1. Parties and scope
1.1. This Data Processing Agreement ("DPA") is entered into between:
- the school, academy trust, local authority or other organisation that uses Report Alchemy (the "Controller"); and
- Sagwa Limited, trading as Report Alchemy, of 22 East Street, Market Harborough, Leicestershire LE16 9AE (the "Processor").
1.2. It applies to all processing of personal data carried out by the Processor on behalf of the Controller through the Report Alchemy service, and forms part of the Terms and Conditions. Where this DPA conflicts with those Terms in relation to data protection, this DPA prevails.
1.3. "Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and any legislation replacing or amending them. Terms such as "personal data", "processing", "controller", "processor" and "data subject" have the meanings given in Data Protection Law.
1.4. This DPA takes effect when accepted through the form on this page by a person authorised to bind the Controller, or when signed in writing by both parties, and continues for as long as the Processor processes personal data on the Controller's behalf.
2. Roles
2.1. The Controller is the controller of pupil personal data entered into the service. The Processor processes that data only on the Controller's behalf.
2.2. The Processor is an independent controller of the account holder's own data — name, email address, billing records and service usage — which it processes to provide, secure, support and bill for the service, as described in its Privacy Policy. That processing is outside the scope of this DPA.
2.3. Where an individual teacher uses the service in the course of their employment, the Controller remains the school, and the teacher acts on the Controller's behalf.
3. Subject matter of the processing
3.1. As required by Article 28(3), the details of the processing are:
| Subject matter | Drafting written pupil reports and related school communications from notes supplied by a teacher. |
|---|---|
| Duration | For as long as the Controller uses the service, plus the retention period in clause 9. |
| Nature and purpose | Storage of pupil records and notes; transmission of those notes to an AI provider to generate text; storage of the generated text; retrieval and editing by the teacher. |
| Types of personal data | Pupil first name; optionally pronouns and year group; free-text observations about attainment, effort, behaviour and next steps written by the teacher; generated report text; the class a pupil belongs to. |
| Categories of data subject | Pupils at the Controller's school, and the Controller's teaching staff who hold accounts. |
| Special category data | None is required or requested. The service provides no field for health, SEN, ethnicity, religion or safeguarding data, and the Controller instructs its staff not to enter any. |
| Children's data | Yes. Nearly all data subjects are children. The Processor's obligations under this DPA are to be read with that in mind. |
4. Processing on documented instructions
4.1. The Processor shall process personal data only on the Controller's documented instructions, which consist of: this DPA, the Terms and Conditions, the settings chosen in the account, and any further written instruction the Controller gives.
4.2. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes Data Protection Law.
4.3. The Processor shall not process personal data for its own purposes, and specifically shall not:
- use pupil data, teachers' notes or generated reports to train, fine-tune or evaluate any artificial intelligence model, whether its own or a third party's;
- sell, rent, licence or otherwise disclose personal data to any third party except the sub-processors listed under clause 6;
- use pupil data for marketing, advertising or profiling of any kind;
- combine pupil data with data from any other source; or
- retain personal data beyond the periods in clause 9.
4.4. Where the Processor is required by law to process personal data other than on the Controller's instructions, it shall inform the Controller before processing unless that law prohibits it.
5. Confidentiality
5.1. The Processor shall ensure that any person authorised to process the personal data is subject to a duty of confidence, whether contractual or statutory, and processes it only as necessary to provide the service.
5.2. Access to production systems is restricted to named individuals with a demonstrable need, and is not shared.
6. Sub-processors
6.1. The Controller gives general written authorisation for the Processor to engage sub-processors. The current list, with the data each receives and where it is processed, is maintained at report-alchemy.com/privacy-policy#subprocessors. At the date of this version the sub-processors handling pupil data are OpenAI, L.L.C. (generation) and Google Cloud Platform (hosting and database, London region).
6.2. The Processor shall give the Controller at least 30 days' notice before adding or replacing a sub-processor that processes pupil data. The Controller may object on reasonable data protection grounds within that period, in which case the parties shall discuss in good faith; if no resolution is reached, the Controller may terminate the service and receive a pro-rata refund of any unused period.
6.3. The Processor shall impose on each sub-processor, by contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for its sub-processors' performance.
7. International transfers
7.1. The application, database and all stored report content are hosted in the United Kingdom (Google Cloud, London, europe-west2).
7.2. Generating report text requires transferring the teacher's notes to OpenAI, L.L.C. in the United States. That transfer is made under the European Commission's Standard Contractual Clauses as supplemented by the UK International Data Transfer Addendum, together with a transfer risk assessment.
7.3. Where the Controller enables pseudonymised generation in its accounts, pupil names are replaced with placeholders before any transfer under clause 7.2, and are restored only on the Processor's UK-hosted systems. The Processor recommends this setting for all school accounts.
8. Security
8.1. The Processor shall implement appropriate technical and organisational measures under Article 32, taking account of the state of the art, the costs of implementation, and the risk to data subjects. The measures in place are published and kept current at report-alchemy.com/data-protection#security, and include encryption in transit and at rest, no password storage of any kind, server-side sessions, per-account data scoping, and a database that refuses unencrypted connections and authorises no public network.
8.2. The Processor shall not materially weaken those measures during the term.
8.3. The Processor states plainly that it holds no ISO 27001 or Cyber Essentials certification and has not commissioned an external penetration test. The Controller accepts this in deciding whether the measures are appropriate to the risk.
9. Retention and deletion
9.1. Pupil records, teachers' notes and generated reports are deleted automatically once the retention period set on the account expires. Available periods are 12, 24 or 36 months from the date a pupil was last written about, or deletion at the end of each academic year on 31 August. The default is 24 months.
9.2. The Controller may instruct a shorter period, a specific deletion date for a specific pupil, or immediate deletion of any pupil, at any time. Immediate per-pupil deletion is available to teachers within the product and takes effect at once.
9.3. On termination, or on the Controller's written request, the Processor shall delete all personal data processed on the Controller's behalf within 30 days, and confirm deletion in writing, unless required by law to retain it.
9.4. Deletion is irreversible in the live system. Encrypted database backups are retained by the hosting provider for up to seven days before ageing out, and are never used to restore an individual record.
10. Assistance to the Controller
10.1. Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests to exercise data subject rights.
10.2. Much of this assistance is built into the product: erasure of an individual pupil, export of all data held on an account, and correction of pupil records are all available to the Controller's staff without contacting the Processor. Where a request cannot be satisfied that way, the Processor shall respond to the Controller within 5 working days.
10.3. If the Processor receives a request directly from a data subject, it shall not respond to it substantively but shall forward it to the Controller without undue delay.
10.4. The Processor shall assist the Controller in complying with Articles 32 to 36, including data protection impact assessments and prior consultation. Its own assessment is published at report-alchemy.com/data-protection/dpia and may be relied on as a starting point.
11. Personal data breaches
11.1. The Processor shall notify the Controller without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting the Controller's personal data.
11.2. The notification shall describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point — so that the Controller can meet its own 72-hour obligation to the Information Commissioner.
11.3. The Processor shall cooperate with the Controller and take reasonable steps to assist in investigating, mitigating and remedying the breach.
12. Audit
12.1. The Processor shall make available to the Controller all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates.
12.2. In the first instance the Processor may satisfy a request by providing written responses, its published documentation and evidence of its measures. Where that is insufficient, an on-site or remote audit may be conducted once in any twelve-month period on 30 days' written notice, during business hours, without unreasonable disruption, and subject to confidentiality. More frequent audits may be conducted following a personal data breach or on the instruction of a supervisory authority.
13. Liability and term
13.1. Each party's liability under this DPA is subject to the limitations in the Terms and Conditions, save that nothing limits liability which cannot lawfully be limited, including liability under Data Protection Law to data subjects.
13.2. This DPA continues while the Processor processes personal data for the Controller. Clauses 5, 9, 11 and 13 survive termination.
13.3. The Processor may update this DPA to reflect changes in law or its service. Where a change materially reduces the Controller's protections, the Processor shall give 30 days' notice, and the Controller may terminate without penalty within that period. The version in force for an account is the one recorded at acceptance until a new version is accepted.
13.4. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Accept this agreement
For someone authorised to bind the school — a headteacher, business manager, DPO or trust officer. We record your name, role, organisation and the time, and both parties are bound from that moment.
Sign in to accept or email admin@report-alchemy.com if your school needs it signed on its own paper.
14. Contact
Sagwa Limited, trading as Report Alchemy22 East Street, Market Harborough, Leicestershire LE16 9AE
Data protection enquiries: admin@report-alchemy.com