Data Processing Agreement
This Data Processing Agreement (“Agreement”) forms part of the Terms & Conditions between QCD Consulting (“Processor”, “we”, “our”, or “us”) and the organisation using Schoolise (“Controller”, “you”). It governs the processing of personal data in line with UK GDPR and applicable data protection law.
Last updated: 25 July 202601 Roles of the Parties
- The Controller — your school or organisation — determines the purposes and means of processing personal data about your students, guardians and staff
- The Processor — Schoolise — processes that personal data on your behalf, solely to provide the platform and the packages you’ve enabled
02 Scope of Processing
Schoolise processes personal data solely to provide its services, including:
- Creating and managing organisation and user accounts
- Operating the Core Platform and any packages you’ve enabled (such as Finance, Safeguarding, or Communications)
- Generating reports, dashboards and analytics
- Providing support and maintaining the platform
03 Types of Data Processed
Depending on which parts of Schoolise your organisation uses, we may process:
- Student and guardian data, such as names, contact details, attendance and academic records
- Staff data, such as names, contact details and role information
- Where the Safeguarding package is enabled, welfare and concern records — treated as a more sensitive category, with restricted, role-based access separate from everyday admin data
- Technical and usage data, such as IP address and system activity logs
04 Instructions from the Controller
Schoolise will only process personal data:
- In line with your organisation’s documented instructions
- As necessary to provide the service you’ve signed up for
- As required by law
05 Confidentiality
All personnel authorised to process personal data on our side are bound by confidentiality obligations, and only access data as required to perform their role.06 Security Measures
We apply appropriate technical and organisational measures to protect personal data, including:
- SSH-encrypted connections between your organisation and Schoolise
- Daily backups of organisation data
- Organisation-level data separation, so one organisation’s data is logically isolated from another’s
- Role-based access controls, with sensitive records such as safeguarding data held to a further restricted standard
- Ongoing monitoring to guard against unauthorised access, loss or misuse
07 Sub-Processors
You authorise Schoolise to use trusted third-party sub-processors, such as hosting and email delivery providers, and, where your organisation enables it, an integration such as AssessMap for Assessments. We will:
- Ensure sub-processors are bound by data protection obligations at least as strong as this Agreement
- Remain responsible for their compliance
A current list of sub-processors is available on request.
08 Data Subject Rights
We’ll assist your organisation, where reasonably possible, in responding to requests from data subjects, including:
- Access requests
- Correction or deletion requests
- Data portability requests
09 Data Breach Notification
In the event of a personal data breach affecting your organisation’s data, Schoolise will:
- Notify you without undue delay
- Provide the information reasonably needed to support your own legal obligations
10 Data Retention and Deletion
When the service ends, or on request, Schoolise will delete or return your organisation’s personal data, retaining it only where required by law or for legitimate operational purposes (such as backups being cycled out over their normal retention period).
11 Audits and Compliance
We’ll make available the information reasonably necessary to demonstrate compliance with this Agreement and applicable data protection law.12 International Transfers
Personal data is processed within the UK or EEA wherever possible. Where data is transferred outside these regions, appropriate safeguards — such as standard contractual clauses — will be in place.13 Liability
Each party remains responsible for its own compliance with applicable data protection law.14 Governing Law
This Agreement is governed by the laws of England and Wales.Questions about this document?
Get in touch and we’ll help directly — there’s no automated ticket queue for anything data-related.