CentreFlow is an operational management tool. Safeguarding responsibilities remain entirely with the tuition centre. This statement clarifies how we handle sensitive data and where responsibility lies.
1. Safeguarding Responsibility
CentreFlow is a software platform, not an education provider or regulated service in its own right. All safeguarding responsibilities remain with the subscribing tuition centre, including:
- Carrying out appropriate DBS checks for all staff who work with children
- Maintaining up-to-date safeguarding policies and procedures
- Designating a Safeguarding Lead within their organisation
- Following statutory guidance including Keeping Children Safe in Education (KCSIE) where applicable
- Reporting and responding to safeguarding concerns in line with legal obligations
2. CentreFlow's Role
CentreFlow supports tuition centres in their operational management by providing digital tools to:
- Record and manage DBS certificate numbers and expiry dates
- Track staff safeguarding training completion and renewal dates
- Manage attendance registers and sign-in/sign-out records
- Store digital consent forms and signed acknowledgements
- Flag compliance gaps through the OFSTED Readiness module
These tools assist centres in maintaining their own compliance records. CentreFlow does not independently verify, validate, or monitor any safeguarding decision or concern.
3. Children's Data
Student data held within CentreFlow may relate to children under the age of 18. This data is particularly sensitive and is treated with additional care:
- Access to student records is restricted by role — staff users have limited access compared to managers
- Centre data is isolated so that no staff or manager from one centre can access another centre's student records
- Data is not shared with third parties except where necessary to deliver the platform (see Subprocessors)
- CentreFlow does not use children's data for any marketing, profiling, or commercial purpose
4. Sensitive Personal Data Categories
Some data recorded in CentreFlow may constitute special category data under UK GDPR, for example:
- Health or medical information entered in student notes
- Learning difficulties or educational needs mentioned in communications
Centres must ensure they have an appropriate lawful basis and explicit consent where required before recording sensitive category data. CentreFlow stores this information as provided and applies the same security controls as to all personal data.
5. Appropriate Access Controls
Tuition centres are responsible for ensuring that:
- Only authorised staff have user accounts within CentreFlow
- Staff user accounts are promptly deactivated when a staff member leaves
- Manager-level access is granted only to individuals who require it
- Passwords are kept confidential and not shared between users
6. Reporting a Concern
If you have a safeguarding concern relating to a child, you must follow your centre's safeguarding policy and report to the relevant statutory authority (e.g., local authority children's services or the police). CentreFlow does not operate a safeguarding referral process.
If you have a concern about how CentreFlow handles data: privacy@centreflow.co.uk