Last updated: January 2026
This Data Processing Agreement (“DPA”) forms part of the Licence Agreement or other written agreement (the “Agreement”) between Education Companion Ltd (company number 16158976) whose registered office is at 21 Woodhill Road, Portishead, Bristol, BS20 7EU (“Education Companion”, “Processor”) and the relevant school, academy, trust or multi-academy trust entering into the Agreement (the “Controller”).
This DPA reflects the requirements of UK data-protection law, including the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
In this DPA, the following terms shall have the meanings set out below. Terms not defined in this table shall have the meanings given to them in the UK GDPR.
Agreement
The Licence Agreement or other written agreement between the Controller and Education Companion governing the provision of the Services.
Controller
The school, academy, trust or multi-academy trust that determines the purposes and means of the Processing of Personal Data.
Data Protection Law
All applicable laws and regulations relating to the processing of Personal Data, including the UK GDPR and the Data Protection Act 2018.
Data Subject
An identified or identifiable natural person to whom Personal Data relates.
DPA
This Data Processing Agreement, including Schedule 1.
International Transfer
A transfer of Personal Data to a country outside the United Kingdom.
Personal Data
Any information relating to an identified or identifiable natural person processed under this DPA.
Personal Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
Processing
Any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, storage, use, disclosure or deletion.
Processor
Education Companion Ltd, which processes Personal Data on behalf of the Controller.
Services
The complaint-management platform and related services provided by Education Companion under the Agreement.
Sub-processor
Any third party appointed by Education Companion to process Personal Data on behalf of the Controller in connection with the Services.
Supervisory Authority
The Information Commissioner’s Office or any other competent data-protection authority.
UK GDPR
The United Kingdom General Data Protection Regulation, as amended and incorporated into UK law.
This DPA shall be interpreted consistently with the Agreement. In the event of a conflict, this DPA shall prevail in respect of data-protection matters.
2.1 The Controller is the Data Controller of the Personal Data processed under this DPA.
2.2 Education Companion acts solely as a Data Processor and shall process Personal Data only on the documented instructions of the Controller, unless required to do otherwise by applicable law.
2.3 Nothing in this DPA shall be construed as creating a joint-controller relationship between the parties.
3.1 Education Companion shall process Personal Data solely for the purpose of providing the Services and performing its obligations under the Agreement.
3.2 The nature, subject matter, duration, categories of Personal Data and categories of Data Subjects are set out in Schedule 1.
3.3 Education Companion shall not process Personal Data for its own purposes, including marketing, profiling or automated decision-making unless with the written consent of the Data Controller.
Education Companion shall:
4.1 Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or international organisation.
4.2 Ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations.
4.3 Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including measures relating to access control, encryption, audit logging and secure hosting environments.
4.4 Not permit access to Personal Data by Education Companion personnel except where necessary for support, onboarding, troubleshooting, system integrity, safeguarding, or security purposes, and ensure that any such access is limited, logged and purpose-bound.
4.5 Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller’s obligations to respond to requests for exercising Data Subject rights.
4.6 Assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR, including in relation to security, breach notification and data-protection impact assessments.
5.1 The Controller authorises Education Companion to appoint Sub-processors to process Personal Data, provided that Education Companion enters into a written agreement with each Sub-processor imposing data-protection obligations substantially equivalent to those set out in this DPA.
5.2 A current list of authorised Sub-processors is maintained at:
https://www.educationcompanion.com/legal/subprocessors
5.3 Education Companion shall inform the Controller of any intended changes to its Sub-processors by updating the above list. The Controller may object to such changes on reasonable data-protection grounds.
6.1 Personal Data may be processed or accessed outside the United Kingdom where required for the provision of the Services.
6.2 Where Personal Data is transferred outside the United Kingdom, Education Companion shall ensure that appropriate safeguards are in place in accordance with UK data-protection law, including the use of the UK International Data Transfer Addendum, standard contractual clauses, or adequacy regulations, as applicable.
7.1 Education Companion shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.
7.2 Such notification shall include all information reasonably required by the Controller to comply with its obligations under UK data-protection law.
8.1 Education Companion shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA.
8.2 The Controller may audit Education Companion’s compliance with this DPA on reasonable notice, subject to confidentiality and security requirements and provided such audit does not unreasonably disrupt Education Companion’s business.
9.1 Upon termination or expiry of the Agreement, Education Companion shall, at the documented instruction of the Controller, delete or return all Personal Data (including copies), unless retention is required by applicable law.
9.2 Education Companion shall confirm completion of deletion or return upon request.
10.1 Each party’s liability arising out of or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement.
10.2 Nothing in this DPA limits liability where such limitation is not permitted under applicable law.
This DPA shall be governed by and construed in accordance with the laws of England and Wales, and the courts of England and Wales shall have exclusive jurisdiction.
Management of complaints, concerns and related communications within schools and trusts.
For the duration of the Agreement, unless otherwise instructed by the Controller.
May be included where uploaded or entered by the Controller in the context of complaint handling.
END OF DATA PROCESSING AGREEMENT
Companion-DPA | V1.0 | 2026
Please reach out to support@educationcompanion.com for the latest data processing agreement