Version 1.1 · 9 June 2026

Data Processing Agreement

This agreement governs how IntelComms Ltd processes personal data on behalf of schools using the IntelComms platform, in compliance with UK GDPR Article 28.

Parties Background Definitions Data processed Processor obligations Controller obligations Security Sub-processors Data subject rights Data breaches International transfers Audit & compliance Termination DPIA Governing law Schedule Signatures

Parties to this Agreement

Data Processor

IntelComms Ltd

Company number: [To be confirmed]

Registered in England and Wales

Email: contact@intelcomms.co.uk

Website: intelcomms.co.uk

Data Controller

[School / Academy / MAT name]

DfE number: [__________]

[Registered address]

Email: [__________]

Data protection contact: [__________]

Together referred to as "the parties". This Data Processing Agreement ("DPA") supplements and forms part of the IntelComms Terms of Service between the parties.

Background

The Controller has engaged the Processor to provide the IntelComms AI WhatsApp communication service, which involves the processing of personal data relating to parents, guardians, and pupils on behalf of the Controller.

The parties enter into this DPA to ensure that such processing is carried out in compliance with UK GDPR, the Data Protection Act 2018, and all other applicable data protection legislation.

This DPA takes precedence over any conflicting provisions in the Terms of Service solely in relation to the processing of personal data.

Definitions

In this DPA, the following terms have the meanings given below. Other capitalised terms have the meanings given in the Terms of Service.

Details of data processing

The following describes the personal data processed by the Processor on behalf of the Controller under this DPA.

CategoryDetails
Subject matterAI-powered WhatsApp communication between parents and the school, including absence reporting and safeguarding alerting
DurationFor the term of the free trial and any subsequent subscription period, as defined in the Terms of Service
Nature of processingCollection, storage, transmission, automated processing, and deletion of personal data
PurposeTo enable the school to communicate with parents via WhatsApp using AI, to log absences automatically, and to escalate safeguarding concerns to the DSL
Data subjectsParents and guardians of pupils at the school; pupils (referenced in absence and safeguarding records)
Categories of dataMobile phone numbers; parent/guardian names; pupil names, year group, and dates of birth; WhatsApp message content; absence reasons and return dates; safeguarding conversation logs
Special category dataSafeguarding-related content may constitute special category data (data concerning health, criminal matters, or child welfare). This is processed primarily under Article 9(2)(g) UK GDPR (substantial public interest) read with Schedule 1, Part 2, paragraph 18 of the Data Protection Act 2018 (safeguarding of children and individuals at risk). Article 9(2)(c) (vital interests) may additionally apply in circumstances involving an immediate threat to life or safety

Processor obligations

The Processor agrees to:

5.1 Instructions

Process Personal Data only on the documented instructions of the Controller, as set out in this DPA and the Terms of Service, unless required to do so by applicable law. If the Processor is required by law to process Personal Data other than as instructed, it will notify the Controller before doing so (unless prohibited by law).

5.2 Confidentiality

Ensure that all personnel authorised to process Personal Data under this DPA are subject to binding confidentiality obligations and have received appropriate data protection training.

5.3 Security

Implement appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Specific measures are detailed in clause 7.

5.4 Sub-processors

Not engage any Sub-processor without prior written authorisation from the Controller (general authorisation is given for the Sub-processors listed in the Schedule to this DPA). Notify the Controller of any intended changes to Sub-processors with at least 30 days' written notice. The Controller may object to a new Sub-processor on reasonable data protection grounds within 14 days of notice; if the Processor cannot accommodate the objection, the Controller may terminate this DPA and the Terms of Service without penalty. Ensure Sub-processors are bound by equivalent data protection obligations.

5.5 Data subject rights

Assist the Controller to fulfil its obligations to respond to Data Subject rights requests, taking into account the nature of the processing. See clause 9 for detail.

5.6 Assistance

Assist the Controller in ensuring compliance with its obligations under Articles 32–36 UK GDPR (security, breach notification, DPIAs, and prior consultation), taking into account the nature of processing and information available to the Processor.

5.7 Deletion and return

At the choice of the Controller, delete or return all Personal Data to the Controller on termination of the Terms of Service, and delete existing copies unless retention is required by applicable law.

5.8 Audit

Make available to the Controller all information necessary to demonstrate compliance with this DPA and permit audits or inspections by the Controller or its appointed auditor, subject to reasonable notice and cost allocation.

Controller obligations

The Controller agrees to:

Security measures

The Processor implements and maintains the following technical and organisational security measures:

Technical measures

Organisational measures

The Processor will review and update these measures periodically to maintain an appropriate level of security in light of evolving risks.

Sub-processors

The Controller grants general authorisation to the Processor to engage the Sub-processors listed in the Schedule to this DPA for the purposes of delivering the Services.

The Processor will:

If the Controller objects to a new Sub-processor on reasonable data protection grounds, the parties will work in good faith to resolve the objection. If it cannot be resolved within 30 days, the Controller may terminate the Terms of Service without penalty.

Data subject rights

Where the Processor receives a request directly from a Data Subject exercising their rights under UK GDPR (access, rectification, erasure, restriction, portability, or objection), it will:

The Processor will implement appropriate technical measures to enable the Controller to access, correct, export, or delete Personal Data through the dashboard where technically feasible.

Personal data breaches

In the event of a personal data breach affecting data processed under this DPA, the Processor will:

The Processor maintains an internal breach register and will make relevant entries available to the Controller on request.

International data transfers

The Processor stores all Personal Data within the European Economic Area (EEA). Where Personal Data is transferred outside the UK or EEA for the purpose of delivering the Services (for example, to Anthropic in the United States for AI processing, or to Meta for WhatsApp message delivery), the Processor relies on the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment, as the lawful basis for such transfers.

Details of international transfers are set out in the Sub-processors schedule. The Processor will notify the Controller of any material change to the legal basis for international transfers and will make copies of relevant transfer agreements available to the Controller on written request.

Audit and compliance

The Processor will make available to the Controller, on reasonable written request (and no more than once per year unless there are specific grounds for concern), information necessary to demonstrate compliance with this DPA. This may include:

Where the Controller requires a more detailed audit, the parties will agree the scope, timing, and cost allocation in advance. Audits must be conducted by the Controller or an appointed third party bound by confidentiality, with a minimum of 14 days' written notice.

Termination and data deletion

On termination of the Terms of Service for any reason:

This DPA will survive termination of the Terms of Service to the extent necessary to govern post-termination processing obligations.

12A. Data Protection Impact Assessments

The Processor acknowledges that the Services involve the processing of children's personal data using automated AI systems, which is likely to require a Data Protection Impact Assessment (DPIA) under Article 35 UK GDPR.

The Processor will:

Schools are encouraged to conduct a DPIA before deploying IntelComms and to document their lawful basis and risk assessment. IntelComms will provide a DPIA support pack on request, email contact@intelcomms.co.uk.

Governing law

This DPA is governed by the laws of England and Wales. Any disputes arising under this DPA will be subject to the exclusive jurisdiction of the courts of England and Wales.

If any provision of this DPA is found to be unenforceable, the remaining provisions will continue in full force and effect.

Schedule: Approved sub-processors

The following sub-processors are approved under this DPA as at the effective date:

Sub-processorPurposeLocationTransfer mechanism
Supabase Database, all personal data including messages, absence records, and safeguarding logs EU West (Ireland) UK adequacy regulations (EEA)
Anthropic (Claude AI) AI processing, message content passed to generate responses using school documents United States UK IDTA / UK Addendum to the EU SCCs
Meta (WhatsApp Cloud API) Message delivery, sends and receives WhatsApp messages between parents and school United States UK IDTA / UK Addendum to the EU SCCs
OpenAI Embeddings, converts school documents and parent message text into a numerical index for AI retrieval. Document and message text, which may contain personal data, is processed by this sub-processor United States UK IDTA / UK Addendum to the EU SCCs
Railway Backend hosting, runs the IntelComms API EU West (Ireland) UK adequacy regulations (EEA)
Resend Email, safeguarding alerts and notifications to school staff EU UK adequacy regulations (EEA)

The Processor will provide written notice of any additions or changes to this list at least 30 days in advance.

Signatures

By signing below, both parties agree to the terms of this Data Processing Agreement. This DPA takes effect on the date of the last signature below.

For IntelComms Ltd (Processor)

For [School name] (Controller)

To request a signed DPA: Email contact@intelcomms.co.uk with your school name and DfE number. We will return a countersigned copy within 5 business days.