Data Processing Agreement
Last updated: 28 July 2026 · Version 2026-07-28
Article 28 UK GDPR · Feedback Flows Ltd (Company No. 16948031)
1. Parties and roles
Processor: Feedback Flows Ltd, C/O Vantage Accounting, 1 Cedar Office Park, Cobham Road, Wimborne, United Kingdom, BH21 7SB (“Processor”).
Controller: the organisation (or sole trader teacher) that determines the purposes and means
of processing student/learner personal data uploaded to the Service.
For account-holder data about teachers/staff using the Service in their own right, Feedback Flows Ltd acts as an independent controller as described in the Privacy Policy. This DPA governs Processor activities relating to Controller Personal Data (primarily student/learner data and related assessment content).
2. Subject matter and duration
The Processor provides AI-assisted marking, feedback, integrity analysis and related education tools. Processing continues for the term of the Controller’s use of the Service and until deletion or return of Controller Personal Data in accordance with this DPA.
3. Nature and purpose of processing
Hosting, storage, retrieval, organisation, analysis (including AI inference via approved sub-processors), transmission, display and deletion of Controller Personal Data as necessary to deliver the features the Controller configures and invokes in the Service. This includes, where purchased, marking-as-a-service performed by authorised Feedback Flows staff on the Controller’s instructions.
4. Types of personal data and data subjects
Data subjects may include:
- Students and learners, including children
- Students who submit work via a private assignment upload link (without creating a Feedback Flows account)
- Teachers and staff (where their data appears in student records or audit contexts as instructed)
Categories of data may include names, contact details, dates of birth, demographic flags (e.g. gender, EAL), educational records, submitted work, marks, feedback, transcripts, detection scores and related metadata. Special category data should not be uploaded unless the Controller has a lawful basis and has instructed the Processor via the Service features; the Controller must minimise such data.
5. Processor obligations (Article 28(3))
- Instructions: The Processor shall process Controller Personal Data only on documented instructions from the Controller, including regarding transfers, unless required by UK law.
- Confidentiality: Persons authorised to process the data are bound by confidentiality.
- Security: The Processor implements appropriate technical and organisational measures as summarised in Annex II.
- Sub-processors: The Controller authorises the sub-processors listed in Annex III / the Sub-processors page. The Processor shall impose equivalent data protection obligations and remain liable for sub-processor performance. The Processor will update the public list for changes; the Controller may object on reasonable data-protection grounds within 14 days of notice of a material new sub-processor, in which case the parties will discuss alternatives in good faith (which may include suspending the affected feature).
- Assistance: Taking into account the nature of processing, the Processor shall assist the Controller with data subject requests, DPIAs and consultations with the ICO, insofar as possible via product features and reasonable cooperation.
- Breach notification: The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller Personal Data, and provide information reasonably available to assist the Controller’s obligations.
- Deletion / return: On termination of the Service (or earlier written request), the Processor shall delete or return Controller Personal Data (except where UK law requires storage), subject to residual backup retention windows described in the Privacy Policy.
- Audits: The Processor shall make available information necessary to demonstrate compliance and allow audits (including inspections) by the Controller or an agreed auditor, on reasonable notice, during business hours, no more than once per year unless a breach or regulator request justifies more frequent review. Remote questionnaires and existing compliance documentation will be preferred where proportionate.
6. Controller obligations
The Controller warrants that it has a lawful basis (and any required transparency notices / parental information) to upload Controller Personal Data, will not instruct unlawful processing, and will use the Service in accordance with the Terms and Acceptable Use Policy.
7. International transfers
Where Controller Personal Data is transferred outside the UK (notably to OpenAI in the United States for AI features), the Processor shall ensure appropriate safeguards (UK IDTA / UK Addendum to EU SCCs or other lawful mechanism) as described for each sub-processor.
8. Liability
Liability under this DPA is subject to the limitations in the Terms of Use, except to the extent liability cannot be limited under applicable data protection law.
Annex I — Details of processing
- Subject matter: Provision of Feedback Flows education SaaS, including optional marking-as-a-service by Processor staff
- Duration: Term of Service + deletion/return period
- Nature/purpose: As section 3
- Data subjects: Students/learners (including children and those who upload via assignment links without accounts); staff as relevant
- Personal data: As section 4
Annex II — Technical and organisational measures
- UK hosting (AWS Lightsail, eu-west-2) for application and PostgreSQL database
- Celery/Redis task broker and result backend on the Processor’s own UK application server
- TLS in transit; HSTS in production; Secure / HttpOnly / SameSite session cookies
- Password hashing (pbkdf2:sha256); CSRF protection; login and signup rate limiting
- Cloudflare Turnstile on registration; optional idle auto-logout; session revocation
- Zip-slip protection on archive uploads; upload size limits
- Administrator access limited to named platform admins; support impersonation is time-limited (30-minute auto-expiry) and logged (admin identity, target user, IP, user agent, start/end)
- Staff performing marking-as-a-service are bound by confidentiality; client-school student records are segregated from ordinary customer tenant data and accessible only to platform administrators
- Enterprise/team audit logs; optional AI student-name anonymisation controls
- Periodic cleanup of assignment upload files (30 days), temp video files (~72 hours) and activity trail (90 days)
Note: MFA is not currently offered. Backup files are compressed; they are not separately encrypted by our backup scripts. Controllers should factor this into their own risk assessments.
Annex III — Sub-processors
See the live list at https://feedbackflows.org/sub-processors, which is incorporated by reference.
Contact
Processor contact for DPA matters: admin@feedbackflows.org.