Transform your history classroom
ActiveHistory provides interactive simulations, self-marking quizzes, lesson plans, worksheets and multimedia activities designed by full-time history teacher Russel Tarr.
Build and deliver complete history courses with resources for classroom teaching, remote learning and independent study - from multimedia lectures to interactive games and historical simulations.
World History teaching resources for the high school classroom: lesson plans, worksheets, quizzes and simulation games for KS3, IGCSE, IB and A-Level teachers.
PRIVACY POLICY & DATA PROCESSING AGREEMENT
ActiveHistory.co.uk Ltd
Version: 3 September 2026
1. Overview
ActiveHistory.co.uk Ltd ("ActiveHistory", "we", "us" or "our") provides online history teaching resources and educational services to schools, teachers and other educational users.
We are committed to protecting personal data and complying with applicable data protection legislation, including the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 and, where applicable, the EU General Data Protection Regulation ("EU GDPR").
We collect and process only the personal data reasonably necessary to provide ActiveHistory services, administer subscriptions and accounts, process payments, provide customer support and maintain the security of the service.
This document explains how ActiveHistory processes personal data and also sets out the terms applicable where ActiveHistory processes personal data on behalf of a school or other educational organisation.
2. Controller and Processor Roles
Depending on the circumstances, ActiveHistory may act either as a data controller or as a data processor.
Where an individual purchases an ActiveHistory subscription directly, ActiveHistory generally acts as the data controller for the personal data required to administer that subscription and account.
Where a school or educational organisation provides personal data to ActiveHistory for the purpose of creating or administering accounts for its staff or students, the school or organisation will generally act as the Controller and ActiveHistory will act as its Processor.
Where this document applies as a Data Processing Agreement ("DPA"), the school or educational organisation is referred to as the Controller and ActiveHistory.co.uk Ltd is referred to as the Processor.
3. Acceptance of this Data Processing Agreement
Where a school or educational organisation uses ActiveHistory and provides personal data to ActiveHistory for processing on its behalf, this document forms the standard Data Processing Agreement between the Controller and ActiveHistory, unless the parties have entered into a separate written data processing agreement.
The Controller may accept this DPA by written confirmation, electronic acceptance, or by entering into an order, subscription or other agreement that expressly incorporates this DPA.
Where the parties enter into a separate written DPA, that agreement takes precedence over this document in the event of any conflict.
The Controller is responsible for ensuring that persons authorised to enter into agreements on its behalf have the necessary authority to accept this DPA.
4. Subject Matter and Purpose of Processing
ActiveHistory processes personal data for the purpose of providing and administering its online educational services.
This may include:
-
creating and maintaining user accounts;
-
authenticating users and providing secure login access;
-
administering school and individual subscriptions;
-
recording subscription status and expiry dates;
-
providing access to educational resources and online activities;
-
communicating with customers about accounts and subscriptions;
-
providing technical and customer support;
-
processing payments and invoices;
-
maintaining the security and integrity of the website and its systems; and
-
complying with legal and accounting requirements.
ActiveHistory will not sell personal data or use personal data supplied by a school for unrelated commercial purposes.
5. Categories of Personal Data
Depending on how the service is used, ActiveHistory may process:
-
name;
-
username or login name;
-
email address;
-
password information, stored in an appropriately protected form;
-
school or institution name;
-
school or institution address;
-
subscription and account information;
-
payment and billing information;
-
records of communications with ActiveHistory;
-
technical information necessary for authentication, security and operation of the website; and
-
information entered into the service by a school or user where necessary for the operation of a particular educational activity.
ActiveHistory seeks to minimise the amount of personal data collected.
Schools should not enter special category personal data or other sensitive personal information into ActiveHistory unless this is specifically necessary for a particular service and appropriate arrangements have been agreed.
6. Categories of Data Subjects
Personal data processed by ActiveHistory may relate to:
-
teachers and other school staff;
-
school administrators;
-
students and pupils using ActiveHistory under the supervision or authorisation of their school;
-
individual subscribers; and
-
persons communicating with ActiveHistory in connection with an account or subscription.
Where a school provides access to ActiveHistory to students, the school is responsible for determining which students are authorised to use the service and what information should be supplied to ActiveHistory.
7. Lawful Basis
Where ActiveHistory acts as Controller, personal data is processed where necessary to provide contracted services, administer subscriptions and payments, comply with legal obligations, maintain the security of the service, or where another lawful basis under applicable data protection legislation applies.
Where ActiveHistory acts as Processor, the Controller determines the appropriate lawful basis for processing and provides the relevant instructions to ActiveHistory.
8. Processing on the Controller's Instructions
Where ActiveHistory acts as Processor, it will process personal data only on the documented instructions of the Controller, including with regard to transfers of personal data, unless processing is required by applicable law.
ActiveHistory will inform the Controller if it believes that an instruction infringes applicable data protection legislation.
The Controller is responsible for ensuring that its instructions to ActiveHistory and its collection and disclosure of personal data are lawful.
9. Confidentiality
ActiveHistory will ensure that persons authorised to process personal data are subject to appropriate confidentiality obligations.
Access to personal data held by ActiveHistory is restricted to those individuals who require access for the administration, operation, support or accounting of the service.
10. Security
ActiveHistory operates its services using appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
The website uses SSL/TLS encryption for communications.
Access to administrative systems is restricted and appropriate authentication and access controls are used.
ActiveHistory maintains procedures designed to identify, investigate and respond to potential security incidents.
11. Sub-processors
The Controller provides ActiveHistory with general authorisation to engage appropriate third-party processors where reasonably necessary to provide the ActiveHistory service.
These may include providers of:
-
website and server hosting;
-
website security and infrastructure;
-
online payment processing;
-
email and communications services;
-
technical support; and
-
related business services.
ActiveHistory will ensure that any sub-processor processing personal data on behalf of the Controller is subject to a written agreement requiring an appropriate level of data protection and confidentiality.
ActiveHistory will remain responsible for the performance of its sub-processors in accordance with applicable data protection law.
Where ActiveHistory proposes to appoint a new sub-processor or materially change an existing sub-processor in a manner relevant to the processing of the Controller's personal data, ActiveHistory will provide the Controller with reasonable information about the proposed change.
The Controller may object to a proposed sub-processor on reasonable data protection grounds. If the parties cannot reasonably resolve such an objection, the parties will discuss an appropriate alternative or other reasonable solution.
12. International Transfers
ActiveHistory will not transfer personal data outside the UK or European Economic Area unless the transfer is permitted under applicable data protection legislation.
Where a restricted international transfer requires an appropriate safeguard, ActiveHistory will use an applicable mechanism recognised under the relevant legislation, such as an adequacy decision or appropriate contractual safeguards, including Standard Contractual Clauses where required.
ActiveHistory will take reasonable steps to ensure that its sub-processors also comply with applicable international transfer requirements.
13. Data Subject Rights
Individuals have rights under applicable data protection legislation, including rights relating to:
-
access to their personal data;
-
correction of inaccurate information;
-
deletion of personal data in appropriate circumstances;
-
restriction of processing;
-
objection to certain processing; and
-
data portability where applicable.
Where ActiveHistory acts as Processor, it will provide reasonable assistance to the Controller in responding to requests from individuals exercising their data protection rights.
Requests relating to personal data supplied by a school should normally be directed to the relevant school in the first instance. ActiveHistory will assist the school where appropriate.
14. Data Retention and Deletion
ActiveHistory retains personal data only for as long as reasonably necessary for the purposes for which it was collected, including the provision of services, account administration, legal and accounting requirements and the resolution of potential disputes.
For standard ActiveHistory accounts, following expiry or termination of an account, personal data will normally be deleted from ActiveHistory's active systems within three months, unless a longer retention period is required by law or is reasonably necessary for legitimate business or legal purposes.
Where ActiveHistory acts as Processor, the Controller may request the deletion or return of personal data at the end of the processing relationship, subject to applicable legal retention requirements.
Where data remains temporarily in routine backups, it will be securely isolated from normal use and deleted in accordance with the applicable backup cycle.
15. Personal Data Breaches
If ActiveHistory becomes aware of a personal data breach affecting personal data processed on behalf of a Controller, it will notify the Controller without undue delay.
Where reasonably available, ActiveHistory will provide information concerning the nature of the breach, the categories of data affected, the likely consequences and the measures taken or proposed to address the breach.
ActiveHistory will take reasonable steps to investigate, contain and remedy the breach and will provide reasonable assistance to the Controller in meeting its legal obligations.
16. Assistance with Compliance
Where ActiveHistory acts as Processor, it will provide reasonable assistance to the Controller, taking into account the nature of the processing and the information available to ActiveHistory, in relation to:
-
security of processing;
-
notification and management of personal data breaches;
-
data protection impact assessments where relevant; and
-
consultations with supervisory authorities where required.
17. Audits and Compliance Information
ActiveHistory will make available to the Controller information reasonably necessary to demonstrate compliance with its obligations as a Processor.
Where reasonably necessary and subject to appropriate confidentiality and security arrangements, ActiveHistory will cooperate with reasonable audits or inspections carried out by the Controller or its authorised representatives.
Audits should be arranged with reasonable notice and conducted in a manner that does not compromise the security, confidentiality or operation of ActiveHistory's systems or the personal data of other customers.
18. Children and Students
ActiveHistory provides educational resources that may be used by students under the supervision or authorisation of schools and teachers.
Schools are responsible for determining whether and how students may access the service and for providing appropriate information and instructions concerning student accounts.
ActiveHistory seeks to collect only the minimum information necessary to provide student access and does not require unnecessary personal information from students.
Where a school provides ActiveHistory with student information, the school remains responsible for ensuring that it has an appropriate lawful basis and authority for providing that information to ActiveHistory.
19. Marketing and Communications
Users may receive service-related communications necessary for the administration of their account or subscription.
Where ActiveHistory sends newsletters or other promotional communications, individuals will be provided with an appropriate opportunity to opt out.
ActiveHistory will not use personal data supplied by a school for unrelated marketing purposes.
20. Payments
Online payments are processed through reputable third-party payment providers.
ActiveHistory does not require customers to provide full payment-card details directly to ActiveHistory's servers.
Payment providers process payment information in accordance with their own privacy and security arrangements and applicable legal requirements.
21. Data Protection Requests and Complaints
Individuals may contact ActiveHistory to request information about the personal data we hold about them or to exercise applicable data protection rights.
Where the request concerns personal data provided by a school and ActiveHistory is acting as Processor, ActiveHistory may refer the individual to the relevant school as Controller and will assist the school where appropriate.
Individuals also have the right to lodge a complaint with the relevant data protection supervisory authority.
22. Changes to this Policy and DPA
ActiveHistory may update this Privacy Policy and Data Processing Agreement from time to time to reflect changes in the service, technology, legal requirements or data-processing arrangements.
The current version will be published on the ActiveHistory website.
Where a material change affects an existing Controller's processing arrangements, ActiveHistory will provide reasonable notice where appropriate.
23. Governing Law
This Data Processing Agreement is governed by the laws of England and Wales, except to the extent that applicable data protection legislation imposes mandatory requirements that cannot lawfully be excluded or varied by agreement.
Nothing in this DPA is intended to restrict or remove any rights or obligations that apply under the UK GDPR, EU GDPR or other applicable data protection legislation.
24. Contact
For questions concerning privacy, data protection or the processing of personal data by ActiveHistory, please contact:
ActiveHistory.co.uk Ltd
Website: https://www.activehistory.co.uk/
Email: [INSERT PRIVACY/CONTACT EMAIL]
DATA PROCESSING AGREEMENT – PROCESSING DETAILS
For the purposes of Article 28 of the UK GDPR and, where applicable, Article 28 of the EU GDPR:
Controller:
The school or educational organisation using ActiveHistory.
Processor:
ActiveHistory.co.uk Ltd.
Subject matter:
Provision and administration of ActiveHistory's online educational services.
Duration:
For the duration of the Controller's use of ActiveHistory, together with the additional period reasonably required for account administration, legal compliance and secure deletion.
Nature and purpose:
Account creation, authentication, subscription administration, provision of educational resources, customer support, security and related service administration.
Categories of personal data:
As described in section 5.
Categories of data subjects:
As described in section 6.
Processing operations:
Collection, recording, organisation, storage, retrieval, use, authentication, transmission where necessary for service provision, and deletion of personal data.
Special category data:
ActiveHistory does not require special category personal data for its standard services. Controllers should not intentionally provide such information unless specifically necessary and agreed.
Processor Obligations
ActiveHistory will:
-
process personal data only on documented instructions from the Controller;
-
maintain appropriate confidentiality;
-
implement appropriate technical and organisational security measures;
-
use sub-processors in accordance with section 11;
-
assist the Controller with applicable data-subject requests;
-
assist the Controller with security, breach notification and other applicable compliance obligations;
-
notify the Controller without undue delay of a personal data breach;
-
delete or return personal data at the end of the processing relationship as required by the Controller, subject to applicable legal retention requirements; and
-
provide reasonable information and cooperation necessary to demonstrate compliance with applicable processor obligations.
Controller Obligations
The Controller will:
-
determine the purposes and lawful basis for processing;
-
provide appropriate documented instructions to ActiveHistory;
-
ensure that personal data supplied to ActiveHistory is accurate and appropriate;
-
provide individuals with any privacy information required by applicable law;
-
determine which staff and students are authorised to access ActiveHistory; and
-
ensure that its use of ActiveHistory complies with applicable data protection legislation.
ActiveHistory.co.uk Ltd
Privacy Policy & Data Processing Agreement
Version 3 September 2026