Data Processing Agreement
For schools, colleges and universities using SimmaSend.
Last updated: 23 September 2026
1. Introduction
This Data Processing Agreement (“DPA”) forms part of the agreement between SimmaSend (“Processor”), operated by James Ward, and the school, college or university using SimmaSend (“Controller”), for the processing of personal data. It ensures compliance with the UK GDPR and the Data Protection Act 2018. SimmaSend is registered with the ICO under reference ZC130082.
2. Scope and duration
The Processor shall process personal data on behalf of the Controller for the purpose of providing the SimmaSend feedback service. Processing begins when the Controller's account is created and continues until the account is deleted or the service is terminated.
3. Nature and purpose of processing
The Processor provides a web-based service enabling the Controller's staff to record audio, video, photo and text feedback for students. This feedback is transcribed and summarised using AI, stored securely, and made available to students via a unique QR-code URL. Processing consists of collecting, storing, organising, retrieving, transmitting (to sub-processors for transcription/summarisation and email delivery), restricting and deleting personal data.
4. Types of personal data processed
- Student first names and last names
- Student email addresses (required — school- or university-issued, provided by a school administrator, used only for feedback notifications that contain no feedback content)
- Teacher names and subjects
- Teacher email addresses (required — provided by a school administrator; used for magic-link sign-in, student-response notifications and school communications)
- Administrator names and email addresses
- Audio recordings, video recordings, photographs and text feedback
- AI-generated transcripts, summaries, titles, subject classifications and action points
- Student text responses to feedback
- Activity/audit-log data (actions taken in the system, including the acting user's email address and related identifiers)
Feedback may incidentally contain special category data. Identifying an appropriate Article 9 condition for any such data is the responsibility of the Controller.
5. Data subjects
- Students (including children) at the Controller's institution
- Teachers and staff at the Controller's institution
- School administrators
6. Obligations of the Processor
6.1. The Processor shall only process personal data on the Controller's documented instructions and this DPA, unless required otherwise by law.
6.2. The Processor shall ensure that all personnel with access to personal data are bound by appropriate confidentiality obligations.
6.3. The Processor shall implement appropriate technical and organisational measures, including: encryption in transit (HTTPS/TLS); database access restricted to server-side application code, with per-request authorisation checks enforcing isolation between Controllers and no direct database access available to end users; private storage buckets with server-generated signed URLs for media, valid for one hour and served only for paths belonging to the relevant feedback record; single-use magic-link authentication (15-minute expiry) for administrators; revocable per-student access tokens, held separately from the internal record identifier, that an administrator can reissue to invalidate a compromised QR-code link immediately without loss of the student's feedback history; personal data scrubbed from error-monitoring reports; daily database backups with seven-day retention; and regular security updates.
6.4. The Processor shall assist the Controller in responding to data subject requests and in ensuring compliance with the Controller's obligations under Articles 32–36 of the UK GDPR (including DPIAs).
6.5. The Processor shall notify the Controller without undue delay, and in any event within 72 hours, upon becoming aware of a personal data breach.
6.6. Upon deletion of a student, deletion of the Controller's account, or termination of the service, the Processor shall permanently delete the relevant personal data, including all media files in storage and all copies, unless retention is required by law, and shall confirm deletion in writing on request.
7. Sub-processors
The Controller agrees that the Processor may use the following sub-processors:
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Supabase (on AWS) | Database and file storage | AWS eu-west-1 (Ireland, EEA) | Within UK adequacy (EEA) |
| Vercel | Hosting and serverless functions | USA | EU-US DPF incl. UK Extension (UK-US data bridge) |
| OpenAI | Transcription (Whisper) and summarisation (GPT-4o-mini) | USA | SCCs + UK Addendum (OpenAI DPA) |
| Resend | Transactional email delivery | USA | EU-US DPF incl. UK Extension (UK-US data bridge) |
| Sentry | Error monitoring (personal data scrubbed) | USA | EU-US DPF incl. UK Extension (UK-US data bridge) |
The Processor has a data processing agreement in place with each sub-processor, and shall notify the Controller before adding or replacing any sub-processor. If the Controller objects, it may terminate the agreement.
8. Data location and international transfers
Application data (database records and media files) is stored in the EEA (Ireland), covered by the UK's adequacy regulations. Audio and video is temporarily transmitted to OpenAI (USA) for processing under SCCs and the UK Addendum; OpenAI does not use API data to train its models and retains it only briefly for abuse monitoring before deletion. Email delivery (Resend, USA), hosting (Vercel, USA) and error monitoring (Sentry, USA) rely on the UK-US data bridge. The Processor ensures each sub-processor provides an appropriate transfer safeguard.
9. Rights of the Controller
9.1. The Controller may request information about the Processor's compliance with this DPA at any time.
9.2. The Controller may audit compliance, subject to at least 4 weeks' notice, during normal business hours, no more than once per 12-month period.
10. Data subject rights
The Processor shall assist the Controller in handling data subject requests (access, rectification, erasure, restriction and portability). Administrators can manage student and teacher data directly through the SimmaSend admin dashboard, including deleting students (which also removes their media). For requests that cannot be handled through the dashboard, the Controller should contact hello@simmasend.com.
11. Termination
Upon termination, the Processor shall permanently delete all personal data (including media files) within 30 days, unless the Controller requests a data export first, and shall confirm deletion in writing on request.
12. Liability
The Processor's liability under this DPA is subject to the limitations in the main Terms and Conditions.
13. Contact
For any query regarding this DPA, contact hello@simmasend.com.