Last Updated: 27/02/2026

Odis Systems Ltd is committed to protecting personal data and respecting the privacy of individuals.

This Privacy Notice explains how personal data may be processed when organisations use the ODISSYS platform to support the delivery of wellbeing and safeguarding related services.

ODISSYS is designed to support organisations such as schools in managing referrals, recording engagement with support services, and monitoring outcomes for young people.

This notice explains how personal data is handled in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data Controller and Data Processor

When ODISSYS is used within a school or organisation:

• The school or organisation acts as the Data Controller

Odis Systems Ltd acts as the Data Processor

The Data Controller determines the purpose and lawful basis for processing personal data.

Odis Systems Ltd processes personal data only on the documented instructions of the Data Controller and in order to provide the ODISSYS service.


Types of Personal Data That May Be Processed

Where ODISSYS is used to support services for young people, the platform may process personal data including:

• Name

• Age or date of birth

• Year group or educational setting

• Referral information

• Session engagement information

• Wellbeing observations

• Support notes recorded by practitioners

The information recorded is limited to what is necessary to support the delivery of services and safeguarding awareness within organisations using the platform.


Purpose of Processing

Personal data may be processed for purposes including:

• Managing referrals for support services

• Recording engagement with interventions

• Recording information relating to the wellbeing or safeguarding of young people so that organisations can monitor concerns and respond appropriately

• Monitoring progress and outcomes of support provided

• Producing reports for organisations about service delivery and impact

ODISSYS is intended to help organisations record and review information relating to support provided to young people.


Lawful Basis for Processing

The lawful basis for processing personal data is determined by the Data Controller, typically the school or organisation responsible for the young person.

This may include lawful bases such as:

Public Task (Article 6(1)(e))

Substantial Public Interest (Article 9(2)(g)) where special category data is involved

Odis Systems Ltd processes personal data only on behalf of the Data Controller.


Access to Personal Data

Access to personal data within ODISSYS is restricted to authorised users.

This may include:

• authorised staff within the school or organisation

• authorised practitioners delivering support services

• system administrators responsible for maintaining the platform

Schools and organisations control which users are granted access to the platform.


Data Security

Odis Systems Ltd takes appropriate organisational and technical measures to help protect personal data from unauthorised access, loss or misuse.

Access to ODISSYS is restricted through individual user accounts and access permissions.

Certain actions within the platform, such as safeguarding and session notes, are recorded within the system to support accountability and safeguarding oversight.


Data Retention

Personal data recorded within ODISSYS is retained only for as long as necessary to support the delivery of services and safeguarding responsibilities.

Where services cease, personal data will be deleted or anonymised when it is no longer required, subject to any legal or safeguarding obligations determined by the Data Controller.


Data Sharing

Odis Systems Ltd does not sell personal data.

Personal data recorded within the platform may be accessible to authorised individuals within the organisation using the platform and to authorised practitioners delivering services.

Access is controlled through user permissions.


Data Subject Rights

Individuals have rights under UK GDPR, including:

• the right to request access to personal data

• the right to request correction of inaccurate information

• the right to request deletion in certain circumstances

• the right to restrict processing

Requests relating to personal data should normally be directed to the Data Controller, which will usually be the school or organisation responsible for the young person.

Odis Systems Ltd will assist Data Controllers where required.


Safeguarding Responsibility

ODISSYS is designed to support organisations in recording and monitoring information relating to wellbeing and safeguarding. However, the platform does not replace an organisation’s safeguarding procedures or statutory responsibilities.

The organisation responsible for the child remains accountable for safeguarding decisions, actions, and responses to any concerns recorded within the system.

ODISSYS should not be relied upon as the sole method of responding to urgent safeguarding concerns. Where a child may be at immediate risk of harm, organisations must follow their safeguarding procedures and contact appropriate services without delay.


Changes to This Privacy Notice

This Privacy Notice may be updated from time to time to reflect changes to services, technology or legal requirements.

The most recent version will always be available on this website.


Contact – Data Protection

For questions relating to this Privacy Notice or data protection matters relating to the ODISSYS platform:

DPA Lead

Email: dod@odissys.com