School and tutor data processing terms
Draft for review — not effective terms or a completed privacy notice.
Version 2026-10-10-draft-3 · Updated 10 October 2026
Draft contractual schedule for processing educational data on a customer’s instructions.
Parties and processing schedule
Customer controller: to be named. SeedSlate processor: legal operator to be confirmed. Apply these terms only where the actual relationship is controller–processor. The operator’s separate account/security purposes need their own assessment.
Subject: hosting and delivering the contracted teaching service. Duration: the agreed service term and agreed return/deletion period. Operations: collect, organise, store, retrieve, transmit to authorised recipients, support and delete. Subjects: students, teachers and authorised customer contacts. Data: identities, memberships, educational work, assignments, results, communications and necessary service metadata. Special-category data is not requested and must not be introduced without written agreement and safeguards.
Processor duties
The proposed processor duties are to act only on documented instructions, including transfer instructions; ensure authorised personnel are bound to confidentiality; implement appropriate technical and organisational measures; and inform the controller if an instruction infringes applicable data-protection law.
The processor must assist with rights requests, security, breach notifications, impact assessments and regulator consultation as applicable. Notify a controller of a personal-data breach without undue delay; the agreed incident contacts and contractual reporting target must be completed.
Provide information needed to demonstrate compliance and permit proportionate audits/inspections under agreed arrangements. At service end, return or delete personal data at the controller’s choice, including copies, unless law requires retention. Backup treatment and deletion capabilities need verification before signing.
Suppliers and security schedule
Authorisation for subprocessors, advance change notices, objection arrangements and equivalent downstream obligations must be agreed. Confirm supplier legal entities, service purpose, locations and transfer safeguards in the signed schedule.
The current app has role-based access checks, authenticated server APIs, separate test storage and owner-only administration. Do not promise certifications, guaranteed UK residency, a backup schedule or an incident SLA that has not been verified. Add an approved security schedule covering access, encryption, backups, vulnerability handling and staff responsibilities before execution.