To facilitate the use of the Eclipse system ("Eclipse"), The Transformative Group Ltd "Transformative") will process the personal data (as defined within Article 4(1) UK GDPR) of pupils, parents and staff members within the Customers Multi-Academy Trust. Depending on how the Customer uses the system this may also entail the processing of visitor, governor and trustee personal data as well as the data of professionals such as doctors, nurses and social workers.
This data processing agreement ("DPA") sets out the obligations of both the Customer as a 'Data Controller' and The Transformative Group as a 'Data Processor' pursuant to Article 28(3) UK GDPR.
1. Definitions
In this DPA the following words shall have the correlating meanings:
| Term | Definition |
|---|---|
| Agreement | This data processing agreement. |
| Business Hours | means the hours of 0900 to 1700 on Working Days. |
| Data Protection Legislation | shall mean the Data Protection Act 2018, the Retained Regulation (EU) 2016/679 (UK GDPR) as incorporated under the European Union (Withdrawal Act) 2018 and as amended by The Data Protection, Privacy and Electronic Communications (Amendment Etc.) (EU Exit) Regulations 2019, and any other laws or regulations applicable in the United Kingdom pertinent to the processing of personal data, in each case as amended or repealed. |
| "personal data", "data subject", "controller", "processor", "process" and "supervisory authority" shall be interpreted in accordance with UK GDPR. | |
| End Date | As defined in clause 2.11 of this DPA. |
| UK GDPR | Shall mean United Kingdom General Data Protection Regulation 2018. |
| Personal Data Breach | means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed. |
| Product | Eclipse |
| Sub Processor | shall mean a processor appointed by Us, as described at clause 2.5 of this DPA. |
| Us, We or Transformative | means The Transformative Group Ltd, a limited company registered in the United Kingdom (CHRN: 13882568). |
| Working Days | means days between Monday to Friday inclusive, which are not designated public holidays as set by the UK Government under the Banking and Financial Dealings Act 1971. |
| You, Your or Customer | means [INSERT NAME OF COMPANY (UKRN:XXXXXXX)] OR [NAME OF CUSTOMER] |
Where a defined term is used in this DPA and a definition is omitted from this DPA, that defined term will take on the definition given in the Terms and Conditions.
2. Processor Clauses
Clause 2.1
In the event that We process Your personal data under or in connection with the Agreement, both parties record their intention that Transformative is the Data Processor and the Customer is the Data Controller in respect of the personal data.
Clause 2.2
Each party shall comply with its obligations under applicable Data Protection Legislation.
Clause 2.3
The Customer authorises Transformative to transfer or otherwise process the personal data outside the UK or the European Economic Area, without obtaining the Customer's specific prior written consent, provided that: the personal data is transferred to or processed in a territory which is subject to adequacy regulations under the Data Protection Legislation that provides adequate protection for the privacy rights of individuals; or Transformative participates in a valid cross-border transfer mechanism under Data Protection Legislation, so that We (and, where appropriate, You) can ensure that appropriate safeguards are in place to ensure an adequate level of protection with respect to the privacy rights of individuals as required by the UK GDPR; or the transfer otherwise complies with Data Protection Legislation.
Clause 2.4
Transformative will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk involved in processing Customer personal data pursuant to the Agreement. We shall assist You through appropriate technical and organisational measures in fulfilling Your obligations as controller in relation to the security of processing Your personal data. Our general security measures are set out in clause 4 of this DPA.
Clause 2.5
Transformative may engage such other processors (“Sub Processors”) as We consider reasonably appropriate for the processing of Customer personal data in accordance with the terms of the Agreement. Any Sub Processors in place as of the Effective Date are outlined in Appendix A of this agreement and are accepted by the Customer.
Clause 2.6
By signing this Agreement, You are providing Us with general written authorisation to add a Sub Processor and/or replace or remove a Sub Processor where We deem necessary, provided that We shall notify You (which will be by email) of the appointment of a new Sub Processor and You may, on reasonable grounds, object to the appointment of a Sub Processor by responding in writing within 10 Working Days of receipt of our email, giving reasons for Your objection. The parties shall work together to reach agreement on the engagement of Sub Processors, and, for the avoidance of doubt, Transformative will not share Customer personal data with any Sub Processor that You have objected to in accordance with this Agreement. We shall ensure that all Sub Processors are bound by contract with Us which include appropriate data processing terms and Transformative shall remain liable for Sub Processors' acts and omissions in connection with this Agreement.
Clause 2.7
In the event that any data subject exercises their rights under applicable Data Protection Legislation against You, Transformative shall use appropriate technical and organisational measures to assist the Customer in fulfilling Your obligations as controller and will provide a suitable response without undue delay (and in any event within 10 Working Days) following our acknowledgement of your written request.
Clause 2.8
Transformative shall promptly notify the Customer in writing in the event that We receive any request, complaint, notice or other communication directly from a third party or data subject which relates directly or indirectly to the processing of Your personal data.
Clause 2.9
In the event that Transformative experiences a Personal Data Breach involving Customer personal data, We will notify You without undue delay and shall assist You to the extent reasonably necessary to mitigate the impact of the Personal Data Breach in addition to any notification to the applicable supervisory authority and data subjects.
Clause 2.10
In the event that You consider that the processing of personal data performed pursuant to the Agreement requires a privacy impact assessment or prior consultation with a supervisory authority to be undertaken then, following written request from You, Transformative shall use reasonable commercial endeavours to provide relevant information and assistance to the Customer to facilitate such a privacy impact assessment or prior consultation.
Clause 2.11
Transformative will provide you with a data protection impact assessment upon request, and prior consultations with supervisory authorities, which are required by Article 35 or 36 of the UK GDPR, in each case solely in relation to the processing of Your personal data by Us.
Clause 2.12
Following either termination or expiry of the Agreement (the "End Date"), Transformative is instructed by the Customer to delete Your personal data which is held by Us. Data uploaded to the product is processed in memory with automatic deletion after the session completes and consequently secure disposal of your data takes place promptly after the the output document has been produced. This period may be extended if a Customer opts-in to our quality assurance as detailed at clause 3.7 below. Where applicable law requires Transformative to retain all or some of Customer personal data, We shall notify You of this lawful requirement.
Clause 2.13
Where requested by the Customer, Transformative will provide all information reasonably necessary to demonstrate Our compliance with clauses 2.2 to 2.12 inclusive, and shall allow for and contribute to audits (including inspections) conducted by You or another auditor mandated by You (where such persons are subject to binding obligations of confidentiality) on an annual basis of no more than once per 365 days (unless directed by the relevant supervisory authority) with reasonable prior notice during Business Hours. You will ensure that your representatives make all reasonable endeavours to minimise any business interruption to Transformative during any such audit. Transformative may charge the Customer for any assistance required to facilitate such audits on a time and materials basis.
Clause 2.14
Without prejudice to any other provision in this Agreement which may apply, You shall for the duration of the contract have in place and maintain any and all appropriate consents from the relevant data subjects and or an appropriate lawful basis for processing the personal data of the data subjects affected by this Agreement.
Clause 2.15
We shall for the duration of the contract use reasonable endeavours to assist You in meeting Your obligations under Articles 32 to 36 (inclusive) of UK GDPR.
Clause 2.16
As a result of any changes in law relating to the protection or treatment of personal data, Transformative shall contact you with an updated DPA within a reasonable timescale. During the intervening period the parties shall act reasonably and in good faith in continuing to apply this DPA in any way that ensures compliance with such law.
Clause 2.17
Nothing in this DPA is intended to govern the processing of personal data as it relates to personal data collected by Us (or a third party or agent instructed by Us) as an independent controller.
3. Details of Processing
3.1 Purpose
The transfer of personal data is required to enable Customers to use the features of the Product.
3.2 Processing Commencement & Scope
Transformative will commence processing of Customer personal data as soon as an employee of the Customer creates an account within the Product. At this point Transformative will be processing the full name and email address of that employee.
Further processing of personal data will take place once a file is uploaded to the Product.
3.3 Categories of Data Subjects
The Product will process the following categories of data subject:
- Pupils
- Parents
- Employees including staff, volunteers, temporary and casual workers or anyone else recorded as such within the uploaded file.
- Any other class of data subject who may be contained in the file uploaded by the Customer.
3.4 Types of Personal Data
Due to the nature of the system as a redaction tool, Transformative will potentially process all types of personal data as defined by Article 4(1) UK GDPR whenever it is present within an uploaded file.
3.5 Data Processing, Retention & Quality Assurance
Documents uploaded to the product are processed in memory with automatic deletion after the session completes.
Customers will also be able to participate in a quality assurance process. Participation in the quality assurance process is entirely optional and explicit consent will be obtained for this processing. In the event that a Customer signs up to this process:
• the data that their account uploads to the product will be stored for a further 30 working days; and
• samples of the uploaded data will be manually reviewed by a Transformative employee to assist in improving the product.
3.6 Payment Processing
If a Customer purchases a license to use the Product the payment can be facilitated through an invoice or direct card payment via the Stripe platform.
If payment is made through Stripe it will not be possible for Transformative to view all of the data used to make the purchase however we will be provided with and subsequently process the following data:
• Customer ID (Stripe internal reference)
• Email address
• Billing name and address
• Metadata that we have attached (e.g. internal order ID, product name)
• Invoice ID (if linked to an invoice or subscription)
• Subscription ID (if recurring)
• Receipt URL (link to the customer's Stripe-hosted receipt)
• CVC check, ZIP/postal code check and address check results
If payment is made through an invoice We will request the following data to produce and supply an invoice to You:
• Contact name
• Email Address
• Phone number (this is an optional field)
We will also require a billing address which includes the street address, city, postcode and country. If You are purchasing a license as an individual these fields will also constitute Your personal data. You are also able to provide us with your VAT Registration Number to be added to the invoice which could constitute personal data if it is a personal VAT registration number as opposed to an organisational VAT number.
4. Security Standards
4.1 Encryption
All data is encrypted in transit and at rest.
4.2 Backup & Recovery
Data snapshots are available which can be restored promptly with a single click.
4.3 Access Control
Transformative employees can only access the system with a secure password login. The login is subject to an enforced password policy requiring at least 8 characters and is subject to formatting rules including use of lower and upper case letters, numbers and special characters.
4.4 Data Access Post-Processing
Once a file has been uploaded to the system and processed it is possible for Customers to download the newly redacted document once the process has been completed. Customers can also access the output document for 30 days after uploading.
4.5 Multi-Factor Authentication
Multi-factor authentication is enabled by default for all Transformative employees.
4.6 Data Location
Customer data uploaded into the Product is stored within the EU-West2 Google Cloud Platform data centre.
4.7 Limited Access
For personal data stored within the Product, Transformative and its sub-processors will not access your personal data unless specifically requested for support purposes or without your explicit consent and direction.
4.8 Contractual obligations
Transformative will impose appropriate contractual obligations upon its workforce engaged in the processing of personal data, including relevant obligations regarding confidentiality, data protection and data security. We will ensure that our workforce engaged in the processing of personal data are informed of the confidential nature of personal data, have received appropriate training in their responsibilities and have executed written confidentiality agreements. We will ensure that such confidentiality agreements survive the termination of the employment or engaged with our workforce.
4.9 Google Cloud Platform Certifications
5. Governing Law and Jurisdiction
This agreement shall be governed by and interpreted in accordance with the laws of England and Wales. Non-contractual obligations (if any) arising out of or in connection with this agreement (including its formation) shall be Governed by the laws of England and Wales.
The parties agree to submit to the exclusive jurisdiction of the Courts of England and Wales in relation to any claim or matter (whether contractual or non-contractual) arising under this agreement.
Appendix A: Sub-Processors
All sub-processors involved in the processing of Customer personal data are detailed below:
| Name | Type of Organisation | What they do | Location |
|---|---|---|---|
| Google Cloud EMEA Limited | Cloud platform | Cloud based storage of data. The data is stored within the Transformative tenant of Google Cloud Platform within the EU-West2 locality | England |
| Pwned Data Intelligence Ltd | Software Developer | Technical development & support of the Product. | England |
| Stripe Payments Europe Limited | Payment Processing | If a customer purchases a licence payment will be facilitated through this sub-processor. | Ireland |