Skip to main content

DPA

Data Processing Agreement template

Pilot procurement and processor-agreement wording for UK school review, ready to adapt with local legal counsel.

Last updated February 16, 2026Account controls

Template parties

Core agreement placeholders to complete before school sign-off.

Controller

[School/Trust legal entity]

Processor

FairCall

Effective date

[DD Month YYYY]

Term

Pilot period unless terminated earlier

Agreement purpose

This template is provided for UK school pilot procurement and data-protection review. Schools should adapt with their legal counsel before signature.

Subject matter and purpose

The Processor provides FairCall software to support equitable cold-calling workflows and teacher reflection. Processing is limited to delivering, securing, and supporting this service under the Controller's documented instructions.

Audit support

Processor will provide reasonable information needed to demonstrate compliance and support Controller audits subject to confidentiality, security, and proportionality constraints.

1. Nature of processing

  • Hosting and storage of account, class, student, lesson, and event records.
  • Authentication, authorization, and tenant isolation controls.
  • Optional outcome logging and post-lesson trend and summary processing.
  • Support and incident-response activities where required.

2. Data categories and data subjects

CategoryExamplesData subjects
Teacher account dataEmail, password hash, auth metadataTeachers
Class and student roster dataClass names, student names, optional IDs and photo URLsStudents
Lesson activity dataAsk events, outcomes, timestamps, absencesTeachers and students

3. Processor obligations

  • Process personal data only on documented instructions from the Controller.
  • Ensure personnel are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures.
  • Assist the Controller with data-subject rights and compliance requests.
  • Notify the Controller of personal-data breaches without undue delay.

4. Security measures (minimum)

  • Encrypted transport in production (HTTPS/TLS).
  • Password hashing and authenticated API access.
  • Teacher-level tenant isolation and ownership checks.
  • Input validation and secure query handling.
  • Access controls on infrastructure and operational tooling.

5. Subprocessors

Controller authorizes the Processor to use the subprocessors listed below and future subprocessors that provide equivalent protections with prior notice where contractually required.

  • Railway (backend and database hosting, UK/EU preferred)
  • Vercel (frontend hosting, region varies by deployment)
  • Cloudflare services (future option for asset or object storage)

6. International transfers

Where personal data is transferred outside the UK, Processor will implement appropriate safeguards and provide transfer details to the Controller on request.

7. Retention, return, and deletion

  • Data retention follows Controller instructions and contractual schedule.
  • Teachers may export and delete data through in-app Account controls.
  • On termination, Processor will return or delete personal data unless legal obligations require retention.

8. Signature block template

For Controller

Name, title, signature, date

For Processor

Name, title, signature, date

Related compliance documents

Continue school review with privacy, terms, and DPIA references.

Need help with school review?

Use the right support path for procurement blockers, compliance questions, or account-level export and deletion controls.