Privacy Notice & Cookie Statement

How MMD uses personal data

Version 1.2 · Last updated 18 July 2026

Introduction

MMD (Madrasah Management Database) is a cloud-based administration platform for madrasahs and educational institutions. This notice explains how personal data is handled through the MMD website, platform, registration, billing and support services.

MMD does not sell personal data and does not store card numbers, card expiry dates or card security codes.

Who we are and how to contact us

MMD is currently operated as an internal pilot. In this notice, “MMD”, “we”, “our” and “us” refer to the platform operator. For privacy questions, contact support@mmdatabase.org.uk.

How we process personal data and why

Information may be supplied directly by users, entered by an institution, generated through use of MMD, or received from a connected service such as a payment or email provider.

Personal dataWhy it is usedUsual lawful basis
Registration, account and contact informationTo create accounts, provide access, communicate with users and provide support.Contract and legitimate interests
Pupil, parent, guardian and staff informationTo provide the educational and administrative functions selected by the institution.The institution determines the lawful basis; MMD normally processes this data on its instructions.
Attendance, assessment, health, safeguarding incident and other institution recordsTo maintain records, manage safeguarding concerns and produce reports requested by the institution.The institution determines the Article 6 basis and, where needed, the Article 9 condition.
MC, receipts, donations, Gift Aid and payment recordsTo administer institutional finance records and MMD subscriptions.Institution instructions, contract, legitimate interests and legal obligation as applicable
Messages, emails and permitted attachmentsTo provide communications selected by users and institutions.Institution instructions, contract and legitimate interests
Authentication, technical, security and selected audit informationTo operate, secure, troubleshoot and improve MMD and prevent misuse.Legitimate interests and legal obligation

MMD does not use solely automated decision-making to make decisions that have a legal or similarly significant effect on an individual.

Our role as controller and processor

An institution using MMD is normally the data controller for the pupil, parent, guardian, staff and operational records it enters. It decides why those records are used and the lawful basis for doing so. MMD normally acts as its data processor.

MMD acts as a controller for the limited information it uses for its own registration, subscription, billing, security, support and legal-compliance purposes.

Institutions are logically separated. Ordinary users from one institution cannot access another institution's records. Authorised MMD Super Administrators have privileged access where necessary to operate, secure and support the platform.

Whom we share personal data with

Personal data may be shared:

  • with authorised users and recipients selected by the relevant institution;
  • with Vercel for hosting and performance services, Supabase for database infrastructure, and GoCardless for subscription payment processing;
  • with Microsoft, Google, an SMTP provider or OpenAI when the relevant optional integration is configured and used;
  • with professional advisers, regulators or law-enforcement bodies where required or reasonably necessary; or
  • as part of a future sale, transfer or reorganisation of MMD, subject to appropriate safeguards.

Institutions can export information from MMD. The institution is responsible for protecting exported copies after they leave the platform.

How we store and transfer personal data

MMD uses cloud infrastructure and applies controls including encrypted HTTPS connections, password hashing, role-based access, session controls, tenant restrictions and two-factor authentication for administrators.

Most institution records are retained for the period required by the institution, subject to law and the service agreement. Current default settings retain messages and email records for 30 days and their attachments for 7 days; authorised settings can change these periods. MMD's own subscription, support, security and compliance records are retained only while required for their purpose or by law.

Some service providers may process data outside the UK. Where required, MMD will use an appropriate safeguard such as UK adequacy regulations or an approved contractual transfer mechanism. Contact us for further information about applicable safeguards.

Cookies and similar technologies

MMD uses essential cookies and browser storage for secure sessions, authentication, preferences and application operation. The website also uses Vercel Analytics and Speed Insights to understand performance and reliability. MMD does not currently use advertising cookies.

Browser settings can be used to remove or block stored information, although blocking essential technologies may prevent MMD from working correctly.

Rights and complaints

Depending on the circumstances and lawful basis, individuals may have rights to access, correct, erase, restrict or object to processing, and to receive portable copies of certain information. Where processing relies on consent, consent can be withdrawn at any time.

Requests about records controlled by an institution should normally be sent to that institution. For information controlled by MMD, email support@mmdatabase.org.uk.

You can also complain to the Information Commissioner's Office through its complaints service.