Data Processing Agreement
Last updated: 24 August 2026
Between Controller and Processor
Version: 1.6
Date: 24 August 2026
This Data Processing Agreement is entered into on the date of the last signature below and governs the use of SENScribe by the Controller's authorised staff.
Parties
This Data Processing Agreement is entered into between:
Controller
Name of school / ETB / board of management / other educational body: ____________________
Registered address: ____________________
Contact name and role: ____________________
Contact email: ____________________
Main Service Agreement / Order Form: ____________________
Date: ____________________
and
Processor
SENScribe Limited
Company number: 813862
Registered address: ARKINS & COMPANY LIMITED, BLOCK 15, Galway Technology Park, Parkmore, Galway, GALWAY, Ireland, H91 AY0Y
Contact: hello@senscribe.ie
The Controller and Processor are together the Parties.
1. Background and Interpretation
- The Controller uses SENScribe to create, maintain, review, export and store Student Support Files and related student-support records.
- The Processor provides the SENScribe service, including encrypted storage, synchronisation, AI-assisted drafting and account services.
- The Parties enter into this Agreement to satisfy Article 28 GDPR and the equivalent requirements of applicable Irish data protection law.
For the purposes of this Agreement:
Customer Datameans personal data processed by the Processor on behalf of the Controller through the SENScribe service.Data Protection Lawmeans Regulation (EU) 2016/679, the Irish Data Protection Act 2018, any other applicable data protection legislation, and any supervisory-authority guidance that the Parties have agreed to observe.Main Service Agreementmeans the SENScribe Terms of Service accepted by the Controller or another written service agreement or Order Form identified above.Servicesmeans the SENScribe application and associated support, sync, storage and AI-assisted drafting services made available to the Controller.
2. Scope and Duration
- This Agreement applies for as long as the Processor processes Customer Data on behalf of the Controller in connection with the Services.
- This Agreement covers:
- teacher account access to the Services
- encrypted storage of student-support records
- encrypted multi-device synchronisation
- redacted and generalised AI drafting and rewrite requests
- export and support operations directly related to the Services
- This Agreement does not cover processing where the Processor acts as independent controller for its own corporate, accounting, tax, security or legal compliance purposes, except that such processing must still comply with Data Protection Law.
- For Customer Data, the Controller is the controller and the Processor is the processor within the meaning of Data Protection Law. Processing for which the Processor acts as an independent controller is recorded in general terms in Annex 4.
3. Subject Matter, Nature and Purpose of Processing
3.1 Subject matter
The subject matter of the processing is the provision of SENScribe as a service for creating, storing, syncing, reviewing and exporting student-support records.
3.2 Nature of processing
The processing may include:
- collection
- recording
- organisation
- structuring
- storage
- encryption
- retrieval
- consultation
- transmission
- synchronisation
- export
- deletion
3.3 Purpose of processing
The purpose of processing is to enable the Controller's authorised staff to:
- produce and maintain Student Support Files and related records
- manage review cycles and interventions
- sync encrypted records across devices
- generate and edit draft educational documentation using browser-redacted and generalised AI-assisted workflows
4. Categories of Data Subjects and Personal Data
4.1 Data subjects
Customer Data may relate to:
- students
- parents or guardians
- teachers, SETs and school staff
4.2 Personal data categories
Customer Data may include:
- teacher account identifiers and login information
- student names and dates of birth
- year group, school level and class/support information
- educational observations, strengths, concerns and interventions
- special educational needs and support information
- plans, reviews, targets, strategies and log entries
- parent comments, student voice and review notes
- staff names or role references contained in records
4.3 Special-category data
Customer Data may include special-category personal data, especially data concerning health and special educational needs, where entered by the Controller.
5. Controller Obligations
The Controller shall:
- ensure that it has a valid lawful basis under Articles 6 and, where required, 9 GDPR for the processing of Customer Data through the Services
- ensure that its authorised users are entitled to use the Services on its behalf
- provide only documented instructions to the Processor
- ensure that personal data entered into the Services is adequate, relevant and limited to what is necessary
- remain responsible for the accuracy, quality and legality of Customer Data and the means by which it acquired Customer Data
- determine retention periods for Customer Data unless the Parties agree a default retention rule in writing
6. Processor Obligations
The Processor shall:
- process Customer Data only on the documented instructions of the Controller, including instructions concerning transfers outside the EEA, unless otherwise required by Union or Member State law; where such law requires processing, the Processor shall inform the Controller of that legal requirement before processing unless the law prohibits that information
- ensure that persons authorised to process Customer Data are subject to confidentiality obligations
- implement appropriate technical and organisational measures to protect Customer Data
- assist the Controller, taking into account the nature of processing and information available to the Processor, with responding to data-subject requests
- assist the Controller with its obligations under Articles 32 to 36 GDPR, taking into account the nature of processing and information available to the Processor
- delete or return Customer Data as provided in Clause 12
- make available to the Controller information reasonably necessary to demonstrate compliance with this Agreement
- immediately inform the Controller if, in the Processor's opinion, an instruction infringes Data Protection Law
7. Documented Instructions
- The Controller instructs the Processor to process Customer Data for the purposes described in this Agreement and the Main Service Agreement.
- The Controller authorises the Processor to:
- host encrypted Customer Data
- sync encrypted Customer Data between authorised devices
- process browser-redacted and generalised prompts for AI drafting and rewrite functions
- provide support and service operations reasonably necessary to deliver the Services
- Additional instructions outside the agreed scope must be documented in writing and may require amendment of the commercial terms, security measures, or both.
8. Confidentiality
- The Processor shall ensure that any person authorised to process Customer Data is under an appropriate duty of confidentiality.
- The Processor shall limit internal access to Customer Data and related systems to what is reasonably necessary.
- The service is designed to restrict the Processor's routine operational access to intelligible student-support content. This design does not alter the Processor's obligations under Data Protection Law.
9. Security Measures
9.1 General obligation
The Processor shall implement appropriate technical and organisational measures as required by Article 32 GDPR.
9.2 Current measures
The Processor represents that the current service includes the following measures:
- browser-side encryption of student-support content before cloud storage
- encrypted transport between supported clients and service endpoints
- authentication and session controls for access to account and synchronisation services
- logical separation of customer data in storage
- restricted routine access by the Processor to intelligible student-support content
- hosting of customer storage in EU/EEA cloud regions and supported AI processing in an EU data zone
- browser-side redaction and generalisation checks for supported AI requests, subject to the limitation in Annex 1
- documented deletion and rolling backup-expiry controls
- limited operational and security logging for service protection and support
9.3 Important accuracy statement
The Parties acknowledge that encryption and access restrictions reduce risk but do not remove the Processor's obligations under Data Protection Law. Encrypted Customer Data remains personal data where Data Protection Law applies.
9.4 Security appendix
Further detail is set out in Annex 2 to this Agreement.
10. Sub-processors
- The Controller grants a general written authorisation for the Processor to engage the sub-processors listed in Annex 3.
- The Processor shall:
- maintain an up-to-date sub-processor list, published at https://senscribe.ie/sub-processors
- notify the Controller of any intended addition or replacement of a sub-processor that will process Customer Data
- impose the same data-protection obligations set out in this Agreement on each sub-processor, to the extent applicable to the services it provides
- The Processor remains fully liable to the Controller for the performance of each sub-processor's obligations under this Agreement.
- For any intended addition or replacement of a sub-processor that will process Customer Data, the Processor shall give the Controller no fewer than thirty (30) days' advance written notice, reflecting reasonable governance timelines for boards of management and ETB approval cycles. Publication of the updated list does not by itself constitute notice; the Processor notifies controller customers directly.
- The Controller may object in writing to the intended change within that notice period, on reasonable data-protection grounds.
- If the Parties cannot resolve an objection raised under this Clause, the Controller may terminate the affected service before the change takes effect, and the Processor shall not engage the objected sub-processor for the Controller's data.
11. Data Subject Rights and Assistance
- Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests for exercising data-subject rights.
- If the Processor receives a request directly from a data subject relating to Customer Data, the Processor shall:
- not respond on the merits unless legally required to do so
- promptly notify the Controller unless legally prohibited
- The Controller acknowledges that where the Service stores only encrypted customer content that the Processor has no technical means to decrypt during normal operation (decryption depends on the Controller's teacher-held credentials or recovery key, as described in the Privacy Whitepaper), certain assistance functions may depend on the Controller's own access to the decrypted content.
12. Retention, Return and Deletion
- The Controller is responsible for setting retention rules for Customer Data unless otherwise agreed in writing.
- During the term, the Controller may delete Customer Data using available product functionality or by instructing the Processor through support channels.
- Upon termination of the Services, the Processor shall, at the choice of the Controller, return Customer Data using the Services' available export methods or delete Customer Data and all existing copies, including copies held by sub-processors, unless Union or Member State law requires storage.
- Where the Controller requests deletion, or after requested return is completed:
- the Processor shall delete Customer Data from active production systems within thirty (30) days of receiving a valid instruction
- Customer Data in backups shall be deleted or rendered inaccessible through the documented rolling thirty-day backup-expiry cycle and remains protected by this Agreement until expiry
- the Processor shall confirm completion in writing on request
- Where Union or Member State law requires continued storage, the Processor shall notify the Controller unless legally prohibited and shall retain the affected data only to the extent and for the duration required by that law.
- If the Controller retains local copies on its own devices, deletion by the Processor cannot erase those controller-controlled copies.
13. Personal Data Breach
- The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting Customer Data.
- The notification shall include, where reasonably available:
- the nature of the breach
- the categories and approximate number of affected data subjects and personal data records
- likely consequences
- measures taken or proposed to address the breach
- contact details for follow-up
- Where all information is not available at once, the Processor shall provide it in phases without undue further delay.
- The Processor shall provide reasonable assistance requested by the Controller in assessing and responding to a personal data breach. Decisions about notifications to data subjects or supervisory authorities remain the Controller's responsibility.
14. Audits and Information Rights
- The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this Agreement.
- The Controller may request reasonable documentary evidence of compliance, including policies, summaries of technical measures, and sub-processor information.
- On reasonable written notice, and no more than once in any twelve-month period unless required by law, requested by a supervisory authority, following a material incident, or based on reasonable grounds to suspect non-compliance, the Controller may request an audit or inspection proportionate to the risk and scope of the processing.
- Any audit must:
- be carried out in a manner that minimises disruption
- avoid access to other customers' data
- respect the Processor's confidentiality and security obligations
- be subject to appropriate confidentiality undertakings by the auditor
- The Processor may satisfy audit obligations by providing recent independent documentation, policies, or detailed written responses where the Controller agrees that this is reasonably sufficient. Where it is not sufficient, the Processor shall allow for and contribute to a reasonable audit or inspection by the Controller or its mandated auditor.
- Where an audit or security review identifies a material finding, the Processor shall address it without undue delay, taking account of its severity and the risk to data subjects, and shall provide the Controller with a written remediation plan on request.
15. International Transfers
- The standard service configuration hosts customer storage in EU/EEA cloud regions and processes supported AI requests within an EU data zone.
- The Processor shall not transfer Customer Data outside the EEA except in accordance with Data Protection Law and this Agreement.
- If a restricted transfer becomes necessary, the Processor shall ensure that a valid GDPR Chapter V transfer mechanism, such as an applicable adequacy decision or Standard Contractual Clauses, is in place before the transfer occurs.
16. Liability and Order of Precedence
- This Agreement forms part of the agreement between the Parties for the Services.
- If there is a conflict between this Agreement and another agreement between the Parties concerning the processing of Customer Data, this Agreement prevails to the extent of that conflict.
- Liability between the Parties is governed by the Main Service Agreement except to the extent prohibited by Data Protection Law.
17. Termination
This Agreement terminates automatically when the Processor no longer processes Customer Data on behalf of the Controller, subject to any surviving obligations regarding deletion, confidentiality, and legal retention.
18. Governing Law and Jurisdiction
This Agreement shall be governed by the laws of Ireland, unless the Main Service Agreement expressly provides otherwise in a manner consistent with Data Protection Law. The courts of Ireland shall have exclusive jurisdiction over any dispute arising out of or in connection with this Agreement, save that either Party may seek injunctive or other urgent relief in any court of competent jurisdiction.
19. Signatures
Signed for and on behalf of the Controller:
Name: ____________________
Title: ____________________
Signature: ____________________
Date: ____________________
Signed for and on behalf of the Processor:
Name: ____________________
Title: ____________________
Signature: ____________________
Date: ____________________
Annex 1: Details of Processing
A. Parties
Controller: the school or educational body identified on page 1.
Processor: SENScribe Limited.
B. Subject matter
Provision of the SENScribe service for the management of Student Support Files and related student-support documentation.
C. Duration
For the term of the services plus any limited post-termination period required to complete deletion, return, or legally required retention.
D. Nature and purpose
- create, review, maintain and export student-support records
- store and sync encrypted records across authorised devices
- generate draft educational content using redacted and generalised AI requests
E. Data subjects
- students
- parents or guardians
- teachers, SETs and school staff
F. Categories of personal data
- teacher identifiers and account data
- student names, dates of birth and educational context data
- support plans, reviews, targets, interventions, log entries and related comments
- encrypted uploaded source or support documents
- sharing, invitation, recipient-email, sync, audit and security metadata
- browser-redacted and generalised AI prompts and outputs; user-entered free text may contain identifiers that automated detection does not recognise
- limited diagnostic and security metadata, which may include user identifiers and technical error information
- special-category educational and support-needs data where entered by the Controller
G. Special categories
May include health and special educational needs information.
H. Processing frequency
Continuous for the duration of service use.
Annex 2: Technical and Organisational Measures
A. Encryption and confidentiality
- student-support content is encrypted in the browser before cloud storage
- supported client connections use encrypted transport
- the service is designed to restrict the Processor's routine operational access to intelligible student-support content
- personnel authorised to process Customer Data are subject to confidentiality obligations
B. Access control and separation
- account and synchronisation services require authenticated access
- session controls restrict access to authorised users
- customer data is logically separated in storage
- internal access is limited to what is reasonably necessary to operate, secure and support the Services
C. Hosting, resilience and monitoring
- customer storage is hosted in EU/EEA cloud regions
- supported AI requests are processed in an EU data zone
- rolling backups support service resilience and expire through the documented thirty-day cycle
- limited operational and security logging supports service protection and incident investigation; covered diagnostic logs have a documented thirty-day retention
D. Data minimisation and AI processing
- supported AI requests undergo browser-side redaction and generalisation checks before transmission
- automated detection reduces risk but may not recognise every identifier in user-entered free text
- student-support record content is not intentionally included in transactional email
E. Retention, deletion and response
- authenticated deletion capability is available for server-side Customer Data
- active-system deletion and backup expiry follow Clause 12
- incident handling and Controller notification follow Clause 13
- sub-processors are contractually bound to applicable data-protection obligations
Additional technical assurance information may be provided where reasonably necessary for the Controller's assessment, subject to appropriate confidentiality and security restrictions.
Annex 3: Approved Sub-processors
Microsoft Ireland Operations Limited
- Services and purpose: EU/EEA cloud hosting, encrypted storage, supported AI processing, transactional email (including Azure Communication Services), security monitoring and operational diagnostics
- Data involved: encrypted customer content; account, request and limited diagnostic metadata; browser-redacted and generalised AI inputs and outputs; recipient and delivery metadata for service email; for secure review invitations only, the email-link half of a split decryption key
- Secure invitation links: for secure review invitations, the decryption key is split between the SENScribe application and the email delivery service. Azure Communication Services receives the email-link half only long enough to place it in the invitation link, and never holds both halves, so no single provider can decrypt a shared file on its own
- Location and safeguards: standard customer storage and supported AI processing are configured in EU/EEA regions or an EU data zone under the Microsoft Products and Services DPA
Plus Five Five, Inc. (Resend)
- Services and purpose: fallback transactional email delivery
- Data involved: recipient address, message content and delivery metadata; student-support record content is not intentionally included
- Location and safeguards: United States; EU-US Data Privacy Framework and EU Standard Contractual Clauses incorporated into Resend's DPA
Processor note:
- If additional sub-processors are added that process Customer Data, this Annex shall be updated and Controllers notified in line with Clause 10.
- The current authoritative list is published at https://senscribe.ie/sub-processors.
Annex 4: Record of Processing for SENScribe-Controlled Operations
This annex records, in general terms, the processing for which SENScribe Limited acts as an independent controller under Clause 2.3. It is maintained to support Article 30 GDPR. It does not cover Customer Data processed on behalf of the Controller, which is addressed in Annexes 1 to 3.
| Processing activity | Purpose and lawful basis | Categories of data subjects | Categories of personal data | Principal recipients | Retention (general terms) |
|---|---|---|---|---|---|
| Service accounts and support | Account creation, authentication, fair-use limits and user support; performance of a contract, and legitimate interests in operating and securing the service | Teachers and other authorised users | Email address; name where provided; school affiliation used for verification; session tokens; usage counts; timestamps; support correspondence | Providers listed in Annex 3 (hosting and email) | For the life of the account and a limited wind-down period after closure or deletion |
| Billing and payments | Subscription payment processing and invoicing; performance of a contract and compliance with legal obligations | Subscribing customers and billing contacts | Billing contact details and payment details | Payment provider (Revolut); invoicing provider (Zoho) | As long as necessary for the contractual relationship and applicable accounting or tax requirements |
| School licence enquiries | Managing prospective-school licence enquiries; legitimate interests in responding to enquiries, and steps at the enquirer's request ahead of a possible contract | Prospective customer contacts | Contact name; school or work email; optional phone number; role; school name and type; estimated staff requiring access; preferred licence; optional message. Pupil or student data is not requested | CRM provider (Zoho CRM) | As long as necessary to handle the enquiry and any resulting relationship, then deleted or minimised |
| Optional usage analytics | Consent-gated website and application usage measurement; consent | Website visitors and app users who accept analytics cookies | Pseudonymous browsing, URL, cookie and device data; Student Support File content is not intentionally sent | Analytics provider (Google Analytics 4) | In accordance with the analytics configuration and the user's cookie choices |
| Security and service logs | Service protection, incident investigation and abuse prevention; legitimate interests in securing the service | Authorised users and visitors | Limited operational and security metadata, which may include user identifiers and technical error information | Providers listed in Annex 3 | Covered diagnostic logs follow the thirty-day retention described in Annex 2 |
Notes:
- Security measures applicable to this processing are those described in Annex 2.
- Where a recipient processes personal data outside the EEA, the Processor relies on an appropriate GDPR Chapter V transfer mechanism, such as an applicable adequacy decision or Standard Contractual Clauses.
Annex 5: EU AI Act Readiness Position
This annex records SENScribe's current position on Regulation (EU) 2024/1689 (the EU AI Act) in general terms. It is a posture statement, not a regulatory classification of any individual deployment, and it will be reviewed as Commission guidance and implementing practice develop.
A. How AI is used
- AI is used only to help authorised staff generate and rewrite draft educational documentation
- Supported AI requests pass browser-side redaction and generalisation checks before transmission, subject to the automated-detection limitation recorded in Annex 1.F
- AI output is drafting assistance only. It does not determine, score, grade or recommend anything about any student, and authorised staff review and remain responsible for what is entered into a record
B. Role under the EU AI Act
- SENScribe provides AI functionality within its own service using third-party AI systems and therefore approaches the EU AI Act as a deployer rather than as a developer of general-purpose AI models
- Most remaining obligations of the EU AI Act, including obligations for high-risk systems under Annex III and transparency obligations under Article 50, apply from 2 August 2026; SENScribe monitors its position as guidance emerges
C. Educational-use boundaries
- The AI functions are not used for admission or selection decisions, assessment, grading or evaluation of students, proctoring, or monitoring of student behaviour during tests
- Systems used for those purposes fall within Annex III of the EU AI Act as high-risk in education; SENScribe's AI-assisted drafting is not offered for those purposes
D. Transparency and safeguards
- AI drafting and rewrite functions are identified as AI-assisted in the product interface, supporting the transparency expectations of Article 50 of the EU AI Act
- No emotion recognition, biometric categorisation or social scoring functionality is provided
- Controllers remain responsible for lawful use of AI-assisted drafts by their staff and for maintaining meaningful human oversight