Last updated: 29 April 2026

1. Introduction and scope

1.1. This Data Processing Agreement (“DPA”) forms part of the agreement between Classroom Secrets Limited (“Processor”, “we”, “us”, “our”) and the organisation or individual using Tandem Teach (“Controller”, “you”, “your”).

1.2. This DPA applies where we process Personal Data on your behalf in connection with your use of Tandem Teach, including the website, platform, AI-assisted tools, generated outputs and associated services (the “Service”).

1.3. This DPA is intended to comply with Article 28 of the UK GDPR and sets out the terms under which we process Personal Data on your behalf.

1.4. In the event of any conflict between this DPA and the Terms and Conditions, this DPA shall prevail in respect of Personal Data processing.

2. Definitions

2.1. In this DPA:

  • “Controller” means the entity that determines the purposes and means of processing Personal Data.
  • “Processor” means Classroom Secrets Limited.
  • “Personal Data” means any information relating to an identified or identifiable natural person.
  • “Processing” has the meaning given in UK GDPR.
  • “UK GDPR” means the United Kingdom General Data Protection Regulation.
  • “Sub-processor” means any third party engaged by the Processor to process Personal Data.
  • “Service” means Tandem Teach and all associated tools and features.

3. Roles of the parties

3.1. The Controller determines the purposes and means of processing Personal Data.

3.2. The Processor processes Personal Data on behalf of the Controller.

3.3. The Controller is responsible for ensuring that any Personal Data submitted to the Service is processed lawfully.

3.4. The Controller shall ensure that it has a lawful basis for processing and for instructing the Processor.

4. Subject matter and duration

4.1. The subject matter of processing is the provision of the Service.

4.2. Processing shall take place for the duration of the Controller’s use of the Service and any applicable retention period set out in the Terms and Conditions and Privacy Policy.

5. Nature and purpose of processing

5.1. The Processor shall process Personal Data only as necessary to provide the Service.

5.2. Processing includes receiving User Input, generating outputs, storing outputs, performing safety checks, monitoring usage, maintaining audit logs, providing support and ensuring system performance and security.

6. Categories of data subjects and data

6.1. Data subjects may include teachers, school staff, administrators and authorised users.

6.2. Personal Data may include account information, contact details, organisational data, usage data, User Input and Generated Output where such data contains personal information.

6.3. The Service is not intended to process personal data relating to pupils or children. The Controller is responsible for ensuring such data is not submitted except where lawful and expressly permitted.

7. Controller obligations

7.1. The Controller shall:

  • 7.1.1. comply with all applicable data protection laws;
  • 7.1.2. ensure that it has a lawful basis for processing Personal Data;
  • 7.1.3. ensure that Personal Data submitted is adequate, relevant and limited to what is necessary;
  • 7.1.4. not submit special category data unless lawful and appropriate;
  • 7.1.5. comply with safeguarding and organisational policies;
  • 7.1.6. ensure that authorised users are appropriately trained;
  • 7.1.7. remain responsible for the accuracy, quality and legality of Personal Data.

8. Processor obligations

8.1. The Processor shall:

  • 8.1.1. process Personal Data only on documented instructions from the Controller unless required by law;
  • 8.1.2. ensure that personnel are subject to confidentiality obligations;
  • 8.1.3. implement appropriate technical and organisational measures;
  • 8.1.4. assist the Controller with data subject rights requests where reasonably required;
  • 8.1.5. assist with compliance obligations relating to security, breaches and impact assessments;
  • 8.1.6. notify the Controller of Personal Data breaches where required by law;
  • 8.1.7. delete or return Personal Data at the end of the provision of services, subject to legal obligations.

9. Security measures

9.1. The Processor implements appropriate technical and organisational measures to protect Personal Data.

9.2. These include input validation, moderation and safety screening, layered AI safety checks, access controls, audit logging, infrastructure security and system monitoring.

9.3. Security measures are subject to ongoing review and improvement.

10. Sub-processors

10.1. The Controller authorises the Processor to engage Sub-processors.

10.2. The Processor shall ensure that Sub-processors are bound by equivalent data protection obligations.

10.3. A list of Sub-processors is set out in the Annex below.

11. International transfers

11.1. Personal Data may be transferred outside the UK where necessary to provide the Service.

11.2. Where such transfers occur, the Processor shall ensure appropriate safeguards are in place, including recognised transfer mechanisms.

12. Data subject rights

12.1. The Processor shall assist the Controller in responding to data subject rights requests where reasonably required.

12.2. Where the Processor receives a request directly, it may redirect the request to the Controller unless required to respond by law.

13. Personal data breaches

13.1. The Processor shall notify the Controller without undue delay where it becomes aware of a Personal Data breach affecting Personal Data processed under this DPA.

13.2. The Processor shall provide reasonable assistance to the Controller in managing the breach.

14. Data retention and deletion

14.1. Personal Data shall be retained only as necessary to provide the Service and comply with legal obligations.

14.2. User Input and Generated Output may be stored temporarily and may be deleted, anonymised or restricted in accordance with the Terms and Conditions and Privacy Policy.

14.3. Safety, audit and monitoring logs may be retained for up to 12 months.

14.4. Upon termination of the Service, Personal Data may be deleted or anonymised following any applicable retention period.

15. Audit and compliance

15.1. The Processor shall make available information reasonably necessary to demonstrate compliance with this DPA.

15.2. Any audit must be reasonable and must not compromise security or confidentiality.

16. AI-specific provisions

16.1. Personal Data may be processed by AI systems solely for generating outputs and performing safety checks.

16.2. The Processor does not use Personal Data submitted to the Service to train AI models.

16.3. AI providers are contractually restricted from using Personal Data for training.

17. Liability

17.1. Liability under this DPA is subject to the limitations set out in the Terms and Conditions.

18. Governing law

18.1. This DPA is governed by the laws of England and Wales.

18.2. The courts of England and Wales shall have jurisdiction.

Schedule of Processing, Personal Data and Data Subjects

The Processor shall comply with any further documented instructions from the Controller relating to the processing of Personal Data, provided such instructions are lawful and consistent with this Agreement.

Subject matter of the processing

Processing of Personal Data submitted by the Controller and its authorised users through the Tandem Teach Service, including AI-assisted tools, account features and associated functionality.

Duration of the processing

Processing shall take place for the duration of the Controller’s use of the Service and any applicable retention period set out in the Terms and Conditions and Privacy Policy.

User Input and Generated Output may be stored for a limited period and may be deleted, anonymised or made inaccessible in accordance with those documents.

Safety, audit and monitoring logs may be retained for up to 12 months where necessary for security, compliance and operational purposes.

Nature and purposes of the processing

Processing is carried out for the purpose of providing the Service and supporting the Controller’s educational, administrative and organisational activities, including drafting content, generating outputs, and facilitating teaching-related workflows.

Processing also includes safety screening, moderation, validation, audit logging, system monitoring and security enforcement.

Type of Personal Data

Personal Data is determined by the Controller and may include account data, contact details and professional information relating to users.

User Input and Generated Output may contain personal data where entered by the Controller.

The Service is not intended to process special category data or identifiable pupil data, and the Controller is responsible for ensuring such data is not submitted except where lawful and expressly permitted.

Categories of Data Subjects

Data subjects are determined by the Controller and may include teachers, school staff, administrators and other authorised users.

The Service is not intended for use with personal data relating to pupils or children.

Data retention and deletion

Generated Output and User Input may be stored temporarily within the Service for user convenience and may be deleted, anonymised or restricted in accordance with the Terms and Conditions and Privacy Policy.

The Controller is responsible for exporting or retaining any data it wishes to keep.

Where tools operate in a browser-only mode, data may not be transmitted to the Processor and may be lost when the session ends.

Upon termination of the Service, data may be deleted or made inaccessible following any applicable retention period.

Annex: Sub-processors

The Controller authorises the Processor to engage Sub-processors to provide the Service. The Processor shall ensure that Sub-processors are subject to contractual obligations consistent with this Agreement.

Core Platform Services

These are necessary for operation of the Service.

Sub-processor Purpose Data processed Location Transfer mechanism
Amazon Web Services (AWS)Hosting, storage, infrastructureAccount data, usage data, stored outputsUK / EUN/A or UK/EU adequacy
Microsoft AzureInfrastructure, AI safety and content servicesInputs, outputs, moderation dataUK / EUN/A or UK/EU adequacy
Anthropic (Claude)AI generation and validationInputs and outputsEU / UK (where available)Contractual safeguards
OpenAIModeration and safety filteringInputs and outputs (filtered)USUK–US Data Bridge / SCCs
Mistral AIBackup AI providerInputs and outputsEUEU adequacy
StripePayment processingBilling and payment dataUSUK–US Data Bridge

Operational and support services

Used to support platform performance and administration.

Sub-processor Purpose Data processed Location Transfer mechanism
SentryError monitoringTechnical logs, IP addressEUEU adequacy
ZohoCRM and account managementAccount and contact dataEUEU adequacy

Website and marketing services

These services are separate from the core AI platform and do not process User Input or Generated Output.

Sub-processor Purpose Data processed Location Transfer mechanism
Plausible AnalyticsDefault cookieless website analyticsAnonymous, aggregated usage data (no cookies, no IP storage)EUEU adequacy
Google Analytics (GA4)Website analytics (loaded only on cookie consent)Cookies, page views, device and browser data, approximate locationUSUK–US Data Bridge
Zoho PageSenseBehavioural analytics, heatmaps, session recording, A/B testing (loaded only on cookie consent)Cookies, click and scroll behaviour, recorded sessions, survey responsesEUEU adequacy
Meta (Facebook) PixelMarketing attributionWebsite interaction dataUSUK–US Data Bridge
LinkedIn Insight TagAdvertising analyticsWebsite interaction dataUSUK–US Data Bridge
TermlyCookie consent managementConsent preferencesUSUK–US Data Bridge

Contact for DPA matters

Data Protection Officer: Edward Riley

Email: [email protected]

Postal: Classroom Secrets, Drakes Industrial Estate, Shay Lane, Halifax, HX3 6RL