groundskeeper.rsjsoftware.com / Privacy Notice

Privacy Notice

RSJ Software — Last updated September 2026

The short version: Groundskeeper runs on your own server. All monitoring data stays on your network and never reaches us. The only personal data we receive is your name and email when you request a licence key, plus anonymous technical telemetry from the running installation.

Who we are

Data controller: RSJ Software
Contact: hello@rsjsoftware.com
Website: rsjsoftware.com

RSJ Software is registered with the Information Commissioner’s Office (ICO) as a data controller. ICO registration number: [to be added on registration].

What data we collect and why

1. Community key request

When you request a free Community licence key, we collect:

DataWhyLawful basis
Your nameTo address licence communicationsLegitimate interest
Email addressTo deliver your key and send important product updatesLegitimate interest
School nameTo understand our user base and provide appropriate supportLegitimate interest
School URNTo identify the school the licence is issued to and prevent abuseLegitimate interest

This data is stored in Cloudflare D1 (EU-hosted) and is only accessed by RSJ Software when processing key requests.

Retention: Once your request is approved or rejected, we automatically remove your name, email address, and role 30 days later, keeping only an anonymised record that a key was issued to your school (the URN and issued key remain, for our own licensing records). Requests still awaiting a decision are unaffected. If you would like this done sooner, email us and we will action it manually.

2. Licence heartbeat

When Groundskeeper is running with an active licence, it sends a daily check-in to api.rsjsoftware.com containing:

DataWhyLawful basis
School identity (URN, name, postcode, Local Authority, phase, type, trust affiliation)Verify the licence, detect out-of-scope use, and track adoption. Fields beyond the URN are sourced from the public DfE GIAS register and are organisational, not personal, dataContract performance
Install ID (anonymous UUID)Count distinct installationsContract performance
Groundskeeper versionIdentify installations needing security updatesLegitimate interest
Active connector countVerify connector limits for your licence tierContract performance
IP addressIncluded automatically by Cloudflare as part of any web request; only a one-way hash is stored, for abuse-rate detection, never the address itselfLegitimate interest

We do not receive any usernames, device names, event logs, Active Directory data, or any other monitoring data in heartbeats.

Retention: A heartbeat record is automatically deleted once an installation has gone quiet (no check-in) for 13 months. If the installation holds an active paid (Pro or Central) licence, its record is kept for as long as that licence remains active even through a quiet spell, so a still-paying school’s history is never lost purely to inactivity. If you would like a record removed sooner — for example after an uninstall — email us and we will remove it manually.

3. Email delivery

Licence keys and product communications are sent via Resend (resend.com), our email delivery provider. Resend processes your email address as a data processor under our instruction. We have a Data Processing Agreement in place with Resend.

4. Pre-release and beta channel reports

By default nothing in this section applies. It applies only to an installation whose administrator has chosen a pre-release or beta update channel under Settings → Updates, to help test Groundskeeper before general release. On the normal release channel none of these features exist, and switching back to the release channel switches them off.

On a pre-release or beta channel, an installation can send a diagnostic report to RSJ Software. It is filed as an issue in RSJ Software’s private code repository on GitHub (GitHub, Inc., acting as our data processor), visible to RSJ Software only:

ReportWhat it containsWhen it is sent
“Report to RSJ” button on a feed eventThat event, the same connector’s last thirty events, the connector’s settings with secrets masked, the installation’s version, and any note you typeOnly when an administrator presses the button
Page error reportThe error message and location from the page’s own script, the address of the failed request if there was one, and the installation’s versionAutomatically, when a page of the dashboard fails in the browser
Self-diagnosis reportThe same as the button, for the event the rule choseAutomatically, when the installation detects a fault in itself, such as one connector flooding the feed
Daily logThe last day of Groundskeeper’s own application log, with names masked before it leaves the server (see below), and the installation’s version. With it, the same day’s counts: how many checks each connector ran, how many failed and how long they took; how many feed events each posted and its commonest event titles (masked the same way); how many monitored machines run the current agent; the database’s size and any slow pages; which connectors are switched on and whether each is running; the week’s busiest sources of dashboard entries and how many each produced; how many monitored machines had each agent check fail, with the commonest error messages; and the server’s Windows version, memory, free disk space, uptime and clock synchronisation. The same day’s dashboard entries (time, source, severity, title and the start of the detail), masked the same way. Groundskeeper’s settings, with every password, key and token removed (only whether one is set), and every name masked the same way. After an update, the installer’s own notes, masked the same wayOnce a day, and when an administrator presses “Send now”. On by default on the pre-release channel; turned off with the tickbox under Settings → Logs

What may be in it: because these reports carry real feed events, they can include device names, server names and the text of the events, and occasionally a user name where an event names one. They never include passwords, API keys or the secrets in your settings, which are masked before sending, and never include students. Lawful basis: consent, given by choosing the channel and, for the button, by pressing it. The daily log is pseudonymised on the server before it is sent: device, server and user names, e-mail addresses, MAC addresses and the host part of IP addresses are replaced by codes (such as device-3f2a) made with a key that never leaves the server, so RSJ Software can see that the same machine failed several times without seeing which machine; only the server can turn a code back into a name. It is stored in RSJ Software’s private Cloudflare database (Cloudflare, Inc., acting as our data processor) and deleted after 14 days. From each day’s counts, the figures alone — numbers of checks, failures, alerts and machines, times and sizes, with no event text, names or codes — are kept for 13 months, so that slow changes over weeks and months can be seen. Retention of the other reports: a report is kept as part of RSJ Software’s engineering record of the fault it describes; ask us at hello@rsjsoftware.com and we will delete any report your installation sent.

Data we do not collect

So the “nothing leaves your network” promise is complete, there is one other outbound connection to note. Groundskeeper periodically checks whether a newer version is available by reading the public release information published on GitHub — for the application itself (github.com/rsjsoftwareltd/groundskeeper) and, if you use the optional local Ollama AI, for Ollama (github.com/ollama/ollama). These are ordinary public version checks: they send no school data, no monitoring data, and no personal data — only the standard outbound web request needed to read a public “latest release” page, which necessarily includes your server’s public IP as the source (as with any website it contacts). GitHub is not our data processor; the request goes from your server directly to GitHub. You can prevent these checks entirely by blocking outbound access to github.com / api.github.com at your firewall — the only effect is that Groundskeeper will not tell you when an update is available.

Cloud AI providers

If you configure Groundskeeper to use a cloud AI provider (OpenAI, Azure OpenAI, Anthropic Claude, or Google Gemini), feed event data will be sent to that provider. In this case:

RSJ Software is not responsible for data processed by third-party AI providers you configure. (Separately, RSJ Software’s own support team may use an AI provider to help diagnose a redacted support bundle you send us — see Third-party processors below; this is unrelated to your own cloud AI provider configuration.)

Third-party processors

ProcessorPurposeLocation
CloudflareDatabase (D1) and API infrastructureEU data residency; Privacy Shield certified
ResendTransactional email deliveryUS-based with EU data handling; DPA in place
AnthropicAI-assisted support triage, used only by RSJ Software staff reviewing a redacted support bundle you send us — never automatic, never part of normal product operationUS-based

Your rights under UK GDPR

You have the right to access, rectify, erase, restrict, object to, or receive a portable copy of the personal data we hold about you. To exercise any right, email hello@rsjsoftware.com. We will respond within one calendar month.

If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner’s Office at ico.org.uk.

Security

All data in transit uses HTTPS/TLS. Cloudflare D1 data is encrypted at rest. The admin panel is protected by authentication and accessible only to RSJ Software personnel. We do not share data with any party not listed in this notice.

Changes to this notice

If we make material changes, we will update the date above and notify active licence holders by email. The current version is always available at groundskeeper.rsjsoftware.com/privacy.