This is the agreement required by Article 28(3) of Regulation (EU) 2016/679 (GDPR). It is a standalone document, incorporated by reference into the School Membership Licence, and applies whenever we handle personal data on the School's behalf.
It can be reviewed, signed, and updated separately from the licence, so a school's data protection officer can be sent this document alone.
Where a member of staff buys an Individual Membership with their own personal email and pays personally, we are the controller for that relationship and our Privacy Policy applies instead.
We process a small amount of staff personal data so that the School's staff can reach the membership materials, attend training, and receive certificates of completion. That is the entire purpose.
For the length of the School Membership, plus the retention periods in section 8.
Members of staff at the School whom the School enrols.
| Data | Why we hold it |
|---|---|
| Staff name | to issue a certificate of completion |
| Staff work email address | to send access links and renewal notices |
| Course or session attendance | to know who has earned a certificate |
| Certificate records (name, course, date) | so a lost certificate can be reissued |
| Billing contact name and email | invoicing and renewal |
No pupil personal data is processed. The School must not send us pupil names, pupil work, assessment records, or any other pupil data. If pupil data reaches us by accident we will tell the School without undue delay and delete it.
No special category data under Article 9 is processed.
We will:
Breach notification: we will notify the School without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting the School's data, with the detail the School needs for its own Article 33 notification.
The School gives general authorisation for the sub-processors below. We will give 30 days' notice before adding or replacing one, and the School may object on reasonable data protection grounds. If we cannot resolve an objection, the School may cancel the remainder of its subscription and receive a pro-rata refund.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Cloudflare, Inc. | website hosting, access gating, edge delivery | US, global edge | EU Standard Contractual Clauses, incorporated into the Cloudflare Data Processing Addendum (v6.4, 3 April 2026). Cloudflare publishes its own sub-processor list at cloudflare.com/gdpr/subprocessors, with 30 days' notice of changes |
| Resend (Plus Five Five, Inc.) | automated purchase confirmation and access-link emails only. Email address only. No names, no attendance data, no certificate records, no correspondence | US | Article 28 Data Processing Addendum, plus EU-US Data Privacy Framework certification and the UK Extension |
| Proton AG | correspondence, certificates and any email we send by hand, from [email protected] | Switzerland | European Commission adequacy decision for Switzerland. No transfer safeguards required |
We hold no self-managed database. Access to materials is granted by a cryptographically signed token, so we store no separate user account records of our own.
Some parties involved in delivering the service determine their own purposes and means for the personal data they hold, and so act as controllers in their own right rather than on our instructions.
Stripe provides payment processing. Under Stripe's own Data Processing Agreement, Stripe Payments Europe Ltd (Ireland), Stripe Technology Company and the relevant Stripe regulated entity are joint controllers of payment data, which they process to meet their own legal obligations for payment services, fraud prevention, anti-money laundering and know-your-customer requirements. Stripe relies on the 2021 EU Standard Contractual Clauses (Modules 1 and 2) through its Data Transfers Addendum and is certified under the EU-US Data Privacy Framework.
The School's billing contact details are therefore governed by Stripe's own privacy terms alongside this agreement. A data subject request concerning payment data may need to be directed to Stripe. We will help identify where a request belongs.
Cloudflare and Resend are US-headquartered, so personal data covered by this agreement is transferred outside the EEA, under the mechanisms named in section 7. Proton is Swiss and covered by an adequacy decision. We do not claim that no data leaves the EEA.
We limit exposure by limiting the data. The personal data reaching a US provider is a single email address, sent so an automated purchase confirmation and access link can be delivered. Names, certificate records and all correspondence are handled through Proton in Switzerland. There is no pupil data, no special category data, no analytics or advertising trackers anywhere on the site, and no personal data inside the access tokens themselves.
| Data | Kept for |
|---|---|
| Access and login records | duration of the subscription, then 30 days |
| Certificate records | 3 years after issue, so a certificate can be reissued |
| Billing records | 6 years, as required by Spanish tax law (Ley General Tributaria) |
Everything else is deleted within 30 days of the subscription ending.
This agreement is governed by Spanish law. Liability follows the School Membership Licence.
Contact for data protection matters: Diana Szyperska, [email protected].
See also: All licences · Terms of Service · Privacy Policy
← Back to aiforschool.net