Make a Beat offers a classroom area for teachers. Where a school uses it, we process pupil data on the school's instructions as a processor under Art. 28 GDPR. The school (or its public body) is then the controller. We provide schools with a data processing agreement on request at contact@make-a-beat.com; it must be concluded before classroom use.
Teacher account: in addition to the account data in section 4, we store the teacher flag and — where provided — the name of the school and a work email address. Legal basis: Art. 6 (1) (b) GDPR.
Classes: class name, the owning teacher, and a join code that lets pupils be assigned to the class. The teacher can close joining at any time.
Pupil accounts: deliberately data-minimising. We store a display name (chosen by the teacher — a first name or initials is fine), a login ID, a four-digit PIN (stored as a hash only), the class assignment and the position in the list. An email address is not required for pupil accounts and we do not ask for one; an optional field for it stays empty unless the school uses it. Pupil accounts do not sign in via Google.
Assignments and submissions: a class can be given assignments with a title, description and due date. When a pupil submits work, we store the project state, an audio file generated from it and — once entered by the teacher — a grade and feedback. Only the pupil concerned and the teacher of that class can see this; it is never public and never appears in the leaderboard.
For pupil accounts: no advertising, no analytics cookies, no reach measurement via Google Analytics or PostHog, no sharing with ad networks, no profiling. AI features can be enabled or blocked per class by the teacher.
Minors: outside a school context our service is aimed at people aged 13 and over; for minors under 16, consent-based processing requires the authorisation of a parent or guardian (Art. 8 GDPR). In a school context, obtaining the necessary permission is the school's responsibility.
Deletion: teachers can delete pupil accounts, classes, assignments and submissions themselves at any time; deleting a class automatically deletes its pupil accounts, assignments and submissions. On a school's request we delete all data of a class. Absent such a request, we delete class data no later than twelve months after the class was last active.