SeedSlateAll documents

School and tutor data processing terms

Draft contractual schedule for processing educational data on a customer’s instructions.

Parties and processing schedule

Customer controller: to be named. SeedSlate processor: legal operator to be confirmed. Apply these terms only where the actual relationship is controller–processor. The operator’s separate account/security purposes need their own assessment.

Subject: hosting and delivering the contracted teaching service. Duration: the agreed service term and agreed return/deletion period. Operations: collect, organise, store, retrieve, transmit to authorised recipients, support and delete. Subjects: students, teachers and authorised customer contacts. Data: identities, memberships, educational work, assignments, results, communications and necessary service metadata. Special-category data is not requested and must not be introduced without written agreement and safeguards.

Processor duties

The proposed processor duties are to act only on documented instructions, including transfer instructions; ensure authorised personnel are bound to confidentiality; implement appropriate technical and organisational measures; and inform the controller if an instruction infringes applicable data-protection law.

The processor must assist with rights requests, security, breach notifications, impact assessments and regulator consultation as applicable. Notify a controller of a personal-data breach without undue delay; the agreed incident contacts and contractual reporting target must be completed.

Provide information needed to demonstrate compliance and permit proportionate audits/inspections under agreed arrangements. At service end, return or delete personal data at the controller’s choice, including copies, unless law requires retention. Backup treatment and deletion capabilities need verification before signing.

Suppliers and security schedule

Authorisation for subprocessors, advance change notices, objection arrangements and equivalent downstream obligations must be agreed. Confirm supplier legal entities, service purpose, locations and transfer safeguards in the signed schedule.

The current app has role-based access checks, authenticated server APIs, separate test storage and owner-only administration. Do not promise certifications, guaranteed UK residency, a backup schedule or an incident SLA that has not been verified. Add an approved security schedule covering access, encryption, backups, vulnerability handling and staff responsibilities before execution.