Data Processing Terms

1. Who is who

“We”, “us” and “our” mean BlueAcorn Education Ltd, registered in England and Wales under company number 17363744, registered office 66 Paul Street, London, England, EC2A 4NA, ICO registration ZC207937. “You” means the school, trust, college or other organisation on whose behalf student information is entered into the service – including where an individual teacher does the entering. “Student information” means personal data about your students that is processed through the service.

For student information you are the controller and we are the processor. You decide what goes in and why; we handle it only to run the service for you.

For information about the teacher’s own account – email address, name, subscription, usage counts – we are the controller in our own right, and our Privacy Policy governs that. These terms do not apply to it.

Words defined in the UK GDPR – controller, processor, personal data, processing, personal data breach, supervisory authority – carry those meanings here. “UK GDPR” and “Data Protection Act 2018” mean those instruments as they apply in the United Kingdom, together with any legislation replacing them.

2. What we process, and why

This section is the description Article 28(3) requires.

3. Acting only on your instructions

We process student information only on your documented instructions, including as to transfers outside the United Kingdom. Your instructions are: these terms, our Terms & Conditions and Privacy Policy, and what you do in the service itself – setting a quiz, running a marking set, keeping a roster. Using a feature is an instruction to carry out the processing that feature performs.

If we are required by law to process student information beyond your instructions, we will tell you before doing so unless the law forbids us from telling you. If we think an instruction of yours breaches data protection law, we will tell you and may pause that processing while it is resolved.

4. Confidentiality

Everyone we allow to access student information is bound by a duty of confidence, whether by contract of employment or otherwise, and is given access only where their role needs it.

5. Security

We apply appropriate technical and organisational measures under Article 32. What they currently are is set out in Annex A. We may change them as the service and the threats to it change, but not in a way that materially reduces protection.

6. Sub-processors

You give us general written authorisation to engage sub-processors. The current list, what each one does, where it is, and whether it sees student information, is published at /subprocessors, which forms part of these terms and carries a dated change history.

Before adding or replacing a sub-processor that would have access to student information, we will give you at least 30 days’ notice by email to the address on the account and by updating that page. If you reasonably object on data protection grounds within those 30 days, tell us and we will try to find another way of providing the affected feature; if we cannot, you may terminate the affected part of the service without penalty and receive a refund of anything paid for the unused remainder of your term.

We impose on every sub-processor obligations no less protective than those in these terms, and we remain fully liable to you for what our sub-processors do.

7. International transfers

Student information is stored at rest only in the United Kingdom or the European Economic Area. Marking and transcription require sending the relevant text or image to AI providers in the United States. Those transfers are made under the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, or another safeguard permitted by Chapter V of the UK GDPR. Section 5 of our Privacy Policy explains each transfer, and forms part of these terms. No student information is sent to our generation provider in China.

We send no student name alongside an answer submitted for marking: what leaves us is the question and the answer, and the link to the student stays in our database.

8. Helping you answer people’s requests

Requests from students or parents about student information are yours to answer, as controller. Taking account of what the processing involves, we will help you with appropriate technical and organisational measures so far as we reasonably can – including access, correction, erasure, restriction, objection and portability. Most of this you can do yourself in the service: a quiz, lesson, marking set or roster entry can be deleted at any time, and deleting it deletes the student information it holds.

If a student or parent contacts us directly, we will not respond to the substance ourselves; we will pass the request to you promptly and tell them we have done so.

9. Helping you with breaches, DPIAs and the ICO

Taking into account the nature of the processing and the information available to us, we will assist you in meeting your obligations under Articles 32 to 36 – security, breach notification to the ICO and to affected people, data protection impact assessments, and prior consultation with the ICO. We publish a pre-completed DPIA pack covering the service, downloadable for Word, which you are welcome to copy into your own template and adapt. It answers every question in a DPIA that is about our service rather than about your school, and we will complete your own supplier security questionnaire if you would rather work from that.

10. Telling you about a breach

If we become aware of a personal data breach affecting student information, we will notify you without undue delay, and in any event within 24 hours of becoming aware of it, at the email address on the account. Our notification will describe what happened, the categories and approximate number of students and records affected so far as known, the likely consequences, and what we are doing about it. Where we cannot provide all of that at once we will provide it in phases without undue delay. It is for you, as controller, to decide whether the ICO or the people affected must be told.

11. Deletion and return

You can delete student information yourself at any time by deleting the quiz, lesson, marking set or roster entry that holds it. When an account is closed, everything attached to it – including student responses, lesson attempts and marking – is deleted with it.

At the end of our provision of the service, we will delete all student information, or return it to you first if you ask within 30 days of the end. We keep nothing afterwards except where UK law requires us to. Ordinary backups and the operational monitoring records described in our Privacy Policy expire on their own cycles; those cycles are set out in Annex A, and nothing in them is used for any purpose other than restoring or maintaining the service.

12. Audits and information

We will make available to you all information reasonably necessary to demonstrate that we are meeting these terms, and will allow and contribute to audits, including inspections, conducted by you or an auditor you appoint. In the first instance we will answer in writing – including by completing your standard supplier security questionnaire – and we would expect that to be enough in most cases. Where it is not, an on-site or remote inspection may take place on 30 days’ notice, no more than once in any twelve months unless a breach or a regulator requires otherwise, during business hours, subject to confidentiality, and in a way that does not disrupt the service to other customers.

13. What you are responsible for

14. Changes, precedence and contact

We may update these terms to keep them accurate or to meet a change in the law. If a change materially affects your rights under them we will give you at least 30 days’ notice by email and in the app, and the previous version continues to apply during that period.

If these terms conflict with our general Terms & Conditions on anything concerning student information, these terms prevail. If they conflict with a separately signed agreement between us, that agreement prevails.

Contact for anything in this document, including audit requests, sub-processor objections and DPIA support: [email protected], or BlueAcorn Education Ltd, 66 Paul Street, London, England, EC2A 4NA.

Annex A – security measures

These are the measures referred to in section 5, as at the version date above.