Privacy Policy
Last updated 11 October 2026
Marqit is a parent-led revision service: an adult account holder creates the account and adds child profiles. This policy explains what personal data we collect, why, and the rights you and your children have. It is written to comply with the UK GDPR and the Data Protection Act 2018.
1. Who we are
Marqit Edge Limited (“Marqit”, “we”, “us”) is the data controller for the personal data described in this policy. You can reach us at admin@marqit.uk.
Registered office: 5 Belgrave Place, Chelmsford, Essex, CM2 6FR, United Kingdom. Company number: 17448384 (registered in England and Wales). ICO registration: ZC257902.
2. The parent-led model
Accounts may only be created by an adult (18 or over) — typically a parent or guardian. The account holder adds child profiles for the students who will use Marqit and is responsible for those profiles. By adding a child, you confirm you have parental responsibility for that child or are otherwise authorised to provide their information and consent to its processing as described here.
3. What we collect
Account holder (parent) data
- Email address and sign-in details. Sign-in is handled by our authentication provider; we never see or store your password.
- Account and billing status, and payment records if you subscribe to a paid plan.
Child profile data
- The child’s name (or nickname) and year group, as entered by the account holder.
- Mock exam attempts: the answers a child submits, scores, marking feedback, timing, and usage history.
Technical data
- Essential session cookies used to keep you signed in.
- Basic operational logs (e.g. error and request logs) generated by our hosting provider.
We do not require a child’s real name, email, date of birth, or any special-category data, and we ask that you do not enter more information about a child than is needed to use the service.
4. How and why we use data
- To provide the service — creating accounts and child profiles, running mock exams, and marking answers. Legal basis: performance of our contract with the account holder.
- To mark answers with AI — a child’s written answers and the relevant mark scheme are sent to our AI marking provider to generate a score and feedback (see section 5). Legal basis: performance of our contract.
- To keep the service secure and working — authentication, abuse prevention, and enforcing fair-use limits. Legal basis: our legitimate interests in running a safe, reliable service.
- To take payment — if you subscribe. Legal basis: performance of our contract and compliance with our legal obligations.
- To contact you — service and account emails such as email verification. Legal basis: performance of our contract. We will only send marketing email with your consent.
5. AI marking and your data
When a child submits a mock exam, their written answers are assessed automatically by an AI service provided by Anthropic, which returns a score and written feedback explaining where marks were and were not awarded.
What is sent.For each written answer we send the exam question, its mark scheme, and the answer the child wrote. We do not send the child’s name, your email address, or any account or profile identifier, so the answer is assessed on its own without anything identifying who wrote it. Multiple-choice answers are checked against the stored correct answer and are not sent at all.
What it is not used for.Children’s answers and feedback are used only to produce and show the marking result, and to let you review past attempts. They are not used for advertising, nor to build profiles of a child for any purpose unrelated to marking their work. Under Anthropic’s terms for the service we use, data submitted through it is not used to train their models.
Accuracy. AI marking is an aid to revision, not an official result, and it will sometimes award or withhold a mark a human examiner would not. It does not decide anything with a legal or similarly significant effect on a child. If you think a mark or a piece of feedback is wrong, email admin@marqit.uk and a person will review it.
6. Service providers (processors)
We use a small number of providers to run the service. They process personal data on our behalf and only for the purposes below.
- Supabase — stores account details, child profiles, mock attempts, answers and marking results, and handles sign-in and password resets.
- Anthropic — assesses submitted written answers and returns a score and feedback, as described in section 5.
- Stripe — takes and manages subscription payments. Card details are entered directly with Stripe and are never held by us.
These providers operate internationally, so personal data may be processed outside the United Kingdom. Transfers of this kind must be covered by safeguards recognised under UK data protection law, such as the UK International Data Transfer Agreement or an addendum to the EU Standard Contractual Clauses. If you would like to know which safeguard applies to a particular provider, email admin@marqit.uk and we will tell you.
7. How long we keep data
We keep account and child profile data for as long as the account is open. Deleting a child profile from your dashboard removes that child’s profile together with their mock attempts, answers and marking feedback. To close an account entirely, email admin@marqit.uk and we will delete the account and the child profiles under it. We keep limited records where the law requires it — for example, billing records for accounting purposes — and payment records held by Stripe are retained under their own retention rules.
8. Your rights
Under UK data protection law you (and, through you as the account holder, your child) have the right to access, correct, delete, restrict, or object to the processing of personal data, and the right to data portability. You can delete child profiles directly from your dashboard. To exercise any other right, email admin@marqit.uk and we will respond within one month.
9. Security
Access to data is restricted at the database level so that an account holder can only reach their own account and their own children’s data. Connections are encrypted in transit, sign-in and password handling are managed by our authentication provider rather than by us, and access to production systems is limited. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.
10. Changes to this policy
We may update this policy from time to time. If we make a material change we will update the date above and, where appropriate, notify the account holder by email.
11. Complaints
If you have a concern about how we handle personal data, please contact us first. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.
