Privacy Notice
The short version: Groundskeeper runs on your own server. All monitoring data stays on your network and never reaches us. The only personal data we receive is your name and email when you request a licence key, plus anonymous technical telemetry from the running installation.
Who we are
Data controller: RSJ Software
Contact: [email protected]
Website: rsjsoftware.com
What data we collect and why
1. Community key request
When you request a free Community licence key, we collect:
| Data | Why | Lawful basis |
|---|---|---|
| Your name | To address licence communications | Legitimate interest |
| Email address | To deliver your key and send important product updates | Legitimate interest |
| School name | To understand our user base and provide appropriate support | Legitimate interest |
| School URN | To identify the school the licence is issued to and prevent abuse | Legitimate interest |
This data is stored in Cloudflare D1 (EU-hosted) and is only accessed by RSJ Software when processing key requests.
Retention: Once your request is approved or rejected, we automatically remove your name, email address, and role 30 days later, keeping only an anonymised record that a key was issued to your school (the URN and issued key remain, for our own licensing records). Requests still awaiting a decision are unaffected. If you would like this done sooner, email us and we will action it manually.
2. Licence heartbeat
When Groundskeeper is running with an active licence, it sends a daily check-in to api.rsjsoftware.com containing:
| Data | Why | Lawful basis |
|---|---|---|
| School identity (URN, name, postcode, Local Authority, phase, type, trust affiliation) | Verify the licence, detect out-of-scope use, and track adoption. Fields beyond the URN are sourced from the public DfE GIAS register and are organisational, not personal, data | Contract performance |
| Install ID (anonymous UUID) | Count distinct installations | Contract performance |
| Groundskeeper version | Identify installations needing security updates | Legitimate interest |
| Active connector count | Verify connector limits for your licence tier | Contract performance |
| IP address | Included automatically by Cloudflare as part of any web request; only a one-way hash is stored, for abuse-rate detection, never the address itself | Legitimate interest |
We do not receive any usernames, device names, event logs, Active Directory data, or any other monitoring data in heartbeats.
Retention: A heartbeat record is automatically deleted once an installation has gone quiet (no check-in) for 13 months. If the installation holds an active paid (Pro or Central) licence, its record is kept for as long as that licence remains active even through a quiet spell, so a still-paying school’s history is never lost purely to inactivity. If you would like a record removed sooner — for example after an uninstall — email us and we will remove it manually.
3. Email delivery
Licence keys and product communications are sent via Resend (resend.com), our email delivery provider. Resend processes your email address as a data processor under our instruction. We have a Data Processing Agreement in place with Resend.
Data we do not collect
- No monitoring data — everything Groundskeeper collects from your infrastructure (device health, event logs, AD data, backup results) stays entirely on your school’s server and is never transmitted to RSJ Software.
- No student data — Groundskeeper does not collect, process, or store any data relating to students.
- No payment data — we do not process card payments or hold any financial information.
So the “nothing leaves your network” promise is complete, there is one other outbound connection to note. Groundskeeper periodically checks whether a newer version is available by reading the public release information published on GitHub — for the application itself (github.com/rsjsoftwareltd/groundskeeper) and, if you use the optional local Ollama AI, for Ollama (github.com/ollama/ollama). These are ordinary public version checks: they send no school data, no monitoring data, and no personal data — only the standard outbound web request needed to read a public “latest release” page, which necessarily includes your server’s public IP as the source (as with any website it contacts). GitHub is not our data processor; the request goes from your server directly to GitHub. You can prevent these checks entirely by blocking outbound access to github.com / api.github.com at your firewall — the only effect is that Groundskeeper will not tell you when an update is available.
Cloud AI providers
If you configure Groundskeeper to use a cloud AI provider (OpenAI, Azure OpenAI, Anthropic Claude, or Google Gemini), feed event data will be sent to that provider. In this case:
- Your school is the data controller for this processing.
- Groundskeeper applies automatic PII scrubbing before sending event data to a cloud AI provider, in two ways: values with a recognisable pattern (email addresses, IP addresses, MAC addresses,
DOMAIN\usernameaccount strings, and hostnames using common naming prefixes) are redacted wherever they appear; and a small set of known data fields that carry a bare account name — such as members of the local Administrators group, or the user named in an account-lockout or group-membership-change event — are always redacted, regardless of what the name looks like. This does not catch a name typed into free-text event detail with no such pattern or known field, or a device name that doesn’t use one of the common naming prefixes. - For UK schools, Azure OpenAI with UK/EU data residency is the most straightforward option for GDPR compliance.
- Ollama (the default) runs entirely on your server and sends nothing externally.
RSJ Software is not responsible for data processed by third-party AI providers you configure. (Separately, RSJ Software’s own support team may use an AI provider to help diagnose a redacted support bundle you send us — see Third-party processors below; this is unrelated to your own cloud AI provider configuration.)
Third-party processors
| Processor | Purpose | Location |
|---|---|---|
| Cloudflare | Database (D1) and API infrastructure | EU data residency; Privacy Shield certified |
| Resend | Transactional email delivery | US-based with EU data handling; DPA in place |
| Anthropic | AI-assisted support triage, used only by RSJ Software staff reviewing a redacted support bundle you send us — never automatic, never part of normal product operation | US-based |
Your rights under UK GDPR
You have the right to access, rectify, erase, restrict, object to, or receive a portable copy of the personal data we hold about you. To exercise any right, email [email protected]. We will respond within one calendar month.
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner’s Office at ico.org.uk.
Security
All data in transit uses HTTPS/TLS. Cloudflare D1 data is encrypted at rest. The admin panel is protected by authentication and accessible only to RSJ Software personnel. We do not share data with any party not listed in this notice.
Changes to this notice
If we make material changes, we will update the date above and notify active licence holders by email. The current version is always available at groundskeeper.rsjsoftware.com/privacy.