complex requests). Exercising your rights is free of charge in most cases.
If you are an end user of an institute (e.g. a student, parent, or staff member), please contact your institute directly, as they are the Controller of that data. We will assist them as Processor.
13. Marketing communications
We may send you marketing about our products and services where you have consented or where we are otherwise permitted to do so. You can opt out at any time by using the “unsubscribe” link in our emails or by contacting us. Opting out of marketing does not affect service or transactional messages necessary to operate your account.
14. Cookies and similar technologies
We use cookies and similar technologies on our websites and Platform. For details of the cookies we use and how to manage your preferences, please see our separate Cookie Policy.
15. Children
The Services are intended for use by institutes and their authorised adult staff. We do not knowingly collect personal data directly from children for our own purposes. Where Customers process student data (which may relate to children) within the Platform, the Customer is the Controller and is responsible for the lawful basis and any required parental/guardian consent.
16. How to contact us and complaints
For any questions, requests, or concerns about this Privacy Policy or our processing of personal data:
We Starter Ltd
52-54 Stourbridge Road, Stourbridge, England, DY9 7DL
Email: privacy@westarter.com
If you are not satisfied with our response, you have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner’s Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
We would, however, appreciate the chance to address your concerns before you approach the ICO, so please contact us first.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will post the updated version on this page and update the “Last updated” date. Where changes are significant, we will provide additional notice (for example, by email or an in-Platform notice).