Overview for Schools

Data Protection Compliance Overview and Frequently Asked Questions

Correct as of August 2026 - updated as needed

Download this overview

Download PDF

Introduction

This document explains how Grupop approaches its obligations under applicable data protection law. It is intended for teachers, schools, pupils, parents and users of Grupop.

The FAQs cover the questions we are most often asked - the personal data collected, how long data is retained, and the data processor and data controller roles.

This document is provided for information purposes only and does not constitute legal advice.

About Grupop

Grupop is an online classroom rewards platform for schools. It helps teachers manage classroom rewards in a fun, engaging way - motivating pupils through a simple points system displayed as animated cauldrons on a classroom screen.

Grupop was designed and created by an Irish teacher with 18 years’ teaching experience and qualifications in primary education, special education needs and computer software.

Grupop Classroom Limited is an Irish registered company, operating out of County Tipperary, Ireland.

Grupop is committed to protecting personal data, adhering to data protection principles and building trust with schools, teachers, parents/guardians and pupils.

Our Approach to Data Protection Compliance

Grupop takes its data protection obligations seriously. Privacy by design and default was at the forefront in the design, build and functionality of Grupop.

Our approach is built on the following principles:

  • Accountability - we maintain documented policies, procedures and records to demonstrate compliance with the data protection principles set out in Article 5 GDPR.
  • Privacy by design and by default - data protection is embedded in Grupop, our processes and services from the outset.
  • Transparency - we provide clear information to schools, teachers, pupils and any other stakeholders on how Grupop works and about how personal data is collected, used, shared and retained.
  • Data minimisation - the design of Grupop has always focused on data minimisation, including the collecting and having access to the minimum amount of personal data, and ensuring that Grupop is data controller of the minimum amount of personal data necessary to ensure functionality and service.
  • Storage limitation - data is only retained for as long as necessary. Please see specific details below.

Key definitions

What is personal data?

Any information relating to an identified or identifiable natural person (a ‘data subject’) - for example a name, an identification number, location data, an online identifier, or factors specific to that person’s physical, economic, cultural or social identity.

What does processing under GDPR mean?

Any operation or set of operations performed on personal data, whether or not by automated means - including collection, recording, organisation, storage, alteration, retrieval, use, disclosure, restriction, erasure or destruction.

What is a data controller?

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data - in other words, the party that decides why and how personal data is used.

What is a data processor?

The natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller - acting only on the controller’s instructions and not for its own purposes.

FAQs

1. How does Grupop comply with its data protection obligations?

Privacy first is at the core of Grupop’s design. As set out above, Grupop’s design was built with a focus on the GDPR principles.

Grupop is built on a Zero-Knowledge design principle. Grupop is designed to collect only the minimum amount of data required to provide the Grupop services.

2. Where does Grupop store personal data?

Grupop is hosted in the EU.

3. Does Grupop transfer data outside of the EU?

Grupop does not transfer data outside the EU. However, the payment provider, Stripe, may process data outside the EU. Stripe has the necessary safeguards in place to compliantly process data from the EU outside the EU.

4. How does Grupop comply with its transfer obligations?

Grupop is hosted in the EU.

We will only transfer your personal data where the transferee is based in a country that has been granted adequacy status by the EU Commission, or where there are appropriate safeguards in place to protect your personal data e.g. standard contractual clauses.

5. Does Grupop process special category data?

No, Grupop does not and is not designed to process special category data (such as health data, racial or ethnic origin, or religious beliefs).

6. What are Grupop’s technical and organisational measures?

Grupop has in place appropriate technical and organisational measures including:

  • Zero-Knowledge architecture - Grupop cannot itself identify pupils from the data held within the platform
  • Pseudonymisation and encryption of personal data
  • Data minimisation by design, so that only the data necessary to provide the service is collected
  • Role-based access controls, limiting access to those who require it
  • EU-based hosting with reputable infrastructure providers
  • Due diligence and data processing agreements with all suppliers
  • Annual archiving and deletion of class and pupil data
  • Audit trails of key actions within the platform (for example, pupil removed or name corrected)
  • Passwords are stored using industry-standard hashing (never in plain text)
  • Data is stored on Microsoft Azure infrastructure which maintains its own extensive security certifications
  • Microsoft Defender for Storage is enabled on our file storage to detect and prevent malicious uploads
  • Personal data will only be processed by third parties on our instructions. Third parties are subject to appropriate data protection, security and confidentiality terms

7. Who is responsible for data protection compliance within Grupop?

Grupop Classroom Limited is responsible for data protection compliance within Grupop.

8. Does Grupop have a Data Protection Officer (DPO)?

Grupop is not required under the GDPR to appoint a DPO. As per question 7, Grupop.ie Limited is responsible for data protection compliance within Grupop.

9. Does Grupop engage suppliers and what due diligence does Grupop conduct on its suppliers?

Grupop only engages trusted suppliers with robust data protection programmes in place.

10. Does Grupop enter into DPAs with its suppliers?

Yes.

11. How long does Grupop retain personal data?

All class/pupil data is archived on 31 July annually.

To retain data for the next Grupop academic year, the teacher must subscribe for that year and submit carry-forward choices in Grupop. Both steps are required by 30 October. Paying without submitting choices does not retain class data - it is deleted on 31 October.

Where renewal is not completed (payment and choices) by 30 October, the data is deleted on 31 October annually.

12. What personal data is Grupop the data controller of?

Grupop is the data controller of account data (e.g. email address, subscription details).

13. What personal data is Grupop the data processor of?

Grupop is the data processor of the pupil data. Grupop processes pupil data on behalf of the school or teacher and for the purpose of providing the Grupop platform.

14. What personal data is the school the data controller of?

The school is the data controller for pupil data. The teacher uses Grupop under the authority of their school and is responsible for ensuring that use complies with their school’s applicable policies and procedures.

Pupil data includes the following:

  • Pupil first name only
  • Avatar customisation choices (predefined digital illustrations provided by Grupop - no pupil photos or images)
  • Group membership within the class
  • Pop count (reward progress)

In addition, the configuration data for teacher resources, pupil’s internal ID, the class ID, the teacher’s ID, the type of action (e.g. pupil removed, name corrected), and the date/time (timestamp) are processed.

Pupil surnames, email addresses, dates of birth, photographs, or any other pupil personal information other than outlined above are not required to use Grupop.

15. How does Grupop handle data subject requests?

Where the school is the data controller Grupop will assist the school in responding to any data subject request.

Where Grupop is the data controller (e.g. admin and account data) requests should be sent to welcome@grupop.ie. Grupop will respond in compliance with its obligations under the GDPR.

16. Is Grupop compliant with the National Schools’ Acceptable Use Policy guidelines?

Grupop is designed with the INTO/DES guidelines for digital tools in primary schools in mind, including:

  • Data minimisation compliance
  • Zero-Knowledge architecture
  • Grupop is hosted in the EU
  • No advertising or tracking utilised
  • No social media features
  • No pupil-to-pupil communication
  • Annual data deletion
  • Teacher-controlled at all times

Further Information

If you have any questions about this document or about Grupop’s data protection practices, please email: welcome@grupop.ie

Data Processing Agreement (DPA)

Download DPA