Data processing agreement
Last updated 2026-08-05
In plain English
This is the part your lawyer will ask for. It says in contract language what the privacy policy says in plain language.
It forms part of the terms of service automatically — you do not need to sign a separate copy, though you can request one.
1. Roles
The customer is the controller. Schoolory is the processor. Where the customer is itself a processor for another controller, Schoolory is a sub-processor.
2. Scope and purpose
We process personal data only to provide the service described in the terms, and only on documented instructions from the customer. Using the product is such an instruction.
Categories of data subject: staff, students, and parents or guardians. Categories of data: identity and contact details, academic records, attendance, and financial records relating to tuition.
3. Confidentiality
Everyone with access to customer data is bound by confidentiality obligations. Access is limited to staff who need it to run or support the service, and every such access is logged.
4. Security
Each customer's data is held in a separate database with separate credentials. Isolation is architectural rather than a query filter.
Data is encrypted in transit and at rest. Credentials for customer databases are encrypted before storage.
Passwords are stored using bcrypt. Sessions can be revoked centrally.
5. Sub-processors
Always in use: Turso (database hosting), Vercel (application hosting), Resend (email delivery), Paddle (payments for your Schoolory subscription, as merchant of record).
Used only when the customer switches the relevant feature on: Anthropic (AI features), Stripe (card payments from parents — funds go to the customer's own Stripe account, not ours), Google (Meet links, and push notifications to the parent app), Zoom and Microsoft (meeting links, as alternatives to Meet), Meta (WhatsApp messages to parents), and VietQR (renders a bank-transfer QR code in the parent app).
Where the customer configures their own SMTP server instead of our email provider, that server is theirs and is not a sub-processor of ours.
We will give 30 days' notice before adding a sub-processor, and the customer may object. Notice goes to the account owner's email address.
6. International transfers
Customers may choose the region their database is hosted in. Where data is transferred outside the EEA, transfers rely on Standard Contractual Clauses with the relevant sub-processor.
7. Assisting the controller
We will assist with data subject requests, data protection impact assessments, and regulator enquiries, taking into account the nature of the processing and the information available to us.
The export tools in the product are designed so that most requests can be answered without contacting us at all.
8. Breach notification
We will notify the customer without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting their data, with the information needed for the customer to meet their own obligations.
9. Deletion and return
On termination, the customer may export all data through the product. Thirty days after termination, the customer's database is deleted in full.
10. Audit
We will make available the information needed to demonstrate compliance with this agreement, and allow for audits by the controller or an auditor they mandate, on reasonable notice and no more than once a year unless a regulator requires otherwise.