Data Processing Agreement
The Article 28 terms on which Kredits processes pupil data for a school. These apply automatically to every school whose staff use Kredits — there is nothing to sign, though we will sign a copy on request.
Last updated 18 September 2026 · UK GDPR Article 28(3)
1. Parties and roles
This agreement is between the School (the controller) and Kredits (“Kredits”, the processor). It applies whenever a member of the School’s staff uses Kredits with pupil data.
It covers pupil data only. Kredits is an independent controller for teacher account data, described in the Privacy Policy.
2. Processing on documented instructions
Kredits processes pupil data only on the School’s documented instructions. The instructions are: the actions the School’s staff take in the app, these terms, and the Terms of Service. Kredits will not process pupil data for any other purpose — in particular not to build profiles, not for advertising, and not to train machine-learning models.
If Kredits is required by law to process data otherwise, it will inform the School first unless the law forbids it.
3. Confidentiality
Everyone authorised to process pupil data is bound by a duty of confidentiality. Kredits is currently operated by one person, so that means one individual; this page is updated if anyone else is given access.
4. Security
Kredits maintains the technical and organisational measures in Annex C, which is incorporated into this agreement. Those measures are described honestly, including their limits.
5. Sub-processors
The School gives general authorisation for the sub-processors listed in Annex B. Kredits imposes data protection terms on each sub-processor no less protective than these, and remains liable for their performance.
Kredits will give at least 30 days notice before adding or replacing a sub-processor, by a notice in the app and an update to this page. The School may object on reasonable data protection grounds, and if the objection cannot be resolved may terminate without penalty.
6. Assisting the School
Kredits assists the School, so far as is reasonable, with:
- Data subject rights — access, rectification, erasure, restriction, portability and objection. Most of this the School’s staff can do directly: the app exports and deletes data without our involvement. If a request reaches us instead, we forward it to the School rather than answering it ourselves.
- Security, breach notification and impact assessments — Articles 32 to 36, taking into account the nature of the processing and the information available to us.
7. Personal data breaches
Kredits will notify the School without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting pupil data. The notification will describe what happened, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken.
The duty to notify the ICO and affected individuals rests with the School as controller.
8. Deletion and return
A teacher may delete pupil data at any time in the app. On termination, or on the School’s written request, Kredits will delete or return all pupil data within 30 days, except where law requires retention. Our hosting provider keeps its own backups, which rotate on its standard cycle.
9. Audit
Kredits will make available the information reasonably needed to demonstrate compliance with Article 28, and will contribute to audits by the School or its auditor, on reasonable notice, no more than once a year unless required by a supervisory authority or following a breach.
In practice the first answer to most audit questions is the Security page, which is written to be specific enough to serve that purpose.
10. International transfers
Pupil data is stored in the EU and the UK, as set out in Annex C. Where a sub-processor transfers data outside the UK or EEA, it does so under the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or an adequacy decision.
11. Term
This agreement runs for as long as Kredits processes pupil data for the School.
Annex A — Details of processing
| Subject matter | Provision of classroom management tools to the School’s teaching staff. |
|---|---|
| Duration | For as long as the School’s staff hold Kredits accounts containing pupil data. |
| Nature and purpose | Storing and displaying class lists; recording behaviour points; recording marks; generating seating plans and groups; synchronising with Google Classroom where a teacher chooses to link it. |
| Categories of data subject | Pupils at the School. |
| Types of personal data | Name; class membership; card or seat number; behaviour points; marks and assignment status; seating position; grouping history; Google Classroom user identifier where Classroom is linked. |
| Special category data | None. The Terms of Service prohibit entering it and the app provides no field for it. |
Annex B — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Ireland Limited (Firebase, Google Cloud Platform) | Hosting, database, server functions, authentication | europe-west1 (Belgium), europe-west2 (London) |
| Twilio SendGrid | Delivery of account recovery codes to teachers who opt in. Does not process pupil data. | United States |
Annex C — Technical and organisational measures
- Access control. Every endpoint touching pupil data verifies a Firebase Authentication session token on each request and derives identity from it, not from client-supplied values. Teacher PINs are stored hashed.
- Encryption in transit. HTTPS/TLS throughout; no unencrypted route exists.
- Encryption at rest. Google Cloud encrypts underlying storage. Google Classroom tokens and teacher recovery email addresses receive additional AES-256-GCM encryption with keys held in Google Secret Manager.
- Data residency. Database in europe-west1 (Belgium); server functions in europe-west2 (London).
- Third-party access control. OAuth uses a single-use random state parameter; disconnecting Google revokes the token at Google and deletes stored tokens and identifier mappings.
- Data subject rights by design. Export and deletion are built into the app and need no involvement from us.
- Change control. Server code is version-controlled with an automated test suite over the sensitive endpoints, and is deployed from version control rather than an individual machine.
- Secret management. Credentials are held in Google Secret Manager and are not present in the codebase.
- Limits, stated plainly. Kredits holds no independent security certification (no Cyber Essentials, ISO 27001 or SOC 2) and has not had an independent penetration test. There is no 24/7 staffed security function.
Signature
These terms apply without signature. A school that needs a signed and dated counterpart for its records can request one at hello@kredits.co.uk.