Policies

Data processing terms for schools and local authorities

The UK GDPR Article 28 terms that apply when we process pupil data on behalf of a school, AP setting or local authority.

These data processing terms form part of our terms of business for schools, alternative provision (AP) settings and local authorities. They apply whenever we process personal data on a client’s behalf to deliver a tuition programme. They are intended to meet the requirements of Article 28 of the UK General Data Protection Regulation (UK GDPR).

1. Definitions and roles

1.1 In these terms, “we”, “us” and “our” mean Cornish Adventures Ltd, trading as Cove Tutors, a company registered in England and Wales with company number 15788616. “Client” means the school, AP setting or local authority that commissions a programme from us.

1.2 “Data protection law” means the UK GDPR, the Data Protection Act 2018 and any other law relating to the processing of personal data that applies in the UK. “Personal data”, “controller”, “processor”, “data subject”, “processing” and “personal data breach” have the meanings given in data protection law.

1.3 “Programme” means the tuition programme described in the client’s order, purchase order or programme agreement. “Client personal data” means personal data we process on the client’s behalf under a programme.

1.4 For client personal data, the client is the controller and we are the processor. The client is responsible for having a lawful basis for the processing, including any condition needed for special category data, and for giving data subjects the information required by Articles 13 and 14 of the UK GDPR.

1.5 We are a controller in our own right for the business contact details of the client’s staff and for our own accounting, tax, safeguarding and recruitment records. Our privacy notice explains how we handle that information.

1.6 If these terms conflict with any other part of our terms of business about the processing of client personal data, these terms take priority.

2. Details of the processing

2.1 Subject matter: the delivery of live online tuition, and related assessment, reporting and safeguarding, to pupils nominated by the client.

2.2 Duration: for the length of the programme, and afterwards only for as long as needed to return or delete client personal data under clause 12, or to keep it where clause 12.3 applies.

2.3 Nature of the processing: collecting, recording, organising, storing, consulting, using, transmitting to the client, restricting and erasing personal data, including real-time audio and video during live lessons held on Google Meet. Lessons are not recorded unless the client and the pupil’s parent or carer have both agreed in writing in advance.

2.4 Purpose of the processing: to plan and deliver tuition; carry out baseline and progress assessments; write lesson notes; share attendance, progress and impact reports with the client; report welfare and safeguarding concerns to the client; and administer the programme.

2.5 Types of personal data:

  • pupil name, year group, school or setting, subjects, exam boards and targets
  • learning needs relevant to tuition, which may include special educational needs and disabilities (SEND) and health information (special category data)
  • baseline assessment results, lesson notes, work completed in lessons, progress records and attendance
  • welfare and safeguarding concerns and related records
  • contact details for the pupil’s parents or carers, where the client provides them
  • names and work contact details of client staff involved in the programme
  • images and voices of pupils during live lessons, seen and heard in real time only, unless recording has been agreed under clause 2.3

2.6 Categories of data subjects: pupils receiving tuition; their parents and carers; and client staff involved in the programme.

3. Our obligations as processor

3.1 We will process client personal data only on the client’s documented instructions, including about transfers outside the UK, unless the law requires us to do otherwise. In that case we will tell the client before processing, unless the law prohibits this on important grounds of public interest.

3.2 The client’s instructions are set out in these terms, our terms of business and the programme agreement. The client may give further reasonable written instructions during the programme. We may charge for instructions that go beyond the agreed programme, after agreeing the cost in writing.

3.3 We will tell the client straight away if we believe an instruction breaks data protection law.

3.4 We will not use client personal data for our own purposes, for marketing, or to train any software or artificial intelligence system, and we will never sell it.

3.5 Nothing in these terms prevents us from making a referral to children’s social care, the police, the local authority designated officer (LADO) or another agency where we reasonably believe it is needed to protect a child from harm. Where we do so, we will inform the client’s designated safeguarding lead the same day, unless doing so would put the child at greater risk or a statutory agency has asked us not to.

4. Confidentiality of personnel

4.1 We will make sure that everyone we authorise to process client personal data, including our tutors, is bound by a written duty of confidentiality or an appropriate statutory duty.

4.2 We will give access only to those who need it to deliver the programme. Tutors can access only the information for the pupils they teach.

4.3 Everyone who works with pupils on our behalf has an enhanced DBS check with barred list (children) and receives data protection and safeguarding training before they begin.

5. Security

5.1 We will take appropriate technical and organisational measures to protect client personal data, as required by Article 32 of the UK GDPR, taking into account the nature of the data, the risks to pupils and the fact that most data subjects are children.

5.2 Those measures include:

  • business Google Workspace accounts for all email, live lessons and record keeping, protected by 2-step verification
  • least privilege access, so each person sees only the data needed for their role, with access removed promptly when someone stops working with us
  • encrypted devices with screen locks and up-to-date software
  • no personal email accounts, personal phones, personal devices or social media for contact with pupils or for storing client personal data
  • live lessons held only through our business Google Meet accounts, with tutors admitting only expected participants
  • special category data stored only in access-restricted folders in our business Google Workspace account
  • secure deletion when data is no longer needed
  • regular review of these measures

5.3 We may update our security measures over time, provided the overall level of protection is not reduced.

6. Sub-processors

6.1 The client gives us general written authorisation to use sub-processors to process client personal data. At the date of these terms, our sub-processors are:

Sub-processor Purpose
Google (Google Workspace) Email, Google Meet for live lessons, Google Drive for lesson notes and records
Cal.com Scheduling of sessions, once our online booking system is live
Cloudflare Hosting of our website

6.2 We will tell the client in writing at least 30 days before adding or replacing a sub-processor. The client may object on reasonable data protection grounds within that period. If it does, we will work with the client in good faith to find a solution. If we cannot, either party may end the affected programme by written notice, and clause 12 will apply.

6.3 We will put a written contract in place with each sub-processor that imposes data protection obligations which give at least the same level of protection as these terms, in particular sufficient guarantees of appropriate technical and organisational measures.

6.4 We remain responsible to the client for the performance of our sub-processors’ obligations.

7. Assistance with data subject rights

7.1 Taking into account the nature of the processing, we will help the client, by appropriate technical and organisational measures, to respond to requests from data subjects to exercise their rights under data protection law.

7.2 If we receive a request directly from a data subject about client personal data, we will pass it to the client within 2 working days and will not respond to it ourselves, except to confirm that we have passed it on, unless the client instructs us to.

8. Assistance with compliance

8.1 Taking into account the nature of the processing and the information available to us, we will help the client to meet its obligations under Articles 32 to 36 of the UK GDPR, including:

  • keeping client personal data secure
  • dealing with and notifying personal data breaches
  • carrying out data protection impact assessments (DPIAs), including by providing information about our processing, security measures and sub-processors
  • any prior consultation with the Information Commissioner’s Office

8.2 We may charge reasonable costs for assistance that goes beyond providing information we already hold, after agreeing the cost with the client in writing.

9. Personal data breaches

9.1 We will notify the client without undue delay, and in any case within 24 hours, after becoming aware of a personal data breach affecting client personal data.

9.2 Our notification will include, as far as we know at the time:

  • the nature of the breach, including the categories and approximate number of data subjects and records concerned
  • the name and contact details of the person at Cove Tutors who can provide more information
  • the likely consequences of the breach
  • the measures we have taken or propose to take to deal with it and reduce any harm

Where we cannot provide all of this at once, we will provide it in stages without further undue delay.

9.3 We will cooperate with the client and take reasonable steps to contain, investigate and recover from the breach. We will not notify the Information Commissioner’s Office or data subjects about a breach of client personal data unless the client instructs us to or the law requires it.

10. International transfers

10.1 We will not transfer client personal data outside the UK, or allow a sub-processor to do so, except where the transfer is protected by an appropriate safeguard under data protection law. These include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework (for certified US organisations), or the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

10.2 The client acknowledges that the sub-processors listed in clause 6.1 may process client personal data outside the UK, including in the European Economic Area and the United States, under the safeguards in their own data processing terms. The client authorises those transfers. We will give the client details of the safeguard used for any sub-processor on request.

11. Audits and information

11.1 We will make available to the client all information reasonably needed to show that we are meeting our obligations under Article 28 of the UK GDPR and these terms.

11.2 We will allow for and contribute to audits, including inspections, by the client or an auditor it appoints, provided that:

  • the client gives at least 30 days’ written notice, unless a personal data breach or a regulator requires a shorter period
  • the audit takes place during normal working hours and does not unreasonably disrupt our business or our tutors’ lessons
  • the auditor is bound by a duty of confidentiality
  • audits take place no more than once in any 12-month period, unless a personal data breach or a regulator requires otherwise

11.3 Where we reasonably can, we will meet an audit request first by providing written information, such as completed questionnaires and copies of our policies. Each party will bear its own costs of an audit.

12. End of the programme

12.1 When the programme ends, or earlier if the client asks in writing, we will at the client’s choice return client personal data to the client in a commonly used electronic format, or securely delete it, and in either case delete existing copies.

12.2 If the client does not tell us its choice within 30 days of the end of the programme, we will return the final reports to the client and securely delete the remaining client personal data. We will confirm the deletion in writing on request.

12.3 We may keep client personal data only where the law requires us to keep it, including safeguarding records that we must keep in line with the current edition of Keeping children safe in education and local safeguarding guidance. Anything we keep will remain protected by these terms and will be used only for the purpose for which it is kept.

13. Client obligations

13.1 The client will make sure that its instructions comply with data protection law and that it has given pupils and their parents or carers appropriate information about our role as processor.

13.2 The client will share with us only the personal data we need to deliver the programme, and will use secure means to send it.

13.3 Where a recording of a lesson is proposed, the client is responsible for obtaining and recording the parent’s or carer’s written agreement and for any other lawful basis it requires.

14. Liability

14.1 Each party’s liability arising from these terms is subject to the limitations and exclusions of liability in our terms of business, except for liability that cannot be limited or excluded by law.

14.2 Nothing in these terms limits either party’s liability to data subjects or to the Information Commissioner’s Office under data protection law.

15. General

15.1 These terms continue for as long as we process client personal data, even after the programme ends.

15.2 We may update these terms to reflect changes in data protection law or guidance from the Information Commissioner’s Office. Any change will apply to a current programme only if it does not reduce the protection given to client personal data, or if the client agrees in writing.

15.3 These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

15.4 Questions about these terms should be sent to hello@covetutors.co.uk.