Data Processing Agreement

Data Processing Agreement

GCSE Classroom Ltd and Customer Schools — Version 2.0

Version 2.0 — Effective 27/08/26

 

Parties and status

This Data Processing Agreement (“DPA”) is between:

GCSE Classroom Ltd, registered in England and Wales under company number 13318939, registered office Tyler House, Tyler Street, Stratford-upon-Avon, CV37 6TY (“Classroom42”, “we”, “Processor”); and

the School or organisation that subscribes to the Classroom42 platform (“School”, “you”, “Controller”).

This DPA forms part of and is incorporated into the Terms & Conditions between us. By subscribing to the platform, the School accepts this DPA. No separate signature is required, though we will provide a countersigned copy on request to support your procurement process — email support@classroom42.com.

Where this DPA conflicts with the Terms & Conditions in relation to the processing of Personal Data, this DPA prevails.

Where the platform is used by an individual rather than an organisation, and that individual purchased their membership directly from us, we act as Controller rather than Processor and this DPA does not apply. Our Privacy Policy governs that relationship.

 

1. Definitions

“Data Protection Laws” — the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any successor or amending legislation.

“Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing”, “Personal Data Breach”, and “Supervisory Authority” have the meanings given in the UK GDPR.

“School Personal Data” — Personal Data processed by Classroom42 on behalf of the School under this DPA, as described in Annex 1.

“Subprocessor” — any third party engaged by Classroom42 to process School Personal Data.

“Services” — the Classroom42 platform and related services provided under the Terms & Conditions.

 

2. Roles

2.1 The School is the Controller of School Personal Data. Classroom42 is the Processor.

2.2 The School is responsible for: establishing and documenting a lawful basis for the processing; issuing the privacy information required by Articles 13 and 14 to pupils, parents, and staff; ensuring the accuracy of data it enters; and ensuring its own use of the platform complies with Data Protection Laws.

2.3 Classroom42 is responsible for processing School Personal Data only as set out in this DPA and on the School’s documented instructions.

2.4 The School warrants that it has the authority to instruct the processing of pupil Personal Data under this DPA.

 

3. Instructions

3.1 We will process School Personal Data only on the School’s documented instructions, including in relation to international transfers, unless required otherwise by law — in which case we will tell you first, unless the law prohibits us from doing so on grounds of important public interest.

3.2 The School’s initial documented instructions are: to process School Personal Data as necessary to provide the Services as described in the Terms & Conditions and Annex 1, and as directed by the School’s authorised users through the platform’s functionality.

3.3 Additional or different instructions may be given in writing to support@classroom42.com. We may charge for instructions that fall outside the scope of the Services, and will tell you before doing so.

3.4 We will notify the School if, in our opinion, an instruction infringes Data Protection Laws. We may suspend that instruction until it is withdrawn, amended, or confirmed.

3.5 We do not use School Personal Data for our own purposes. We do not sell it, do not use it for advertising, and do not use it to train artificial intelligence models — neither our own nor those of any third party. We may use aggregated and irreversibly anonymised statistics that cannot identify any individual, School, or class to operate and improve the Services.

 

4. Confidentiality and personnel

4.1 Everyone we authorise to process School Personal Data is bound by a written duty of confidentiality that survives the end of their engagement.

4.2 We limit access to those who need it to deliver the Services and apply role-based access controls.

4.3 We provide data protection awareness training to personnel with access to School Personal Data.

 

5. Subprocessors

5.1 The School gives general written authorisation for Classroom42 to engage Subprocessors, subject to this clause.

5.2 A list of subprocessors is available on request.

 

6. Security

6.1 We implement and maintain appropriate technical and organisational measures under Article 32 UK GDPR, described in Annex 2.

6.2 We review those measures at least annually and after any material change to the Services or infrastructure. We may update them, provided the level of protection is not reduced.

6.3 The School is responsible for security within its own control: managing teacher and pupil accounts, deactivating leavers promptly, keeping credentials confidential, and configuring the platform appropriately.

 

7. Personal Data Breach

7.1 We will notify the School without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data Breach affecting School Personal Data.

7.2 Notification will be sent to the School’s registered data protection contact by email, and will include, to the extent known: the nature of the breach; the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point for further information. Where the full picture is not available immediately, we will provide information in phases without further undue delay.

7.3 We will assist the School in meeting its own obligations under Articles 33 and 34 — including notification to the ICO and, where required, to affected Data Subjects.

7.4 We will not notify the ICO or Data Subjects about a breach affecting School Personal Data on the School’s behalf unless the School instructs us to.

7.5 Breach contact: support@classroom42.com / 01789 569299. Schools should provide us with a data protection contact email at onboarding so notifications reach the right person.

7.6 We maintain an internal record of breaches and will make relevant extracts available to the School on request.

 

8. Assisting the School

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with:

8.1 Data Subject rights — responding to requests for access, rectification, erasure, restriction, portability, and objection. If a Data Subject contacts us directly about School Personal Data, we will not respond substantively but will redirect them to the School and inform the School without undue delay. Teachers can fulfil most requests directly through the Teacher Dashboard; where they cannot, we will help.

8.2 Security obligations (Article 32) — providing information about our measures.

8.3 Data Protection Impact Assessments (Article 35) — providing information about the Services, the AI processing described in Annex 1, our Subprocessors, and our security measures.

8.4 Prior consultation with the ICO (Article 36), where required.

8.5 Assistance under 8.1–8.4 is provided at no charge where the request is reasonable and proportionate. We may charge a reasonable fee for assistance that is excessive or repetitive, and will tell you before incurring any charge.

 

9. International transfers

9.1 School Personal Data is stored and processed in the United Kingdom — see Annex 1. Error monitoring data is processed in the European Union (Germany).

9.2 Where a transfer outside the UK occurs — including where a UK-hosted Subprocessor is incorporated outside the UK and may access data for support or administration — we ensure an appropriate safeguard under Article 46 is in place. This will be one or more of: the UK International Data Transfer Agreement (IDTA); the UK Addendum to the EU Standard Contractual Clauses; an adequacy decision (including in respect of the EU); or the recipient’s certification under the UK Extension to the EU–US Data Privacy Framework.

9.3 We carry out and document transfer risk assessments for transfers to countries without a UK adequacy decision, and apply supplementary technical measures — encryption in transit and at rest, and minimisation of the data transferred.

9.4 The School authorises Classroom42 to enter into transfer mechanisms with Subprocessors on the School’s behalf as its agent, or to rely on the School’s own signature where a Subprocessor requires it.

 

10. Retention, return and deletion

10.1 We retain School Personal Data for the duration of the School’s subscription.

10.2 On expiry or termination, we will delete School Personal Data from live systems within 30 days, unless the School asks us in writing before the end of that period to retain it (for example, pending renewal) or to return it.

10.3 Deletion during the subscription. The School may ask us at any time to delete a pupil, a class, or a cohort — for example, when pupils leave. Teachers can do this through the Teacher Dashboard; we will action written requests within 30 days.

10.4 Backups. Deleted data may persist in encrypted backups and point-in-time recovery snapshots for up to 2 days after deletion from live systems, after which it is overwritten in the ordinary backup cycle. We do not restore backups to recover deleted Personal Data except where necessary to recover from a system failure, and if we do so we will re-apply outstanding deletions.

10.5 We may retain School Personal Data where required by law, and will inform the School of the nature and duration of any such retention.

10.6 We will confirm deletion in writing on request.

 

11. Liability

11.1 Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms & Conditions, except that nothing limits liability that cannot lawfully be limited.

11.2 Nothing in this DPA affects a Data Subject’s rights under Article 82 UK GDPR, or either party’s direct liability to a Supervisory Authority.

11.3 Where both parties are liable for the same damage, liability is apportioned according to each party’s responsibility under Article 82(5).

 

12. Term, changes and general

12.1 This DPA takes effect when the School first subscribes and continues while we process School Personal Data.

12.2 We may update this DPA to reflect changes in law, regulatory guidance, or the Services. Material changes will be notified at least 30 days in advance, by email and on this page. Continued use after the effective date constitutes acceptance. Where a change materially reduces the protection given to School Personal Data — which we do not anticipate — the School may terminate the affected Services with a pro-rata refund.

12.3 Notices under this DPA go to support@classroom42.com and to the School’s registered contact.

12.4 If any provision is held invalid, the remainder continues in force.

12.5 This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.

 

ANNEX 1 — Details of processing

Required by Article 28(3) UK GDPR

1. Subject matter

Provision of the Classroom42 online learning and assessment platform, including AI-assisted marking of exam-style questions.

2. Duration

For the term of the School’s subscription, plus the retention period in clause 10.

3. Nature and purpose

Hosting, storing, organising, retrieving, transmitting, analysing, and deleting School Personal Data in order to: create and manage teacher and pupil accounts; deliver learning content, quizzes, and exam-style questions; record pupil responses; generate marks and feedback; present progress information to teachers and pupils; provide technical support; and maintain the security and reliability of the platform.

4. Categories of Data Subject

•             Pupils at the School

•             Teachers and teaching staff at the School

•             School administrative staff with platform access

5. Categories of Personal Data

Category           Detail

Identity              Name

Contact             Email address

Account            Username, hashed password, role, account status, last login

Organisational             School, class, group, teaching set

Assessment    Answers to quizzes and exam-style questions, including free text written by the pupil

Assessment output    AI-generated marks and written feedback; teacher-adjusted marks; teacher comments

Usage Topics attempted, dates and times of activity, progress records

Technical          IP address, browser and device type, session identifiers, diagnostic and error data

6. Special category data

None is requested or required. The platform is not designed to collect data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health, sex life, or sexual orientation.

Free-text answer fields could technically receive such data if a pupil typed it. Schools should instruct pupils that answer fields are for exam responses only. If we become aware that special category data has been entered, we will inform the School and delete it on instruction.

7. Automated processing — AI marking

This section describes processing that involves School Personal Data leaving Classroom42’s infrastructure. Schools should include it in their own DPIA.

What is processed: when a pupil submits a free-text answer, the answer text, the question, and the associated mark scheme are transmitted to our AI subprocessor, which returns a suggested mark and written feedback. That output is stored against the pupil’s record in our UK database.

Identifiers: Requests to the AI provider contain only the question text, the mark scheme, the teacher's optional marking instructions, the maximum marks, and the pupil's typed answer. No pupil name, email address, username, user ID, attempt ID, class, school, or IP address is included in the prompt or in the request metadata. The prompt is assembled server-side from a fixed template with a closed set of placeholders — there is no placeholder for pupil identity, so no identifying field can be interpolated into it. Requests originate from our server, not the pupil's browser, so the pupil's IP address is never exposed to the provider. The only identifier attached to a request is a numeric course ID sent as dashboard metadata; it identifies course content, not a person. Answers are therefore pseudonymised at the point of transmission: the provider receives an unattributed piece of work with no means of linking it to an individual.

Provider: OpenAI.

Training: School Personal Data is not used to train or improve any AI model.

Retention by the provider: Inputs and outputs are not stored at rest by OpenAI. Inputs and outputs may be retained by OpenAI for up to 30 days for abuse monitoring, then deleted unless OpenAI is legally required to retain them.

Human involvement: AI-generated marks and feedback are suggestions for teacher review. Teachers can view, amend, or reject any AI output. AI marking does not produce a legal or similarly significant effect on a pupil, does not constitute a qualification, and is not reported to any exam board. This processing is therefore not solely automated decision-making within Article 22 UK GDPR.

Accuracy: AI-generated marks are not guaranteed accurate. Schools should ensure teachers review AI output before relying on it or communicating it as a formal assessment.

 

ANNEX 2 — Technical and organisational measures

Required by Article 32 UK GDPR

Access control

•             Role-based access; least privilege

•             Passwords stored using industry-standard one-way hashing; never stored in plain text and not recoverable by us

•             Teachers control pupil account creation and deactivation within their own School

Encryption

•             TLS for all connections between users and the platform, and between our infrastructure and Subprocessors

•             Encryption at rest for the primary database, backups, and object storage

•             Secrets and credentials held in managed secret storage, not in source control

Infrastructure and separation

•             Production, staging, and development environments are separated, with distinct credentials and databases

•             Production deployment is gated behind protected branch controls and review

•             Production database access is restricted to named personnel

•             Infrastructure is provided by established cloud providers with their own certified physical and operational security

Resilience and recovery

•             Automated backups with point-in-time recovery

•             Scheduled snapshots retained for 2 days

•             Recovery procedures tested periodically

Software security

•             Routine dependency patching and vulnerability monitoring

•             Code review before production deployment

•             Bot and denial-of-service protection at the network edge

Organisational

•             Written confidentiality obligations for all personnel with data access

•             Data protection awareness training

•             Documented incident response and breach notification procedure

•             Subprocessor due diligence before engagement and on review

•             Data protection by design and default in new features

Certifications

We are also registered with the Information Commissioner’s Office (ICO) under registration number ZB259604.

 

Requesting a signed copy

Schools requiring a countersigned DPA for their procurement records should email support@classroom42.com. We will return an executed PDF, ordinarily within 5 working days.

 

GCSE Classroom Ltd, registered in England and Wales, company number 13318939. ICO registration ZB259604

Download DPA