Privacy policy
Multicast is a Cast recording and accessibility service supplied to schools, colleges and other institutions. This policy explains what we hold, why, and what rights people have over it.
Who controls the data
Your institution is the data controller for the staff and student records it creates in Multicast. [Legal entity name] acts as a data processor on the institution's instructions. Where those roles differ from this description, the written agreement between us takes precedence.
What we hold
- Account details. Name, email address, the institution an account belongs to, and the permissions granted to it.
- Cast content. Recordings made by staff, along with transcripts, captions, key points and questions generated from them.
- Learning support settings. The accessibility tools enabled for an individual student, where staff have set them.
- Usage records. Which Casts an account has opened, questions submitted to a teacher, and an administrative log of account and permission changes.
We do not ask for or store payment card details, home addresses, or any special category data beyond what a member of staff chooses to record when configuring accessibility support.
Why we hold it
To deliver the service the institution has asked for: making Casts available to the right students, providing accessibility tooling, and giving staff the administrative records they need. Processing is carried out under the institution's instructions, on the lawful basis they have determined, which for a state school is normally the performance of a public task.
Who else is involved
We use a small number of infrastructure providers to run the service: Google Firebase for authentication and the database, and Cloudflare for hosting, video storage, transcription and email delivery. They process data on our behalf under their own data processing terms. We do not sell data, and we do not use Cast content to train models offered to anyone else.
Where it is held and for how long
Data is held on infrastructure in [region]. Cast recordings are kept until deleted by the member of staff who made them, or until the institution's account is closed. Deleting an account removes its profile, its accessibility settings and its class memberships. Administrative log entries are retained for [retention period] so that changes remain auditable.
Children's data
Student accounts are created by staff at the institution, not by students themselves, and no marketing is ever sent to them. Where a student is below the age at which they can exercise their own data rights, those rights are exercised by the institution or by a parent or guardian through it.
Rights
People have the right to access their data, to have inaccuracies corrected, to have data erased in some circumstances, to restrict or object to processing, and to receive a copy in a portable form. Requests should go to your institution first, as the controller. They can be raised with us at info@fireboundinteractive.uk and we will assist the institution in answering them. Complaints can be made to the Information Commissioner's Office.
Security
Access is controlled per institution: staff and students can only reach material belonging to their own organisation, and Casts can be restricted further to a single class. Video is served through short-lived links tied to the person requesting them. Passwords are never set or seen by staff, who send an invitation and let each person choose their own.
