Data Processing Agreement

The Article 28 terms under which we process personal data on a school's behalf. This is the document your data protection officer or governing body will want to see — and it is written to be checked, not skimmed.

Last updated 5 August 2026 · Ummah Design, United Kingdom

1. Roles

The School is the data controller. It decides what pupil, family and staff data is collected and why. Ummah Design is the processor, acting only on the School’s documented instructions — which, for day-to-day purposes, means the actions the School takes in the platform, plus this agreement and the Terms of Service.

If we ever believe an instruction breaches data protection law, we will say so before acting on it.

2. Subject matter, duration, nature and purpose

We process personal data to run the School’s admissions, timetabling, attendance, homework, communications and fee collection, for as long as the subscription is in force, plus the return-and-deletion window in section 9.

3. Categories of data subject

  • Pupils (including children under 13)
  • Parents, guardians and emergency contacts
  • Teachers and school staff
  • Prospective families who apply or join a waiting list

4. Categories of personal data

CategoryExamples
IdentityName, date of birth, gender, year group, pupil reference
ContactParent email, telephone, WhatsApp number, address
EducationClass enrolment, timetable, attendance and punctuality, homework submissions and teacher feedback, lesson recordings
FinancialFees, discounts and scholarship status, invoice and payment history. Card details are never held by us — they go directly to Stripe.
PastoralAttendance and engagement flags, notes recorded by staff, complaints, deregistration reasons
TechnicalSign-in records, IP address, device/browser, audit log of administrative actions

Special category data

The platform is not designed as a store for special category data (health, religion, ethnicity and similar). Free-text fields such as pastoral notes could contain it if School staff enter it; where that happens the School must satisfy itself it has an Article 9 condition. We apply the same technical protections to those fields as to all other data.

5. Our obligations

  • Process only on the School’s documented instructions.
  • Ensure everyone with access is bound by confidentiality.
  • Apply the security measures in section 6.
  • Engage sub-processors only under section 7.
  • Assist the School with data-subject requests, impact assessments and consultations with the ICO.
  • Notify the School without undue delay and in any event within 48 hours of becoming aware of a personal data breach, with the facts we hold at that point, and keep the School updated as we learn more. This leaves the School a clear day inside its own 72-hour deadline for reporting to the ICO.
  • Make available the information needed to demonstrate compliance, and allow audits under section 10.

6. Security measures

  • Isolation. Every request is scoped to one school; access is verified server-side on every page and every action, not merely hidden in the interface.
  • Encryption. TLS 1.2/1.3 in transit; encryption at rest; integration credentials separately encrypted with AES-256-GCM.
  • Authentication. Passwords hashed with bcrypt; optional two-factor authentication for every staff account, enforceable school-wide; brute-force throttling on sign-in; sessions revocable server-side.
  • Least privilege. Role tiers separate day-to-day administration from finance, pricing and staff pay.
  • Accountability. Administrative actions written to an append-only audit log, retained at least 2 years.
  • Resilience. Encrypted backups at least daily, held in more than one location and restore-tested; dedicated EU hosting.
  • Safeguarding by design. Pupil accounts cannot change their own password or contact other pupils; pupil-authored board posts require teacher approval before publication; lesson recordings are enrolment-gated and stream-only.

7. Sub-processors

The School authorises the following sub-processors:

Sub-processorPurposeLocation
Hetzner Online GmbHHosting, database, backupsGermany
Cloudflare, Inc.DNS, TLS, network protectionEU/UK entry
Stripe, Inc.Payment processing (on the School’s own connected account)EU/US
Resend, Inc.Transactional emailEU/US
Zoom Communications, Inc.Live lessons, attendance events and recordings — under the School’s own Zoom account and termsPer School’s Zoom account
Anthropic, PBCAI assistant features, only where the School enables themUS

We will give at least 30 days’ notice before adding or replacing a sub-processor. If the School reasonably objects on data protection grounds and we cannot offer an alternative, the School may terminate without penalty.

8. International transfers

Pupil and family data is stored in the UK/EEA. Where a sub-processor may process data outside the UK/EEA (for example Stripe, Resend or Anthropic), transfers rely on the UK International Data Transfer Addendum or Standard Contractual Clauses together with that provider’s safeguards.

9. Return and deletion

The School may export its data from the admin area at any time. On termination we retain the tenant for 30 days so the School can complete an export, then delete it. Encrypted backups age out within 90 days of that deletion. We may retain records we are legally obliged to keep (for example invoices for accounting), and audit-log entries where retention is necessary for safeguarding accountability.

10. Audit

On reasonable written notice, and no more than once a year unless required by a regulator or following a breach, we will answer a written security questionnaire and provide documentation evidencing the measures in section 6.

Where that is not enough for the School to satisfy itself, or where a regulator requires it, the School — or an independent auditor it appoints — may carry out an inspection. Inspections are arranged at a mutually agreed time, are subject to confidentiality, and must not compromise the security or the privacy of any other school on the platform. We bear our own costs for the annual review above; the School bears the cost of any further inspection it asks for.

11. Liability and precedence

This agreement is subject to the limits of liability in the Terms of Service. Where this agreement and the Terms conflict on the processing of personal data, this agreement prevails.

12. Signature

These terms take effect when the School begins using the platform, and are incorporated into the Terms of Service by reference. Where a school’s governance requires a signed copy, we will provide and countersign one on request — print this page or email ummah.design@gmail.com.

Questions about this document? Contact Ummah Design at ummah.design@gmail.com.