GDPR
Last updated 1 October 2026
How ISMS meets UK GDPR for the mosques, madrasahs and consultancies that use it.
1. Our role
You decide what records to keep about your pupils, parents, applicants and staff, so you are the data controller. We run the software that holds them, so we are your data processor. We only use your records to provide ISMS to you.
2. Our agreement with you
3. Where your data is kept
4. How we keep it safe
Each organisation's records are kept separate at the database level. Connections are encrypted, passwords are stored hashed, sign-in supports two-factor authentication, staff only see what their role allows, and sensitive actions are logged.
5. Requests from parents, pupils and applicants
If someone asks you for a copy of their data, or to correct or delete it, you can view and edit their record in ISMS. For anything you cannot do yourself, we will help so you can reply within the one month the law allows.
6. If something goes wrong
If we find a breach affecting your data, we will tell you within 48 hours, so you have time to report it to the ICO within your 72 hours.
7. When you leave
We will give you a copy of your data on request, while you use ISMS or when you leave. When your subscription ends, we delete your data within 90 days unless the law requires us to keep it.
8. Questions
Email hello@ismsuk.com and we will answer any data protection question, or fill in your supplier questionnaire.
Questions about this page: hello@ismsuk.com · GDPR · Privacy policy · Cookie policy · Data processing terms