How to use this DPA. Schools with a Data Protection Officer (DPO) can review this template as an initial position paper before contract. alevelmathrevision.com is happy to sign it as-is, or to accept the school's standard DPA if provided (subject to review). Where fields are marked [LIKE THIS], the school should complete them on execution.
1. Parties & role
This Data Processing Agreement ("DPA") is entered into between:
- The Controller — [School legal name, address, ICO/DPA registration number], acting as data controller in relation to student and staff personal data processed via alevelmathrevision.com.
- The Processor — Peter Bromfield trading as alevelmathrevision.com, registered address: [registered address], contact: pbromfield@alevelmathrevision.com, acting as data processor.
This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the Controller's licence to use the alevelmathrevision.com platform ("the Service").
2. Subject-matter and duration of processing
The Processor processes personal data solely to deliver the contracted Service for the duration of the school's licence period, plus a retention tail of 30 days after termination during which the Controller may request data export.
3. Nature and purpose of the processing
- Authenticate students, teachers, and administrators.
- Record and display each learner's own progress (streaks, revealed mark schemes, checklist ticks, Path-to-A* progress).
- Enable teachers to view aggregate class progress and assign homework across UK 9MA0 and IAL boards.
- Send transactional emails (weekly digests, homework notifications, receipts).
- Detect abuse and enforce rate limits.
4. Categories of data subjects and personal data
| Category of data subject | Categories of personal data |
| Students enrolled by the school | Name (if provided), school email address, class assignments, per-question attempts and scores, streaks, revealed-scheme records, Path-to-A* progress. |
| Teachers & administrators | Name, email, role, homework assignments authored, class-management events. |
5. Sub-processors
The Controller authorises the Processor to engage the following sub-processors, each bound by contractual obligations at least equivalent to this DPA:
| Sub-processor | Service | Region |
| Google LLC (Firebase / Cloud Functions / Firestore / Firebase Auth) | Application hosting, authentication, database, serverless functions | europe-west1 (Belgium) & europe-west3 (Frankfurt) |
| Google LLC (Cloud Storage) | PDF and asset storage | europe-west |
| Stripe Payments Europe Limited | Card processing for licence purchases (GBP) | Ireland / EU |
| Resend Inc. | Transactional email delivery (receipts, homework notifications) | United States (bound by SCCs — see Section 8) |
| Google LLC (Gemini API) | AI grading and content-generation. Payloads contain student submissions but no name/email; requests are non-retained per Google's terms. | United States (bound by SCCs — see Section 8) |
The Processor will give the Controller at least 30 days' written notice of any change in sub-processors.
6. Obligations of the Processor
- Process personal data only on documented instructions from the Controller.
- Ensure that persons authorised to process the personal data are subject to appropriate confidentiality obligations.
- Take all technical and organisational measures required under Article 32 UK/EU GDPR (see Section 7).
- Assist the Controller with data-subject requests and DPIAs.
- At the choice of the Controller, delete or return all personal data at the end of the Service.
- Notify the Controller without undue delay after becoming aware of a personal data breach.
7. Technical and organisational measures (Article 32)
- Encryption in transit — TLS 1.2+ on every endpoint; HSTS enforced.
- Encryption at rest — Firestore documents and Cloud Storage objects are encrypted at rest using Google-managed keys.
- Access control — Firestore Security Rules restrict reads and writes; owner/school-admin escalation is server-side.
- Backups — daily Firestore automatic backups retained for 30 days.
- Logging — admin access is logged with actor email and timestamp; retained for at least 12 months.
- Rate limiting & abuse controls — per-user quotas on write endpoints.
- Vulnerability management — dependencies audited on every build.
8. International transfers
Where personal data is transferred to a sub-processor outside the UK/EEA (currently Resend Inc. and Google Gemini API), transfers are safeguarded by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum (IDTA).
9. Data subject rights
- Access / portability — export in JSON on written request.
- Rectification — direct edit via the student's own account or admin escalation.
- Erasure — deletion within 30 days of instruction.
- Restriction / objection — pause a student's access via the class-code interface.
10. Personal data breach
The Processor will notify the Controller of a personal data breach without undue delay and in any case within 48 hours of becoming aware.
11. Return or deletion at end of processing
At the Controller's written choice at the end of the licence, and no later than 30 days after termination, the Processor will either return all personal data (JSON) or delete all such personal data and certify deletion in writing.
12. Term, priority, and governing law
This DPA is governed by the law of England and Wales, with non-exclusive jurisdiction of the English courts.
13. Signatures
________________________________________
For the Controller
Name: [full name]
Title: [Head / DPO]
Date: [DD-MM-YYYY]
________________________________________
For the Processor
Name: Peter Bromfield
Title: Founder, alevelmathrevision.com
Date: on execution