<img alt="" src="https://imaginativeagile.com/816675.png" style="display:none;">

iAM Compliant Data Processing Agreement

iAM GDPR Knight (transparent bg)

This Data Processing Agreement (“DPA”) records the terms upon which iAM Compliant Limited (“we”, “us” or “our”) will process personal data on behalf of users of its browser-based app (”you” or “your”).

This DPA is incorporated into, and governed by our Terms of Use.

DEFINITIONS

  1. Controller, Processor, Data Subject, Personal Data, Personal Data Breach, processing and appropriate technical and organisational measures: as defined in the Data Protection Legislation.

  2. Data Protection Legislation: all applicable data protection and privacy legislation in force from time to time in the UK including the UK GDPR; the Data Protection Act 2018 (DPA 2018) (and regulations made thereunder) and the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) as amended.

  3. Domestic Law: the law of the United Kingdom or a part of the United Kingdom.

  4. UK GDPR: has the meaning given in section 3(10) (as supplemented by section 205(4)) of the Data Protection Act 2018.

  5. Any other defined terms shall have the meaning set out in our Terms of Use.

1. DATA PROTECTION

  1. 1.1 Both parties will comply with all applicable requirements of the Data Protection Legislation. This DPA is in addition to, and does not relieve, remove or replace, a party's obligations or rights under the Data Protection Legislation.

  2. 1.2 The parties acknowledge that for the purposes of the Data Protection Legislation, you are the Controller and we are the Processor. Annex 1 sets out the scope, nature and purpose of processing by us, the duration of the processing and the types of Personal Data and categories of Data Subject.

  3. 1.3 Without prejudice to the generality of para 1.1, you will ensure that you have all necessary appropriate consents and notices in place to enable lawful transfer of the Personal Data to us and/or lawful collection of the Personal Data by us on your behalf for the duration and purposes of this agreement. You hereby indemnify us against all costs, claims, damages, expenses, losses and liabilities (including legal costs) incurred by us, our officers, and employees arising out of or in connection with any breach of this paragraph.

  4. 1.4 Without prejudice to the generality of para 1.1, we shall, in relation to any Personal Data processed in connection with the performance by us of our obligations under this agreement:

    1.  process that Personal Data only on your written instructions unless we are required by Domestic Law to otherwise process that Personal Data. Where we are relying on Domestic Law as the basis for processing Personal Data, we shall promptly notify you of this before performing the processing required by the Domestic Law unless the Domestic Law prohibits us from so notifying you;

    2. ensure that we have in place appropriate technical and organisational measures to protect against unauthorised or unlawful processing of Personal Data and against accidental loss or destruction of, or damage to, Personal Data, appropriate to the harm that might result from the unauthorised or unlawful processing or accidental loss, destruction or damage and the nature of the data to be protected, having regard to the state of technological development and the cost of implementing any measures (those measures may include, where appropriate, pseudonymising and encrypting Personal Data, ensuring confidentiality, integrity, availability and resilience of its systems and services, ensuring that availability of and access to Personal Data can be restored in a timely manner after an incident, and regularly assessing and evaluating the effectiveness of the technical and organisational measures adopted by it);

    3. ensure that all personnel who have access to and/or process Personal Data are obliged to keep the Personal Data confidential; and

    4. not transfer any Personal Data outside of the UK or EEA unless the following conditions are fulfilled:

      1. you or we have provided appropriate safeguards in relation to the transfer;

      2. the data subject has enforceable rights and effective legal remedies;

      3. we comply with our obligations under the Data Protection Legislation by providing an adequate level of protection to any Personal Data that is transferred; and

      4. we comply with reasonable instructions notified to us in advance by you with respect to the processing of the Personal Data;

    5. assist you, at your cost, in responding to any request from a Data Subject and in ensuring compliance with your obligations under the Data Protection Legislation with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators;

    6. notify you without undue delay and where feasible within 72 hours on becoming aware of a Personal Data Breach;

    7. at your written direction, delete or return Personal Data and copies thereof to you on termination of the agreement unless required by Domestic Law to store the Personal Data; and

    8. maintain complete and accurate records and information to demonstrate our compliance with this DPA and allow for audits by you or your designated auditor at your cost no more than once per year and on prior reasonable written notice and immediately inform you if, in our opinion, an instruction infringes the Data Protection Legislation.

  5. 1.5 You consent to us appointing the parties listed in Annex 2 as a third-party processor of Personal Data under this agreement. We confirm that we have entered or (as the case may be) will enter with the third-party processor into a written agreement [substantially on that third party's standard terms of business which reflect and will continue to reflect the requirements of the Data Protection Legislation. As between you and us, we shall remain fully liable for all acts or omissions of any third-party processor appointed by us pursuant to this paragraph. We will give you prior written notice of the appointment of any new third-party processor, including full details of the processing to be undertaken by the subprocessor. If, within seven calendar days of receipt of that notice, you notify us in writing of any objections (on reasonable grounds) to the proposed appointment (“Objection Notice”), we will not appoint such subprocessor. If the appointment of that subprocessor is necessary to the continuing performance of the Services we may terminate the User Subscriptions within 30 days of receipt of the Objection Notice without liability to you.

Annex 1 Processing, Personal Data and Data Subjects

  1. Subject matter of the processing: The subject matter of the data processing under this DPA is the data you access via our app (“Customer Data”).

  2. Nature and purpose of processing: We will collect, store and provide access to Customer Data in the course of providing the Services for the intended uses set out in our Terms of Use, solely for the following purposes: (i) processing to perform the Services in accordance with the Terms of Use; (ii) processing initiated by you in your use of the Services (including processing of data obtained from third parties); and (iii) processing to comply with any other reasonable instructions provided by you (e.g., via email or support tickets) that are consistent with the Terms of Use.

  3. Duration of the processing: The duration of the processing under this DPA is until the expiration or termination of the Terms of Use.

  4. Types of Personal Data: Names, addresses, date of birth, contact details, medical records, education data (including national curriculum year group and pupil UPN; class name / number).

  5. Categories of Data Subject: School contractors and employees, students (and next of kin/guardians), teachers.

Annex 2 Sub-processors

 

Sub-Processor

Service(s)

Primary / Selectable Data Centre Regions

Heroku (Salesforce)

Web Hosting

EU (Ireland), UK (London) - moving in 2026

Amazon Web Services (AWS)

RDS, CloudFront, S3

EU - Dublin

Cloudinary

Media Asset management

EU (Frankfurt/Ireland), US, Global CDN

Vimeo

Media / Video Hosting

US Primary, Global CDN

Wonde

Data integration / User Provisioning

UK & EU (AWS Ireland)