Bytewise
Policy

Privacy Notice.

Version 2 · 2026-07-17

How Nimbyx collects, uses and protects your personal data, in line with UK data protection law.

ICO registration reference: ZC196580

This notice explains how Nimbyx Limited ("Nimbyx") handles your personal information.

About Nimbyx and Bytewise

Who Nimbyx is: Nimbyx ("we") is the company that owns and runs Bytewise, and builds software and services for schools and other educational settings. We operate only in the United Kingdom.

What Bytewise is: Bytewise is the online meal-ordering and top-up system that Nimbyx owns and runs.

Nimbyx is entered on the Information Commissioner's Office (ICO) register under reference ZC196580, which you can view at https://ico.org.uk/ESDWebPages/Entry/ZC196580.

Nimbyx Limited is a private limited company registered in England and Wales (company number 17288718). Our registered office is Rose House, Old Sawmill Place, Bell Lane, Little Chalfont, Amersham, Buckinghamshire, HP6 6FA.

Please remember - Bytewise is a tool. Bytewise is software and, like any software, it can occasionally get things wrong, be interrupted or behave unexpectedly, and it depends on data and systems provided by others (including schools, operators, the Wonde integration and our payment partner). So far as the law allows, Nimbyx is not responsible for any inaccuracy, error, omission, loss or outcome that results from using or relying on the system or the data within it, or from any fault, failure or downtime.

In this notice you'll find:

  • why we use your information
  • our legal grounds for using it
  • the information we hold and our role
  • how we keep it secure
  • your data protection rights
  • who we share information with, and where it is stored
  • how long we keep it
  • cookies, updates and how to contact us

Why we use your information

Nimbyx designs, builds, sells, runs and maintains software for schools and other educational settings - including meal ordering and top-ups, payment collection and processing, meal and kitchen management, and communication with guardians (together, "our products and services").

We provide these to schools, trusts, local authorities and catering operators (our "Customers"), and to the guardians who use them ("Users"). Where a guardian uses Bytewise directly, the Bytewise Terms & Conditions for Guardians also apply.

We use personal data to:

  • deliver the products and services that have been contracted for;
  • confirm the identity of a Customer or User where needed;
  • prevent and detect crime, fraud and money laundering;
  • run and administer the service day to day;
  • improve our products and services, and ask for feedback (only using anonymised data for research and analysis);
  • offer new products and services that are relevant and reasonably expected; and
  • meet our legal and regulatory duties.

If we ever plan to use your information for a new purpose, we will tell you about it beforehand.

Our legal grounds for using your data

Data protection law sets out the grounds ("lawful bases") on which personal data may be used. Which one applies depends on the product or service in question, and is decided by whoever is the data controller.

Where Nimbyx acts as a data processor for a product or service, the Customer (usually the school) decides the lawful basis. This is typically that processing is necessary for a task carried out in the public interest, and/or for the legitimate interests of the controller.

Where Nimbyx acts as a data controller for a product or service, we rely on our legitimate interests. Where we carry out research, we rely on your consent.

Special-category data: health, medical, dietary and allergy information

A pupil's allergy and dietary information is health information and is "special category" data under Article 9 of the UK GDPR (it can also reveal beliefs, for example where a diet is religious). The same is true of the medical records a school can choose to share with Bytewise (see below). For this information the school is the data controller and Nimbyx is its data processor. Schools do not usually rely on a parent's consent to process pupils' health data; they rely on grounds such as their legal obligations, a task carried out in the public interest (keeping pupils safe and running the school) and, in an emergency, the child's vital interests. The school decides the lawful basis and gives the matching privacy information to guardians.

Where a school approves the relevant Wonde permission, Bytewise also receives a pupil's medical records from the school's MIS. This information is read-only: it is shown to authorised school and catering staff to help them support and safeguard the pupil (for example, awareness of a medical need relevant at mealtimes), and it does not drive the allergen and dietary meal controls, which are managed within Bytewise. As with allergy and dietary information, the school is the data controller and Nimbyx is its data processor; corrections should be made in the school's MIS, which is the source.

This information belongs to the school. Nimbyx only processes it on the school's documented instructions, to help keep pupils safe at mealtimes. Guardians can view a pupil's allergy and dietary details in Bytewise and add further detail at any time, and can ask the school to add or amend detail on request. Our handling of this data is governed by the Bytewise Data Processing Agreement (for schools) between Nimbyx and the school; if anything in this notice conflicts with that agreement on data-protection matters, the Data Processing Agreement prevails.

Whatever the lawful basis, we only ever process data where there is a fair and reasonable ground to do so, in full compliance with data protection law.

The information we hold, and our role

To provide our products and services we obtain and use various categories of personal data, either from the Customer or from the User. The exact data depends on the product or service.

For Bytewise, the school is the data controller for the pupil and guardian data it holds or provides - including allergy, dietary and medical (health) data, and photographs - and Nimbyx is the school's data processor, handling it on the school's instructions. Nimbyx acts as an independent data controller only for the direct account relationship with guardians (for example, the login credentials it issues and the consent records it keeps). Where Nimbyx is the school's processor, the Bytewise Data Processing Agreement (for schools) applies and prevails over this notice on data-protection matters if they conflict.

The table below lists the categories of personal data used in Bytewise, and, for each, whether Nimbyx acts as processor or controller:

Data subject Information Data type Notes / source
Student (pupil) Forename, surname, known-as name Processor From the school MIS (via Wonde)
Student Date of birth, gender, year group, registration class Processor From the school MIS (via Wonde)
Student Unique Pupil Number (UPN) and MIS identifiers Processor Statutory pupil identifier; from the school MIS
Student Free School Meal / Pupil Premium eligibility Processor From the school MIS; used only for meal entitlement and pricing
Student Allergens (including severity, EpiPen flag and free-text notes) and dietary requirements Processor Special-category health data (UK GDPR Art. 9). The school is the controller; Nimbyx processes it on the school's instructions. Recorded by a guardian or the school
Student Medical records from the school MIS Processor Special-category health data (UK GDPR Art. 9). Synced read-only from the school MIS (via Wonde) where the school approves it; shown to authorised staff to help support and safeguard the pupil
Student Photograph Processor From the school MIS (via Wonde), where the school approves it; shown only to authorised staff at the pupil's school or its caterer to confirm identity at the point of service. Never published, and never used for automated or biometric recognition
Student Meal selections, orders and wallet/spend history Processor Generated through use of the service
Guardian Title, forename, surname Processor From the school MIS and/or provided by the guardian
Guardian Email address, telephone number(s), home address Processor Encrypted at rest
Guardian Relationship to the child and parental-responsibility status Processor From the school MIS; governs access and who may give consent
Guardian Account credentials and authentication data (hashed password, two-factor, passkeys) Controller The direct account relationship with the guardian; passwords are hashed, never stored in the clear
Guardian Consent records (which document and version was accepted, and when) Controller The direct account relationship with the guardian; evidence of consent
Guardian Payment and wallet transaction history and balances Processor Card details are handled by our payment partner (Worldpay); Bytewise does not store full card details
School / operator staff Name, work email, role and permissions, authentication data Processor To administer the service for their school or operator
All users IP address, browser and device information Processor Collected automatically to operate and secure the service
All users Essential and functional cookies Processor See "Cookies" below
All users Audit records of significant actions Processor For security, safeguarding and accountability

Where the table shows "Controller", Nimbyx decides the purpose because it relates to the direct account relationship with the guardian (see the section above).

We may also collect basic details (such as name, address, email or phone number) when a Customer gives us information about its staff, when a guardian registers, or when someone signs up to a newsletter, completes a form on our site, or contacts us. We do not use analytics cookies or third-party analytics tools; basic technical information is processed only to operate and secure the service.

If you take part in research, we may collect your name, email, organisation, postcode, job role and any accessibility needs you choose to share. We may do this when you speak with our team, when you complete a survey, or when you volunteer for a specific research activity.

Keeping your information secure

Only the employees who need it have access to your information, and only to run our products and services. We use appropriate technical and organisational measures to protect the confidentiality, integrity and availability of your data in storage, in transit and while it is processed, and we keep these under regular review. Card payments are handled by PCI-DSS compliant providers, and Bytewise does not store full card details.

Where a support tool or partner operates outside the UK or EEA, we make sure suitable safeguards are in place to protect your data.

The main safeguards we rely on are:

Area Method / standard What it means
Data in transit TLS 1.2 / 1.3 Data moving between your device and our services is encrypted.
Data at rest AES-256 Stored data and databases are encrypted, with sensitive fields additionally encrypted at the application layer.
Access control Role-based access & MFA Access is on a least-privilege basis, with multi-factor authentication for administrators and per-school data separation.
Payment data PCI-DSS Card payments are handled by PCI-DSS compliant providers; we do not store full card details.
Monitoring Logging, auditing & testing Systems are monitored, significant actions are recorded in an append-only audit trail, and security is tested regularly.

Where your data is stored, and who processes it

Your core Bytewise data is stored in the United Kingdom. We rely on a small number of carefully chosen providers, each bound by contract to process data only on our instructions and in line with data protection law:

Service Provider Purpose Privacy notice
Cloud hosting & compute Laravel Cloud (on Amazon Web Services, UK) Hosting the Bytewise platform. https://laravel.com/cloud/legal/privacy
Database Neon UK-hosted PostgreSQL database (via Laravel Cloud). https://www.databricks.com/legal/privacynotice
Storage, CDN & web-application firewall Cloudflare File storage, content delivery and protection against attack. https://www.cloudflare.com/en-gb/privacypolicy/
Transactional email Resend Sending account, service and notification emails. Certified under the UK Extension to the EU-US Data Privacy Framework. https://resend.com/legal/privacy-policy
School data integration Wonde Secure sync of pupil and guardian data from the school MIS, including, where the school approves it, pupil medical records and photographs. https://www.wonde.com/legal/privacy/uk/
Application monitoring Laravel Nightwatch EU-hosted performance monitoring and error diagnostics. https://laravel.com/legal/privacy

Card and online payments are handled separately by our payment partner, Worldpay. Your personal data is held primarily in the UK. Some processing takes place in the EU, an adequate jurisdiction under UK data protection law, for example application monitoring via Laravel Nightwatch. The only routine transfer to a country outside the UK and EEA is transactional email via Resend (United States), covered by the UK Extension to the EU-US Data Privacy Framework. Where any data is transferred outside the UK or EEA we ensure equivalent protection using Standard Contractual Clauses or the UK International Data Transfer Addendum. If we add or change a provider, we will update this notice.

Apart from these providers, we only disclose your information where: we are legally required to (for example to law enforcement or a regulator); there is a duty to disclose in the public interest; disclosure is needed to protect our interests (for example to prevent or detect fraud); or you have given us permission.

How long we keep your information

We keep information only for as long as we need it for the purposes in this notice, or for as long as the law requires:

  • Pupil and guardian personal data (including allergy, dietary and medical information, and photographs): kept while the pupil is enrolled and using Bytewise. When the pupil leaves, or the school closes or deactivates the account, we securely delete or anonymise it within 12 months, unless we must keep specific records for longer. As the school is the controller for pupil data, requests to change or remove it are handled with the school.
  • Payment and transaction records: kept for 6 years to meet UK tax, accounting and audit requirements.
  • Consent records: kept while we rely on the consent, and for a reasonable period afterwards, so we can show it was given.
  • Audit and security logs: kept for up to 7 years to support security, safeguarding and accountability.
  • Support enquiries: kept only as long as needed to deal with the enquiry, plus a short period afterwards.

Where a school is the controller for the data it has provided, the school's own retention rules also apply and it remains responsible for that data.

Your data protection rights

You have the following rights over the personal data we hold when providing our products and services.

  • Access: you can ask for a copy of your personal data and details of how we process it. You can often see this directly in Bytewise; otherwise you can make a Data Subject Access Request (DSAR).
  • Rectification: you can ask us to correct inaccurate information. You can usually update your own details in Bytewise; otherwise contact us, or - for data the school holds and provides - your child's school.
  • Erasure: you can ask us to delete your information; depending on the circumstances we may or may not be obliged to.
  • Objection: you can object to our processing; depending on the circumstances we may or may not be obliged to stop.
  • Restriction: you can ask us to limit how we process your data; depending on the circumstances we may or may not be obliged to.
  • Portability: you can ask to receive the data you gave us in a structured, commonly used, machine-readable format.
  • Complaint: if you think we have infringed your rights, you can complain to the ICO - in particular in the country where you live or work, or where you believe the issue arose.

Making a request

To exercise your rights, email our Data Protection Officer at dpo@nimbyx.co.uk, with "privacy" in the subject and a clear description of what you need, or write to us at our registered address. It helps if you tell us the particular records you are after (for example payment history). We may ask you to confirm your identity first.

There is no charge, and we aim to respond within one month. Under the Data (Use and Access) Act 2025, if a request is especially complex or we need more information to find your data, we may pause that one-month period until you provide it. We carry out a reasonable and proportionate search of the systems where your data is most likely to be held, and usually provide it electronically (for example as a CSV or PDF). Where records also contain other people's data, we may need to redact those parts. You can also contact the ICO or your local Citizens Advice.

If you are unsure, we may need to request additional information to confirm your identity before acting on a request.

Cookies

Bytewise sets only first-party cookies, all of which are strictly necessary or functional; we do not use performance, analytics, advertising or third-party cookies. Full details are in our Cookie Policy.

Updates to this notice

We review this notice regularly and publish the current version on our website.

Our Data Protection Officer

We have appointed a Data Protection Officer (DPO). You can reach them at:

dpo@nimbyx.co.uk

or

Data Protection Officer
Nimbyx Limited
Rose House, Old Sawmill Place
Bell Lane, Little Chalfont
Amersham, Buckinghamshire
HP6 6FA

Contacting us

For general queries about Nimbyx, email support@nimbyx.co.uk. For help with Bytewise, email parentsupport@nimbyx.co.uk (guardians), operatorsupport@nimbyx.co.uk (operators) or schoolsupport@nimbyx.co.uk (schools). For data-protection queries, please use the Data Protection Officer details above.

Related policies

Please read this notice alongside our other policies, each available on the Nimbyx Website: the Bytewise Terms of Use; the Bytewise Terms & Conditions for Guardians; our Cookie Policy; and the Bytewise Data Processing Agreement (for schools).

Parent company ownership

Nimbyx Limited has a parent company, Rocket Rose Holdings. Although Rocket Rose Holdings holds an interest in Nimbyx, no customer data is shared with, or accessible by, the parent company or its staff. Only employees of Nimbyx Limited have appropriate access to customer data.

Contact usA Nimbyx product · © 2026 Bytewise