top of page

Privacy Policy

Oracy Spark · Last updated 25 August 2026

1. Who we are

Oracy Spark is operated by David Currie, a sole trader trading as David Currie Education. For UK data-protection law, David Currie is the controller of the personal information described in this policy.

Contact: hello@oracyspark.com

2. Scope

This policy explains how we use personal information about website visitors, prospective and current school customers, account users and people who contact us. Oracy Spark is not designed to collect pupil personal information. Schools must not enter or upload pupil names, responses, safeguarding information or other pupil personal data.

3. Information we collect

Identity and contact information: name, role, email address, telephone number if supplied, school or organisation, and correspondence.

Account information: username or email, subscription status, login and security information, and account preferences.

Transaction information: purchases, invoices, payment status, renewal and cancellation records. Wix Payments and its payment partners process card or bank details; we do not ordinarily receive or store full card details.

Technical and usage information: IP address, device and browser information, dates and times of access, pages or features used, referral information, cookie identifiers and diagnostic/security logs.

Marketing information: communication preferences, campaign interactions and records of consent or objection where relevant.

We generally obtain information directly from the individual or the School, automatically through the website, and from service providers involved in hosting, accounts, analytics and payments.

4. Why we use information and our lawful bases

To set up accounts, provide access, administer subscriptions, take payment, renew or cancel subscriptions, provide support and enforce the Terms: necessary for our contract with the School and/or our legitimate interests in delivering and managing the service.

To maintain financial, tax and business records and respond to lawful requests: legal obligation and legitimate interests.

To secure, diagnose, prevent misuse of and improve the service: legitimate interests in operating a safe, reliable and useful service.

To respond to enquiries and manage our relationship with schools and contacts: legitimate interests and, where relevant, steps connected with a contract.

To send service messages such as receipts, account notices, security notices and renewal reminders: contract and legitimate interests. These are not optional marketing messages.

To send marketing: consent where required by electronic-marketing law, or legitimate interests where the law permits business-to-business marketing. Every marketing email will provide an unsubscribe or objection route.

To use non-essential cookies or similar technologies: consent, where required. See the Cookie Policy.

Where we rely on legitimate interests, we consider whether the use is necessary and balance our interests against the individual’s rights. Individuals may object as explained below.

5. Who receives information

We disclose personal information only where reasonably necessary. Recipients may include:

Wix and Wix Payments, which provide website hosting, member accounts, subscription, communication and payment functionality;

payment, banking and fraud-prevention partners used by Wix Payments;

email, workspace, analytics, cookie-management, IT support, professional advisory and bookkeeping providers that we use;

HM Revenue & Customs, regulators, courts, law-enforcement bodies or other authorities where required or permitted by law; and

a genuine purchaser or successor if the business is sold or reorganised, subject to appropriate confidentiality and data-protection safeguards.

We do not sell personal information.

6. International transfers

Some service providers may process information outside the United Kingdom. Where UK data-protection law restricts a transfer, we rely on an applicable adequacy regulation, approved contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum, or another lawful transfer mechanism. Information about the safeguards relevant to an individual may be requested from us.

7. Retention

Account and subscription information: for the subscription and normally up to 24 months afterwards, unless needed longer for a dispute, security issue or legal claim.

Financial, invoice and transaction records: normally at least five years after the relevant 31 January tax-return deadline, or longer where tax law or an enquiry requires it.

Routine enquiries and support correspondence: normally up to 24 months after the matter closes.

Cancellation, consent, unsubscribe and objection records: as long as reasonably needed to honour the request and demonstrate compliance.

Technical, security and analytics records: according to the settings and retention periods of the relevant service, minimised where possible and not kept longer than needed for security, diagnosis or analysis.

We may retain information longer where necessary to establish, exercise or defend legal claims, comply with a legal duty, investigate fraud or resolve a dispute. We securely delete or anonymise information when it is no longer needed.

8. Cookies

We use cookies and similar technologies for site operation, security, member login, preferences, payments and, subject to the visitor’s choices, analytics or marketing. Non-essential technologies are controlled through the website’s cookie-consent settings. See the Cookie Policy for more information.

9. Security

We use reasonable technical and organisational safeguards appropriate to the nature of the information, including access controls, secure service providers, account authentication and proportionate monitoring. No online service can guarantee absolute security. Users must protect their login details and notify us promptly of suspected compromise.

10. Individual rights

Depending on the circumstances, an individual may have rights to:

be informed about our use of personal information;

request access to personal information;

request correction of inaccurate or incomplete information;

request deletion or restriction of processing;

object to processing based on legitimate interests and object at any time to direct marketing;

receive certain information in a portable format; and

withdraw consent at any time, without affecting earlier lawful processing.

These rights are not absolute. To exercise one, email hello@oracyspark.com. We may ask for proportionate information to verify identity and will respond within the period required by law.

We do not currently use personal information to make solely automated decisions producing legal or similarly significant effects.

11. Complaints

Please contact us first so that we can try to resolve the concern. Individuals also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk or by using the contact details published there.

 

12. Changes

We may update this policy to reflect changes in the service, providers or law. The current version and update date will be published on the website. We will give appropriate notice where a change materially affects individuals.

© Oracy Spark. All rights reserved.

All content, including prompts, resources, and materials, is protected by copyright law.

No part of this website may be reproduced, distributed, or transmitted in any form without prior written permission.

Contact: hello@oracyspark.com

 

Policies

FAQ

​​​

bottom of page