Data Processing Agreement - EduTables
Last updated: 10 September 2026 · Version: 1.0a
This document is a template provided for convenience and does not constitute legal advice. Bracketed items marked [CONFIRM: ...] are facts the operator of EduTables must verify and fill in, and the whole document should be reviewed by a qualified solicitor or data protection adviser before being relied upon as a binding commitment to a school or trust.
This Data Processing Agreement (the “DPA”) is entered into between EduTables Ltd (“we”, “our”, or “us”) and the organisation, school, trust, or other legal entity using EduTables (the “Customer”). It supplements, is incorporated into, and forms part of the Site / Organisation Agreement between the parties (the “Agreement”). Where this DPA and the Agreement conflict on a matter of data protection, this DPA takes precedence; on all other matters, the Agreement governs.
1. Definitions
“UK GDPR”, “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach” and “Special Category Data” have the meanings given in Article 4 of the UK GDPR (Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018, as amended) and the Data Protection Act 2018. “Sub-processor” means any processor engaged by us to process Personal Data on the Customer’s behalf. “Customer Personal Data” means Personal Data the Customer or its Authorised Users upload to, or process using, the Service, as described in Schedule 1.
2. Roles of the Parties
The parties agree that, in respect of Customer Personal Data, the Customer is the Controller and we are the Processor, as those terms are used in the UK GDPR. This DPA does not apply to data we process as a controller in our own right (for example account, billing, and support data) — that processing is described in our Privacy Policy.
3. Details of Processing
The subject matter, duration, nature and purpose of the processing, and the categories of Personal Data and Data Subjects, are set out in Schedule 1.
4. Our Obligations as Processor
We shall:
- process Customer Personal Data only on the Customer’s documented instructions — which include the Customer’s ordinary configuration and use of the Service’s features — unless required to do otherwise by UK law, in which case we will inform the Customer of that legal requirement before processing, unless the law prohibits this;
- ensure that any person we authorise to process Customer Personal Data is subject to a binding duty of confidentiality;
- implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as summarised in Schedule 3 and as required by Article 32 UK GDPR;
- not engage another processor (a Sub-processor) without the Customer’s prior general or specific written authorisation, as set out in clause 5;
- taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as reasonably possible, in fulfilling the Customer’s obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the UK GDPR;
- assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the information available to us;
- at the Customer’s choice, delete or return all Customer Personal Data after the end of the provision of services relating to processing, and delete existing copies unless UK law requires storage, in accordance with clause 9; and
- make available to the Customer information reasonably necessary to demonstrate compliance with this clause 4 and allow for, and contribute to, audits (including inspections) as set out in clause 8.
5. Sub-processors
The Customer gives us general written authorisation to engage the Sub-processors listed in Schedule 2, which is published and kept up to date at this URL. We will impose data protection obligations on each Sub-processor that are no less protective than those set out in this DPA, by contract, and we remain fully liable to the Customer for a Sub-processor’s performance of those obligations.
Where we intend to add or replace a Sub-processor, we will update Schedule 2 and, where the addition or replacement is material, give the Customer reasonable advance notice by email or in-app notification, so that the Customer may object on reasonable data protection grounds. If the Customer objects and the parties cannot agree a resolution, either party may terminate the affected part of the Service on notice, without prejudice to fees already due.
The optional AI Assistant Access feature described in our Privacy Policy involves an additional, member-chosen Sub-processor that is engaged only where the Customer’s own administrator has separately and explicitly authorised it — see Privacy Policy §4a for the full detail and current transfer-mechanism table, which is not duplicated here to avoid the two documents drifting out of step.
6. International Transfers
Where a Sub-processor listed in Schedule 2 is located outside the UK, we ensure the transfer is protected by one of: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, an International Data Transfer Agreement, or certification under the UK Extension to the EU–US Data Privacy Framework where the recipient holds one — as recorded against that Sub-processor in Schedule 2.
7. Security
We maintain the technical and organisational measures summarised in Schedule 3, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects. Further detail is available on reasonable request.
8. Data Subject Requests and Audit
Because the Customer is the controller of Customer Personal Data, requests from Data Subjects should ordinarily be directed to the Customer. Where we receive such a request directly, we will, unless prohibited by law, inform the Customer without undue delay and not respond ourselves except on the Customer’s instruction. The Service includes built-in tooling for the Customer to export and erase a Data Subject’s records itself, without needing to raise a request with us.
We will make available to the Customer, on reasonable written request no more than once in any 12-month period (or at any time following a Personal Data Breach affecting Customer Personal Data), information reasonably necessary to demonstrate compliance with this DPA, and will permit and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable confidentiality and scheduling safeguards and at the Customer’s cost unless the audit identifies a material breach of this DPA.
9. Personal Data Breach
We will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, after becoming aware of a Personal Data Breach affecting Customer Personal Data, providing such information as we then have available to assist the Customer in meeting its own notification obligations under Articles 33 and 34 UK GDPR, and will provide further information as it becomes available without undue delay.
10. Return and Deletion of Data
On termination of the Agreement, we will make Customer Personal Data available for export for the period described in the Data Retention section of our Privacy Policy, after which it will be deleted or anonymised in accordance with that policy, save that we may retain data we are required to keep by law or for the establishment, exercise, or defence of legal claims.
11. Liability
Each party’s liability arising out of or in connection with this DPA (including under Article 82 UK GDPR) is subject to the limitations and exclusions of liability set out in the Agreement, save that nothing in the Agreement or this DPA limits or excludes either party’s liability for death or personal injury caused by its negligence, for fraud or fraudulent misrepresentation, or for any liability which cannot lawfully be limited or excluded.
12. Term
This DPA takes effect on the date the Customer accepts the Agreement and continues for as long as we process Customer Personal Data on the Customer’s behalf, notwithstanding termination of the Agreement itself.
13. Governing Law and Contact
This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales. Data protection queries relating to this DPA should be sent to privacy@edutables.com. [CONFIRM: whether a Data Protection Officer has been appointed, per our Record of Processing Activities.]
Schedule 1 — Details of Processing
| Subject matter | Personal Data the Customer uploads to, or generates within, its tables, reports, forms and other items on the Service. |
| Duration | For as long as the Agreement subsists, and thereafter only as described in clause 10. |
| Nature and purpose | Storage; structuring and organisation; retrieval and display; filtering and access restriction; calculation and aggregation; charting and reporting; transmission by email attachment, API feed, calendar feed and public share link, at the Customer’s configuration; export to CSV, Excel, PDF, Word and PowerPoint; pseudonymisation on request; and erasure. |
| Categories of Data Subjects | Determined by the Customer. Typically includes pupils (including children), parents and carers, teaching and support staff, governors, applicants, and external contacts. |
| Categories of Personal Data | Determined entirely by the Customer — the Service imposes no fixed schema. The Customer should assume this may include Special Category Data (for example SEN status, health or medical needs, ethnicity, religion, free-school-meal eligibility, or safeguarding and behaviour notes) and, in behaviour or safeguarding records, criminal offence data within the meaning of Article 10 UK GDPR. |
Schedule 2 — Sub-processors
This list is published here and versioned; see clause 5 for how changes are notified.
| Sub-processor | Role | Data | Location | Transfer mechanism |
| Amazon Web Services (hosting the Service on Lightsail) | Infrastructure hosting | All application and Customer Personal Data, at rest and in transit | [CONFIRM: AWS region] | AWS Data Processing Addendum. [CONFIRM: accepted, and whether the region is inside the UK/EEA] |
| Mailgun (Sinch) | Transactional and scheduled email delivery | Recipient address, message subject/body; scheduled report attachments may contain Customer Personal Data | EU | EU-hosted endpoint. [CONFIRM: DPA signed with Sinch] |
| Stripe | Payment processing (billing contact only — no Customer Personal Data) | Billing contact name/email, subscription data. No card details reach us. | [CONFIRM: EU or US contracting entity] | Stripe's published Data Processing Agreement; Standard Contractual Clauses / Data Privacy Framework as applicable to the contracting entity. [CONFIRM] |
| Your chosen AI provider (optional, e.g. Anthropic, OpenAI, Google, Microsoft) | Optional AI Assistant Access, engaged only on your explicit authorisation | Whatever the tools you grant return — may include full table contents | Typically USA | See Privacy Policy §4a for the current, provider-by-provider transfer mechanism table |
Fonts, scripts, and stylesheets are served from EduTables's own infrastructure, not from any third party, so no additional visitor-facing sub-processor arises from them. Background map tile imagery (where the Customer has separately enabled it in Site Settings) is served by whichever provider that setting names, disclosing the viewing user's IP address and the map area viewed.
Schedule 3 — Technical and Organisational Measures
- Tenant isolation: every database query is scoped to the Customer's own tenant, and record identifiers are 128-bit random values rather than sequential, so records cannot be enumerated across tenants.
- Access control: per-item permission levels and custom views restrict both which rows and which columns a user can see, enforced on our servers so restricted data is never sent to a user's browser in the first place — applied consistently across the grid, exports, API feeds and share links.
- Authentication: passwords hashed with bcrypt (cost factor 12) plus a per-user salt; optional passkey (WebAuthn) and two-factor authentication; login rate limiting; an optional per-organisation IP address allow-list.
- Session and transport security: session cookies are HttpOnly, SameSite, and Secure; session identifiers are regenerated on login; state-changing requests are protected by a per-session CSRF token; all traffic to the Service is encrypted in transit (TLS).
- Injection resistance: all database queries use parameterised statements.
- Upload handling: uploaded files are checked against an allow-list of file extensions, their true content type is verified (not just the claimed one), size limits are enforced, and the storage location is configured so uploaded files cannot be executed as code.
- Audit trail: changes to table data record the previous value, the user who made the change, and when, and are visible to the Customer's own administrators as an Activity Log; this trail is append-only.
- Referential integrity monitoring: an automated scanner checks for orphaned or dangling references between records.
- Automated testing: a suite of automated tests covers core data-handling logic; testing that specifically exercises cross-tenant isolation is planned but not yet in place — see clause 8 for how to request current status.
- Retention: a published, enforced schedule automatically deletes or anonymises operational log data after a defined period per category (see our Privacy Policy's Data Retention section); the Customer separately controls the retention period of its own Activity Log via Site Settings.
- Backup and availability: [CONFIRM: current backup, tested-restore and monitoring/alerting arrangements before relying on this bullet — see our Record of Processing Activities, gap G-03.]
- Encryption at rest: [CONFIRM: whether the database volume is encrypted at rest.]
This document is a template provided for convenience and does not constitute legal advice. It should be reviewed by a qualified solicitor or data protection adviser before being relied upon as a binding Data Processing Agreement, and every [CONFIRM: ...] item above resolved first.