# Data Processing Agreement — Grademy × School
**Version:** 1.0
**Effective:** 2026-07-01
**Provider:** Grademy Ltd (registered in England + Wales, company no. 14XXXXXX)
**ICO Registration:** ZA123456

---

## 1. Parties
This Data Processing Agreement ("DPA") forms part of the main Services Agreement between:
- **Controller:** The School (the educational institution named in the Order Form)
- **Processor:** Grademy Ltd (the AI tutoring platform provider)

## 2. Subject matter
Grademy processes personal data on behalf of the School to deliver AI-powered tutoring services to pupils enrolled at the School.

## 3. Nature and purpose of processing
- Diagnostic assessment (academic gaps only)
- Adaptive tutoring delivery
- Progress tracking
- Teacher dashboard reporting
- Parent communication (where parental consent obtained)

## 4. Categories of data subjects
- Pupils (Year 1–13, ages 5–18)
- Teachers and school staff
- Parents (where signed up directly)

## 5. Categories of personal data
- Pupil: name, year group, school, diagnostic answers, time-on-task, mode selections, progress data
- Teacher: name, email, role, school, login activity
- Parent: name, email (where direct signup)

## 6. Lawful basis
- Article 6(1)(a) — consent
- Article 6(1)(f) — legitimate interests (educational provision)
- Article 9(2)(g) — substantial public interest (education)

## 7. Duration
Processing continues for the duration of the Services Agreement plus 30 days for data return/deletion.

## 8. Sub-processors
See live list at /security/sub-processors. Grademy will notify Controller 30 days before adding new sub-processors.

## 9. Controller obligations
- Obtain parental consent for under-13 pupils
- Maintain record of consent
- Notify Grademy of any consent withdrawals within 7 days
- Provide list of enrolled pupils + year groups

## 10. Processor obligations
- Process data only on documented Controller instructions
- Ensure confidentiality of authorised personnel
- Implement appropriate technical and organisational measures (see Annex A)
- Engage sub-processors only with Controller authorisation
- Assist Controller with data subject rights requests within 30 days
- Delete or return all data at end of Services Agreement
- Make available all information necessary to demonstrate compliance

## 11. Data subject rights
Grademy will assist the Controller in fulfilling:
- Right to access (1 month SLA)
- Right to rectification (immediate)
- Right to erasure (30 days)
- Right to portability (JSON export, 7 days)
- Right to object (immediate)

## 12. International transfers
No personal data leaves the UK + EU. Where sub-processors are US-based, transfers are protected by Standard Contractual Clauses + UK Addendum.

## 13. Security measures (Annex A)
- TLS 1.3 in transit
- AES-256 at rest
- Per-pupil encryption keys
- MFA mandatory for all staff
- SSO via Google + Microsoft
- 24/7 SOC monitoring
- Annual penetration test
- Cyber liability insurance £5M

## 14. Breach notification
Grademy will notify Controller within 72 hours of becoming aware of any personal data breach.

## 15. Audit rights
Controller may audit Processor's compliance with this DPA once per year, with 30 days notice, during business hours, without disrupting operations.

## 16. Liability
Grademy's liability under this DPA is capped at £5,000,000 per incident, subject to the limits in the main Services Agreement.

## 17. Governing law
This DPA is governed by the laws of England and Wales. Disputes subject to exclusive jurisdiction of English courts.

---

**Signed for Grademy Ltd:**
Amir Khan, Founder + CEO
Date: 2026-07-01

**Signed for School:**
________________________________
Name, Role
Date: ____________

---

## ANNEX A — Technical and Organisational Measures

### Access control
- Role-based access (pupil, teacher, school admin, MAT admin, DPO)
- MFA mandatory for all staff accounts
- SSO via Google + Microsoft
- Quarterly access reviews

### Encryption
- TLS 1.3 for all data in transit
- AES-256 for all data at rest
- Per-pupil encryption keys for diagnostic data
- HSM-backed key management

### Operational security
- Cyber Essentials Plus certified
- 24/7 SOC monitoring via sub-processor
- Annual penetration test by CREST-accredited firm
- Quarterly vulnerability scans
- Patch SLA: critical 24h, high 7d, medium 30d

### Data lifecycle
- Default retention: end of academic year + 30 days
- Pseudonymisation of analytics data after 90 days
- Secure deletion: NIST 800-88 purge

### Incident response
- 72-hour breach notification SLA
- Documented incident runbook tested quarterly
- Forensic investigation by certified team
- Post-incident report + remediation plan

### Business continuity
- RPO: 1 hour
- RTO: 4 hours
- Multi-region backup (London primary, Dublin secondary)
- Quarterly DR test

### Personnel
- Background checks for all staff with data access
- Annual data protection training (mandatory)
- Confidentiality clauses in employment contracts
- Clean desk policy enforced

### Vendor management
- DPA required for all sub-processors
- Annual sub-processor security review
- Right to audit sub-processors (passed through)

---

**Document version:** 1.0 (2026-07-01)
**Next review:** 2027-07-01
**Owner:** Grademy DPO (dpo@grademy.work)