Parties to this Agreement
Data Processor
IntelComms Ltd
Company number: [To be confirmed]
Registered in England and Wales
Email: contact@intelcomms.co.uk
Website: intelcomms.co.uk
Data Controller
[School / Academy / MAT name]
DfE number: [__________]
[Registered address]
Email: [__________]
Data protection contact: [__________]
Together referred to as "the parties". This Data Processing Agreement ("DPA") supplements and forms part of the IntelComms Terms of Service between the parties.
Background
The Controller has engaged the Processor to provide the IntelComms AI WhatsApp communication service, which involves the processing of personal data relating to parents, guardians, and pupils on behalf of the Controller.
The parties enter into this DPA to ensure that such processing is carried out in compliance with UK GDPR, the Data Protection Act 2018, and all other applicable data protection legislation.
This DPA takes precedence over any conflicting provisions in the Terms of Service solely in relation to the processing of personal data.
Definitions
In this DPA, the following terms have the meanings given below. Other capitalised terms have the meanings given in the Terms of Service.
- "Controller", the school, academy, or MAT identified above as the Data Controller
- "Processor", IntelComms Ltd, acting as Data Processor on behalf of the Controller
- "Personal Data", any information relating to an identified or identifiable natural person processed under this DPA
- "Processing", any operation performed on Personal Data, including collection, storage, use, transmission, and deletion
- "Sub-processor", any third party engaged by the Processor to process Personal Data on behalf of the Controller
- "UK GDPR", the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018
- "Data Subject", a parent, guardian, or pupil whose personal data is processed under this DPA
- "Supervisory Authority", the Information Commissioner's Office (ICO)
Details of data processing
The following describes the personal data processed by the Processor on behalf of the Controller under this DPA.
| Category | Details |
|---|---|
| Subject matter | AI-powered WhatsApp communication between parents and the school, including absence reporting and safeguarding alerting |
| Duration | For the term of the free trial and any subsequent subscription period, as defined in the Terms of Service |
| Nature of processing | Collection, storage, transmission, automated processing, and deletion of personal data |
| Purpose | To enable the school to communicate with parents via WhatsApp using AI, to log absences automatically, and to escalate safeguarding concerns to the DSL |
| Data subjects | Parents and guardians of pupils at the school; pupils (referenced in absence and safeguarding records) |
| Categories of data | Mobile phone numbers; parent/guardian names; pupil names, year group, and dates of birth; WhatsApp message content; absence reasons and return dates; safeguarding conversation logs |
| Special category data | Safeguarding-related content may constitute special category data (data concerning health, criminal matters, or child welfare). This is processed primarily under Article 9(2)(g) UK GDPR (substantial public interest) read with Schedule 1, Part 2, paragraph 18 of the Data Protection Act 2018 (safeguarding of children and individuals at risk). Article 9(2)(c) (vital interests) may additionally apply in circumstances involving an immediate threat to life or safety |
Processor obligations
The Processor agrees to:
5.1 Instructions
Process Personal Data only on the documented instructions of the Controller, as set out in this DPA and the Terms of Service, unless required to do so by applicable law. If the Processor is required by law to process Personal Data other than as instructed, it will notify the Controller before doing so (unless prohibited by law).
5.2 Confidentiality
Ensure that all personnel authorised to process Personal Data under this DPA are subject to binding confidentiality obligations and have received appropriate data protection training.
5.3 Security
Implement appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Specific measures are detailed in clause 7.
5.4 Sub-processors
Not engage any Sub-processor without prior written authorisation from the Controller (general authorisation is given for the Sub-processors listed in the Schedule to this DPA). Notify the Controller of any intended changes to Sub-processors with at least 30 days' written notice. The Controller may object to a new Sub-processor on reasonable data protection grounds within 14 days of notice; if the Processor cannot accommodate the objection, the Controller may terminate this DPA and the Terms of Service without penalty. Ensure Sub-processors are bound by equivalent data protection obligations.
5.5 Data subject rights
Assist the Controller to fulfil its obligations to respond to Data Subject rights requests, taking into account the nature of the processing. See clause 9 for detail.
5.6 Assistance
Assist the Controller in ensuring compliance with its obligations under Articles 32–36 UK GDPR (security, breach notification, DPIAs, and prior consultation), taking into account the nature of processing and information available to the Processor.
5.7 Deletion and return
At the choice of the Controller, delete or return all Personal Data to the Controller on termination of the Terms of Service, and delete existing copies unless retention is required by applicable law.
5.8 Audit
Make available to the Controller all information necessary to demonstrate compliance with this DPA and permit audits or inspections by the Controller or its appointed auditor, subject to reasonable notice and cost allocation.
Controller obligations
The Controller agrees to:
- Ensure it has a valid lawful basis for the processing described in this DPA before instructing the Processor to commence processing
- Provide parents and guardians with appropriate privacy information about the IntelComms service, including that their WhatsApp messages will be processed by an AI system
- Ensure that personal data provided to the Processor (including parent contact lists and pupil data) is accurate and up to date
- Designate a named Designated Safeguarding Lead (DSL) to receive safeguarding alerts from the Processor
- Manage Authorised User access and promptly remove access for staff who leave the school
- Notify the Processor promptly of any suspected or confirmed data breach relating to the Services
- Not instruct the Processor to process Personal Data in a way that would cause the Processor to violate applicable data protection law
Security measures
The Processor implements and maintains the following technical and organisational security measures:
Technical measures
- All data encrypted in transit using TLS 1.2 or above
- All data encrypted at rest using AES-256 or equivalent
- All personal data stored within the European Economic Area (Supabase EU West, Ireland)
- Webhook signature validation using HMAC-SHA256 to authenticate all inbound messages
- Message deduplication to prevent double-processing of personal data
- Role-based access controls limiting staff access to data on a need-to-know basis
- All access to production systems logged and monitored
- Automated backups of all personal data
Organisational measures
- All IntelComms personnel with access to personal data are subject to confidentiality agreements
- Data protection training provided to all relevant personnel
- Access to school data by IntelComms personnel is logged and limited to support, legal compliance, and security purposes
- Incident response procedures in place for data breaches
- Regular review of sub-processor compliance
The Processor will review and update these measures periodically to maintain an appropriate level of security in light of evolving risks.
Sub-processors
The Controller grants general authorisation to the Processor to engage the Sub-processors listed in the Schedule to this DPA for the purposes of delivering the Services.
The Processor will:
- Give the Controller at least 30 days' written notice before adding or replacing any Sub-processor that processes Personal Data
- Ensure each Sub-processor is bound by data processing obligations equivalent to those in this DPA
- Remain liable to the Controller for the acts and omissions of its Sub-processors to the same extent as if the Processor had performed the processing directly
If the Controller objects to a new Sub-processor on reasonable data protection grounds, the parties will work in good faith to resolve the objection. If it cannot be resolved within 30 days, the Controller may terminate the Terms of Service without penalty.
Data subject rights
Where the Processor receives a request directly from a Data Subject exercising their rights under UK GDPR (access, rectification, erasure, restriction, portability, or objection), it will:
- Promptly forward the request to the Controller
- Not respond to the Data Subject directly unless instructed by the Controller
- Provide the Controller with reasonable assistance to fulfil the request within the statutory timeframe (one calendar month)
The Processor will implement appropriate technical measures to enable the Controller to access, correct, export, or delete Personal Data through the dashboard where technically feasible.
Personal data breaches
In the event of a personal data breach affecting data processed under this DPA, the Processor will:
- Notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach
- Provide the Controller with sufficient information to enable it to meet its own notification obligations to the ICO (within 72 hours) and to affected Data Subjects where required
- Include in the notification: the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed to address the breach
- Cooperate fully with the Controller in investigating, mitigating, and remedying the breach
The Processor maintains an internal breach register and will make relevant entries available to the Controller on request.
International data transfers
The Processor stores all Personal Data within the European Economic Area (EEA). Where Personal Data is transferred outside the UK or EEA for the purpose of delivering the Services (for example, to Anthropic in the United States for AI processing, or to Meta for WhatsApp message delivery), the Processor relies on the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment, as the lawful basis for such transfers.
Details of international transfers are set out in the Sub-processors schedule. The Processor will notify the Controller of any material change to the legal basis for international transfers and will make copies of relevant transfer agreements available to the Controller on written request.
Audit and compliance
The Processor will make available to the Controller, on reasonable written request (and no more than once per year unless there are specific grounds for concern), information necessary to demonstrate compliance with this DPA. This may include:
- Confirmation of security certifications held
- Summary of relevant internal policies and procedures
- Access logs relating to the Controller's data
Where the Controller requires a more detailed audit, the parties will agree the scope, timing, and cost allocation in advance. Audits must be conducted by the Controller or an appointed third party bound by confidentiality, with a minimum of 14 days' written notice.
Termination and data deletion
On termination of the Terms of Service for any reason:
- The Processor will cease all processing of Personal Data within 14 days
- Within 30 days of a written request from the Controller, the Processor will either return all Personal Data to the Controller in a portable format (CSV or JSON) or delete it securely, at the Controller's choice
- The Processor will confirm in writing when deletion is complete
- Notwithstanding the above, the Processor may retain Personal Data where required by applicable law, in particular, safeguarding logs which must be retained for a minimum of 7 years
This DPA will survive termination of the Terms of Service to the extent necessary to govern post-termination processing obligations.
12A. Data Protection Impact Assessments
The Processor acknowledges that the Services involve the processing of children's personal data using automated AI systems, which is likely to require a Data Protection Impact Assessment (DPIA) under Article 35 UK GDPR.
The Processor will:
- Cooperate fully with the Controller in conducting any DPIA required in relation to the Services
- Make available relevant technical information, including details of data flows, automated processing logic, security measures, and sub-processor arrangements, to support the Controller's DPIA
- Notify the Controller of any material changes to the Services that may necessitate a new or updated DPIA
- Maintain its own record of processing activities as required by Article 30 UK GDPR and make this available to the Controller on request
Schools are encouraged to conduct a DPIA before deploying IntelComms and to document their lawful basis and risk assessment. IntelComms will provide a DPIA support pack on request, email contact@intelcomms.co.uk.
Governing law
This DPA is governed by the laws of England and Wales. Any disputes arising under this DPA will be subject to the exclusive jurisdiction of the courts of England and Wales.
If any provision of this DPA is found to be unenforceable, the remaining provisions will continue in full force and effect.
Schedule: Approved sub-processors
The following sub-processors are approved under this DPA as at the effective date:
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase | Database, all personal data including messages, absence records, and safeguarding logs | EU West (Ireland) | UK adequacy regulations (EEA) |
| Anthropic (Claude AI) | AI processing, message content passed to generate responses using school documents | United States | UK IDTA / UK Addendum to the EU SCCs |
| Meta (WhatsApp Cloud API) | Message delivery, sends and receives WhatsApp messages between parents and school | United States | UK IDTA / UK Addendum to the EU SCCs |
| OpenAI | Embeddings, converts school documents and parent message text into a numerical index for AI retrieval. Document and message text, which may contain personal data, is processed by this sub-processor | United States | UK IDTA / UK Addendum to the EU SCCs |
| Railway | Backend hosting, runs the IntelComms API | EU West (Ireland) | UK adequacy regulations (EEA) |
| Resend | Email, safeguarding alerts and notifications to school staff | EU | UK adequacy regulations (EEA) |
The Processor will provide written notice of any additions or changes to this list at least 30 days in advance.
Signatures
By signing below, both parties agree to the terms of this Data Processing Agreement. This DPA takes effect on the date of the last signature below.
For IntelComms Ltd (Processor)
For [School name] (Controller)
To request a signed DPA: Email contact@intelcomms.co.uk with your school name and DfE number. We will return a countersigned copy within 5 business days.