Data Processing Agreement
Last updated:
Version 1.0.0
1. Introduction and Scope
This Data Processing Agreement ("DPA") forms part of the agreement between Gradespace LTD ("Gradespace", "we", "us") and the customer ("Customer") for the use of our products, including TargetGrade, CareMaSym, AccountGrade, and BuildGrade (the "Products").
It applies wherever Gradespace processes personal data on behalf of the Customer, and reflects the requirements of the UK GDPR and the Data Protection Act 2018 (together, "Data Protection Law"), including Article 28 UK GDPR.
For personal data Gradespace processes for its own purposes (for example, Customer account, billing, and website data), Gradespace acts as controller and our Privacy Policy applies.
2. Roles of the Parties
- Customer as controller: The Customer (for example, a tuition provider, school, care provider, or employer) determines the purposes and means of processing the personal data it submits to the Products and is responsible for its lawful basis, transparency to data subjects, and any required consents.
- Gradespace as processor: Gradespace processes that personal data only on the Customer's documented instructions, as set out in this DPA and the applicable service agreement.
- Role review: Where a specific processing purpose makes Gradespace a controller or joint controller, the parties will document that allocation for the relevant purpose.
3. Processing Instructions
Gradespace shall:
- Process Customer personal data only on the Customer's documented instructions, unless required otherwise by law (in which case we will inform the Customer unless the law prohibits it);
- Immediately inform the Customer if, in our opinion, an instruction infringes Data Protection Law;
- Ensure persons authorised to process the data are bound by confidentiality obligations;
- Not use Customer personal data to train AI models, for advertising, or for any purpose other than providing the Products;
- Not sell Customer personal data.
4. Special-Category and Children's Data
Health and social-care data (CareMaSym)
CareMaSym may process special-category health and social-care information. The Customer is responsible for identifying an Article 9 UK GDPR condition for this processing. Gradespace applies heightened safeguards: role-based access so staff see only what they need, audit logging of access to sensitive records, encryption at rest and in transit, and defined retention and deletion for service-user records, care notes, and medication/care information.
Children's data (TargetGrade)
TargetGrade processes children's data in an education context. Gradespace designs the product with the ICO Age Appropriate Design Code (Children's Code) in mind and configures each deployment to the minimum fields the Customer needs. Grade predictions and study recommendations are assistive and subject to teacher review; no solely automated decision with legal or similarly significant effect is made about a student, children's data is not used to train AI models, and optional features that expand processing are enabled only on the Customer's documented instruction following a supplementary privacy assessment.
5. Security Measures
Taking into account the nature of the processing, Gradespace implements appropriate technical and organisational measures under Article 32 UK GDPR, including:
- Encryption of data in transit (TLS) and at rest;
- Role-based access control, least-privilege access, and multi-factor authentication for administrative access;
- Audit logging, monitoring, and alerting for access to sensitive data;
- Secure development practices, dependency management, and regular security review;
- Backups with tested restoration, and environment separation;
- Staff confidentiality obligations and data protection training.
6. Sub-processors
The Customer provides general authorisation for Gradespace to engage the sub-processors listed in our Sub-processor Register. Gradespace shall:
- Impose data protection obligations on each sub-processor equivalent to those in this DPA;
- Remain liable to the Customer for the performance of its sub-processors;
- Give the Customer prior notice of the addition or replacement of sub-processors, allowing the Customer a reasonable opportunity to object on data protection grounds.
7. Assistance with Data Subject Rights
Taking into account the nature of the processing, Gradespace will assist the Customer with appropriate technical and organisational measures in responding to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, and objection).
If a data subject contacts Gradespace directly about data we process on the Customer's behalf, we will promptly refer the request to the Customer and coordinate as needed, rather than responding on the Customer's behalf unless instructed.
8. Personal Data Breach
Gradespace maintains a documented breach response procedure covering detection, containment, assessment, notification, and post-incident review. In the event of a personal data breach affecting Customer personal data, Gradespace will:
- Notify the Customer without undue delay after becoming aware of the breach, so the Customer can meet its own obligations (including the UK GDPR 72-hour ICO notification timeframe where it applies);
- Provide information on the nature of the breach, the data and data subjects affected, likely consequences, and measures taken or proposed;
- Contain the incident (for example, disabling accounts, isolating systems, rotating credentials), preserve evidence, and document the incident and remedial actions.
9. DPIAs and Prior Consultation
Gradespace will provide reasonable assistance to the Customer with data protection impact assessments and, where required, prior consultation with the ICO, in each case relating to processing performed by Gradespace under this DPA. Gradespace maintains its own DPIAs for higher-risk processing in the Products, including CareMaSym and TargetGrade.
10. International Transfers
Gradespace is based in the United Kingdom. Where Customer personal data is transferred outside the UK (for example, to sub-processors operating in the United States or European Union), Gradespace ensures an appropriate transfer mechanism is in place, such as:
- UK adequacy regulations for the destination country;
- The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses;
- Any other valid mechanism under Data Protection Law.
Transfer details for each sub-processor are recorded in the Sub-processor Register.
11. Return and Deletion of Data
At the end of the services, Gradespace will, at the Customer's choice, return or delete all Customer personal data, and delete existing copies unless UK law requires continued storage. Unless otherwise agreed:
- The Customer may export its data before termination;
- Customer personal data is deleted from live systems within 30 days of termination;
- Backup copies are overwritten on the normal backup rotation cycle, after which deletion is complete.
12. Audit and Information
Gradespace will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, on reasonable notice and no more than once per year unless required by a supervisory authority or following a personal data breach.
Annex A — Description of Processing by Product
TargetGrade
- Purpose:
- Education services: class and assessment management, target and predicted grades, attendance, and learner progress for tuition providers and schools.
- Data subjects:
- Students (including children); parents/guardians; teachers/tutors; provider staff.
- Personal data:
- Student identity and enrolment details, attendance, assessment results, and target/predicted grades, as configured by the customer. Pilot deployments are configured to the minimum fields needed (name and school year plus assessment data).
- Notes:
- Involves children’s data. Processing is limited to the customer’s documented instructions. Grade predictions and study recommendations are assistive tools subject to teacher review — no solely automated decision with legal or similarly significant effect is made about a student, and student data is not used to train AI models. Optional features that expand processing (for example, exam proctoring) are enabled only on the customer’s instruction and documented in a supplementary assessment.
CareMaSym
- Purpose:
- Care management and rota services for care providers.
- Data subjects:
- Service users; carers and other staff.
- Personal data:
- Service-user records and care information, which may include special-category health and social-care data; staff records and rotas.
- Notes:
- May involve special-category data under Article 9 UK GDPR. Access is role-based so carers see only what they need, and access to sensitive records is audit-logged.
AccountGrade
- Purpose:
- Payroll and accounting services.
- Data subjects:
- Employees and staff of the customer.
- Personal data:
- Payroll and financial data, including bank details, tax and National Insurance identifiers.
- Notes:
- Payroll identifiers are treated as restricted information with least-privilege access.
BuildGrade
- Purpose:
- AI-assisted software-delivery planning: project blueprints, estimates, and client quote sharing.
- Data subjects:
- Customer users and project members; the customer’s clients where included in quotes and message threads.
- Personal data:
- Names, emails, project details, quote content, and client–builder messages where provided by the customer.
- Notes:
- Generally lower privacy risk; processed under the same security, retention, and deletion controls.
Duration of processing: the term of the applicable service agreement, plus the return/deletion period in section 11.
Contact
Questions about this DPA, or requests for a countersigned copy, should be sent to our Privacy & Data Protection Lead:
Email: privacy@thegradespace.com
Address: Gradespace LTD, 86-90 Paul Street, London EC2A 4NE, United Kingdom