Effective 9 June 2026

Privacy Notice

This notice explains how IntelComms Ltd collects, uses, and protects personal information, including the data of parents, pupils, and school staff processed through our platform.

Who we are Our commitments About this notice Data controller vs processor What we collect Parent & pupil data Lawful basis Sub-processors Sharing & access Security Retention Automated processing Children's data Your rights Safeguarding data Changes Contact

Who we are

We are IntelComms Ltd, a company registered in England and Wales. IntelComms provides an AI-powered WhatsApp communication service for UK primary schools, enabling schools to answer parent queries automatically, log absences, and escalate safeguarding concerns.

Our data protection commitments

About this notice

This Privacy Notice, together with our Terms of Service, sets out how IntelComms handles personal data. It applies to:

We will update this notice when we change how we process data. We will notify schools of material changes with at least 30 days' notice.

Data controller vs data processor

This distinction matters for schools' own GDPR compliance.

IntelComms as Data Controller

IntelComms acts as a Data Controller for information we collect directly to run our business, such as the contact details of staff who sign up for a trial or subscription.

IntelComms as Data Processor

When a school uses the IntelComms platform, the school is the Data Controller for all personal data processed through the service, including parent messages, pupil absence records, and safeguarding logs. IntelComms acts as the school's Data Processor, processing data only on the school's instructions and in accordance with our Data Processing Agreement (DPA). Schools may view our Data Processing Agreement online, or request a signed copy by emailing contact@intelcomms.co.uk.

Our Terms of Service, together with a Data Processing Agreement containing the terms required by Article 28(3) UK GDPR, constitute the written contract required to legitimise this processing relationship. Schools should ensure parents are informed that an AI-powered WhatsApp messaging service is in operation via their school's own privacy notice.

As your Data Processor, IntelComms will assist schools, taking into account the nature of the processing and the information available to us, with data protection impact assessments (DPIAs), responses to data subject requests, and consultations with the ICO, in line with Article 28(3) UK GDPR. Because the service involves automated processing of children's data and special category (safeguarding) data using AI, we recommend that every school completes a DPIA before going live, and we can provide information to support it.

What we collect as Data Controller

When you contact us or sign up

When a school enquires about IntelComms, requests a free trial, or becomes a subscriber, we collect:

Purpose: To manage enquiries, set up and administer accounts, provide onboarding support, and deliver the service.

Lawful basis: Contract, this processing is necessary to fulfil or prepare to fulfil our agreement with the school.

Retention: We retain this information for the duration of the subscription and for up to 12 months following closure of an account, unless a longer period is required by law.

When you visit our website

We may use analytics tools to collect anonymised information about how visitors use intelcomms.co.uk. This does not identify individuals and is used solely to improve the website. We do not use advertising or cross-site tracking cookies. Where any analytics cookies or similar technologies that are not strictly necessary are used, we will request your consent first in line with the Privacy and Electronic Communications Regulations (PECR).

Lawful basis: Legitimate interests, understanding how schools find and use our website helps us improve it.

Parent, guardian & pupil data

This is the most sensitive data processed through IntelComms.

What is processed

How messages are processed

When a parent sends a WhatsApp message to the school's IntelComms number, the message is received by our backend, passed to Anthropic's Claude AI to generate a response using only the school's approved documents, and the response is sent back to the parent via Meta's WhatsApp Cloud API. The message and response are logged in the school's secure dashboard.

Important for schools: Schools must inform parents that their WhatsApp messages to the school number will be processed by an AI system. This should be included in the school's own privacy notice and communicated to parents when the service is introduced.

Lawful basis for processing parent and pupil data

IntelComms processes parent and pupil data as a Data Processor, on behalf of the school as Data Controller. The school is responsible for establishing and documenting the lawful basis for this processing. We recommend schools rely on one or more of the following:

Special category and criminal offence data

Safeguarding and welfare information is special category data under Article 9 UK GDPR, and may in some cases include criminal offence data under Article 10. Processing this data lawfully requires an additional condition beyond the Article 6 lawful bases listed above:

IntelComms processes special category and criminal offence data only as a Data Processor, on the documented instructions of the school, and applies the enhanced access controls described in the Safeguarding data section.

Note for academies and independent schools: The Public Task basis applies to maintained schools exercising statutory functions. Academies and independent schools are independent legal entities and may need to rely on Legitimate Interests or Consent as the lawful basis for some processing. Schools are encouraged to seek advice from their DPO to confirm the appropriate basis for their specific circumstances.

In our capacity as Data Controller (for school staff contact details), our lawful basis is Contract for account management and Legitimate Interests for website analytics.

Sub-processors

We use the following sub-processors to deliver the IntelComms service. Each has been assessed for GDPR compliance and is covered by a data processing agreement.

Sub-processor Purpose Data location
Supabase Database, stores all school data, parent messages, absence records, and safeguarding logs EU West (Ireland)
Anthropic (Claude AI) AI response generation, message content is passed to the Claude API to generate replies based on school documents United States (UK International Data Transfer Agreement / UK Addendum to the EU SCCs applies)
Meta (WhatsApp Cloud API) Message delivery, sends and receives WhatsApp messages between parents and the school number United States (UK International Data Transfer Agreement / UK Addendum to the EU SCCs applies)
OpenAI Embeddings, used to convert school documents and the text of parent messages into a numerical index so the AI can retrieve the most relevant information. Document text and message content (which may contain personal data) are processed by this sub-processor for this purpose United States (UK International Data Transfer Agreement / UK Addendum to the EU SCCs applies)
Railway Backend hosting, runs the IntelComms API that connects all components EU West (Ireland)
Resend Email, sends safeguarding alerts and system notifications to school staff EU / EEA (transfers from the UK covered by the UK adequacy regulations)

Where personal data is transferred outside the UK, we put in place an appropriate safeguard for the transfer. For transfers to the European Economic Area we rely on the UK's adequacy regulations. For transfers to the United States and other third countries we use the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment.

We will give schools no less than 30 days' written notice before adding any new sub-processor that processes personal data, during which a school may object to the change on reasonable data protection grounds.

Sharing and access to personal information

School authorised users

School staff designated as Authorised Users by the school will have access to parent messages, absence records, and safeguarding logs through the IntelComms dashboard. The school is responsible for managing who has access and for removing access when staff leave.

IntelComms employees

Authorised IntelComms employees may access school data solely for the purpose of providing support, investigating technical issues, or fulfilling legal obligations. All such access is logged. Employees sign confidentiality agreements and are trained in data protection.

Legal requirements

We may disclose personal information to third parties where required to comply with a legal obligation, prevent fraud, protect the safety of individuals, or enforce our Terms of Service.

Sale or transfer of business

If IntelComms Ltd or substantially all of its assets are sold or transferred, schools will be notified in advance and personal data may be transferred to the acquiring organisation subject to the same protections as this notice.

Security

Our technical and organisational security measures include:

Where IntelComms acts as Data Controller (for example, for school staff contact details), we will report a qualifying personal data breach to the ICO without undue delay and, where feasible, within 72 hours, as required by UK GDPR. Where IntelComms acts as Data Processor (for parent, pupil, and safeguarding data), we will notify the affected school without undue delay after becoming aware of a personal data breach, so that the school, as Data Controller, can meet its own reporting obligations to the ICO and, where required, to affected individuals.

Retention

We retain personal data only for as long as necessary for the purposes for which it was collected:

On termination of a subscription, we will delete or return all Customer Data within 30 days of written request, except where retention is required by law.

Automated processing and decision-making

IntelComms uses AI to generate responses to parent messages automatically, without a human reviewing each message before it is sent.

What is automated

What is not automated

IntelComms does not make automated decisions with legal or similarly significant effects on data subjects within the meaning of Article 22 UK GDPR. Specifically:

Your right to human review

Any parent who receives an AI-generated response may ask to speak with school staff at any time, and may ask the school to review any response they believe was inaccurate. Schools can configure IntelComms to direct parents to the office for any query type.

Your rights

Under UK GDPR, individuals have the following rights in relation to their personal data:

For parents and pupils: Because IntelComms acts as a Data Processor on behalf of your school, requests relating to data processed through the service (messages, absence records, safeguarding logs) should in the first instance be directed to your school as the Data Controller. The school will then instruct us accordingly.

For school staff: Requests relating to your contact details held by IntelComms as Data Controller should be sent to contact@intelcomms.co.uk.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been handled unlawfully.

Children's data

IntelComms processes information about pupils as part of absence logging and safeguarding alerting. This processing is carried out on behalf of the school as Data Controller. Pupils' data processed through IntelComms includes names, year groups, and dates of birth, used solely to verify the parent-pupil relationship and to attribute absence records correctly.

IntelComms is not directed at children. The service is designed exclusively for use by parents, guardians, and school staff. Children do not interact with IntelComms directly. The ICO's Children's Code (Age Appropriate Design Code) does not apply to IntelComms as it is not an online service likely to be accessed by children.

Schools should ensure that their own privacy notices and parent communications make clear that IntelComms processes pupil reference data (name, year group, date of birth) solely for the purposes described above.

Safeguarding data

IntelComms scans every inbound parent message for content that may indicate a welfare concern, including references to harm, abuse, neglect, or distress. Where such content is detected:

Safeguarding logs are retained for a minimum of 7 years. Access is restricted to Authorised Users with DSL-level access and to authorised IntelComms personnel for support purposes.

For schools: IntelComms is a communication tool, not a safeguarding case management system. Schools remain responsible for all safeguarding decisions and actions following an alert. The IntelComms audit trail supports, but does not replace, the school's own safeguarding records and processes.

Changes to this notice

We will update this notice from time to time as we develop new features, in response to legal changes, or when we change how we process data. Schools will be notified of material changes with at least 30 days' written notice.

9 June 2026
Added Article 9/10 special category and criminal offence data conditions and the Appropriate Policy Document requirement; clarified the international transfer mechanism (UK IDTA / UK Addendum and adequacy regulations); corrected the description of data sent to sub-processors for embeddings; split personal data breach notification responsibilities between IntelComms as controller and as processor; added DPIA assistance, a sub-processor objection right, and a PECR cookies statement.
18 May 2026
Initial publication of IntelComms Privacy Notice.

Contact us

If you have any questions about this Privacy Notice, want to exercise your rights, or have concerns about how your data is handled, please contact us:

Email: contact@intelcomms.co.uk

Website: intelcomms.co.uk

Post: IntelComms Ltd, [Registered Address]

We aim to respond to all data protection enquiries within 5 business days. For formal subject access requests, we will respond within one calendar month as required by UK GDPR.