Data Processing Agreement

Version 1.0 Last updated 11 October 2026 England and Wales

This agreement applies when ActivityOS handles personal data on behalf of a school, club, studio or other organisation that uses the ActivityOS platform. It forms part of the main agreement between the two parties, and the customer accepts it by creating an account or using the platform.

ProcessorStephen Butterworth, a sole trader trading as ActivityOS, of c/o North Wales Accounting, Apartment 31, St. Trillo's Court, Rhos Promenade, Rhos on Sea, Conwy, LL28 4PY ("ActivityOS", "we")
ControllerThe school, studio, club or organisation that holds an ActivityOS account (the "Customer")

1Definitions

1.1

Data Protection Laws means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, each as amended from time to time, including by the Data (Use and Access) Act 2025.

1.2

Personal Data, Data Subject, Controller, Processor, Processing, Personal Data Breach and Special Category Data have the meanings given in the Data Protection Laws.

1.3

Customer Data means all Personal Data that the Customer or its users enter into, upload to or create through the ActivityOS platform, including data about pupils, parents, guardians and staff.

1.4

Services means the ActivityOS platform and related support, as described in the main agreement. Sub-processor means a third party we engage to process Customer Data.

2Roles and scope

2.1

For Customer Data, the Customer is the Controller and ActivityOS is the Processor.

2.2

Schedule 1 sets out the subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects.

2.3

ActivityOS is a separate Controller of the account data it holds about the Customer's users for its own purposes, such as managing accounts, billing the subscription, security and support. That data is covered by our Privacy Policy and not by this agreement.

3Instructions

3.1

We process Customer Data only on the Customer's documented instructions, including on transfers outside the UK, unless the law requires otherwise. If it does, we will tell the Customer before processing unless the law prevents us. The main agreement, this agreement and the Customer's use and configuration of the platform are the Customer's complete instructions.

3.2

If we believe an instruction breaks the Data Protection Laws, we will tell the Customer promptly and may pause that instruction until it is clarified.

3.3

We do not sell Customer Data or use it for advertising. We use it only to provide, secure and support the Services.

4Customer responsibilities

4.1

The Customer is responsible for having a lawful basis for the data it enters and for telling Data Subjects, including parents and guardians, how their data is used.

4.2

Most pupils are children. Where the Customer relies on consent, for example for photographs, performances or sharing health information, it must obtain it from a parent or guardian and keep the record up to date.

4.3

If the Customer records health information, it must have a condition under Article 9 of the UK GDPR. If it records DBS check information, it must have a lawful basis under Article 10 and the Data Protection Act 2018. The Customer should enter only what it needs.

4.4

The Customer controls who has access to its account and what each staff member can see, and is responsible for keeping sign-in details secure.

5Confidentiality

5.1

Everyone we authorise to process Customer Data is bound by a duty of confidentiality and can access it only as far as their work requires.

6Security

6.1

We keep appropriate technical and organisational measures in place to protect Customer Data, including:

  • (a)encryption in transit using TLS;
  • (b)storage on infrastructure that encrypts data at rest;
  • (c)separation between customers, using row-level security so each Customer's data is visible only to its own authorised users;
  • (d)role-based access, so the Customer's owner decides which modules staff can use, and parents and guardians can see only records linked to their own children;
  • (e)verification of signatures on payment and email provider notifications before acting on them;
  • (f)weekly database backups, encrypted with AES-256 before they are stored; and
  • (g)access to production systems limited to the people who need it.
6.2

We review these measures regularly. We may change them, but not in a way that reduces the overall level of protection.

7Sub-processors

7.1

The Customer gives general authorisation for us to use the Sub-processors listed in Schedule 2.

7.2

We will give at least 30 days' notice, by email or in the platform, before adding or replacing a Sub-processor.

7.3

The Customer may object on reasonable data protection grounds during that notice period by writing to the contact in clause 16. We will try to resolve the objection. If we cannot, the Customer may end the affected Services and receive a pro-rata refund of fees paid for the period after termination.

7.4

We have a written contract with each Sub-processor that gives data protection obligations no less protective than this agreement, except that Google Drive is used only to hold backups that are encrypted before upload, so Google cannot read them. We remain responsible to the Customer for each Sub-processor's performance.

8International transfers

8.1

Customer Data is stored in Germany. The UK recognises the European Economic Area as providing adequate protection for personal data.

8.2

Some Sub-processors process data outside the UK and EEA, including in the United States. We allow this only where a lawful transfer mechanism applies: the UK Extension to the EU-US Data Privacy Framework (the UK-US Data Bridge) for certified providers, or the ICO's International Data Transfer Agreement or UK Addendum to the EU standard contractual clauses. Schedule 2 states the position for each Sub-processor.

8.3

The Customer instructs us to make the transfers described in Schedule 2.

9Data subject rights

9.1

We help the Customer respond to requests from Data Subjects, such as access, correction and deletion, through the platform's tools and, where needed, direct assistance.

9.2

If a Data Subject contacts us directly about Customer Data, we will not respond on the Customer's behalf. We will pass the request to the Customer without undue delay.

10Personal data breaches

10.1

We will tell the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Data.

10.2

The notice will describe, as far as we know, what happened, the categories and approximate number of people and records affected, the likely consequences, what we have done and what we propose to do, and a contact for questions. We may provide this in stages as we learn more.

10.3

We will take reasonable steps to contain the breach and will co-operate so the Customer can meet its own duties to notify the ICO and affected individuals.

11Assistance

11.1

Taking into account the nature of the Processing and the information we hold, we will help the Customer meet its obligations under Articles 32 to 36 of the UK GDPR, which cover security, breach notification, data protection impact assessments and prior consultation with the ICO.

12Audits and information

12.1

On reasonable written request, we will give the Customer the information needed to show that we comply with this agreement and Article 28 of the UK GDPR.

12.2

The Customer, or an independent auditor bound by confidentiality, may audit our compliance once in any 12 months, or sooner after a Personal Data Breach or if a regulator requires it. The Customer must give at least 30 days' written notice, audit during business hours, avoid unreasonable disruption and pay its own costs.

12.3

We may meet an audit request by providing recent third-party audit reports or certifications for our Sub-processors and written answers to a reasonable security questionnaire, where these give the information required. An audit does not extend to other customers' data.

13Retention and deletion

13.1

We keep Customer Data while the Customer's account is active. The Customer decides what to keep and can delete records at any time.

13.2

Unless the Customer instructs otherwise, the platform applies these rules:

  • (a)students, classes, festivals and events that the Customer deletes are held for 30 days and then permanently deleted;
  • (b)invoices that the Customer deletes are held for six years before permanent deletion, because they are financial records; and
  • (c)declined registration requests are deleted after 90 days.
13.3

When the agreement ends, or on the Customer's written request, we will make Customer Data available for export for 30 days and then permanently delete it from live systems within a further 30 days, unless the law requires us to keep it. Encrypted backups are deleted on their normal weekly cycle, and no later than six weeks after the live data is deleted. Some records are kept for the periods in Schedule 1, for example invoices for six years.

13.4

On request, we will confirm in writing that deletion is complete.

14Liability

14.1

Each party's liability under this agreement is subject to the limits in the main agreement. Nothing in this agreement limits liability that the law does not allow to be limited.

15Term, changes and law

15.1

This agreement lasts for as long as we process Customer Data.

15.2

We may update it to reflect changes in the law or the Services. We will give at least 30 days' notice of material changes and keep the version history below.

15.3

If this agreement conflicts with the main agreement on the handling of Customer Data, this agreement prevails.

15.4

This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

16Data protection contact

16.1

For questions about this agreement, to raise an objection under clause 7, or to report a concern about how Customer Data is handled, contact hello@activityos.co.uk.

Stephen Butterworth, trading as ActivityOS, c/o North Wales Accounting, Apartment 31, St. Trillo's Court, Rhos Promenade, Rhos on Sea, Conwy, LL28 4PY.

Schedule 1Details of processing

Subject matter
Providing the ActivityOS platform, which helps schools, clubs and studios run classes, bookings, attendance, invoicing and communication with parents.
Duration
The term of the agreement, plus the deletion period in clause 13.
Nature and purpose
Storing, organising, displaying, sending and deleting Customer Data so the Customer can manage its classes, timetables, enrolments, attendance registers, invoices and payments, competition entries and results, events, uniform orders, staff and communications with parents and guardians.
Data subjects
  • Pupils and students, many of whom are children
  • Parents, guardians and emergency contacts
  • Teachers, staff and contractors of the Customer
  • Prospective pupils and parents who request a trial or register an interest
Personal data
  • Pupils: name, date of birth, school attended, class enrolments, attendance, progression, competition entries and results, notes
  • Parents and guardians: name, email, phone, relationship to the pupil, emergency contacts, collection notes
  • Consents: photograph, social media, performance, medical treatment and health data consents, with dates
  • Staff: name, email, role and permissions, DBS check level, dates and certificate number
  • Billing: invoices, payment status and references, the Customer's bank details, direct debit mandate references and the last two digits of a parent's bank account
  • Communications: messages between teachers and parents, email broadcasts with delivery and open status, push notification subscriptions
  • Technical: sign-in details, and IP address and browser information recorded when someone accepts terms or submits a public registration form
Special category data

Pupil health information entered by the Customer or by parents on its behalf: allergies, medical conditions, emergency action, GP name and phone number. See clause 4.3.

Article 9
Criminal offence data

DBS check records for staff, where the Customer chooses to record them.

Article 10

Schedule 2Sub-processors

By accepting this agreement, the Customer approves these Sub-processors. Customer Data is stored in Germany and may be processed by the others as described.

Supabase, Inc. Database

Purpose
Database hosting and user authentication.
Data
All Customer Data held in the platform.
Location
Germany (Frankfurt, AWS eu-central-1).
Transfers
Stored in Germany. The UK recognises the EEA as adequate. Supabase's data processing agreement includes standard contractual clauses with the UK Addendum for any support access from outside the UK and EEA.

Cloudflare, Inc. Hosting

Purpose
Hosting the ActivityOS web app, running the platform's server-side processing and network security.
Data
Customer Data while a request is being processed. No Customer Data is stored in Cloudflare databases.
Location
Global network. Requests are handled in a data centre near the user.
Transfers
Cloudflare's data processing addendum, which includes standard contractual clauses with the UK Addendum, and Cloudflare's Data Privacy Framework certification.

Resend, Inc. Email

Purpose
Sending email from the platform: invoices, payment reminders, sign-in and account emails, and messages the Customer sends to parents.
Data
Recipient names and email addresses, message content, delivery and open status.
Location
United States.
Transfers
Resend's data processing agreement, which includes standard contractual clauses with the UK Addendum, and the UK-US Data Bridge where Resend is certified.

Stripe Payments UK Ltd and Stripe, Inc. Payments

Purpose
Card payments for fees, uniform and events, and subscription billing.
Data
Payer name, email, amounts and payment references. ActivityOS does not receive or store full card numbers. Stripe is also an independent Controller for fraud prevention and its legal obligations.
Location
United Kingdom, EEA and United States.
Transfers
Stripe's data processing agreement, which includes standard contractual clauses with the UK Addendum, and Stripe's Data Privacy Framework certification.

GoCardless Ltd Direct debit

Purpose
Direct debit collection, only where the Customer has turned it on.
Data
Parent name and email, mandate and payment references, and the last two digits of the bank account.
Location
United Kingdom and EEA.
Transfers
None expected. GoCardless processes in the UK and EEA, both covered by UK adequacy rules.

Google LLC (Google Drive) Backups

Purpose
Storing weekly database backups.
Data
Encrypted backup files. They are encrypted with AES-256 before upload, and Google does not hold the key.
Location
Google's global infrastructure.
Transfers
Google's Data Privacy Framework certification (UK-US Data Bridge) and its standard contractual clauses. Files are encrypted before upload.

Browser push services Notifications

Purpose
Delivering push notifications to users who have turned them on, through Google (Firebase Cloud Messaging), Apple or Mozilla, depending on the user's browser.
Data
Notification text, which can include a pupil's name, and the user's browser subscription token.
Location
United States and global.
Transfers
Google, Apple and Mozilla each rely on the UK-US Data Bridge or standard contractual clauses with the UK Addendum. Payloads are encrypted in transit.