Summary: TrendShield does not monitor students, families, or private communications. We collect only the minimum information needed to provide our service to schools and safeguarding professionals. We process publicly available social media content to identify online risks to young people — we do not hold personal data about children.
1. Who we are
TrendShield ("we", "us", "our") is a safeguarding intelligence platform operated in the United Kingdom. We provide online risk monitoring and weekly safeguarding briefings to schools, multi-academy trusts, local authorities and safeguarding professionals.
For the purposes of UK data protection law, TrendShield is the data controller in respect of personal data processed through the TrendShield platform and website.
Contact details
Data Controller: TrendShield
Company number: 16995322
Website: trendshield.co.uk
Data protection enquiries: privacy@trendshield.co.uk
General contact: hello@trendshield.co.uk
If you have questions about how we handle your personal data, please contact us at privacy@trendshield.co.uk before raising a complaint with the ICO. We aim to respond to all data protection enquiries within 10 working days.
2. Data we collect
We collect different categories of information depending on your relationship with TrendShield.
School and organisation staff (registered users)
- Account information: Name, job title, role (e.g. Designated Safeguarding Lead), work email address
- Organisation information: School name, local authority, school type, age range served
- Authentication data: Hashed passwords, session identifiers (stored in HttpOnly cookies)
- Usage data: Pages visited, features used, alerts reviewed, briefings downloaded — used to improve the service
- Concern submissions: Information submitted via the concern submission tool (relating to potential safeguarding risks, not to individual children)
Website visitors
- Standard web server logs (IP address, browser type, referring page, timestamp) retained for up to 30 days for security monitoring
- Cookie preferences (see our Cookie Policy)
Pilot programme applicants
- Name, role, school name, local authority, school type, work email address
- Optional: freeform text describing your safeguarding challenges
What we do NOT collect
- Personal data about children or students
- Personal data about parents, carers or families
- Private social media content, direct messages or personal accounts
- Sensitive personal data (e.g. health, ethnicity, religion) unless voluntarily provided in a concern submission
- Biometric data
- Financial information beyond that processed by our payment provider for subscription billing
3. How we use your data
| Purpose | Data used |
|---|---|
| Providing the TrendShield platform and school dashboard | Account, organisation, and session data |
| Generating and delivering weekly safeguarding briefings | Organisation data (school type, age range, region) |
| Sending risk alerts and notifications | Work email address, notification preferences |
| Improving the accuracy and relevance of our intelligence | Anonymised usage data, feedback |
| Processing pilot programme applications | Applicant contact and organisation details |
| Responding to enquiries and support requests | Contact details, message content |
| Complying with legal obligations | As required by applicable law |
| Detecting and preventing fraud and misuse | Log data, session data |
We do not use your personal data for marketing to third parties, and we do not sell or rent personal data to any third party.
4. Legal basis for processing
We rely on the following lawful bases under UK GDPR Article 6:
| Processing activity | Legal basis |
|---|---|
| Providing the platform to registered users | Contract (Article 6(1)(b)) — necessary to fulfil our agreement with your school or organisation |
| Sending service communications (alerts, briefings) | Contract (Article 6(1)(b)) |
| Security monitoring and fraud prevention | Legitimate interests (Article 6(1)(f)) — to protect our platform and users |
| Improving the platform through usage analytics | Legitimate interests (Article 6(1)(f)) — to make TrendShield more useful to safeguarding professionals |
| Responding to enquiries | Legitimate interests (Article 6(1)(f)) |
| Complying with legal obligations | Legal obligation (Article 6(1)(c)) |
| Optional analytics cookies | Consent (Article 6(1)(a)) |
5. Data retention
We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law.
| Data type | Retention period |
|---|---|
| Active user accounts | Duration of the subscription or access agreement, plus 30 days after closure |
| Closed or deleted accounts | Account data deleted within 30 days of closure; anonymised usage logs may be retained up to 12 months |
| Pilot programme applications | 12 months from application date, or duration of pilot, whichever is longer |
| Email enquiries and support tickets | 24 months from last correspondence |
| Web server logs | 30 days |
| Financial transaction records | 7 years (legal requirement) |
On request, we will delete your personal data sooner, subject to legal retention obligations.
6. Your rights under UK GDPR
As a data subject, you have the following rights. We will respond to all valid requests within one calendar month.
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may ask us to correct inaccurate or incomplete personal data.
- Right to erasure ("right to be forgotten"): You may request deletion of your personal data where we have no overriding legal obligation to retain it.
- Right to restriction of processing: You may ask us to pause processing in certain circumstances while a dispute is resolved.
- Right to data portability: Where processing is based on consent or contract, you may ask us to provide your data in a machine-readable format.
- Right to object: You may object to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Rights in relation to automated decision-making: We do not make solely automated decisions that produce legal or similarly significant effects about individuals.
To exercise any of these rights, email privacy@trendshield.co.uk. We may need to verify your identity before processing your request.
7. International data transfers
TrendShield is a UK-based platform. We aim to store and process all personal data within the United Kingdom or the European Economic Area (EEA).
Where we use third-party processors that may transfer data outside the UK/EEA (for example, AI processing services), we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the ICO or European Commission
- Processing only data that does not identify individual children or families
- Contractual restrictions on sub-processing and data retention
A list of our key third-party processors and their locations is provided in section 8 below.
8. Third-party processors
We use carefully selected third-party services to deliver the TrendShield platform. Each processor is bound by a data processing agreement and may only process data as instructed by us.
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Cloud database and authentication — stores account, organisation and session data | EU (AWS eu-west-1) |
| OpenAI | AI-powered trend analysis and briefing generation — processes trend content, not personal data | USA (SCCs in place) |
| Resend | Transactional email delivery (briefings, alerts, notifications) | USA (SCCs in place) |
| Google (Custom Search API) | Public web content discovery for trend monitoring — no personal data submitted | USA (SCCs in place) |
| YouTube (Google) | Public video content discovery for trend monitoring — no personal data submitted | USA (SCCs in place) |
| Replit (hosting) | Platform hosting and deployment infrastructure | USA (SCCs in place) |
We do not share personal data with advertisers, data brokers or any third party for their own commercial purposes.
9. Security measures
We apply industry-standard technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration or destruction. These include:
- TLS encryption for all data in transit
- Encrypted database storage at rest
- HttpOnly, Secure, SameSite session cookies — session identifiers are never exposed in URLs or local storage
- Role-based access control — staff can only access data relevant to their school
- Hashed password storage (passwords are never stored in plain text)
- Regular security reviews of platform code and dependencies
- Principle of least privilege for internal system access
In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay where required by law.
10. Children's data statement
TrendShield does not collect, store or process personal data about children.
Our platform is designed for use by safeguarding professionals — Designated Safeguarding Leads, deputy DSLs, school staff and trust safeguarding leads. TrendShield accounts are only available to adults acting in a professional safeguarding capacity.
Our trend monitoring activity analyses publicly available social media content at a population level to identify risk trends. We do not collect, profile or identify individual children, students or young people in this process.
Where a concern submission contains information about a child (for example, details of a safeguarding incident), this information is entered by the school's safeguarding professional and is handled in accordance with the school's own data protection policies. Schools using TrendShield remain the data controller for any pupil-related information they enter into the platform.
11. Public-source monitoring statement
TrendShield identifies online risks by monitoring publicly available content on social media platforms, public websites, and open internet sources. This includes:
- Publicly accessible posts, videos and content on TikTok, Instagram, YouTube and similar platforms
- Publicly indexed web content via search APIs
- Publicly visible trending topics and search signals
We do not:
- Access private messages, private accounts or restricted content
- Create profiles of individual social media users
- Monitor specific named individuals, students or families
- Use data obtained through data scraping that violates platform terms of service
Our AI systems analyse aggregated patterns in publicly available content to identify emerging risks — they do not identify, track or profile individual people. See our AI Transparency Notice for more detail.
12. ICO registration and complaints
TrendShield is registered with the Information Commissioner's Office (ICO) as required under UK data protection law. Our ICO registration number is ZC124009.
If you believe we have not handled your personal data in accordance with this policy or UK GDPR, you have the right to lodge a complaint with the ICO:
Information Commissioner's Office
Website: ico.org.uk
Helpline: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We encourage you to contact us directly at privacy@trendshield.co.uk before contacting the ICO — we would like the opportunity to address your concern first.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. When we make material changes, we will notify registered users by email and update the "Last updated" date at the top of this page.
Continued use of TrendShield after the effective date of an updated policy constitutes acceptance of the revised terms. If you do not agree with a material change, you may close your account by contacting us at privacy@trendshield.co.uk.