Data Processing Terms
Version 1.0 · 2 September 2026
These terms are the written contract required by Article 28(3) of the UK GDPR. They apply whenever you use BA Productivity to handle information about your students, and they set out what we may do with that information, what we must do to protect it, and what you can require of us. They form part of our Terms & Conditions and take effect when you accept those terms – there is nothing you need to sign. If your school requires its own paper instead, or a signed counterpart of this document, email [email protected] and we will provide one.
- Who is who
- What we process, and why
- Acting only on your instructions
- Confidentiality
- Security
- Sub-processors
- International transfers
- Helping you answer people’s requests
- Helping you with breaches, DPIAs and the ICO
- Telling you about a breach
- Deletion and return
- Audits and information
- What you are responsible for
- Changes, precedence and contact
- Annex A – security measures
1. Who is who
“We”, “us” and “our” mean BlueAcorn Education Ltd, registered in England and Wales under company number 17363744, registered office 66 Paul Street, London, England, EC2A 4NA, ICO registration ZC207937. “You” means the school, trust, college or other organisation on whose behalf student information is entered into the service – including where an individual teacher does the entering. “Student information” means personal data about your students that is processed through the service.
For student information you are the controller and we are the processor. You decide what goes in and why; we handle it only to run the service for you.
For information about the teacher’s own account – email address, name, subscription, usage counts – we are the controller in our own right, and our Privacy Policy governs that. These terms do not apply to it.
Words defined in the UK GDPR – controller, processor, personal data, processing, personal data breach, supervisory authority – carry those meanings here. “UK GDPR” and “Data Protection Act 2018” mean those instruments as they apply in the United Kingdom, together with any legislation replacing them.
2. What we process, and why
This section is the description Article 28(3) requires.
| Subject matter | Providing the BA Productivity service: generating teaching material, running quizzes and lessons, and marking student work. |
| Duration | For as long as your account or your teachers’ accounts remain open, and afterwards only for the short period described in section 11. |
| Nature of the processing | Collection, recording, storage, retrieval, transmission to the AI providers listed in our Privacy Policy for the purpose of marking or transcription, display back to the teacher, and erasure. |
| Purpose | Only to provide the service to you and to keep it secure and working. We do not use student information for our own purposes, do not sell it, do not profile students, and do not train any AI model on it. |
| Types of personal data | The name a student types or that a teacher enters on a roster; answers a student writes to a quiz or lesson; drawings submitted as answers; answer text a teacher types, pastes or uploads for marking; the marks and written feedback produced; and the time of each submission or attempt. Photographs of handwritten work are transcribed and not stored. |
| Categories of data subject | Your students, who are typically children. |
| Special category data | None is required by the service, and our terms ask you not to enter it. If any reaches us it is because you put it there, and you remain responsible for having a condition for it under Article 9 and Schedule 1 of the Data Protection Act 2018. |
3. Acting only on your instructions
We process student information only on your documented instructions, including as to transfers outside the United Kingdom. Your instructions are: these terms, our Terms & Conditions and Privacy Policy, and what you do in the service itself – setting a quiz, running a marking set, keeping a roster. Using a feature is an instruction to carry out the processing that feature performs.
If we are required by law to process student information beyond your instructions, we will tell you before doing so unless the law forbids us from telling you. If we think an instruction of yours breaches data protection law, we will tell you and may pause that processing while it is resolved.
4. Confidentiality
Everyone we allow to access student information is bound by a duty of confidence, whether by contract of employment or otherwise, and is given access only where their role needs it.
5. Security
We apply appropriate technical and organisational measures under Article 32. What they currently are is set out in Annex A. We may change them as the service and the threats to it change, but not in a way that materially reduces protection.
6. Sub-processors
You give us general written authorisation to engage sub-processors. The current list, what each one does, where it is, and whether it sees student information, is published at /subprocessors, which forms part of these terms and carries a dated change history.
Before adding or replacing a sub-processor that would have access to student information, we will give you at least 30 days’ notice by email to the address on the account and by updating that page. If you reasonably object on data protection grounds within those 30 days, tell us and we will try to find another way of providing the affected feature; if we cannot, you may terminate the affected part of the service without penalty and receive a refund of anything paid for the unused remainder of your term.
We impose on every sub-processor obligations no less protective than those in these terms, and we remain fully liable to you for what our sub-processors do.
7. International transfers
Student information is stored at rest only in the United Kingdom or the European Economic Area. Marking and transcription require sending the relevant text or image to AI providers in the United States. Those transfers are made under the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, or another safeguard permitted by Chapter V of the UK GDPR. Section 5 of our Privacy Policy explains each transfer, and forms part of these terms. No student information is sent to our generation provider in China.
We send no student name alongside an answer submitted for marking: what leaves us is the question and the answer, and the link to the student stays in our database.
8. Helping you answer people’s requests
Requests from students or parents about student information are yours to answer, as controller. Taking account of what the processing involves, we will help you with appropriate technical and organisational measures so far as we reasonably can – including access, correction, erasure, restriction, objection and portability. Most of this you can do yourself in the service: a quiz, lesson, marking set or roster entry can be deleted at any time, and deleting it deletes the student information it holds.
If a student or parent contacts us directly, we will not respond to the substance ourselves; we will pass the request to you promptly and tell them we have done so.
9. Helping you with breaches, DPIAs and the ICO
Taking into account the nature of the processing and the information available to us, we will assist you in meeting your obligations under Articles 32 to 36 – security, breach notification to the ICO and to affected people, data protection impact assessments, and prior consultation with the ICO. We publish a pre-completed DPIA pack covering the service, downloadable for Word, which you are welcome to copy into your own template and adapt. It answers every question in a DPIA that is about our service rather than about your school, and we will complete your own supplier security questionnaire if you would rather work from that.
10. Telling you about a breach
If we become aware of a personal data breach affecting student information, we will notify you without undue delay, and in any event within 24 hours of becoming aware of it, at the email address on the account. Our notification will describe what happened, the categories and approximate number of students and records affected so far as known, the likely consequences, and what we are doing about it. Where we cannot provide all of that at once we will provide it in phases without undue delay. It is for you, as controller, to decide whether the ICO or the people affected must be told.
11. Deletion and return
You can delete student information yourself at any time by deleting the quiz, lesson, marking set or roster entry that holds it. When an account is closed, everything attached to it – including student responses, lesson attempts and marking – is deleted with it.
At the end of our provision of the service, we will delete all student information, or return it to you first if you ask within 30 days of the end. We keep nothing afterwards except where UK law requires us to. Ordinary backups and the operational monitoring records described in our Privacy Policy expire on their own cycles; those cycles are set out in Annex A, and nothing in them is used for any purpose other than restoring or maintaining the service.
12. Audits and information
We will make available to you all information reasonably necessary to demonstrate that we are meeting these terms, and will allow and contribute to audits, including inspections, conducted by you or an auditor you appoint. In the first instance we will answer in writing – including by completing your standard supplier security questionnaire – and we would expect that to be enough in most cases. Where it is not, an on-site or remote inspection may take place on 30 days’ notice, no more than once in any twelve months unless a breach or a regulator requires otherwise, during business hours, subject to confidentiality, and in a way that does not disrupt the service to other customers.
13. What you are responsible for
- Having a lawful basis for the student information you put into the service, and, where relevant, a condition under Article 9 and Schedule 1 of the Data Protection Act 2018 for any special category data.
- Telling students and parents about this processing in your own privacy notice – you may reproduce anything from ours that helps.
- Carrying out a data protection impact assessment where one is required. We will help; see section 9.
- Entering no more student information than the work actually needs. The service asks for a name and an answer, and nothing about health, religion, ethnicity, sexuality, safeguarding or any other special category data.
- Deciding how long to keep the work, in line with your own retention policy, and deleting it when you no longer need it.
- Keeping your teachers’ accounts secure, and telling us promptly when someone leaves.
14. Changes, precedence and contact
We may update these terms to keep them accurate or to meet a change in the law. If a change materially affects your rights under them we will give you at least 30 days’ notice by email and in the app, and the previous version continues to apply during that period.
If these terms conflict with our general Terms & Conditions on anything concerning student information, these terms prevail. If they conflict with a separately signed agreement between us, that agreement prevails.
Contact for anything in this document, including audit requests, sub-processor objections and DPIA support: [email protected], or BlueAcorn Education Ltd, 66 Paul Street, London, England, EC2A 4NA.
Annex A – security measures
These are the measures referred to in section 5, as at the version date above.
- Encryption in transit. All traffic to the service and to every provider we use runs over HTTPS/TLS.
- Passwords. Stored as bcrypt hashes with a work factor of 12, never recoverable. Password reset links are stored only as a hash, expire after one hour and can be used once.
- Sessions. Cookies are HTTP-only, sent only over HTTPS in production, and expire after seven days. A session secret is required at start-up; the application refuses to run without one.
- Access control. Teachers see only their own content. Organisation administrators see membership and usage counts, never content, marking or students. Production database access is limited to the people who need it.
- Lesson and quiz attempts. Each attempt is bound to the browser that started it by a secret issued at the time, so entering another student’s name does not open their work.
- Rate limiting. Sign-in, password reset and related endpoints are rate limited.
- Minimisation in transit to AI providers. Answers are sent for marking without the student’s name. Every marking request is restricted to a fixed set of assessed providers and excludes any provider that stores or trains on what it receives.
- Monitoring. Our error, performance and cost monitoring excludes the text of anything sent to a model and masks database query values, so no student work or name enters it. Those records are held in Sweden and deleted after 30 days.
- Storage location. The application runs in London; the database is hosted in Amsterdam, the Netherlands. Uploaded slide images are stored in the United Kingdom.
- Deletion integrity. Student information is linked to the teacher account by database constraints that cascade on delete, so closing an account removes the attached student records rather than orphaning them.
- Input handling. User-supplied HTML is sanitised before storage or display.
- Backups. The managed database service takes regular encrypted backups, retained within the EEA and kept for two days on a rolling basis. Anything deleted from the service has therefore gone from our backups as well within 48 hours.