Data Processing Agreement
Between:
Data Controller: [School Name] ("the School") Data Processor: AI Safeguarding ("the Provider")
Effective Date: [Date]
1. Purpose
This Data Processing Agreement ("DPA") sets out the terms under which the Provider processes personal data on behalf of the School in connection with the AI Safeguarding Training Platform ("Scope").
Scope is a training platform that simulates safeguarding conversations for staff development. It is not a live safeguarding decision-making system.
2. Definitions
- Personal Data: Information relating to an identified or identifiable natural person, as defined in UK GDPR.
- Processing: Any operation performed on personal data, including collection, storage, use, and deletion.
- Data Subjects: Staff members of the School who use the platform for safeguarding training.
- Sub-processor: A third party engaged by the Provider to process personal data on behalf of the School.
3. Data processed
| Category | Data elements | Purpose | Retention | |----------|--------------|---------|-----------| | Account data | Staff name, email, role | Authentication and access control | Until account deletion | | Voice recordings | Audio of staff during training sessions | Enable voice-first training, evidence of practice | 14 days | | Transcripts | Text transcriptions of staff speech | Evaluate training performance | 12 months | | Interaction traces | Turn-by-turn records, evaluation scores, pathway progress | Assess safeguarding competence | 12 months | | Assessment outputs | Generated session summaries, strengths/concerns | Provide training feedback | 12 months | | Security logs | Login events, session tokens (hashed), IP addresses | Security monitoring, incident investigation | Retained for compliance |
4. Lawful basis
The School processes staff personal data under contract — staff training is delivered as part of the School's contractual obligations to its employees and its statutory duty to ensure safeguarding competence.
5. Obligations of the Provider
The Provider shall:
a) Process personal data only on documented instructions from the School, unless required by law.
b) Ensure that persons authorised to process personal data are subject to confidentiality obligations.
c) Implement appropriate technical and organisational security measures, including:
- Multi-factor authentication for administrative access
- Encryption in transit (TLS 1.3) and at rest (server-side encryption for stored audio)
- Revocable session management with token rotation
- Role-based access control with organisation-scoped data isolation
- Automated retention enforcement by data class
- Structured audit logging of security-relevant events
- Daily automated backups with tested restore capability
d) Not engage a sub-processor without prior written consent of the School. Current sub-processors are listed in Schedule A.
e) Assist the School in responding to data subject rights requests (access, erasure, restriction).
f) Delete or return all personal data at the end of the service, at the School's choice, unless retention is required by law.
g) Make available all information necessary to demonstrate compliance and allow for audits.
h) Notify the School without undue delay (and in any event within 24 hours) upon becoming aware of a personal data breach.
6. Obligations of the School
The School shall:
a) Ensure it has a lawful basis for processing staff personal data through the platform.
b) Inform staff that safeguarding training data will be processed through the platform, via its staff privacy notice.
c) Ensure staff understand they must not enter real safeguarding case data (real children's names, real disclosures) into the platform.
d) Designate a contact for data protection queries related to the platform.
7. Sub-processors
The Provider uses the following sub-processors. The School consents to the use of these sub-processors as listed. The Provider will notify the School before adding or replacing a sub-processor.
Schedule A — Current Sub-processors:
| Sub-processor | Purpose | Location | Data received | |--------------|---------|----------|---------------| | DigitalOcean | Infrastructure hosting | London, UK (LON1) | All platform data (encrypted) | | OpenAI | Language model for persona generation | USA (API) | Scenario context, conversation turns. No user identifiers. | | ElevenLabs | Voice synthesis and transcription | EU/USA (API) | Persona response text (TTS), trainee audio (STT). No identifiers. |
All sub-processors are engaged under contracts that impose equivalent data protection obligations.
8. International transfers
Where personal data is transferred outside the UK (e.g. to OpenAI or ElevenLabs API servers), the Provider ensures appropriate safeguards are in place, including:
- Standard Contractual Clauses (where applicable)
- Provider DPAs with zero-retention or limited-retention clauses
- Feature flags that allow the School to disable external AI providers entirely, falling back to deterministic-only mode with no external data sharing
9. Data subject rights
The Provider will assist the School in fulfilling data subject rights requests:
- Access: The School's administrator can view and export staff session data.
- Erasure: The School's administrator can delete all data for a specific user via the platform's erasure function. Deletions are logged in an audit trail.
- Restriction: Staff accounts can be deactivated by the administrator.
10. Data breach notification
In the event of a personal data breach, the Provider will:
a) Notify the School within 24 hours of becoming aware of the breach.
b) Provide details of: what data was affected, how many individuals, what measures have been taken, recommended actions for the School.
c) Cooperate with the School's Data Protection Officer and, if required, the ICO.
The School is responsible for notifying the ICO within 72 hours if the breach is reportable.
11. Term and termination
This DPA remains in effect for the duration of the service agreement between the School and the Provider.
Upon termination:
- The Provider will delete all School data within 30 days, unless the School requests data return.
- The Provider will confirm deletion in writing.
- Backup copies will be deleted within their normal retention cycle (7 days).
12. Liability
The Provider's liability under this DPA is subject to the terms of the main service agreement between the parties.
13. Governing law
This DPA is governed by the laws of England and Wales.
Signed for the School:
Name: ___________________________ Role: ___________________________ Date: ___________________________
Signed for AI Safeguarding:
Name: ___________________________ Role: ___________________________ Date: ___________________________
This DPA should be reviewed by the School's Data Protection Officer before signing. It supplements the main service agreement and the Provider's Terms of Use.