Data Processing Agreement

The Article 28 terms on which Kredits processes pupil data for a school. These apply automatically to every school whose staff use Kredits — there is nothing to sign, though we will sign a copy on request.

Last updated 18 September 2026 · UK GDPR Article 28(3)

1. Parties and roles

This agreement is between the School (the controller) and Kredits (“Kredits”, the processor). It applies whenever a member of the School’s staff uses Kredits with pupil data.

It covers pupil data only. Kredits is an independent controller for teacher account data, described in the Privacy Policy.

2. Processing on documented instructions

Kredits processes pupil data only on the School’s documented instructions. The instructions are: the actions the School’s staff take in the app, these terms, and the Terms of Service. Kredits will not process pupil data for any other purpose — in particular not to build profiles, not for advertising, and not to train machine-learning models.

If Kredits is required by law to process data otherwise, it will inform the School first unless the law forbids it.

3. Confidentiality

Everyone authorised to process pupil data is bound by a duty of confidentiality. Kredits is currently operated by one person, so that means one individual; this page is updated if anyone else is given access.

4. Security

Kredits maintains the technical and organisational measures in Annex C, which is incorporated into this agreement. Those measures are described honestly, including their limits.

5. Sub-processors

The School gives general authorisation for the sub-processors listed in Annex B. Kredits imposes data protection terms on each sub-processor no less protective than these, and remains liable for their performance.

Kredits will give at least 30 days notice before adding or replacing a sub-processor, by a notice in the app and an update to this page. The School may object on reasonable data protection grounds, and if the objection cannot be resolved may terminate without penalty.

6. Assisting the School

Kredits assists the School, so far as is reasonable, with:

7. Personal data breaches

Kredits will notify the School without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting pupil data. The notification will describe what happened, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken.

The duty to notify the ICO and affected individuals rests with the School as controller.

8. Deletion and return

A teacher may delete pupil data at any time in the app. On termination, or on the School’s written request, Kredits will delete or return all pupil data within 30 days, except where law requires retention. Our hosting provider keeps its own backups, which rotate on its standard cycle.

9. Audit

Kredits will make available the information reasonably needed to demonstrate compliance with Article 28, and will contribute to audits by the School or its auditor, on reasonable notice, no more than once a year unless required by a supervisory authority or following a breach.

In practice the first answer to most audit questions is the Security page, which is written to be specific enough to serve that purpose.

10. International transfers

Pupil data is stored in the EU and the UK, as set out in Annex C. Where a sub-processor transfers data outside the UK or EEA, it does so under the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or an adequacy decision.

11. Term

This agreement runs for as long as Kredits processes pupil data for the School.

Annex A — Details of processing

Subject matterProvision of classroom management tools to the School’s teaching staff.
DurationFor as long as the School’s staff hold Kredits accounts containing pupil data.
Nature and purposeStoring and displaying class lists; recording behaviour points; recording marks; generating seating plans and groups; synchronising with Google Classroom where a teacher chooses to link it.
Categories of data subjectPupils at the School.
Types of personal dataName; class membership; card or seat number; behaviour points; marks and assignment status; seating position; grouping history; Google Classroom user identifier where Classroom is linked.
Special category dataNone. The Terms of Service prohibit entering it and the app provides no field for it.

Annex B — Sub-processors

Sub-processorPurposeLocation
Google Ireland Limited (Firebase, Google Cloud Platform)Hosting, database, server functions, authenticationeurope-west1 (Belgium), europe-west2 (London)
Twilio SendGridDelivery of account recovery codes to teachers who opt in. Does not process pupil data.United States

Annex C — Technical and organisational measures

Signature

These terms apply without signature. A school that needs a signed and dated counterpart for its records can request one at hello@kredits.co.uk.