Nomass.AI develops education technology and applied AI for nurseries, training providers and colleges, as part of the ASKN Ltd ecosystem.
For the purposes of UK data protection law, the data controller for this website is [Registered legal entity name], a company registered in England and Wales under company number [company number], with its registered office at [registered office address]. We are registered with the Information Commissioner's Office under registration number [ICO registration number].
Our Data Protection Officer / data protection lead is [name or role title, and contact address].
It matters which relationship you have with us, because our responsibilities differ.
We are the data controller. We decide what information is collected here and why. This policy explains that in full.
Where a nursery, training provider or college uses software developed by Nomass.AI, that organisation is the data controller for the information held about its children, learners, parents and staff. We act as a data processor, handling that information only on the organisation's documented instructions and under a written data processing agreement.
If you are a parent, carer or learner and you want to see, correct or delete records held about you or your child, please contact the nursery, college or training provider directly. They control those records. We will support them in responding, but we cannot act on those records without their instruction.
We keep this deliberately minimal. Through this website we collect:
We use Google Fonts to load the typefaces on this site. When a page loads, your browser requests those font files from Google, and your IP address is visible to Google as part of that request. [Consider self-hosting the fonts to remove this transfer entirely]
We do not use advertising pixels, behavioural tracking, or third-party analytics on this website, and we do not buy or sell personal information.
| What we do | Why | Lawful basis |
|---|---|---|
| Reply to your enquiry or demo request | To answer the question you asked us | Legitimate interests — responding to a request you initiated |
| Discuss pilots, partnerships or integrations | To explore working together | Legitimate interests, or steps prior to entering a contract |
| Keep the website secure and available | To prevent abuse and diagnose faults | Legitimate interests — network and information security |
| Meet legal and regulatory obligations | Record-keeping, accounting, responding to regulators | Legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you can object at any time — see Your rights.
This website is aimed at education professionals and organisations. It is not directed at children, and we do not knowingly collect personal information about children through it. Please do not submit information about a child through the enquiry form. If you believe a child's information has been sent to us in error, contact us and we will delete it.
Children's and learner information is processed within our software, not through this website — and there we act as a processor for the education setting, as described in section 2. In that role we are committed to:
Our software may hold information that UK data protection law treats as special category or otherwise sensitive — including SEND records, health information, safeguarding records and, where a setting records it, information about ethnicity or religion.
We process this only as a processor, on the instructions of the education setting, and only where that setting has identified a valid lawful basis and an Article 9 condition. We apply additional access restrictions to this information within our systems. We do not use it for our own purposes.
We do not sell personal information. We share it only where necessary:
Where we act as a processor for an education setting, we do not share that setting's data with anyone except the sub-processors named in our agreement with them, and we notify them of changes.
Nomass.AI works across the United Kingdom, Saudi Arabia and the wider GCC. This means personal information may in some circumstances be accessed from, or transferred to, countries outside the UK.
Where that happens, we put in place a transfer mechanism recognised under UK law — such as the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — together with a transfer risk assessment. [Specify which countries, which mechanism, and where each system is hosted. This is the section a data protection auditor will examine most closely.]
Where we hold information as a processor, retention is set by the education setting in its agreement with us, and we delete or return the information at the end of the contract on their instruction.
We apply technical and organisational measures appropriate to the sensitivity of the information, including encryption in transit, role-based access control, authentication controls, audit logging, backups, and staff access on a need-to-know basis. [Add specifics you can actually evidence — e.g. encryption at rest, penetration testing schedule, Cyber Essentials or ISO 27001 status, breach response times]
If a personal data breach occurs, we will report it to the ICO where required within 72 hours of becoming aware, notify affected individuals where the risk to them is high, and — where we act as a processor — notify the education setting without undue delay.
Nomass.AI develops AI-assisted functionality intended to reduce administrative work and surface information for professional attention. Our position is that AI supports professional judgement rather than replacing it.
We do not make decisions producing legal or similarly significant effects about any individual by solely automated means. Where our software highlights a pattern, drafts text or flags something for review, the outcome remains subject to the judgement of a qualified professional at the education setting. Assessment, safeguarding, SEND and other regulated decisions always remain with the setting's staff.
We do not use children's or learners' personal information from customer settings to train general-purpose AI models. [Confirm this reflects your actual technical practice before publishing — it is a commitment you must be able to stand behind.]
This website does not set cookies, and does not use local storage, analytics or advertising trackers. If that changes — for example if we add analytics — we will update this policy and, where the law requires it, ask for your consent first.
Under UK data protection law you have the right to:
To exercise any of these, email privacy@nomass.ai. We will respond within one month. There is no charge in normal circumstances.
If your request concerns records held by a nursery, college or training provider using our software, please contact that organisation — see section 2.
If you have a question or concern about how we handle personal information, contact us first at privacy@nomass.ai and we will try to resolve it.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority:
We update this policy when our practices change. The date at the top shows when it was last revised. Where changes are significant, we will make that clear on this page.