Last updated: 21 July 2026

Data Processing Agreement

Template notice. This Data Processing Agreement ("DPA") is a good-faith starting template, not legal advice. It must be reviewed and adapted by qualified legal counsel for your jurisdiction and business before you sign or rely on it. Bracketed placeholders such as [Customer], [jurisdiction] and [notice period] must be completed. The terms that actually govern a relationship are those in the DPA signed with the individual Customer; where this template and a signed agreement differ, the signed agreement controls.

This DPA forms part of the agreement (the "Agreement") between [Customer] (the "Customer") and [Company legal name] ("Vidyalaya", "we", "us") for the Customer's use of the Vidyalaya school-management platform (the "Service"). It governs our processing of personal data on the Customer's behalf and applies to the extent that applicable data-protection law (such as the EU/UK GDPR, India's DPDP Act, or FERPA) applies to that processing.

1. Parties & roles

For personal data processed through the Service on the Customer's behalf:

  • The Customer is the data controller (or, where it acts for another controller, the processor) and determines the purposes and means of the processing.
  • Vidyalaya is the data processor (or sub-processor) and processes that data only on the Customer's documented instructions.

Vidyalaya acts as a controller in its own right only for the limited data described in our Privacy Policy — for example account-administration and website contact data — which is outside the scope of this DPA.

2. Subject matter & duration

The subject matter of the processing is the provision of the Service to the Customer. Processing continues for the term of the Agreement and for any additional period during which we are permitted or required to retain the data under Section 11 or applicable law.

3. Nature & purpose of processing

We process personal data to host, operate, secure, support and improve the Service for the Customer — including storage, retrieval, organisation, transmission, backup, and deletion or anonymisation of records — solely to deliver the Service as described in the Agreement and on the Customer's instructions. The Agreement, this DPA, and the Customer's configuration and use of the Service constitute the Customer's complete documented instructions. We do not sell personal data, and we do not use student data for advertising or to train models.

4. Categories of data subjects & personal data

Depending on the Customer's use of the Service, the processing may concern the following categories of data subjects and personal data:

  • Data subjects: students (including children); parents and guardians; teaching and administrative staff; and other individuals whose records the Customer chooses to hold.
  • Personal data: identity and contact details; admissions and enrolment records; attendance and timetables; exam and assessment results; fees and payment records; HR and payroll data; library, transport, hostel and health records; and communications logs.
  • Special-category / sensitive data: the Service may hold data about children and, where the Customer configures it, health and other sensitive information. The Customer is responsible for ensuring it has a valid basis to process such data.

5. Processor obligations

Vidyalaya will:

  • Process on instructions: process personal data only on the Customer's documented instructions, including as to international transfers, unless required otherwise by law — in which case we will inform the Customer first, unless the law prohibits it.
  • Confidentiality: ensure that personnel authorised to process the data are bound by confidentiality and access it only on a need-to-know basis.
  • Security measures: implement appropriate technical and organisational measures. These include per-tenant data isolation enforced in the application and, progressively, at the database with PostgreSQL row-level security; fine-grained, least-privilege role-based access control (RBAC) with segregation of duties; hardened authentication; encryption in transit; and audit logging of privileged actions. Our current measures are described on the Security page, which forms part of this DPA by reference.
  • Assist the Customer in meeting its own obligations, taking into account the nature of the processing and the information available to us (see Sections 7 and 8).

6. Sub-processors

The Customer provides general authorisation for Vidyalaya to engage sub-processors to support the Service, provided each is bound by data-protection obligations no less protective than those in this DPA, and Vidyalaya remains liable for their performance. Current sub-processors include:

  • [Cloud hosting / infrastructure provider] — hosting and storage — [region]
  • [Email / notification provider] — transactional and service messaging — [region]
  • [Payment processor] — fee and payment processing — [region]
  • [Support / helpdesk tooling] — customer support — [region]

We will give the Customer [notice period] advance notice of any intended addition or replacement of a sub-processor so the Customer has an opportunity to object on reasonable data-protection grounds. A current list is available on request.

7. Data-subject rights assistance

Taking into account the nature of the processing, Vidyalaya will assist the Customer, by appropriate technical and organisational measures and so far as possible, to respond to requests from data subjects exercising their rights — including access, rectification, erasure, restriction, portability and objection. Where we receive such a request directly, we will promptly forward it to the Customer and will not respond except on the Customer's instruction. The Service provides self-service tooling for data-subject access requests (DSAR), returning a complete, consistent export of a student's record, and for erasure by anonymisation — each logged as a privileged action.

8. Personal-data breach notification

Vidyalaya will notify the Customer without undue delay, and in any event within [notice period] of becoming aware of a personal-data breach affecting the Customer's data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. We will cooperate with the Customer and take reasonable steps to mitigate the breach. This is not an acknowledgement of fault or liability.

9. International transfers

Personal data may be processed in the region the Customer selects via the Service's regional configuration ("country packs") or in other locations where we or our sub-processors operate. Where a transfer is subject to cross-border transfer rules, the parties will put an appropriate transfer mechanism in place — for example the EU/UK Standard Contractual Clauses ("SCCs") or another lawful mechanism — as set out in [transfer mechanism / Annex]. [Confirm actual hosting region(s) and transfer mechanism with counsel.]

10. Audits

Vidyalaya will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. To protect the confidentiality and security of other customers, audits are subject to reasonable notice of [notice period], confidentiality obligations, a frequency of no more than [frequency] (except where required by a supervisory authority or following a breach), and may be satisfied by up-to-date documentation, security summaries or third-party reports where available. [Costs and scope to be agreed with counsel.]

11. Return & deletion on termination

On expiry or termination of the Agreement, and at the Customer's choice, Vidyalaya will return or delete (or anonymise) the personal data it processes on the Customer's behalf, and delete existing copies, unless applicable law requires continued retention (for example, financial records). Deletion or return will be completed within [notice period] of the Customer's request. Backups are purged in the ordinary backup-rotation cycle.

12. Liability & governing law

Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement and our Terms of Service. This DPA is governed by the laws of [jurisdiction], and the parties submit to the courts of [jurisdiction], except where mandatory data-protection law provides otherwise. If any provision of this DPA conflicts with the Agreement on the subject of data protection, this DPA controls; on all other matters, the Agreement controls. [Confirm governing law, venue and liability terms with counsel.]

Related

See also our Privacy Policy, Terms of Service and Security overview. To discuss a signed DPA for your school, get in touch.