Last updated: 10 September 2026 · Version: 1.0a
This document is a template provided for convenience and does not constitute legal advice. Bracketed items marked [CONFIRM: ...] are facts the operator of EduTables must verify and fill in, and the whole document should be reviewed by a qualified solicitor or data protection adviser before being relied upon as a binding commitment to a school or trust.
This Data Processing Agreement (the “DPA”) is entered into between EduTables Ltd (“we”, “our”, or “us”) and the organisation, school, trust, or other legal entity using EduTables (the “Customer”). It supplements, is incorporated into, and forms part of the Site / Organisation Agreement between the parties (the “Agreement”). Where this DPA and the Agreement conflict on a matter of data protection, this DPA takes precedence; on all other matters, the Agreement governs.
“UK GDPR”, “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach” and “Special Category Data” have the meanings given in Article 4 of the UK GDPR (Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018, as amended) and the Data Protection Act 2018. “Sub-processor” means any processor engaged by us to process Personal Data on the Customer’s behalf. “Customer Personal Data” means Personal Data the Customer or its Authorised Users upload to, or process using, the Service, as described in Schedule 1.
The parties agree that, in respect of Customer Personal Data, the Customer is the Controller and we are the Processor, as those terms are used in the UK GDPR. This DPA does not apply to data we process as a controller in our own right (for example account, billing, and support data) — that processing is described in our Privacy Policy.
The subject matter, duration, nature and purpose of the processing, and the categories of Personal Data and Data Subjects, are set out in Schedule 1.
We shall:
The Customer gives us general written authorisation to engage the Sub-processors listed in Schedule 2, which is published and kept up to date at this URL. We will impose data protection obligations on each Sub-processor that are no less protective than those set out in this DPA, by contract, and we remain fully liable to the Customer for a Sub-processor’s performance of those obligations.
Where we intend to add or replace a Sub-processor, we will update Schedule 2 and, where the addition or replacement is material, give the Customer reasonable advance notice by email or in-app notification, so that the Customer may object on reasonable data protection grounds. If the Customer objects and the parties cannot agree a resolution, either party may terminate the affected part of the Service on notice, without prejudice to fees already due.
The optional AI Assistant Access feature described in our Privacy Policy involves an additional, member-chosen Sub-processor that is engaged only where the Customer’s own administrator has separately and explicitly authorised it — see Privacy Policy §4a for the full detail and current transfer-mechanism table, which is not duplicated here to avoid the two documents drifting out of step.
Where a Sub-processor listed in Schedule 2 is located outside the UK, we ensure the transfer is protected by one of: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, an International Data Transfer Agreement, or certification under the UK Extension to the EU–US Data Privacy Framework where the recipient holds one — as recorded against that Sub-processor in Schedule 2.
We maintain the technical and organisational measures summarised in Schedule 3, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects. Further detail is available on reasonable request.
Because the Customer is the controller of Customer Personal Data, requests from Data Subjects should ordinarily be directed to the Customer. Where we receive such a request directly, we will, unless prohibited by law, inform the Customer without undue delay and not respond ourselves except on the Customer’s instruction. The Service includes built-in tooling for the Customer to export and erase a Data Subject’s records itself, without needing to raise a request with us.
We will make available to the Customer, on reasonable written request no more than once in any 12-month period (or at any time following a Personal Data Breach affecting Customer Personal Data), information reasonably necessary to demonstrate compliance with this DPA, and will permit and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable confidentiality and scheduling safeguards and at the Customer’s cost unless the audit identifies a material breach of this DPA.
We will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, after becoming aware of a Personal Data Breach affecting Customer Personal Data, providing such information as we then have available to assist the Customer in meeting its own notification obligations under Articles 33 and 34 UK GDPR, and will provide further information as it becomes available without undue delay.
On termination of the Agreement, we will make Customer Personal Data available for export for the period described in the Data Retention section of our Privacy Policy, after which it will be deleted or anonymised in accordance with that policy, save that we may retain data we are required to keep by law or for the establishment, exercise, or defence of legal claims.
Each party’s liability arising out of or in connection with this DPA (including under Article 82 UK GDPR) is subject to the limitations and exclusions of liability set out in the Agreement, save that nothing in the Agreement or this DPA limits or excludes either party’s liability for death or personal injury caused by its negligence, for fraud or fraudulent misrepresentation, or for any liability which cannot lawfully be limited or excluded.
This DPA takes effect on the date the Customer accepts the Agreement and continues for as long as we process Customer Personal Data on the Customer’s behalf, notwithstanding termination of the Agreement itself.
This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales. Data protection queries relating to this DPA should be sent to privacy@edutables.com. [CONFIRM: whether a Data Protection Officer has been appointed, per our Record of Processing Activities.]
| Subject matter | Personal Data the Customer uploads to, or generates within, its tables, reports, forms and other items on the Service. |
| Duration | For as long as the Agreement subsists, and thereafter only as described in clause 10. |
| Nature and purpose | Storage; structuring and organisation; retrieval and display; filtering and access restriction; calculation and aggregation; charting and reporting; transmission by email attachment, API feed, calendar feed and public share link, at the Customer’s configuration; export to CSV, Excel, PDF, Word and PowerPoint; pseudonymisation on request; and erasure. |
| Categories of Data Subjects | Determined by the Customer. Typically includes pupils (including children), parents and carers, teaching and support staff, governors, applicants, and external contacts. |
| Categories of Personal Data | Determined entirely by the Customer — the Service imposes no fixed schema. The Customer should assume this may include Special Category Data (for example SEN status, health or medical needs, ethnicity, religion, free-school-meal eligibility, or safeguarding and behaviour notes) and, in behaviour or safeguarding records, criminal offence data within the meaning of Article 10 UK GDPR. |
This list is published here and versioned; see clause 5 for how changes are notified.
| Sub-processor | Role | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Amazon Web Services (hosting the Service on Lightsail) | Infrastructure hosting | All application and Customer Personal Data, at rest and in transit | [CONFIRM: AWS region] | AWS Data Processing Addendum. [CONFIRM: accepted, and whether the region is inside the UK/EEA] |
| Mailgun (Sinch) | Transactional and scheduled email delivery | Recipient address, message subject/body; scheduled report attachments may contain Customer Personal Data | EU | EU-hosted endpoint. [CONFIRM: DPA signed with Sinch] |
| Stripe | Payment processing (billing contact only — no Customer Personal Data) | Billing contact name/email, subscription data. No card details reach us. | [CONFIRM: EU or US contracting entity] | Stripe's published Data Processing Agreement; Standard Contractual Clauses / Data Privacy Framework as applicable to the contracting entity. [CONFIRM] |
| Your chosen AI provider (optional, e.g. Anthropic, OpenAI, Google, Microsoft) | Optional AI Assistant Access, engaged only on your explicit authorisation | Whatever the tools you grant return — may include full table contents | Typically USA | See Privacy Policy §4a for the current, provider-by-provider transfer mechanism table |
Fonts, scripts, and stylesheets are served from EduTables's own infrastructure, not from any third party, so no additional visitor-facing sub-processor arises from them. Background map tile imagery (where the Customer has separately enabled it in Site Settings) is served by whichever provider that setting names, disclosing the viewing user's IP address and the map area viewed.
This document is a template provided for convenience and does not constitute legal advice. It should be reviewed by a qualified solicitor or data protection adviser before being relied upon as a binding Data Processing Agreement, and every [CONFIRM: ...] item above resolved first.