Draft version: 27 August 2026
Who controls the data?
The commercial operator of InstructorLane is the controller for instructor account, billing, security and support data. Each instructor may separately act as controller for pupil information entered into their workspace. InstructorLane provides the hosted processing platform.
Information processed
Account identity and email, authentication and session information, subscription status, pupil contact and training records, lesson diary information, availability, instructor notes, progress evidence, payment records entered by the instructor, messages, technical logs and files uploaded to the workspace.
Purposes and lawful bases
Data is used to provide the contracted service, secure accounts, synchronise workspaces, process requested billing, prevent abuse, support users and meet legal obligations. Instructors must identify and document their own lawful basis for pupil records.
Cloud providers and international transfers
The service architecture may use Cloudflare for hosting/storage, Stripe for subscription billing, an email provider for recovery messages and a configured AI provider for optional AI requests. Appropriate contractual and transfer safeguards must be verified before production launch.
Retention and rights
Workspace data is retained while the account remains open, including when paid access is paused, unless deletion is requested or a documented retention rule applies. Individuals may have rights of access, correction, deletion, restriction, objection and portability. Requests should be sent to the verified privacy contact inserted before launch.
Pupil transparency
Instructors should give pupils an appropriate privacy notice explaining what they record, why, who receives it and how long it is retained.