Last updated: 29 April 2026
1. Introduction and scope
1.1. This Data Processing Agreement (“DPA”) forms part of the agreement between Classroom Secrets Limited (“Processor”, “we”, “us”, “our”) and the organisation or individual using Tandem Teach (“Controller”, “you”, “your”).
1.2. This DPA applies where we process Personal Data on your behalf in connection with your use of Tandem Teach, including the website, platform, AI-assisted tools, generated outputs and associated services (the “Service”).
1.3. This DPA is intended to comply with Article 28 of the UK GDPR and sets out the terms under which we process Personal Data on your behalf.
1.4. In the event of any conflict between this DPA and the Terms and Conditions, this DPA shall prevail in respect of Personal Data processing.
2. Definitions
2.1. In this DPA:
- “Controller” means the entity that determines the purposes and means of processing Personal Data.
- “Processor” means Classroom Secrets Limited.
- “Personal Data” means any information relating to an identified or identifiable natural person.
- “Processing” has the meaning given in UK GDPR.
- “UK GDPR” means the United Kingdom General Data Protection Regulation.
- “Sub-processor” means any third party engaged by the Processor to process Personal Data.
- “Service” means Tandem Teach and all associated tools and features.
3. Roles of the parties
3.1. The Controller determines the purposes and means of processing Personal Data.
3.2. The Processor processes Personal Data on behalf of the Controller.
3.3. The Controller is responsible for ensuring that any Personal Data submitted to the Service is processed lawfully.
3.4. The Controller shall ensure that it has a lawful basis for processing and for instructing the Processor.
4. Subject matter and duration
4.1. The subject matter of processing is the provision of the Service.
4.2. Processing shall take place for the duration of the Controller’s use of the Service and any applicable retention period set out in the Terms and Conditions and Privacy Policy.
5. Nature and purpose of processing
5.1. The Processor shall process Personal Data only as necessary to provide the Service.
5.2. Processing includes receiving User Input, generating outputs, storing outputs, performing safety checks, monitoring usage, maintaining audit logs, providing support and ensuring system performance and security.
6. Categories of data subjects and data
6.1. Data subjects may include teachers, school staff, administrators and authorised users.
6.2. Personal Data may include account information, contact details, organisational data, usage data, User Input and Generated Output where such data contains personal information.
6.3. The Service is not intended to process personal data relating to pupils or children. The Controller is responsible for ensuring such data is not submitted except where lawful and expressly permitted.
7. Controller obligations
7.1. The Controller shall:
- 7.1.1. comply with all applicable data protection laws;
- 7.1.2. ensure that it has a lawful basis for processing Personal Data;
- 7.1.3. ensure that Personal Data submitted is adequate, relevant and limited to what is necessary;
- 7.1.4. not submit special category data unless lawful and appropriate;
- 7.1.5. comply with safeguarding and organisational policies;
- 7.1.6. ensure that authorised users are appropriately trained;
- 7.1.7. remain responsible for the accuracy, quality and legality of Personal Data.
8. Processor obligations
8.1. The Processor shall:
- 8.1.1. process Personal Data only on documented instructions from the Controller unless required by law;
- 8.1.2. ensure that personnel are subject to confidentiality obligations;
- 8.1.3. implement appropriate technical and organisational measures;
- 8.1.4. assist the Controller with data subject rights requests where reasonably required;
- 8.1.5. assist with compliance obligations relating to security, breaches and impact assessments;
- 8.1.6. notify the Controller of Personal Data breaches where required by law;
- 8.1.7. delete or return Personal Data at the end of the provision of services, subject to legal obligations.
9. Security measures
9.1. The Processor implements appropriate technical and organisational measures to protect Personal Data.
9.2. These include input validation, moderation and safety screening, layered AI safety checks, access controls, audit logging, infrastructure security and system monitoring.
9.3. Security measures are subject to ongoing review and improvement.
10. Sub-processors
10.1. The Controller authorises the Processor to engage Sub-processors.
10.2. The Processor shall ensure that Sub-processors are bound by equivalent data protection obligations.
10.3. A list of Sub-processors is set out in the Annex below.
11. International transfers
11.1. Personal Data may be transferred outside the UK where necessary to provide the Service.
11.2. Where such transfers occur, the Processor shall ensure appropriate safeguards are in place, including recognised transfer mechanisms.
12. Data subject rights
12.1. The Processor shall assist the Controller in responding to data subject rights requests where reasonably required.
12.2. Where the Processor receives a request directly, it may redirect the request to the Controller unless required to respond by law.
13. Personal data breaches
13.1. The Processor shall notify the Controller without undue delay where it becomes aware of a Personal Data breach affecting Personal Data processed under this DPA.
13.2. The Processor shall provide reasonable assistance to the Controller in managing the breach.
14. Data retention and deletion
14.1. Personal Data shall be retained only as necessary to provide the Service and comply with legal obligations.
14.2. User Input and Generated Output may be stored temporarily and may be deleted, anonymised or restricted in accordance with the Terms and Conditions and Privacy Policy.
14.3. Safety, audit and monitoring logs may be retained for up to 12 months.
14.4. Upon termination of the Service, Personal Data may be deleted or anonymised following any applicable retention period.
15. Audit and compliance
15.1. The Processor shall make available information reasonably necessary to demonstrate compliance with this DPA.
15.2. Any audit must be reasonable and must not compromise security or confidentiality.
16. AI-specific provisions
16.1. Personal Data may be processed by AI systems solely for generating outputs and performing safety checks.
16.2. The Processor does not use Personal Data submitted to the Service to train AI models.
16.3. AI providers are contractually restricted from using Personal Data for training.
17. Liability
17.1. Liability under this DPA is subject to the limitations set out in the Terms and Conditions.
18. Governing law
18.1. This DPA is governed by the laws of England and Wales.
18.2. The courts of England and Wales shall have jurisdiction.
Schedule of Processing, Personal Data and Data Subjects
The Processor shall comply with any further documented instructions from the Controller relating to the processing of Personal Data, provided such instructions are lawful and consistent with this Agreement.
Subject matter of the processing
Processing of Personal Data submitted by the Controller and its authorised users through the Tandem Teach Service, including AI-assisted tools, account features and associated functionality.
Duration of the processing
Processing shall take place for the duration of the Controller’s use of the Service and any applicable retention period set out in the Terms and Conditions and Privacy Policy.
User Input and Generated Output may be stored for a limited period and may be deleted, anonymised or made inaccessible in accordance with those documents.
Safety, audit and monitoring logs may be retained for up to 12 months where necessary for security, compliance and operational purposes.
Nature and purposes of the processing
Processing is carried out for the purpose of providing the Service and supporting the Controller’s educational, administrative and organisational activities, including drafting content, generating outputs, and facilitating teaching-related workflows.
Processing also includes safety screening, moderation, validation, audit logging, system monitoring and security enforcement.
Type of Personal Data
Personal Data is determined by the Controller and may include account data, contact details and professional information relating to users.
User Input and Generated Output may contain personal data where entered by the Controller.
The Service is not intended to process special category data or identifiable pupil data, and the Controller is responsible for ensuring such data is not submitted except where lawful and expressly permitted.
Categories of Data Subjects
Data subjects are determined by the Controller and may include teachers, school staff, administrators and other authorised users.
The Service is not intended for use with personal data relating to pupils or children.
Data retention and deletion
Generated Output and User Input may be stored temporarily within the Service for user convenience and may be deleted, anonymised or restricted in accordance with the Terms and Conditions and Privacy Policy.
The Controller is responsible for exporting or retaining any data it wishes to keep.
Where tools operate in a browser-only mode, data may not be transmitted to the Processor and may be lost when the session ends.
Upon termination of the Service, data may be deleted or made inaccessible following any applicable retention period.
Annex: Sub-processors
The Controller authorises the Processor to engage Sub-processors to provide the Service. The Processor shall ensure that Sub-processors are subject to contractual obligations consistent with this Agreement.
Core Platform Services
These are necessary for operation of the Service.
| Sub-processor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage, infrastructure | Account data, usage data, stored outputs | UK / EU | N/A or UK/EU adequacy |
| Microsoft Azure | Infrastructure, AI safety and content services | Inputs, outputs, moderation data | UK / EU | N/A or UK/EU adequacy |
| Anthropic (Claude) | AI generation and validation | Inputs and outputs | EU / UK (where available) | Contractual safeguards |
| OpenAI | Moderation and safety filtering | Inputs and outputs (filtered) | US | UK–US Data Bridge / SCCs |
| Mistral AI | Backup AI provider | Inputs and outputs | EU | EU adequacy |
| Stripe | Payment processing | Billing and payment data | US | UK–US Data Bridge |
Operational and support services
Used to support platform performance and administration.
| Sub-processor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Sentry | Error monitoring | Technical logs, IP address | EU | EU adequacy |
| Zoho | CRM and account management | Account and contact data | EU | EU adequacy |
Website and marketing services
These services are separate from the core AI platform and do not process User Input or Generated Output.
| Sub-processor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Plausible Analytics | Default cookieless website analytics | Anonymous, aggregated usage data (no cookies, no IP storage) | EU | EU adequacy |
| Google Analytics (GA4) | Website analytics (loaded only on cookie consent) | Cookies, page views, device and browser data, approximate location | US | UK–US Data Bridge |
| Zoho PageSense | Behavioural analytics, heatmaps, session recording, A/B testing (loaded only on cookie consent) | Cookies, click and scroll behaviour, recorded sessions, survey responses | EU | EU adequacy |
| Meta (Facebook) Pixel | Marketing attribution | Website interaction data | US | UK–US Data Bridge |
| LinkedIn Insight Tag | Advertising analytics | Website interaction data | US | UK–US Data Bridge |
| Termly | Cookie consent management | Consent preferences | US | UK–US Data Bridge |
Contact for DPA matters
Data Protection Officer: Edward Riley
Email: [email protected]
Postal: Classroom Secrets, Drakes Industrial Estate, Shay Lane, Halifax, HX3 6RL