Data processing agreement for schools
Version: dpa-v1
1. Who this agreement is between
- The school (the controller): the school a teacher names when they first sign in to Pipkin and accept this agreement for it.
- Us (the processor): The Build Brain Ltd, 10 Buzzard Close, Verwood, Dorset, BH31 7DH, company number 15035752, which runs Pipkin.
A member of school staff accepts this agreement for the school when they first sign in and tick that they teach at the school. We record the version accepted and the date and time.
Authority. The member of staff who accepts confirms that the school has authorised them to enter into this agreement on its behalf. On that basis this agreement binds the school from the moment it is accepted. It is in writing in electronic form, as Article 28(9) of the UK GDPR allows.
If the school tells us that a member of staff accepted without its authority, we will follow the school's instructions about that teacher's classes: keep them under this agreement, or delete them under section 9.
Signing a copy. The school may also sign a copy of this agreement, and we will countersign it. Ask at privacy@hellopipkin.com. A signed copy has the same terms as the version accepted online; it does not change them.
For the pilot, we ask the school to sign. Before the pilot class starts, we will ask the school's business manager, data protection officer (DPO) or headteacher to sign a copy. This is a recommendation, not a condition of the online acceptance. It means the person who looks after the school's contracts and data protection knows this agreement exists, can add Pipkin to the school's records and DPIA, and puts beyond doubt that whoever accepted could do so for the school.
This agreement is made under Article 28 of the UK GDPR. Words such as "personal data", "controller", "processor" and "personal data breach" mean what they mean in the UK GDPR.
Schools outside England. The teacher tells us the school's country when they first sign in. The schedule for that country, at the end of this agreement, is part of this agreement for that school. Where the schedule and the rest of this agreement differ, the schedule wins for that school. A school is only ever bound by its own country's schedule.
2. What the processing is
Subject matter. Pipkin's class feature. A parent or carer joins their child's Pipkin profile to a class with the class code. With the school's teacher, the class can see how much practice each child does each week.
Duration. From the first time the school's teacher accepts this agreement until the class data is deleted under section 9.
Nature and purpose. We store, show and delete class data so the school's teacher can:
- let children into a class, or say no;
- see each child's weekly practice counts;
- show a weekly class board, if the teacher turns it on;
- download the class as a spreadsheet.
We do not use class data for anything else. We do not use it for advertising, profiling, research or selling.
Data subjects. Children aged 4 to 11 in the school's classes.
Personal data. For each child in a class:
- a class nickname, made of two words from fixed lists (for example "Brave Otter");
- the animal picture the child chose on their device;
- whether they are waiting or in the class, the date they asked to join, and the date they were let in;
- the version of the wording the grown-up agreed to when joining (
join-v1), and its date; - their board choice ("Show me" or "Just me"), and whether the teacher set "Just me" for them;
- a team, if the teacher uses teams;
- up to 3 initials, if the teacher adds them (only the teacher sees these);
- each week: how many puzzles they finished, Seeds they earned and times-tables facts they learned, with a note if the numbers were too big and were capped;
- the last week their device sent counts;
- for each device linked to the child (at most 2): a random id, a one-way hash of the device's secret key, and the date it was linked.
We never hold a child's name, email, age, date of birth, year group, sex, photo, answers, typed text, how long anything took, location, device id or IP address.
3. The school's instructions
We process class data only on the school's documented instructions. This agreement, and what the school's teacher does in the teacher console (letting children in, setting initials and teams, turning the board on, downloading, deleting), are those instructions.
If UK law requires us to process class data in another way, we will tell the school first, unless the law forbids it.
If we think an instruction breaks data protection law, we will tell the school straight away.
4. Confidentiality
Only people who need to run Pipkin can reach class data. Each of them is bound to keep it confidential.
5. Security
We protect class data with these measures:
- Class data is stored in one Cloudflare D1 database created in Cloudflare's EU jurisdiction.
- Every connection uses HTTPS.
- Sign-in and device keys are 32 random bytes. We store only their one-way hashes.
- Teacher email addresses are encrypted (AES-GCM). We look them up by a keyed hash.
- The teacher's session cookie is secure, HTTP-only and same-site only. Changes from the console must come from Pipkin's own address.
- A teacher can only see and change their own classes. Asking for another teacher's class gets the same answer as a class that does not exist.
- Every request is checked: its size, its exact fields and every value. A child's device never receives the initials a teacher adds, the teacher's email, or any other child's id or details. It does receive its own class membership's id and its class's id: random identifiers with no personal data in them.
- Class codes are 8 characters (about 282 billion possible codes). Guessing is limited per address, per network and across the whole service, and the teacher must let every child in.
- Requests are rate limited.
- Our logs hold no request contents, emails, keys, codes or IP addresses.
- A record of teacher actions (such as letting a child in or deleting a class) is kept for up to 13 months. It names the class, or the random id of the child's class membership, never a child's name or nickname.
6. Sub-processors
The school agrees that we use Cloudflare, Inc. to host Pipkin, run its code, store the database (in the EU) and send sign-in and reminder emails. Cloudflare processes data for us under Cloudflare's customer data processing addendum.
Cloudflare's addendum binds Cloudflare, for class data, to duties of the same kind as this agreement puts on us. In particular, Cloudflare must:
- process the data only to provide its services and on our written instructions;
- make sure that only authorised people can reach it, each bound to keep it confidential;
- protect it with the security measures listed in the addendum;
- tell us without undue delay of any personal data breach, and help us with it;
- help us with rights requests, data protection impact assessments and consultation with the ICO;
- delete or return the data when its service ends;
- show it is keeping its addendum, mainly through independent audit reports;
- use its own sub-processors only under written terms no less protective than its addendum, and give at least 30 days' notice of a new one.
This is how we meet Article 28(4) of the UK GDPR. Where Cloudflare's terms work differently from ours (for example, Cloudflare answers audits mainly with independent reports, not visits), we pass on to the school what Cloudflare gives us. We will tell the school promptly of any new sub-processor Cloudflare notifies to us that may process class data.
We will tell the school at least 30 days before we add or replace a sub-processor, by email to the teacher who accepted this agreement. The school may object in that time. If we cannot meet the objection, the school may delete its classes, which ends this agreement.
We remain fully responsible to the school for what our sub-processors do, as if we had done it ourselves.
7. Helping with rights requests
Parents and children have rights over their data, such as to see it or have it deleted. The school decides these requests.
- A grown-up can leave a class at any time in Pipkin's settings. Leaving deletes the child's class data at once.
- The teacher can download, remove or delete class data in the console at any time.
- If a request reaches us, we pass it to the school without delay and do not answer it ourselves.
- If the school needs our help with a request, we will give it within 10 working days.
We will also help the school with security, with data protection impact assessments and with any consultation with the Information Commissioner's Office (ICO), as far as we can given what we hold.
8. Personal data breaches
If we become aware of a personal data breach affecting class data, we will tell the school without undue delay, and we aim to do so within 24 hours. We will tell the school what happened, what data and how many children may be affected, what we have done and what we suggest. We will add details as we learn them.
The school decides whether to report the breach to the ICO, which it must do within 72 hours of becoming aware of it where it is reportable.
9. Deleting class data
- When a grown-up leaves a class, or the teacher removes a child, that child's class data is deleted at once.
- Weekly counts are deleted when they are 20 weeks old.
- A child whose device has sent nothing for 10 weeks is removed from the class.
- A request to join that the teacher has not answered is deleted after 14 days.
- A class is deleted 30 days after its end date (the next 31 August, unless the teacher keeps it for another school year). The teacher is emailed 14 days before.
- If the teacher deletes the class or their account, the class data is deleted at once.
- If the teacher does not sign in for 13 months, their account and classes are deleted, after a warning email 30 days before.
Deletion removes the rows from the database. Our database provider keeps a restore point for up to 30 days, so deleted data can only be brought back within that time, and only by us restoring the whole database after a fault. Every deletion also keeps, for 30 days, a record that it happened: the random id of each deleted class and of each deleted child's class membership (never a name or nickname), and a scrambled form of a deleted teacher's email address. Every class code that stops working (changed by the teacher, or its class deleted) is kept for 30 days in scrambled form only, never the code itself, and a join with it is refused. If we ever restore, we use these records to delete again every class, every child's class data and every teacher account that was deleted after the restore point, and to give a new code to any class the restore handed an old code back, so an old code never works again. After 30 days the data is gone for good.
The school can download its class data before deletion. We do not keep a copy.
10. Information and audits
We will give the school the information it needs to show that this agreement is being kept, including this agreement, our data protection impact assessment and a description of our security measures. We will allow and help with audits, including inspections, by the school or an auditor it appoints, as set out below.
First, a written questionnaire. The school (or its DPO) may send us written questions about how we keep this agreement. We will answer fully and honestly within 30 days, free of charge. We expect this to be enough for most schools.
An audit only where reasonably needed. The school may audit us, on site or remotely, only where:
- our answers do not reasonably show that we are keeping this agreement;
- there has been a personal data breach affecting the school's class data; or
- the ICO or another regulator requires it.
How often. No more than once in any 12 months, except after a personal data breach affecting the school's class data or where a regulator requires it.
Notice and conduct. The school gives us at least 30 days' written notice, and less only after such a breach. The audit takes place in normal working hours and is limited to class data and how we handle it. The auditor must keep what they learn confidential, must not be a competitor of Pipkin, and must not see other schools' data. Cloudflare's systems are covered by Cloudflare's own audit reports, which we pass on as far as Cloudflare's terms allow; they cannot be inspected through us.
Cost. The school pays for its own audit, including its auditor. If the audit finds that we have materially broken this agreement, we pay the school's reasonable audit costs and put the problem right at our own cost.
Nothing in this section limits the ICO's own powers.
11. Where data is held
Class data is stored in Cloudflare's EU jurisdiction. Cloudflare's network also carries each request through its data centre nearest the user, which is usually in the UK.
Storage in the EU. UK law approves transfers of personal data to the countries of the EU and EEA. They are treated as approved by regulations under Article 45A of the UK GDPR (Data Protection Act 2018, Schedule 21, paragraphs 4 and 5, as amended by the Data (Use and Access) Act 2025 from 5 February 2026). Before that date this was called "adequacy", and many documents still use that word. So storage in the EU needs no further safeguard.
Access from outside the UK and EU. Cloudflare, Inc. is a US company. Its staff or systems outside the UK and EU may sometimes reach class data, for example to run, support or secure its network. Where that is a restricted transfer under the UK GDPR, Cloudflare's addendum (clause 6.2) applies the European Commission's standard contractual clauses as amended by the ICO's International Data Transfer Addendum (the "UK Addendum"). Those are appropriate safeguards under Article 46 of the UK GDPR.
We will not move class data to any other country without first telling the school, giving it the chance to object as in section 6, and putting a safeguard the UK GDPR accepts in place.
12. Liability
Each of us is responsible for keeping the data protection law that applies to it. Nothing in this agreement, or in the terms for teachers, relieves either of us of our own duties and liabilities under the UK GDPR and the Data Protection Act 2018.
What is never limited. Nothing in this agreement limits:
- any right a child, parent or carer has to compensation under Article 82 of the UK GDPR, or the ICO's powers, including its fines;
- the school's right to recover from us the part of any compensation it has paid to a child, parent or carer that our breach of this agreement, or of our duties as a processor, caused (Article 82(5));
- liability for death or personal injury caused by negligence, for fraud, or for anything else the law does not allow us to limit.
Fines. Each of us bears any fine the ICO imposes on it. Neither of us asks the other to pay its fines.
Other loss. Apart from what is never limited, neither of us is liable to the other under this agreement for indirect or consequential loss, or for loss of profit, revenue or goodwill. Our total liability to the school for any other loss caused by our breach of this agreement (for example, the school's reasonable costs of dealing with a breach we caused: writing to families, staff time) is £5,000 in any 12 months.
The £100 limit in the terms for teachers does not apply to this agreement.
13. Law and disputes
Unless the schedule for the school's country says otherwise, this agreement, and any dispute about it, is governed by the law of England and Wales. Disputes are handled as the terms for teachers set out (raise it with us first; then the courts of England and Wales). This does not affect anyone's right to complain to the ICO.
14. Ending this agreement
This agreement ends when all the school's class data has been deleted, whether by the teacher, by the school's request or under section 9. Sections 8 to 13 continue to apply to anything that happened before then.
15. Contact
privacy@hellopipkin.com
The Build Brain Ltd, 10 Buzzard Close, Verwood, Dorset, BH31 7DH
ICO registration: applied for in October 2026, fee paid. We will add the registration number here when the ICO issues it.
Regional schedules
Each schedule below applies only to a school in that country. Section 1 explains how.
Schedule A: England, Wales, Scotland and Northern Ireland
The rest of this agreement applies as written. In addition:
- Who "the school" is. It means whoever is the controller for the school's pupils' data: for example the governing body, the academy trust or the proprietor in England and Wales; the council (as education authority) or the independent school's proprietor in Scotland; the Board of Governors, the Education Authority or the proprietor in Northern Ireland. If the teacher named the school but the council or trust is the controller, this agreement is with the council or trust.
- Scotland and Northern Ireland. If the school asks, this agreement is governed by the law of Scotland or of Northern Ireland, and that country's courts decide disputes, instead of England and Wales.
Schedule B: Ireland, and other countries of the EU and EEA
- Which law. In this agreement, "the UK GDPR" means the EU General Data Protection Regulation (Regulation (EU) 2016/679) and, in Ireland, the Data Protection Act 2018. "The ICO" means the Data Protection Commission in Ireland, or the school's own supervisory authority in another EU or EEA country. "UK law" means EU law or the law of the school's country. This agreement is the contract Article 28(3) of the GDPR requires.
- Breaches. We tell the school as section 8 says, so that it can report to its supervisory authority within 72 hours where that is needed.
- Where data is held. Class data is stored in Cloudflare's EU jurisdiction, so it stays in the EU. We are in the United Kingdom. The European Commission has decided that the UK protects personal data adequately (its renewed decision of December 2025), so data can come to us without a further safeguard. Where Cloudflare, Inc. reaches data from outside the EU, the EU standard contractual clauses in Cloudflare's addendum apply.
- Our representative in the EU. Our representative under Article 27 of the GDPR, and our legal representative under Article 13 of the EU Digital Services Act, is named here before any school in the EU or EEA can set up classes. A school, parent or regulator may contact them instead of us.
- Reporting content. Anyone can tell us about class names or display names they think are illegal or break our rules, as Keeping classes safe explains. When we change or remove something a teacher typed, we tell the teacher what we did, why, and how to challenge it.
- Law and disputes. This agreement is governed by the law of Ireland, or of the EU or EEA country where the school is if the school asks, and the courts of that country decide disputes.
Schedule C: United States
- Which law. This schedule covers the Children's Online Privacy Protection Act (COPPA) and the FTC's COPPA Rule, the Family Educational Rights and Privacy Act (FERPA), and state student privacy laws. Where the rest of this agreement says "the UK GDPR" or "the ICO", read it as these laws and the regulator that enforces them.
- COPPA: the school authorises for parents. Pipkin collects information from children in the class only for the use and benefit of the school, and for no other commercial purpose. On that basis the school agrees, in place of each child's parent, to that collection, as the FTC's guidance for schools allows. The school confirms that the decision to use Pipkin was made by the school or district under its own policy for online services, not by a teacher acting alone. This agreement, the privacy notice for classes (its section for US schools) and the teacher console are our notice to the school of what we collect, how we use it and what we disclose.
- Parents' rights. A parent can see in Pipkin exactly what is shared, and can leave the class at any time, which deletes their child's class data at once. A parent can also ask the school, or us, to review or delete it; we pass requests to the school (section 7).
- FERPA: we act as a school official. We provide a service the school would otherwise provide itself. The school controls how class data is used and kept, through this agreement and the teacher console. We use class data only for the purposes in section 2, and we do not disclose it to anyone except Cloudflare as section 6 allows, or as the school directs. The school decides whether to include us in its annual notice of who counts as a school official. If a parent asks the school to see their child's records, we help within 10 working days.
- State student privacy laws. We never use class data for targeted advertising, never build a profile of a child except for the school's purpose, never sell it, keep it secure as section 5 says, and delete it when the school asks. Class data belongs to the school and stays under its control. When the school asks at the end of its use of Pipkin, we confirm deletion in writing.
- Breaches. We tell the school as section 8 says, and in any case within the shortest time any state law that applies to the school sets. We help the school tell parents where the law requires it.
- A state agreement instead. If the school or district prefers, we will sign the Student Data Privacy Consortium's National Data Privacy Agreement, or its state's version, together with any form its state law requires (for example New York's Parents' Bill of Rights and data security plan). Once signed, that agreement wins where it differs from this one.
- Where data is held. Class data is stored in the EU, not the United States. If a law or policy that applies to the school requires storage in the United States, the school should not set up classes; please tell us.
- Law and disputes. This agreement is governed by the law of the state where the school is, and the courts of that state decide disputes. The limit on our liability in section 12 is the US dollar amount equal to £5,000 on the day the claim is made.
Schedule D: Australia
- Which law. The school is bound by the Privacy Act 1988 (Cth) or by its own state or territory's privacy law. In this agreement, "the UK GDPR" means the law that binds the school, and "the ICO" means the Office of the Australian Information Commissioner or the school's state or territory privacy regulator.
- We keep the same standards. Even where the Privacy Act's small business exemption would let us off, we handle class data as if we were bound by the Australian Privacy Principles, and by the school's state or territory privacy principles where its law asks its contracted service providers to be bound by them.
- Breaches. We tell the school as section 8 says, so it can assess the breach and notify under the Notifiable Data Breaches scheme, or its state's scheme, where needed.
- Where data is held. Class data is held outside Australia, in the EU. We hold it only for the school and under its control. Our privacy notice for classes tells families where it is kept.
- Law and disputes. England and Wales, as section 13 says, unless the school asks for the law of its own state or territory; then that law applies and its courts decide disputes.
Schedule E: New Zealand
- Which law. The school is bound by the Privacy Act 2020. In this agreement, "the UK GDPR" means that Act and "the ICO" means the Privacy Commissioner.
- We hold class data for the school. We hold it only as the school's agent, for the school's purposes and under its control, as section 11 of the Privacy Act 2020 describes. We do not use or disclose it for our own purposes.
- Breaches. We tell the school as section 8 says, so it can notify the Privacy Commissioner and affected people as soon as practicable where a breach is notifiable.
- Where data is held. Class data is held outside New Zealand, in the EU, by us for the school.
- Law and disputes. England and Wales, as section 13 says, unless the school asks for New Zealand law; then New Zealand law applies and its courts decide disputes.
Schedule F: Somewhere else
- A school in the EU or EEA uses Schedule B, not this one.
- For every other country, the rest of this agreement applies as written. The school confirms that the law that binds it lets it use a service run from the United Kingdom that stores class data in the EU, on these terms. If its law asks for something more, the school tells us before it sets up classes, and we will say whether we can add it.
- Where we cannot offer classes. We do not offer classes where the law requires pupils' data to be stored in that country, or where UK sanctions stop us.