Everything your school needs to say yes
A ready-made pack for IT managers, DPOs and school leaders. Covers GDPR, data retention, security, safeguarding and everything else your procurement team needs.
What is Extended Essay Dashboard?
Extended Essay Dashboard is a structured, school-based digital platform that supports IB students through every stage of their Extended Essay — from initial idea to final submission. It provides milestone tracking, a research workspace, supervisor communication tools, and reflection journaling, all within a secure school-controlled environment.
Who is it for?
IB students writing their Extended Essay, their supervisors, EE Coordinators, and school administrators responsible for programme oversight.
What does it do?
Guides students through 18 structured milestones, tracks progress, enables supervisor feedback, logs reflections and manages research sources.
Who controls the data?
The school is the data controller. We act as a data processor operating strictly under the school's instructions and applicable data protection law.
Data Collection
Clear, proportionate, and limited to what is needed to run the service.
What we do collect
- Teacher and supervisor name and email address
- Student name and school year group
- Extended Essay project data (title, research question, subject)
- Milestone progress and supervisor feedback
- Reflection journal entries
- Meeting records between student and supervisor
- Research source lists annotated by the student
- Login timestamps and basic usage analytics
What we do NOT collect
- ✕ Dates of birth or identification numbers
- ✕ Medical, SEND or pastoral records
- ✕ Device identifiers or persistent tracking cookies
- ✕ Browsing history outside the platform
- ✕ Financial or payment details (handled by Stripe)
- ✕ Social media profiles or external accounts
- ✕ Biometric data of any kind
- ✕ Data from third-party ad networks
GDPR Readiness
We have designed the platform with UK and EU GDPR compliance in mind from the ground up.
Lawful basis
The subscribing school, as controller, determines the appropriate lawful basis for its student and staff processing. We process school data under the school’s documented instructions and our service contract.
Data minimisation
We collect only the data necessary for the educational management purpose. No excessive or redundant fields.
Retention limits
Active data is retained while needed to provide the service. Archive and deletion decisions follow the school’s controller instructions, applicable law and the hosting provider’s backup lifecycle.
Subject access
Students and staff can request access to their data. Schools can export and provide this directly from the platform.
Right to erasure
Schools can delete individual user records or request full school data deletion at any time.
DPA available
We can provide a Data Processing Agreement (DPA) for schools that require one. Contact us to request.
Data Storage & Retention
Where is data stored?
Platform data is hosted on Base44 managed cloud infrastructure in the UK data region. Base44 Support has confirmed completion of the migration for all our apps.
How long is data retained?
Active school data is retained while needed to provide the service. Schools can archive users, and deletion/retention requests are handled in line with the school’s controller responsibilities and applicable law.
What about deleted users?
Account deletion removes appropriate live application records. Records needed for school continuity or security may be retained only where appropriate, including de-identified audit records.
Are backups retained?
Residual backup copies are managed by the hosting infrastructure provider for disaster recovery and follow that provider’s backup lifecycle. They are not exposed through the live application.
Is data used for advertising?
No. Data is never used for advertising, marketing profiling or sold to any third party.
Is student data used to train AI?
No. Student data is not used to train public AI models. Any AI-assisted features within the platform operate on anonymised or user-initiated prompts only.
Can we request deletion?
Yes. Schools can request deletion of school data by contacting hello@extended-essay.com. We will work with the school as controller to scope and complete the request, subject to applicable legal, contractual and infrastructure requirements.
Breach notification
If we become aware of a personal-data breach affecting school data, we will notify the affected school as controller without undue delay and provide information reasonably required for its regulatory assessment.
Security Overview
Technical and organisational measures in place to protect school and student data.
Encryption in transit
All data is transmitted over HTTPS/TLS.
School data isolation
Tenant-scoped records carry a school identifier and are protected by row-level security combining school scope, identity, role and assigned-supervisor ownership.
Role-based access
Students, supervisors, coordinators and admins each see only what their role permits.
Audit logging
Security-sensitive administrative actions are recorded in the application audit log, with additional operational logging provided by the hosting platform.
Access controls
Authentication is required for all non-public pages, with tenant and role authorization additionally enforced in the data layer.
Managed hosting
Hosted on Base44 managed infrastructure in the UK data region. Base44 Support has confirmed completion of the migration of all our apps to that region. Base44 states that it is SOC 2 Type II and ISO 27001 certified.
School Data Isolation
Tenant-scoped records carry a school identifier and are protected by row-level security in the data layer. Access rules combine school scope with authenticated identity, role and, where applicable, assigned-supervisor ownership. Interface filtering is an additional safeguard, not the primary security boundary.
Safeguarding & Student Privacy
Extended Essay Dashboard is designed for use with students aged 15–19 in international school settings. We take student privacy and online safety seriously.
The platform does not include public profiles, social feeds, or any feature that exposes student content to the public internet. All communication between students and supervisors happens within the closed school environment.
Authentication alone does not grant access to school data. A student must have a valid school invitation/provisioning record before a trusted school and role are assigned.
Sub-processors & Third-party Services
We use a small number of carefully selected third-party services to run the platform.
| Service | Purpose | Location |
|---|---|---|
| Base44 (hosting) | Cloud infrastructure and database hosting | United Kingdom — our apps have been migrated to the UK data region |
| Stripe | Payment processing (no student data shared) | USA / EU |
| Resend | Transactional email delivery | USA |
IT / DPO Approval Checklist
Use this checklist as a starting point for your school's internal sign-off process.
Get in touch
We're happy to answer compliance questions, provide a DPA, or book a call with your IT team.
Disclaimer: This page and the associated Approval Pack PDF are provided to support school due diligence and do not replace the school's own legal, data protection or procurement review. Schools should seek independent legal advice where required.