Market Simulation Studio

Privacy notice

This explains what Market Simulation Studio stores about teachers and about students, why, and how to get it removed. It is written to be read by a teacher, not only by a lawyer. If your school needs a formal document for its records, ask us and we will send one.

Version 1.1. Published 15 August 2026. Applies to market.thebusiness.school only.

What is in here

  1. Who is responsible
  2. What we store about a teacher
  3. What we store about a student
  4. Why we process it, and our legal basis
  5. What we never collect
  6. Where the data is held
  7. Our service provider
  8. International transfers
  9. How long we keep things
  10. Deleting your own simulations
  11. Removing a shared simulation from the library
  12. Requests from a student, parent or school
  13. Children
  14. Security
  15. Cookies and browser storage
  16. Your rights
  17. Complaining
  18. Contact us
  19. Changes to this notice

1. Who is responsible

Market Simulation Studio is run by TBS Education Ltd Oy, a limited company registered in Finland.

Company
TBS Education Ltd Oy
Business ID
3614159-3
Registered office
Lahti, Finland
ICO registration
ZC133810
Email
support@thebusiness.school

In data protection language we are the controller for the information described here. That means we decide what the service collects and we answer for it. We say this plainly because it is what is true today: teachers sign up on their own, without a contract between us and their school, so we are not simply acting on a school's instructions.

Your school stays responsible for its own decision to use the tool in class, for its own pupil records, and for telling pupils and parents which tools it uses. If your school would rather we act as its processor under a written agreement, email us and we will arrange that.

Because we are established in Finland and also serve schools in the UK, both the EU GDPR and the UK GDPR apply to us. Section 17 tells you which regulator to go to.

2. What we store about a teacher

There are no accounts, no sign-up form and no passwords. The first time you save a simulation, your browser is given a long secret code called a teacher token, and your personal link contains it.

  • A one-way fingerprint of your token. We store only a hashed version, never the token itself. That means we cannot work out your link, and one teacher's link can never open another teacher's work. It also means that if you lose your link, we cannot recover it for you.
  • A display name, if you type one. Optional, up to 40 characters. It is up to you whether that is your real name.
  • The date your record was created.
  • The simulations you save. Everything you wrote: title, subject, description, age level, and the text of every block.
  • An author name, if you share a simulation publicly. You type this yourself at the moment of sharing, and it is shown to other teachers. Leave it blank if you would rather stay anonymous.

We do not ask for your email address, your school, or your subject department, and there is nowhere in the product to enter them.

3. What we store about a student

Students never create an account. They open a link or scan a code, type a name label, and play. We want to be exact about the rest, because a short honest list is more useful to you than a reassuring vague one.

When a student joins a lesson, the session record holds:

  • The name label they typed. Free text, up to 30 characters. A first name or a nickname is enough and is what we recommend. See the note below.
  • Their team, if the teacher is running the lesson in teams.
  • The time they joined and their place in the join order.
  • Every decision they made, with the option they picked and the effect it had, recorded against their name label.
  • Anything they wrote in a writing task. Free text, up to 2000 characters per answer, recorded against their name label. This is stored so the teacher can read and mark it. Nothing is marked automatically.
  • Their running scores in the simulation.

Please tell your class to use a first name or a nickname. The join screen asks for a name and does not currently stop a student typing their full name. Anything a student types is stored as typed, and it is visible to you on the teacher dashboard. One sentence before you start the lesson is the most effective privacy control in the whole product.

Written answers are exactly that: free text a child wrote. Please also remind students not to put personal details, contact information or anything about other people into a writing task.

4. Why we process it, and our legal basis

WhatWhyLegal basis
Teacher token fingerprint So your personal link opens your work, and only yours Legitimate interests
Your saved simulations So your work is still there next term, and on another computer Legitimate interests
Author name on a shared simulation To credit you, when you choose to be credited Legitimate interests
Student name label So the class can see who is who, and so the teacher can follow progress Legitimate interests
Decisions and written answers To run the lesson, show results on the board, and let the teacher mark the writing Legitimate interests

What "legitimate interests" means here. It is one of the six lawful reasons for processing data in the UK and EU GDPR. It applies when an organisation has a genuine need, the processing is limited to what that need requires, and it does not override the interests of the people involved. Our need is to make a lesson work. We keep the data set to a name label and the answers given in the lesson, we do not build profiles, and we do not use any of it for advertising.

The law says the balance must be weighed especially carefully when the person is a child. That is why the student data set is as small as it is, why students have no accounts, and why nothing follows a student from one lesson to the next.

We do not rely on consent, because we do not ask students for consent and it would be wrong to imply otherwise. Your school may be relying on its own legal basis, often public task, for its decision to run the lesson. That is your school's basis, not ours, and your school's own privacy notice should cover it.

You can object to processing based on legitimate interests. See section 16.

5. What we never collect

  • No student accounts, usernames or passwords.
  • No student email addresses, surnames or dates of birth. There is nowhere to enter them.
  • No payments. There is no payment processing in the product at all.
  • No advertising, no ad networks, no tracking pixels.
  • No analytics of any kind.
  • No third party scripts, stylesheets or fonts. Every file the page loads comes from this site.
  • No AI or machine learning. Nothing is sent to any AI service, and nothing is auto-marked or auto-generated.
  • No health, ethnicity, religion, or other special category data.
  • No location tracking.
  • We never sell data, and we never share it with anyone for their own purposes.

Nothing about a class ever reaches the public library. When a teacher shares a simulation, we take a copy of the simulation itself and nothing else. Student names, answers, results and join codes live in a separate store that the library part of the system cannot read. This is enforced in the code and there is an automated test that checks it on every release.

The one thing to watch is content you write yourself: if a teacher types a real pupil's name into a simulation and then shares it, that text becomes public. Please do not put pupil names into simulation content.

6. Where the data is held

The site, the part of it that saves your work, and the stored data all run on Netlify, which runs on Amazon Web Services.

We want to be straight with you about location, because it is a fair question and the honest answer is not the one schools usually hope for. We have not pinned the service to a European region. The service runs in Netlify's default region, which Netlify documents as US East (Ohio, United States). Netlify does not publish the region for the type of storage we use, so we are not going to claim one.

Treat the data as processed in the United States, protected by the safeguards in section 8. We are looking at moving to a European region, and when that is confirmed we will say so here and raise the version number of this notice. We would rather under-promise here than have you find out later.

7. Our service provider

Netlify is the only company that handles this data for us. It hosts the website, runs the code that saves and loads simulations and sessions, and stores the data. It acts as our processor, which means it may only handle the data to provide the service to us, under a data processing agreement that forms part of Netlify's standard terms.

Netlify in turn uses its own suppliers. The ones Netlify names publicly are Amazon Web Services for infrastructure, and Datadog, CrowdStrike, WorkOS and Fivetran for monitoring, security, access management and internal data movement. Netlify publishes and updates this list itself.

Like any web host, Netlify records ordinary technical information when a page is requested, such as IP address, browser type and the address requested. We do not add any tracking of our own on top of that.

We have no other processors. No email platform, no analytics provider, no CRM, no AI service.

8. International transfers

Because processing happens outside the UK and the EEA, as explained in section 6, personal data is transferred internationally. The safeguards are Netlify's, and they are the standard ones:

  • Standard Contractual Clauses. Netlify uses the clauses published by the European Commission under Implementing Decision 2021/914. These are a contract approved by regulators that carries your protections with the data.
  • Data Privacy Framework. Netlify is certified under the EU-US, UK Extension and Swiss-US Data Privacy Frameworks.

We hold no certification of our own, and we are not going to imply one. These safeguards are Netlify's, and we rely on them.

9. How long we keep things

Classroom data is temporary. Class sessions are checked every day and permanently deleted once they are at least 30 days old. A teacher can delete a session sooner from its dashboard.

WhatHow long
Your saved simulations Until you delete them. They are your working files and we assume you want them next year.
Your teacher record Until you ask us to delete it. There is no self-service delete for the record itself yet.
A shared library entry Until you withdraw it, or delete the simulation it came from.
Class sessions, including student name labels, decisions and written answers Up to 30 days. A daily automated check deletes sessions that are at least 30 days old. Because the check runs once a day, deletion may complete during the following 24 hours. Teachers can delete a session immediately from its dashboard.
Drafts and the token in your own browser Until you clear your browser data. See section 15.
Netlify's technical logs Set by Netlify under its own policy, not by us.

To remove a lesson immediately, open its teacher dashboard and choose Delete session data, then confirm. This permanently removes the whole session record, including every name, decision, result and written answer.

If the dashboard link is unavailable, email support@thebusiness.school with the join code. We aim to complete a verified deletion request within 7 days and will confirm when it is done.

10. Deleting your own simulations

  1. Open your personal link, which is the My simulations page.
  2. Find the simulation and choose Delete.
  3. Confirm.

Deleting a simulation also withdraws it from the public library automatically, so you never leave a public copy behind that you thought you had removed.

One thing it does not do. Deleting a saved simulation does not immediately delete lessons already run from it. Those session records are separate, expire automatically after 30 days, and can be removed sooner from each session's teacher dashboard.

To delete your teacher record itself, including the display name and every simulation in one go, email us from any address and include your personal link, or tell us the display name and roughly when you started. We will confirm once it is gone.

11. Removing a shared simulation from the library

Sharing is always your choice, and it is always reversible.

  1. Open your personal link.
  2. Find the shared simulation and choose Stop sharing.

It disappears from the public Explore listing immediately, and the stored public copy is removed with it. Your own copy stays in your account, untouched.

Copies that other teachers already made into their own accounts stay with them, in the same way a photocopied worksheet does. We cannot reach into another teacher's private work to remove those.

If you have lost the personal link to a simulation you shared and need it taken down, email support@thebusiness.school with the title and roughly when you shared it. We can remove any library entry directly.

12. Requests from a student, parent or school

Anyone can ask what we hold about them, ask for a copy, or ask us to delete it. There is a practical wrinkle worth knowing about first.

We usually cannot identify a student on our own. We hold a name label with no email, no account and no class list, so "Charlie" in a session tells us nothing about which Charlie that is. This is a deliberate side effect of collecting so little, and it is good for the student, but it means we need the join code to find anything.

The quickest route:

  1. Ask the teacher first. The teacher has the join code and can see the whole session on their dashboard. Very often they can answer the question in a minute without involving us at all.
  2. Then email us at support@thebusiness.school with the join code, the name label as typed, and roughly what date the lesson was.

We will respond within one month, which is the deadline the UK and EU GDPR set. There is no charge. If a request is unusually complex we may extend by up to two further months, and we will tell you within the first month if that happens.

We may need to ask a question or two to be satisfied who you are, especially before deleting anything, so that one person cannot erase another person's work. We will not ask for ID documents.

Schools: if you need a data processing agreement, a record of the categories of data, or answers for a data protection impact assessment, email us and say what your data protection lead needs.

13. Children

This tool is designed for classroom use, so most of the people playing it are children. That shaped the whole design.

  • No accounts, ever. A student is never asked to register, and never asked for an email address.
  • Nothing follows a student between lessons. The only thing stored in a student's browser is a temporary reference that lets them rejoin the same lesson, and it disappears when the tab closes. There is no profile, no history and no way to link one lesson to another.
  • No advertising and no tracking. Nothing about a child is used for marketing, profiling or automated decision making.
  • A name label, not an identity. A first name or nickname is all the game needs.
  • Private by default. Sharing to the public library is an explicit choice, applies only to teacher-written simulations, and can never include anything about a class.

We do not knowingly collect anything from a child other than through a lesson their teacher set up. We rely on the teacher and the school to decide whether the lesson is appropriate for their class and to handle telling pupils and parents, in the same way as for any other classroom resource.

If you believe a child has put personal information into a written answer and you want it removed, email us with the join code and we will delete it. You do not need to explain why.

14. Security

  • Everything travels over HTTPS.
  • Your token is never stored. We keep only a one-way fingerprint of it, so even someone with full access to our storage could not work out your personal link.
  • Teacher work, the public library and class sessions live in three separate stores. The code that serves the public library physically cannot read a class session.
  • Students only ever receive the current screen. Never the whole simulation, never the hidden effects behind the other options, never another student's or team's state.
  • The teacher dashboard requires a session token. Knowing the join code alone lets someone play, not watch the class.
  • Everything stored goes through validation and size limits before it is written.

The honest limitation. There are no passwords, so your personal link is the key to your work. Anyone who gets that link can read and edit everything you have saved, and it cannot be changed or revoked. Bookmark it, do not put it on a projector, do not paste it into a shared document, and do not give it to a class. If you think it has been seen, email us and we will delete the record so nothing is left behind it.

No online service is perfectly secure. If something does go wrong and it is likely to put people at risk, we will report it to the relevant regulator within 72 hours of becoming aware, and tell affected teachers and schools without undue delay.

15. Cookies and browser storage

This site sets no cookies at all. Not for analytics, not for advertising, not for anything. That is why you have never seen a cookie banner here, and why there is nothing to consent to.

The site does use two ordinary browser storage areas to make the product work. Neither is shared with anyone and neither leaves your device except when you save your work.

What is storedWhoWhyHow long
Your teacher token Teacher So this browser opens your saved simulations Until you clear your browser data
Your current draft Teacher Autosave, so a closed tab does not lose your work Until you clear your browser data
Preview data Teacher To show your draft in the student view Until replaced by the next preview
A reference to the lesson you joined Student So a refresh does not throw you out of the game Deleted when the browser tab closes

The student one uses session storage, which browsers clear automatically at the end of the session. Nothing about a student is left on a shared school computer after the tab is closed.

You can clear all of it at any time through your browser's "clear browsing data" settings. If you clear a teacher browser without having saved your personal link somewhere, your work cannot be recovered.

16. Your rights

Under the UK GDPR and the EU GDPR you have the following rights. They apply to teachers, to students, and to a parent acting for a child.

Access
Ask what we hold about you and get a copy.
Rectification
Have anything wrong corrected.
Erasure
Ask us to delete it. For simulations and library entries you can do this yourself, immediately, without asking.
Restriction
Ask us to stop using it while a question about it is sorted out.
Portability
Get your data in a reusable file. Teachers can export a backup of every simulation from the My simulations page at any time.
Objection
Object to processing we base on legitimate interests. Tell us why it affects you, and we will stop unless we have compelling grounds that override it.
Automated decisions
Nothing here is decided by an automated process, and nothing is auto-marked or profiled. Scores in a simulation are part of the game, not a judgement about a person.

To use any of these, email support@thebusiness.school. It is free, and we will reply within one month. Section 12 explains what to include so we can actually find the data.

17. Complaining

Please tell us first if something is wrong, because we can usually fix it faster than anyone else. But you never have to go through us, and you can complain to a regulator at any time.

Because we are a Finnish company serving schools in the UK, there are two regulators, and you can use whichever fits you.

In the UK

Information Commissioner's Office (ICO)

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline 0303 123 1113
ico.org.uk/make-a-complaint

Our ICO registration is ZC133810.

In Finland and the EU

Office of the Data Protection Ombudsman
Tietosuojavaltuutetun toimisto

PO Box 800, 00531 Helsinki, Finland
tietosuoja.fi/en

You can also complain to the authority in your own EU country.

18. Contact us

One address covers everything in this notice, and a person reads it.

support@thebusiness.school

TBS Education Ltd Oy, business ID 3614159-3, registered office in Lahti, Finland. ICO registration ZC133810. We will give the full postal address on request.

We are a small company and we have not appointed a data protection officer, because we are not required to have one. Questions come straight to us and are answered by us.

Useful things to say in your email: the join code if it is about a lesson, the title if it is about a shared simulation, and what you would like to happen.

19. Changes to this notice

If we change what we collect, why, how long we keep it, or where it is held, we will update this page and raise the version number. The version and date at the top always tell you which one you are reading.

One further improvement is being considered:

  • A possible move to European hosting, which would change section 6 and reduce what section 8 has to cover.

We will not quietly widen what we collect. If that ever changed, it would appear here first.

Version 1.1. Published 15 August 2026. Covers market.thebusiness.school. The main thebusiness.school privacy policy covers our other sites.

Market Simulation Studio by TBS Education Ltd Oy

Business ID 3614159-3 · ICO registration ZC133810 · Registered in Lahti, Finland

Back to Market Simulation Studio