Skip to content
Legal Centre

Legal Centre

Privacy, data processing, information security, cookie use and sub-processor information for PE Blueprint schools and trusts.

Privacy Policy

Privacy Policy

Last updated: 17 September 2026

This Privacy Policy explains how Active365 Learning Group Ltd collects, uses, stores and protects personal information when you use PE Blueprint or visit our website.

1. Introduction

This Privacy Policy explains how Active365 Learning Group Ltd ("Active365", "PE Blueprint", "we", "our", "us") collects, uses, stores and protects personal information when you use the PE Blueprint platform or visit www.peblueprint.co.uk.

Company Name: Active365 Learning Group Ltd. Company Number: 17363516.

Registered Office: 8 Mercia Business Village, Torwood Close, Westwood Business Park, Coventry, England, CV4 8HX.

  • Visitors to our website
  • Schools using PE Blueprint
  • Multi-Academy Trusts
  • Local authorities
  • Authorised staff users
  • Enquiries made through our website

2. Our Role

For enquiries, marketing and account administration, Active365 acts as the Data Controller.

For customer data uploaded by schools, including pupil assessment information, Active365 acts as the Data Processor.

Where schools upload pupil information into PE Blueprint, the school generally remains the Data Controller, while Active365 acts as the Data Processor for that customer data.

  • What information is uploaded
  • Why it is processed
  • How long it should be retained

3. Information We Collect

School account information may include name, email address, job title, school name, telephone number, billing information and organisation details.

Schools may upload pupil information including first name, last name, year group, class, PE assessment results, progress records, Pupil Premium status, English as an Additional Language status and Special Educational Needs and Disabilities status.

The platform is designed specifically for PE delivery and assessment.

  • We do not require safeguarding records
  • We do not require medical records
  • We do not require social care records
  • We do not require disciplinary records

4. Information Collected Automatically

When using our website or platform we may collect technical information to help maintain security and improve performance.

  • IP address
  • Browser type
  • Operating system
  • Device information
  • Pages visited
  • Login activity
  • Session information

5. How We Use Information

We process information to provide PE Blueprint and related services. We never sell personal information.

  • Provide PE Blueprint
  • Create PE Readiness reports
  • Generate pupil assessment reports
  • Support curriculum planning
  • Deliver CPD resources
  • Provide customer support
  • Manage subscriptions
  • Maintain platform security
  • Improve platform functionality
  • Create anonymous national benchmarking

6. Lawful Basis

For our own business activities we rely on contract, legitimate interests, legal obligation and consent where appropriate.

Schools remain responsible for identifying the lawful basis for processing pupil information.

7. National Benchmarking

PE Blueprint provides benchmarking insights. Assessment data may be used only where it has been anonymised, aggregated and stripped of identifiable information.

No individual pupil, teacher or school will be identified without written permission.

8. Sharing Information

We only share information where necessary. Every provider is selected carefully and required to protect customer information appropriately.

  • Cloud infrastructure providers
  • Authentication providers
  • Payment providers
  • Email delivery providers
  • Analytics providers

9. International Transfers

Where customer information is transferred outside the UK, appropriate legal safeguards will be implemented.

10. Security

We protect information using appropriate technical and organisational measures. No online service can guarantee absolute security, but we continually work to maintain appropriate safeguards.

  • HTTPS encryption
  • Secure authentication
  • Restricted administrative access
  • Security monitoring
  • Software updates
  • Access controls
  • Secure cloud infrastructure

11. Data Retention

Customer data remains available during an active subscription. Following termination, schools may request export of their information or secure deletion.

Unless legally required otherwise, confirmed deletion requests will normally be completed within 30 days.

12. Individual Rights

Individuals may have rights including access, correction, deletion, restriction and objection. Requests relating to pupil information should normally be made through the school.

13. Contact

Email: legal@peblueprint.co.uk

Address: Active365 Learning Group Ltd, 8 Mercia Business Village, Coventry, CV4 8HX.

Data Processing Agreement

Data Processing Agreement

Version 1.0

This Data Processing Agreement forms part of every PE Blueprint subscription.

1. Parties

Data Controller: The subscribing School, Multi-Academy Trust or Local Authority.

Data Processor: Active365 Learning Group Ltd.

2. Purpose

Active365 processes personal information solely to provide PE Blueprint.

3. Subject Matter

Processing includes providing PE assessments, reporting, curriculum planning, PE Readiness scoring and progress tracking.

4. Duration

Processing continues for the duration of the subscription unless otherwise agreed.

5. Categories of Personal Data

Staff information may include name, email and job title. Pupil information may include first name, last name, year group, class, PE assessment results, progress records, Pupil Premium, EAL and SEND.

6. Categories of Data Subjects

The categories of data subjects covered by this agreement are listed below.

  • Pupils
  • Teachers
  • PE Leads
  • School Leaders
  • Authorised Staff

7. Processor Obligations

Active365 agrees to the following processor obligations:

  • Process information only on documented instructions
  • Maintain confidentiality
  • Implement appropriate security
  • Assist with Subject Access Requests
  • Assist with correction requests
  • Assist with deletion requests
  • Notify customers of qualifying personal data breaches without undue delay
  • Return or delete customer data at contract end
  • Ensure authorised Sub-processors provide appropriate protections

8. Confidentiality

Anyone authorised to access customer information must be subject to confidentiality obligations.

9. Security

Active365 maintains appropriate technical and organisational measures.

  • Encrypted transmission
  • Authentication controls
  • Restricted administrative access
  • Monitoring
  • Software updates

10. Personal Data Breaches

Where a qualifying personal data breach occurs, Active365 will respond without undue delay.

  • Notify the Customer without undue delay
  • Provide available information
  • Cooperate with investigations
  • Assist with legal obligations where reasonably required

11. Sub-processors

Active365 may appoint authorised Sub-processors where necessary. Appropriate contractual safeguards will be maintained.

12. International Transfers

Appropriate safeguards will be implemented where international transfers occur.

13. End of Contract

Schools may choose to receive an export or request secure deletion.

Information Security

Information Security Policy

Version 1.0

Active365 protects customer information through appropriate technical and organisational measures.

1. Purpose

Active365 protects school and pupil information through appropriate technical and organisational security measures.

2. Security Principles

We aim to protect confidentiality, integrity and availability.

3. Access Control

Access is restricted through appropriate account and administrative controls.

  • Individual accounts
  • Strong passwords
  • Least-privilege access
  • Administrative controls

4. Authentication

Users are responsible for keeping login credentials secure.

5. Encryption

Customer information is protected using encrypted HTTPS connections.

6. Platform Security

Security measures include software updates, monitoring, restricted administrative access and secure infrastructure.

7. Staff Responsibilities

Anyone authorised to access customer information must maintain confidentiality.

8. Incident Management

Security incidents are investigated promptly. Where a qualifying personal data breach affects customer information, schools will be notified without undue delay.

9. Business Continuity

Backups and recovery procedures are maintained where implemented to support service continuity.

10. Policy Review

This policy is reviewed periodically.

Sub-Processors

Sub-Processor Schedule

Version 1.0

Active365 may use carefully selected service providers to deliver PE Blueprint.

Purpose

Active365 uses carefully selected third-party providers to support delivery of PE Blueprint.

Where these providers process Customer Data, appropriate contractual safeguards are maintained.

Current Categories of Sub-processors

The categories of service providers below may support delivery, security and operation of PE Blueprint.

Service
Purpose
Cloud Hosting Provider
Platform hosting
Database Provider
Secure data storage
Authentication Provider
User login
Email Delivery Provider
System emails
Payment Provider
Subscription processing
Monitoring Provider
Platform performance

Sub-processor Standards

Every authorised provider must meet appropriate standards before processing Customer Data.

  • Protect Customer Data appropriately
  • Process information only where necessary
  • Operate under appropriate contractual protections where required

Request Information

Customers may request information about current authorised Sub-processors through our legal contact address.