This explains what Market Simulation Studio stores about teachers and about students, why, and how to get it removed. It is written to be read by a teacher, not only by a lawyer. If your school needs a formal document for its records, ask us and we will send one.
Version 1.1. Published 15 August 2026. Applies to market.thebusiness.school only.
Market Simulation Studio is run by TBS Education Ltd Oy, a limited company registered in Finland.
In data protection language we are the controller for the information described here. That means we decide what the service collects and we answer for it. We say this plainly because it is what is true today: teachers sign up on their own, without a contract between us and their school, so we are not simply acting on a school's instructions.
Your school stays responsible for its own decision to use the tool in class, for its own pupil records, and for telling pupils and parents which tools it uses. If your school would rather we act as its processor under a written agreement, email us and we will arrange that.
Because we are established in Finland and also serve schools in the UK, both the EU GDPR and the UK GDPR apply to us. Section 17 tells you which regulator to go to.
There are no accounts, no sign-up form and no passwords. The first time you save a simulation, your browser is given a long secret code called a teacher token, and your personal link contains it.
We do not ask for your email address, your school, or your subject department, and there is nowhere in the product to enter them.
Students never create an account. They open a link or scan a code, type a name label, and play. We want to be exact about the rest, because a short honest list is more useful to you than a reassuring vague one.
When a student joins a lesson, the session record holds:
Please tell your class to use a first name or a nickname. The join screen asks for a name and does not currently stop a student typing their full name. Anything a student types is stored as typed, and it is visible to you on the teacher dashboard. One sentence before you start the lesson is the most effective privacy control in the whole product.
Written answers are exactly that: free text a child wrote. Please also remind students not to put personal details, contact information or anything about other people into a writing task.
| What | Why | Legal basis |
|---|---|---|
| Teacher token fingerprint | So your personal link opens your work, and only yours | Legitimate interests |
| Your saved simulations | So your work is still there next term, and on another computer | Legitimate interests |
| Author name on a shared simulation | To credit you, when you choose to be credited | Legitimate interests |
| Student name label | So the class can see who is who, and so the teacher can follow progress | Legitimate interests |
| Decisions and written answers | To run the lesson, show results on the board, and let the teacher mark the writing | Legitimate interests |
What "legitimate interests" means here. It is one of the six lawful reasons for processing data in the UK and EU GDPR. It applies when an organisation has a genuine need, the processing is limited to what that need requires, and it does not override the interests of the people involved. Our need is to make a lesson work. We keep the data set to a name label and the answers given in the lesson, we do not build profiles, and we do not use any of it for advertising.
The law says the balance must be weighed especially carefully when the person is a child. That is why the student data set is as small as it is, why students have no accounts, and why nothing follows a student from one lesson to the next.
We do not rely on consent, because we do not ask students for consent and it would be wrong to imply otherwise. Your school may be relying on its own legal basis, often public task, for its decision to run the lesson. That is your school's basis, not ours, and your school's own privacy notice should cover it.
You can object to processing based on legitimate interests. See section 16.
Nothing about a class ever reaches the public library. When a teacher shares a simulation, we take a copy of the simulation itself and nothing else. Student names, answers, results and join codes live in a separate store that the library part of the system cannot read. This is enforced in the code and there is an automated test that checks it on every release.
The one thing to watch is content you write yourself: if a teacher types a real pupil's name into a simulation and then shares it, that text becomes public. Please do not put pupil names into simulation content.
The site, the part of it that saves your work, and the stored data all run on Netlify, which runs on Amazon Web Services.
We want to be straight with you about location, because it is a fair question and the honest answer is not the one schools usually hope for. We have not pinned the service to a European region. The service runs in Netlify's default region, which Netlify documents as US East (Ohio, United States). Netlify does not publish the region for the type of storage we use, so we are not going to claim one.
Treat the data as processed in the United States, protected by the safeguards in section 8. We are looking at moving to a European region, and when that is confirmed we will say so here and raise the version number of this notice. We would rather under-promise here than have you find out later.
Netlify is the only company that handles this data for us. It hosts the website, runs the code that saves and loads simulations and sessions, and stores the data. It acts as our processor, which means it may only handle the data to provide the service to us, under a data processing agreement that forms part of Netlify's standard terms.
Netlify in turn uses its own suppliers. The ones Netlify names publicly are Amazon Web Services for infrastructure, and Datadog, CrowdStrike, WorkOS and Fivetran for monitoring, security, access management and internal data movement. Netlify publishes and updates this list itself.
Like any web host, Netlify records ordinary technical information when a page is requested, such as IP address, browser type and the address requested. We do not add any tracking of our own on top of that.
We have no other processors. No email platform, no analytics provider, no CRM, no AI service.
Because processing happens outside the UK and the EEA, as explained in section 6, personal data is transferred internationally. The safeguards are Netlify's, and they are the standard ones:
We hold no certification of our own, and we are not going to imply one. These safeguards are Netlify's, and we rely on them.
Classroom data is temporary. Class sessions are checked every day and permanently deleted once they are at least 30 days old. A teacher can delete a session sooner from its dashboard.
| What | How long |
|---|---|
| Your saved simulations | Until you delete them. They are your working files and we assume you want them next year. |
| Your teacher record | Until you ask us to delete it. There is no self-service delete for the record itself yet. |
| A shared library entry | Until you withdraw it, or delete the simulation it came from. |
| Class sessions, including student name labels, decisions and written answers | Up to 30 days. A daily automated check deletes sessions that are at least 30 days old. Because the check runs once a day, deletion may complete during the following 24 hours. Teachers can delete a session immediately from its dashboard. |
| Drafts and the token in your own browser | Until you clear your browser data. See section 15. |
| Netlify's technical logs | Set by Netlify under its own policy, not by us. |
To remove a lesson immediately, open its teacher dashboard and choose Delete session data, then confirm. This permanently removes the whole session record, including every name, decision, result and written answer.
If the dashboard link is unavailable, email support@thebusiness.school with the join code. We aim to complete a verified deletion request within 7 days and will confirm when it is done.
Deleting a simulation also withdraws it from the public library automatically, so you never leave a public copy behind that you thought you had removed.
One thing it does not do. Deleting a saved simulation does not immediately delete lessons already run from it. Those session records are separate, expire automatically after 30 days, and can be removed sooner from each session's teacher dashboard.
To delete your teacher record itself, including the display name and every simulation in one go, email us from any address and include your personal link, or tell us the display name and roughly when you started. We will confirm once it is gone.
Sharing is always your choice, and it is always reversible.
It disappears from the public Explore listing immediately, and the stored public copy is removed with it. Your own copy stays in your account, untouched.
Copies that other teachers already made into their own accounts stay with them, in the same way a photocopied worksheet does. We cannot reach into another teacher's private work to remove those.
If you have lost the personal link to a simulation you shared and need it taken down, email support@thebusiness.school with the title and roughly when you shared it. We can remove any library entry directly.
Anyone can ask what we hold about them, ask for a copy, or ask us to delete it. There is a practical wrinkle worth knowing about first.
We usually cannot identify a student on our own. We hold a name label with no email, no account and no class list, so "Charlie" in a session tells us nothing about which Charlie that is. This is a deliberate side effect of collecting so little, and it is good for the student, but it means we need the join code to find anything.
The quickest route:
We will respond within one month, which is the deadline the UK and EU GDPR set. There is no charge. If a request is unusually complex we may extend by up to two further months, and we will tell you within the first month if that happens.
We may need to ask a question or two to be satisfied who you are, especially before deleting anything, so that one person cannot erase another person's work. We will not ask for ID documents.
Schools: if you need a data processing agreement, a record of the categories of data, or answers for a data protection impact assessment, email us and say what your data protection lead needs.
This tool is designed for classroom use, so most of the people playing it are children. That shaped the whole design.
We do not knowingly collect anything from a child other than through a lesson their teacher set up. We rely on the teacher and the school to decide whether the lesson is appropriate for their class and to handle telling pupils and parents, in the same way as for any other classroom resource.
If you believe a child has put personal information into a written answer and you want it removed, email us with the join code and we will delete it. You do not need to explain why.
The honest limitation. There are no passwords, so your personal link is the key to your work. Anyone who gets that link can read and edit everything you have saved, and it cannot be changed or revoked. Bookmark it, do not put it on a projector, do not paste it into a shared document, and do not give it to a class. If you think it has been seen, email us and we will delete the record so nothing is left behind it.
No online service is perfectly secure. If something does go wrong and it is likely to put people at risk, we will report it to the relevant regulator within 72 hours of becoming aware, and tell affected teachers and schools without undue delay.
This site sets no cookies at all. Not for analytics, not for advertising, not for anything. That is why you have never seen a cookie banner here, and why there is nothing to consent to.
The site does use two ordinary browser storage areas to make the product work. Neither is shared with anyone and neither leaves your device except when you save your work.
| What is stored | Who | Why | How long |
|---|---|---|---|
| Your teacher token | Teacher | So this browser opens your saved simulations | Until you clear your browser data |
| Your current draft | Teacher | Autosave, so a closed tab does not lose your work | Until you clear your browser data |
| Preview data | Teacher | To show your draft in the student view | Until replaced by the next preview |
| A reference to the lesson you joined | Student | So a refresh does not throw you out of the game | Deleted when the browser tab closes |
The student one uses session storage, which browsers clear automatically at the end of the session. Nothing about a student is left on a shared school computer after the tab is closed.
You can clear all of it at any time through your browser's "clear browsing data" settings. If you clear a teacher browser without having saved your personal link somewhere, your work cannot be recovered.
Under the UK GDPR and the EU GDPR you have the following rights. They apply to teachers, to students, and to a parent acting for a child.
To use any of these, email support@thebusiness.school. It is free, and we will reply within one month. Section 12 explains what to include so we can actually find the data.
Please tell us first if something is wrong, because we can usually fix it faster than anyone else. But you never have to go through us, and you can complain to a regulator at any time.
Because we are a Finnish company serving schools in the UK, there are two regulators, and you can use whichever fits you.
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline 0303 123 1113
ico.org.uk/make-a-complaint
Our ICO registration is ZC133810.
Office of the Data Protection Ombudsman
Tietosuojavaltuutetun toimisto
PO Box 800, 00531 Helsinki, Finland
tietosuoja.fi/en
You can also complain to the authority in your own EU country.
One address covers everything in this notice, and a person reads it.
TBS Education Ltd Oy, business ID 3614159-3, registered office in Lahti, Finland. ICO registration ZC133810. We will give the full postal address on request.
We are a small company and we have not appointed a data protection officer, because we are not required to have one. Questions come straight to us and are answered by us.
Useful things to say in your email: the join code if it is about a lesson, the title if it is about a shared simulation, and what you would like to happen.
If we change what we collect, why, how long we keep it, or where it is held, we will update this page and raise the version number. The version and date at the top always tell you which one you are reading.
One further improvement is being considered:
We will not quietly widen what we collect. If that ever changed, it would appear here first.
Version 1.1. Published 15 August 2026. Covers market.thebusiness.school. The main thebusiness.school privacy policy covers our other sites.