PipkinPlay with Pipkin

Data processing agreement for schools

Version: dpa-v1

1. Who this agreement is between

A member of school staff accepts this agreement for the school when they first sign in and tick that they teach at the school. We record the version accepted and the date and time.

Authority. The member of staff who accepts confirms that the school has authorised them to enter into this agreement on its behalf. On that basis this agreement binds the school from the moment it is accepted. It is in writing in electronic form, as Article 28(9) of the UK GDPR allows.

If the school tells us that a member of staff accepted without its authority, we will follow the school's instructions about that teacher's classes: keep them under this agreement, or delete them under section 9.

Signing a copy. The school may also sign a copy of this agreement, and we will countersign it. Ask at privacy@hellopipkin.com. A signed copy has the same terms as the version accepted online; it does not change them.

For the pilot, we ask the school to sign. Before the pilot class starts, we will ask the school's business manager, data protection officer (DPO) or headteacher to sign a copy. This is a recommendation, not a condition of the online acceptance. It means the person who looks after the school's contracts and data protection knows this agreement exists, can add Pipkin to the school's records and DPIA, and puts beyond doubt that whoever accepted could do so for the school.

This agreement is made under Article 28 of the UK GDPR. Words such as "personal data", "controller", "processor" and "personal data breach" mean what they mean in the UK GDPR.

Schools outside England. The teacher tells us the school's country when they first sign in. The schedule for that country, at the end of this agreement, is part of this agreement for that school. Where the schedule and the rest of this agreement differ, the schedule wins for that school. A school is only ever bound by its own country's schedule.

2. What the processing is

Subject matter. Pipkin's class feature. A parent or carer joins their child's Pipkin profile to a class with the class code. With the school's teacher, the class can see how much practice each child does each week.

Duration. From the first time the school's teacher accepts this agreement until the class data is deleted under section 9.

Nature and purpose. We store, show and delete class data so the school's teacher can:

We do not use class data for anything else. We do not use it for advertising, profiling, research or selling.

Data subjects. Children aged 4 to 11 in the school's classes.

Personal data. For each child in a class:

We never hold a child's name, email, age, date of birth, year group, sex, photo, answers, typed text, how long anything took, location, device id or IP address.

3. The school's instructions

We process class data only on the school's documented instructions. This agreement, and what the school's teacher does in the teacher console (letting children in, setting initials and teams, turning the board on, downloading, deleting), are those instructions.

If UK law requires us to process class data in another way, we will tell the school first, unless the law forbids it.

If we think an instruction breaks data protection law, we will tell the school straight away.

4. Confidentiality

Only people who need to run Pipkin can reach class data. Each of them is bound to keep it confidential.

5. Security

We protect class data with these measures:

6. Sub-processors

The school agrees that we use Cloudflare, Inc. to host Pipkin, run its code, store the database (in the EU) and send sign-in and reminder emails. Cloudflare processes data for us under Cloudflare's customer data processing addendum.

Cloudflare's addendum binds Cloudflare, for class data, to duties of the same kind as this agreement puts on us. In particular, Cloudflare must:

This is how we meet Article 28(4) of the UK GDPR. Where Cloudflare's terms work differently from ours (for example, Cloudflare answers audits mainly with independent reports, not visits), we pass on to the school what Cloudflare gives us. We will tell the school promptly of any new sub-processor Cloudflare notifies to us that may process class data.

We will tell the school at least 30 days before we add or replace a sub-processor, by email to the teacher who accepted this agreement. The school may object in that time. If we cannot meet the objection, the school may delete its classes, which ends this agreement.

We remain fully responsible to the school for what our sub-processors do, as if we had done it ourselves.

7. Helping with rights requests

Parents and children have rights over their data, such as to see it or have it deleted. The school decides these requests.

We will also help the school with security, with data protection impact assessments and with any consultation with the Information Commissioner's Office (ICO), as far as we can given what we hold.

8. Personal data breaches

If we become aware of a personal data breach affecting class data, we will tell the school without undue delay, and we aim to do so within 24 hours. We will tell the school what happened, what data and how many children may be affected, what we have done and what we suggest. We will add details as we learn them.

The school decides whether to report the breach to the ICO, which it must do within 72 hours of becoming aware of it where it is reportable.

9. Deleting class data

Deletion removes the rows from the database. Our database provider keeps a restore point for up to 30 days, so deleted data can only be brought back within that time, and only by us restoring the whole database after a fault. Every deletion also keeps, for 30 days, a record that it happened: the random id of each deleted class and of each deleted child's class membership (never a name or nickname), and a scrambled form of a deleted teacher's email address. Every class code that stops working (changed by the teacher, or its class deleted) is kept for 30 days in scrambled form only, never the code itself, and a join with it is refused. If we ever restore, we use these records to delete again every class, every child's class data and every teacher account that was deleted after the restore point, and to give a new code to any class the restore handed an old code back, so an old code never works again. After 30 days the data is gone for good.

The school can download its class data before deletion. We do not keep a copy.

10. Information and audits

We will give the school the information it needs to show that this agreement is being kept, including this agreement, our data protection impact assessment and a description of our security measures. We will allow and help with audits, including inspections, by the school or an auditor it appoints, as set out below.

First, a written questionnaire. The school (or its DPO) may send us written questions about how we keep this agreement. We will answer fully and honestly within 30 days, free of charge. We expect this to be enough for most schools.

An audit only where reasonably needed. The school may audit us, on site or remotely, only where:

How often. No more than once in any 12 months, except after a personal data breach affecting the school's class data or where a regulator requires it.

Notice and conduct. The school gives us at least 30 days' written notice, and less only after such a breach. The audit takes place in normal working hours and is limited to class data and how we handle it. The auditor must keep what they learn confidential, must not be a competitor of Pipkin, and must not see other schools' data. Cloudflare's systems are covered by Cloudflare's own audit reports, which we pass on as far as Cloudflare's terms allow; they cannot be inspected through us.

Cost. The school pays for its own audit, including its auditor. If the audit finds that we have materially broken this agreement, we pay the school's reasonable audit costs and put the problem right at our own cost.

Nothing in this section limits the ICO's own powers.

11. Where data is held

Class data is stored in Cloudflare's EU jurisdiction. Cloudflare's network also carries each request through its data centre nearest the user, which is usually in the UK.

Storage in the EU. UK law approves transfers of personal data to the countries of the EU and EEA. They are treated as approved by regulations under Article 45A of the UK GDPR (Data Protection Act 2018, Schedule 21, paragraphs 4 and 5, as amended by the Data (Use and Access) Act 2025 from 5 February 2026). Before that date this was called "adequacy", and many documents still use that word. So storage in the EU needs no further safeguard.

Access from outside the UK and EU. Cloudflare, Inc. is a US company. Its staff or systems outside the UK and EU may sometimes reach class data, for example to run, support or secure its network. Where that is a restricted transfer under the UK GDPR, Cloudflare's addendum (clause 6.2) applies the European Commission's standard contractual clauses as amended by the ICO's International Data Transfer Addendum (the "UK Addendum"). Those are appropriate safeguards under Article 46 of the UK GDPR.

We will not move class data to any other country without first telling the school, giving it the chance to object as in section 6, and putting a safeguard the UK GDPR accepts in place.

12. Liability

Each of us is responsible for keeping the data protection law that applies to it. Nothing in this agreement, or in the terms for teachers, relieves either of us of our own duties and liabilities under the UK GDPR and the Data Protection Act 2018.

What is never limited. Nothing in this agreement limits:

Fines. Each of us bears any fine the ICO imposes on it. Neither of us asks the other to pay its fines.

Other loss. Apart from what is never limited, neither of us is liable to the other under this agreement for indirect or consequential loss, or for loss of profit, revenue or goodwill. Our total liability to the school for any other loss caused by our breach of this agreement (for example, the school's reasonable costs of dealing with a breach we caused: writing to families, staff time) is £5,000 in any 12 months.

The £100 limit in the terms for teachers does not apply to this agreement.

13. Law and disputes

Unless the schedule for the school's country says otherwise, this agreement, and any dispute about it, is governed by the law of England and Wales. Disputes are handled as the terms for teachers set out (raise it with us first; then the courts of England and Wales). This does not affect anyone's right to complain to the ICO.

14. Ending this agreement

This agreement ends when all the school's class data has been deleted, whether by the teacher, by the school's request or under section 9. Sections 8 to 13 continue to apply to anything that happened before then.

15. Contact

privacy@hellopipkin.com

The Build Brain Ltd, 10 Buzzard Close, Verwood, Dorset, BH31 7DH

ICO registration: applied for in October 2026, fee paid. We will add the registration number here when the ICO issues it.

Regional schedules

Each schedule below applies only to a school in that country. Section 1 explains how.

Schedule A: England, Wales, Scotland and Northern Ireland

The rest of this agreement applies as written. In addition:

Schedule B: Ireland, and other countries of the EU and EEA

Schedule C: United States

Schedule D: Australia

Schedule E: New Zealand

Schedule F: Somewhere else