← Back to home

Data processing agreement

The processor terms required by GDPR Article 28. This forms part of the contract between your school and us, and it is where the pupil-data obligations live.

Last updated
26 July 2026
Effective from
26 July 2026

Draft — not yet reviewed by legal counsel

This document describes how the product actually works, but it has not been reviewed by a qualified lawyer and some company details are still outstanding. It is published for transparency and is not yet a binding legal document. Anything marked ▲ to be supplied is a known gap.

1. Subject matter and duration

Subject matterProvision of a hosted school management system to the school.
DurationFor as long as the school’s subscription is active, plus the 30-day post-termination export window.
Nature and purposeStorage, organisation, retrieval, structuring and transmission of school records for the purpose of school administration — enrolment, timetabling, attendance, assessment, fee collection and communication.
Categories of data subjectPupils, parents and guardians, teaching and administrative staff, and the school’s own account holders.
Types of personal dataAs set out in §2 below, including special category data where the school chooses to record it.

2. The data covered

PeopleData
PupilsName, date of birth, nationality, identity-document number and expiry, admission number, photograph, contact email, previous school, sibling links, class and enrolment history, attendance records, assessment marks and report cards, fee and payment records, transport, library and boarding records where those modules are enabled
Special category: Medical conditions, allergies, medication, dietary requirements and safeguarding notes, where a school chooses to record them
Parents and guardiansName, relationship to pupil, email address, telephone number, postal address, and the payment and correspondence history associated with their account
StaffName, staff identifier, work email and telephone, employment and contract dates, qualifications and expiry, subject certifications, background-check status, work authorisation, campus scope, timetable and teaching load
Special category: Background-check status, where a school chooses to record it
All account holdersLogin email, hashed password, multi-factor authentication enrolment, session and sign-in records, and an audit trail of the actions taken in the system

3. Processing only on instructions

We process personal data only on the school’s documented instructions, including in relation to international transfers, unless the law requires otherwise — in which case we will tell the school before processing, unless the law forbids us from doing so.

The school’s documented instructions are: this agreement, the terms of service, and the configuration choices and actions the school takes in the product. Using a feature is an instruction to process the data that feature needs.

If we consider an instruction to breach data protection law, we will tell the school promptly and may decline to act on it.

4. Confidentiality

Anyone we authorise to process personal data is bound by a duty of confidentiality that survives the end of their engagement, and is given access only to the extent their role requires it.

5. Security measures

We implement appropriate technical and organisational measures under GDPR Article 32. As currently implemented these include:

  • Tenant isolation. Every record is scoped to its school and campus at the data-access layer, and access is enforced there rather than in individual screens.
  • Encryption in transit for all connections, enforced at the domain level.
  • Credential protection. Passwords are hashed and never stored in readable form. Multi-factor authentication is available. Invitation and password-reset links expire after one hour and can be used once.
  • Session binding. A session is bound to a single school; a token issued for one cannot be used against another.
  • Least privilege. Roles are bound to invitations and can only narrow by scope, never widen. A user cannot elevate themselves.
  • Audit logging. An immutable 7-year log records who changed what, when, and in which campus. It cannot be edited or erased by any user, including a school administrator.
  • Separation of sensitive data. Medical and safeguarding information is held apart from the main record, permission-gated, and excluded from published documents by design.

The security page describes this in more detail, including the measures we have not implemented. We hold no SOC 2 report and no ISO 27001 certification and do not represent otherwise.

6. Sub-processors

The school gives general authorisation for us to engage sub-processors. The current list is published at /sub-processors and today comprises Cloudflare, Inc. and Postmark (ActiveCampaign, LLC).

  • We give at least 30 days’ notice before adding a sub-processor.
  • The school may object on reasonable data-protection grounds. If we cannot resolve the objection, the school may terminate the affected part of the service without penalty and receive a refund of prepaid, unused fees.
  • Each sub-processor is bound by written terms no less protective than these, and we remain fully liable to the school for their performance.

7. International transfers

The primary database is hosted in Western Europe. Transactional email is delivered through a provider in the United States, and static assets are served from the location nearest the visitor.

Where personal data is transferred outside the UK or EEA, the transfer is made under the European Commission’s Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum, supplemented by the measures in §5.

8. Assistance to the school

Taking into account the nature of the processing, we will assist the school with:

  • Data subject requests. The product lets a school find, correct, export and delete records itself, which is usually faster than asking us. Where a request cannot be satisfied through the product, we will help.
  • Requests sent to us by mistake. If a parent, pupil or staff member contacts us directly, we will not act on the records. We will forward the request to the school and tell the person we have done so.
  • Security, breach notification and impact assessments under Articles 32 to 36, including providing the information a school needs to complete a DPIA.

9. Personal data breaches

We will notify the school without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting its data — so that the school can meet its own 72-hour regulatory deadline with time to spare.

Our notification will describe, so far as we know it at the time:

  • the nature of the breach and the data and people affected;
  • the likely consequences;
  • the measures taken or proposed in response;
  • a contact point for further information.

We will not delay an initial notification in order to complete an investigation. Reporting to a supervisory authority and to affected individuals is the school’s decision as controller.

10. Deletion and return

At the end of the agreement the school may export its data for 30 days. After that we delete it from live systems. Backups age out on their own cycle and are not selectively retrievable.

Retention while the agreement is running:

WhatHow longSet by
Pupil, guardian and staff recordsFor as long as the school's subscription is activeThe school decides its own retention schedule. Classbell retains records until the school deletes them or the account is closed.
Audit log7 yearsFixed by Classbell and not shortenable by a school, because an audit trail that a user can erase is not an audit trail. Records who changed what, when, and in which campus.
Financial records — invoices, payments, receiptsRetained for the life of the account, and never deleted in placePayments are reversed with a compensating entry rather than deleted, and receipt numbering stays gapless. This is an accounting-integrity requirement, not a data-minimisation choice.
Invitation and password-reset links1 hour, single-useExpire automatically. School-owner activation links last 72 hours.
Data after account closure30 days, then deletedA 30-day window to export or reinstate, after which customer data is deleted from live systems. Backups age out on their own cycle.
Suspended or dormant accountsRetained, not deletedSuspension walls access to the portal but retains all data, so a school that resolves a billing issue gets its records back intact.

11. Audits and information

We will make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the school or an auditor it mandates.

In practice we ask that audits be at reasonable notice, no more than once a year unless a breach or a regulator requires otherwise, conducted so as not to disrupt the service or compromise the confidentiality of other customers’ data, and at the school’s cost.

12. Liability and precedence

This agreement forms part of the terms of service. Where this agreement and the terms of service conflict on a data protection matter, this agreement prevails.

13. Contact

Data protection enquiries, audit requests and breach correspondence: Privacy contact address — to be supplied.

Data Protection Officer: DPO name — to be supplied DPO email — to be supplied

Processor: Registered legal name — to be supplied, of Registered address — to be supplied.