Data Processing Agreement
Version date: 15 July 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the Customer as controller and 25Thirty Ltd as processor for use of Bridge Admissions.
1. Definitions
Terms such as controller, processor, personal data, data subject, processing, personal data breach and supervisory authority have the meanings given in applicable UK data-protection law.
“Applicable Data Protection Law” means the UK GDPR, the Data Protection Act 2018, PECR where applicable, and any replacement or amendment applying to the processing.
“Customer Personal Data” means personal data processed by the Supplier on behalf of the Customer through the service.
2. Processing details
The subject matter, duration, nature, purpose, personal-data types and data-subject categories are set out in Annex 1.
The Customer instructs the Supplier to process Customer Personal Data to provide, secure, maintain and support the service, perform the agreement, and follow additional documented lawful instructions.
3. Documented instructions
The Supplier will process Customer Personal Data only on the Customer’s documented instructions, including instructions relating to international transfers, unless UK law requires otherwise. Where legally permitted, the Supplier will inform the Customer before processing required by law.
The Supplier will promptly inform the Customer if it believes an instruction infringes Applicable Data Protection Law. The Supplier may pause the affected processing while the parties address the concern.
4. Confidentiality
The Supplier will ensure that people authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality and receive relevant training.
5. Security
The Supplier will implement appropriate technical and organisational measures, taking account of the state of the art, implementation costs, nature and scope of processing, and risks to individuals.
Current measures are described in Annex 2. The Supplier may update them provided it does not materially reduce overall protection.
6. Subprocessors
The Customer gives general written authorisation for the Supplier to appoint subprocessors.
The Supplier will:
- publish or provide an up-to-date list of subprocessors;
- notify the Customer at least 30 days before adding or replacing a subprocessor that will process Customer Personal Data;
- give the Customer a reasonable opportunity to object on legitimate data-protection grounds;
- enter into a written agreement requiring substantially equivalent data-protection obligations;
- remain responsible to the Customer for the subprocessor’s performance of those obligations.
If the parties cannot reasonably resolve a valid objection, the Customer may terminate the affected service before the change takes effect and receive a pro-rata refund for the unused affected period.
7. International transfers
The Supplier will not make a restricted transfer of Customer Personal Data unless a lawful transfer mechanism is in place.
Where required, the parties will enter into or incorporate the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another approved safeguard. The Supplier will carry out required transfer risk assessments and implement supplementary measures where appropriate.
8. Data-subject rights
Taking account of the nature of processing, the Supplier will provide reasonable assistance through appropriate technical and organisational measures to help the Customer respond to requests to exercise data-subject rights.
If the Supplier receives a request relating to Customer Personal Data, it will not respond substantively except on the Customer’s instructions or where required by law. It will direct the requester to the Customer where appropriate and notify the Customer without undue delay.
Additional work beyond standard product functionality may be chargeable where reasonable and agreed.
9. Assistance and compliance
Taking account of the nature of processing and information available, the Supplier will reasonably assist the Customer with:
- security of processing;
- breach notification obligations;
- data-protection impact assessments;
- prior consultation with the ICO;
- demonstrating compliance with controller-processor obligations.
The Customer remains responsible for its own legal duties, decisions and risk assessments.
10. Personal data breaches
The Supplier will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
The notice will include available information about:
- the nature of the breach;
- affected categories and approximate numbers of individuals and records;
- likely consequences;
- measures taken or proposed;
- a contact for further information.
Information may be provided in phases as it becomes available. Notification does not amount to an admission of fault.
The Supplier will take reasonable steps to contain, investigate and remediate the breach and cooperate with the Customer. The Customer is responsible for notifications to individuals and regulators unless otherwise agreed or legally required.
Operational target for initial notification: [WITHIN 24 HOURS OF CONFIRMED AWARENESS / OTHER TARGET].
11. Deletion and return
At the Customer’s choice, the Supplier will return or delete Customer Personal Data at the end of services, unless UK law requires retention.
Standard export, deletion and backup expiry periods are set out in the Customer Terms. The Supplier will delete existing copies through normal secure processes, including expiry from backups, and may retain only information legally required in a protected form.
12. Audit information
The Supplier will make available information reasonably necessary to demonstrate compliance with this DPA.
The Supplier may satisfy requests using current independent reports, certifications, penetration-test summaries, policies and questionnaires.
Where that is insufficient, the Customer may conduct an audit no more than once in any 12-month period, unless required by a regulator or following a material incident. Audits must:
- give at least 30 days’ notice;
- occur during normal business hours;
- avoid unreasonable disruption;
- protect other customers’ information and Supplier security;
- be performed by an independent, suitably qualified auditor;
- be at the Customer’s cost, unless a material breach by the Supplier is found.
No audit may require access to another customer’s data, source code, vulnerability details that would create security risk, or information protected by third-party confidentiality.
13. Customer obligations
The Customer warrants that:
- it has a lawful basis for processing and issuing instructions;
- it has provided required privacy information;
- its instructions comply with Applicable Data Protection Law;
- Customer Personal Data is adequate, relevant and limited to what is necessary;
- it will not require the Supplier to process prohibited data without written agreement and appropriate safeguards;
- it will configure permissions and retention appropriately.
14. Order of precedence
If there is a conflict concerning personal-data processing, this DPA takes precedence over the Customer Terms, except where an Order Form expressly identifies and varies a particular clause of this DPA.
Annex 1 – Processing description
| Item | Description |
|---|---|
| Subject matter | Hosting and operation of an admissions and family relationship-management platform, including configuration, support, maintenance, security, import, export and integrations selected by the Customer. |
| Duration | For the subscription term and the agreed export, deletion and backup-rotation period. |
| Nature and purpose | Collection, storage, organisation, retrieval, consultation, transmission, reporting, workflow automation, communication support, access control, backup, troubleshooting and deletion, solely to provide the service. |
| Data subjects | Prospective, current and former applicants and pupils; parents; guardians; family members; emergency and professional contacts; school staff; authorised users; suppliers and other contacts entered by the Customer. |
| Personal data | Names; contact and identity details; family relationships; school and year-group information; admissions status and history; communications; appointments; attendance or availability; tasks; notes; documents; technical and audit data; user account data. |
| Potential special-category or sensitive data | Health, disability, SEND, safeguarding, ethnicity, religion, dietary or accessibility information, and other sensitive notes, only where the Customer chooses and has a lawful basis. The Customer should minimise and appropriately restrict this information. |
| Frequency | Continuous or as initiated by authorised users and integrations. |
| Controller rights and obligations | The Customer determines purposes and means, manages lawful basis and transparency, handles individual rights, configures access and retention, and provides lawful instructions. |
Annex 2 – Technical and organisational measures
Complete this annex against the real system.
Governance
- named security and privacy responsibilities;
- staff confidentiality and access-control procedures;
- supplier due diligence and written processing terms;
- incident-response and business-continuity procedures;
- periodic risk and policy review.
Access control
- unique user accounts;
- role-based and least-privilege access;
- multi-factor authentication [AVAILABLE/REQUIRED];
- secure password and session controls;
- joiner, mover and leaver processes;
- privileged-access restriction and logging.
Encryption
- encryption in transit using current TLS;
- encryption at rest for production databases and backups;
- secure management of keys and secrets;
- no credentials committed to source code.
Application and infrastructure
- secure development and code review;
- dependency and vulnerability management;
- separation of production and non-production environments;
- tenant-isolation controls;
- logging, alerting and monitoring;
- malware and abuse protections;
- regular backups and restoration testing;
- patching and change management;
- periodic penetration testing [FREQUENCY].
Data management
- configurable permissions;
- export and deletion processes;
- retention controls;
- minimisation of production data in support and testing;
- secure deletion and backup expiry;
- audit trails for material actions [CONFIRM SCOPE].
Resilience
- hosting region: [REGION];
- backup frequency: [FREQUENCY];
- recovery point objective: [RPO];
- recovery time objective: [RTO];
- availability target: [TARGET];
- tested incident and recovery procedures.
Annex 3 – Approved subprocessors
See the current Subprocessor List at [URL], incorporated into this DPA.