Data Processing Agreement (DPA)

Last updated:

How acceptance works

When a member of your school staff with delegated authority ticks the "I accept" box during onboarding, that click has the same legal effect as a counter-signature on a paper contract. Under English contract law a clearly presented click-wrap acceptance forms a binding agreement, and under UK GDPR Article 28(9) a processing contract is valid where it is "in writing, including in electronic form". A counter-signed Word or PDF version is available on request and has identical legal effect.

1. Plain English preamble

Plain English: This document explains how Shuttle Learning handles your pupils' and teachers' data, and protects your school legally.

This Data Processing Agreement ("DPA") is between your school ("the School", the Controller) and Shuttle Learning Limited ("Shuttle Learning", the Processor), whose registered office is 167–169 Great Portland Street, London, England, W1W 5PF. The School decides why and how pupil and teacher data is used, and Shuttle Learning processes that data only to run an educational app that teaches OCR GCSE Computer Science (J277) in Python. UK GDPR Article 28 requires a written contract whenever a processor handles personal data for a controller, and this DPA is that contract. Pressing "I accept" during onboarding binds the School to this DPA.

2. Definitions

Controller — the body that decides the purposes and means of processing; here, the School. Processor — the body that processes on the Controller's behalf; here, Shuttle Learning. Personal Data — information relating to an identified or identifiable living person. Data Subject — the individual the Personal Data is about (students and teachers). Processing — any operation performed on Personal Data. Sub-processor — another processor engaged by Shuttle Learning; here, Google. Personal Data Breach — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data. School — the institution accepting this DPA. Student — a pupil aged 14 to 16 (a minor). Educational App — Shuttle Learning's Firebase-backed web platform. Attempts — records capturing a student's mark, feedback, marking notes and metadata; submitted source code is processed only to produce the mark and is then deleted (see §14). Lesson Summaries — per-student, per-lesson AI "What Went Well" and "Even Better If" notes plus MCQ scores. Gemini Outputs — scores and feedback produced by Google's Gemini API.

Aggregated Anonymised Data — data derived from pupil data that has been processed so that it relates to groups of individuals and does not identify, and cannot reasonably be used (by Shuttle Learning or anyone else) to identify or single out, any individual. It comprises per-question totals of the kind described in §14a. Once data meets this definition it is no longer Personal Data.

3. Parties and how acceptance works (Art 28(9))

The parties are the School (Controller) and Shuttle Learning Limited (Processor). Acceptance is by click-wrap: a member of school staff with delegated authority (a Head Teacher, Deputy Head, Head of Department, or Data Protection Officer) creates the school's first teacher account and ticks the acceptance box during onboarding. This binds the School. UK GDPR Article 28(9) provides that the contract shall be in writing, including in electronic form, and English contract law (consistent with the Law Commission's 2019 report on electronic execution) treats a clearly presented "I accept" tick, made with intent to authenticate, as valid acceptance forming a binding contract. A counter-signed Word or PDF version is available from support@shuttlelearning.com with identical legal effect.

4. Scope, subject matter and duration

The duration runs from the date the School accepts this DPA at onboarding until termination under Section 13. The School's identifying details (name, address and contact) and the acceptance date are captured automatically and recorded against the accepted version, as described in Section 23.

5. Nature and purpose of processing

Plain English: Educational use only. We do not advertise, profile, sell data or train AI on student work.

Processing is for educational purposes only. Shuttle Learning explicitly does NOT: serve advertising; profile students for commercial purposes; sell Personal Data; or use student work to train or improve AI models. The Gemini API is used on its paid tier, and Google's Gemini API Additional Terms of Service state that when paid services are used, Google does not use prompts or responses to improve its products and processes them in accordance with its Data Processing Addendum for products where Google is a data processor.

There is no analytics, advertising, tracking or behavioural processing of any kind in the Educational App. Shuttle Learning may generate Aggregated Anonymised Data as permitted by §14a; this is not Personal Data and cannot be linked to any student. This reflects the data-minimisation and "no commercial use of pupils' intellectual property" expectations in the ICO Children's Code and the DfE's "Generative AI: product safety expectations" (22 January 2025).

6. Categories of personal data and data subjects

Categories of Personal Data: school Microsoft email; Firebase Auth UID; display name; role (student or teacher, set by Shuttle Learning's server at account creation and not selectable by the user); classroom membership (classId, teacherId, student UID lists, join code); submitted source code (processed to produce the mark, then deleted — see §14); MCQ answers; Gemini scores, feedback and marking notes; Lesson Summaries; rate-limit counters; "report a problem" messages and any work attached to them; and server logs (account identifiers, lessonId, questionId and counts; pupil email addresses and pupil work are not logged). Approximate country-level location may be inferred. Data subjects: students (minors aged 14 to 16) and teachers. Shuttle Learning does NOT process home address, phone number, payment details, biometrics, advertising identifiers, or any location beyond approximate country.

7. Documented instructions from the Controller (Art 28(3)(a))

The School instructs Shuttle Learning to process the categories listed in Section 6 to deliver the Educational App according to its functionality, and for no other purpose without further documented instruction. This DPA, together with the onboarding configuration, constitutes the School's documented instructions. If a legal obligation requires Shuttle Learning to process outside these instructions, including in relation to transfers to a third country, it will inform the School first unless the law prohibits this on important grounds of public interest. Under Article 28(10), a processor that determines the purposes and means of processing is considered a controller in respect of that processing, and Shuttle Learning accepts controller responsibility in any such case.

8. Confidentiality (Art 28(3)(b))

All Shuttle Learning personnel authorised to process Personal Data are committed to confidentiality, whether by contract or an appropriate statutory duty. This covers employees, temporary workers and contractors with access to Personal Data. Access is granted on a least-privilege, need-to-know basis, and is logged and reviewed.

9. Security measures (Art 28(3)(c) + Art 32)

Plain English: A layered set of technical and organisational controls. The list below is illustrative, not exhaustive.

Taking into account the state of the art, the costs of implementation and the risks to data subjects, Shuttle Learning implements appropriate technical and organisational measures under Article 32, including: Microsoft school sign-in restricted to pre-enabled school domains, with roles set server-side at account creation; Firestore Security Rules that deny direct client writes to grading data; all grading writes performed server-side via the Google Admin SDK; encryption in transit (HTTPS) and at rest; per-user rate limits (30 submissions per minute, 200 per day); a cap of 8,000 characters per submission; secrets such as GEMINI_API_KEY held in Google Secret Manager; multi-factor authentication on all developer and admin accounts; UK and EU data residency; deletion of submitted source code at the point of marking; and regular review against ICO and NCSC guidance. See Annex B for detail. This list is illustrative and not exhaustive; measures evolve as risks change.

10. Sub-processors (Art 28(2) + Art 28(4))

Plain English: Google is our only sub-processor. We tell you before any new one and you can object.

The School gives general written authorisation for Shuttle Learning to engage sub-processors. Shuttle Learning's sole sub-processor is Google (Google LLC and Google Cloud EMEA Limited), providing six services: Firebase Authentication; Cloud Firestore (eur3 multi-region); Cloud Functions (europe-west1); Firebase Hosting; Cloud Logging; and the Gemini API paid tier (gemini-2.5-flash-lite), used for both marking and classification as described in §16. Shuttle Learning will give 30 days' notice by email of any new or replacement sub-processor, giving the School the opportunity to object on reasonable data-protection grounds within that window; if the objection cannot be resolved, either party may terminate. Shuttle Learning imposes on its sub-processors the same data protection obligations as set out in this DPA, and remains fully liable to the School for its sub-processors' compliance. Google's Cloud Data Processing Addendum is incorporated by reference.

11. Assistance with data subject rights (Art 28(3)(e))

Taking into account the nature of processing, Shuttle Learning assists the School by appropriate technical and organisational measures, insofar as possible, to respond to data subject requests under Articles 15, 16, 17, 18, 20, 21 and 22. Service level: Shuttle Learning will respond to a written request for assistance within 5 working days, unless complexity requires longer, in which case it will notify the School in advance. Shuttle Learning routes any direct student or parent request to the School, which instructs Shuttle Learning accordingly.

Scope of erasure. On the School's instruction to erase a student, Shuttle Learning deletes: submitted work, lesson summaries, class memberships, the user profile, "report a problem" messages, and the sign-in account. Shuttle Learning retains a deletion receipt recording the account identifier, what was deleted and when, in order to demonstrate that the request was carried out (accountability, Article 5(2)). The receipt contains no pupil work.

12. Personal data breaches (Art 28(3)(f) + Art 33–34)

Plain English: We tell you without undue delay and within 24 hours, and help you respond.

Shuttle Learning will notify the School without undue delay and within 24 hours of becoming aware of a Personal Data Breach, providing the information required by Article 33(3): the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed. The School decides whether to notify affected data subjects under Article 34; Shuttle Learning will assist. Where Shuttle Learning is itself controller for some data, it will notify the ICO directly where required.

13. Termination and return or deletion of data (Art 28(3)(g))

On termination, at the School's choice, Shuttle Learning will return all Personal Data in a portable format AND delete its copies within 30 days. Daily backups are retained for 7 days and then overwritten; point-in-time recovery is not enabled. Any copy remaining in a backup is put beyond use and is automatically overwritten within 7 days, consistent with ICO guidance that data in backups need not be deleted instantly provided it is beyond use and deleted on the next cycle. Shuttle Learning will confirm deletion in writing on request. The School may request mid-term deletion of individual students under Section 11.

14. Retention while the agreement is in force

Plain English: Everything has a deletion date, except teacher accounts, which we remove by hand when the agreement ends.

Submitted source code is deleted at the moment the score and feedback are saved. If marking fails, the code is retained for up to 24 hours so the failure can be investigated, and is then deleted automatically.

Pupil work and progress data (scores, feedback, marking notes and Lesson Summaries) are deleted 12 months after the end of the school year to which they belong; the school year ends on 1 August. Pupil accounts and class memberships are deleted 12 months after the account was last signed in to. "Report a problem" messages, including any work a pupil chose to attach, are deleted within 30 days of the report being resolved. Class records and join codes are not pupil data and are not on this schedule.

Teacher accounts and teacher data are not deleted automatically. They are retained for the duration of the agreement with the School and removed manually when it ends.

These retention periods are implemented by an automated deletion job. All retention periods are overridable by the School in writing.

14a. Aggregated Anonymised Data

Plain English: We keep anonymous per-question totals — such as how many pupils found a question hard — to improve our teaching materials. They identify nobody.

14a.1 The School instructs and authorises Shuttle Learning to create Aggregated Anonymised Data from pupil data. Creating it is Processing carried out on the School's documented instructions for the purposes of Article 28.

14a.2 Method. After a submission has been marked, a separate classification step receives only the score, feedback and marking notes — never the pupil's source code — and returns a single label from a fixed list of fourteen (for example "syntax error", "off by one"). It cannot return free text. Multiple-choice questions are classified without AI involvement, and the option chosen by the pupil is not recorded. Shuttle Learning then stores one record containing only: lesson identifier, question identifier, whether the attempt was code or a quiz, the label, whether the pupil scored none, some or all of the available marks, and the date (date only, never a time). The record contains no name, account identifier, class, source code or feedback.

14a.3 Deletion of the underlying records. These records are combined into per-question totals and the underlying records are then deleted, so that no record remains which could be matched back to an individual submission.

14a.4 Suppression of small groups. A question attempted fewer than 10 times produces no visible breakdown, and any single error label occurring fewer than 5 times is suppressed, so that no individual can be singled out. Shuttle Learning does not attempt, and does not permit any third party to attempt, to re-identify any individual from Aggregated Anonymised Data, and does not combine it with other data for that purpose. These measures are reviewed periodically against changes in technology and re-identification risk.

14a.5 Use. Shuttle Learning may retain and use the per-question totals for its own purposes, namely improving its teaching materials and the Service, without time limit. Only Shuttle Learning has access to them; they are not exposed to pupils or teachers.

14a.6 For the avoidance of doubt, Shuttle Learning does NOT use identifiable pupil data — including submitted source code, or marks and feedback attributable to an individual — for product development, research, analytics for its own purposes, or the training of any AI model. Marks and feedback attributable to an individual are processed solely as processor to deliver the Service.

15. International transfers

Plain English: Storage stays in the EU. Gemini calls may touch US infrastructure, covered by approved transfer terms.

Storage and compute are pinned to EU regions. Cloud Firestore uses the eur3 multi-region, comprising read-write replicas in europe-west1 (Belgium) and europe-west4 (Netherlands) with a witness replica in europe-north1 (Finland), so stored data remains within the EU; Cloud Functions run in europe-west1. Gemini API calls may process prompts on Google infrastructure that could include the United States. Any such restricted transfer relies on the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum (the ICO-approved mechanisms in force since 21 March 2022), as incorporated into Google's Cloud Data Processing Addendum, supported by a transfer risk assessment. Shuttle Learning will not initiate new restricted transfers without an appropriate Article 46 safeguard in place.

16. AI-marked submissions (Gemini)

Plain English: Marking uses the paid Gemini API. Google does not train on paid prompts. The AI's marks are formative; the teacher assesses the pupil.

Marking uses the paid Gemini API tier (gemini-2.5-flash-lite). Google's Gemini API Additional Terms of Service state that when paid services are used, Google does not use prompts or responses to improve its products. Submissions are capped at 8,000 characters before being sent.

Two calls are made to Google per submission. The first (marking) receives the student's submitted source code or quiz answer plus the lesson and question identifiers, and returns a score and feedback. The second (classification) receives only the score, feedback and marking notes produced by the first — never the source code — and returns one label from a fixed list, used solely for the Aggregated Anonymised Data described in §14a. Neither prompt contains the student's name or email address.

Retention by Google. Zero Data Retention (ZDR) is not enabled for Shuttle Learning's Gemini configuration. Google's standard abuse-monitoring logging therefore applies: for paid services Google logs prompts and responses for a limited period (currently up to 55 days) solely to detect violations of its Prohibited Use Policy and any required legal or regulatory disclosures, does not use them to train its models, and then deletes them. Both calls described above are subject to that logging and may transit outside the UK and EU including the US (see §15). Shuttle Learning keeps its configuration under review and will notify the School of any material change.

The AI's score is decision-support and formative feedback. It is never a grade of record and is not solely-automated decision-making within the meaning of Article 22: the score is validated server-side before it is shown, a teacher has visibility of marking, and the teacher retains responsibility for assessing the student.

17. Audit and compliance (Art 28(3)(h))

Shuttle Learning maintains records of its processing activities under Article 30 and makes available to the School all information necessary to demonstrate compliance with Article 28. On reasonable written notice (at least 30 days) and no more than once per 12 months (unless following a Personal Data Breach), the School may conduct an audit or inspection, or rely on a third-party audit or industry certification that Shuttle Learning provides. Audit costs are borne by the School unless material non-compliance is found, in which case Shuttle Learning bears reasonable costs.

18. Liability and indemnity

Each party is liable for its own breach of this DPA and of UK GDPR, and nothing in this DPA relieves either party of its direct responsibilities under UK GDPR. Liability is capped at £10,000. [TO CONFIRM with solicitor: state whether the cap is per claim, per year or in aggregate, and whether £10,000 is appropriate for children's-data processing — a school's procurement team may query it.] Carve-outs from the cap apply for: fines or losses arising from the other party's breach; intellectual property infringement; and breach of confidentiality. Nothing limits liability that cannot be limited or excluded by law, including liability for death or personal injury caused by negligence. Any limitation of liability must be fair and reasonable under the Unfair Contract Terms Act 1977.

19. Governing law and jurisdiction

This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

20. Variations and entire agreement

Variations are valid only in writing; electronic acceptance counts as writing for this purpose. This DPA, together with its annexes and the onboarding configuration, is the entire agreement on data processing between the parties and supersedes prior arrangements on that subject.

21. Annex A — Sub-processor list

The live current list is maintained at https://shuttlelearning.com/legal/sub-processors.

Sub-processor service

Provider

Processing location

Reference

Firebase Authentication

Google LLC / Google Cloud EMEA Ltd

EU/UK

Google Cloud DPA

Cloud Firestore

Google LLC / Google Cloud EMEA Ltd

eur3 (Belgium, Netherlands; witness Finland)

Google Cloud DPA

Cloud Functions

Google LLC / Google Cloud EMEA Ltd

europe-west1 (Belgium)

Google Cloud DPA

Firebase Hosting

Google LLC / Google Cloud EMEA Ltd

Global CDN, EU origin

Google Cloud DPA

Cloud Logging

Google LLC / Google Cloud EMEA Ltd

EU/UK

Google Cloud DPA

Gemini API (paid tier, gemini-2.5-flash-lite) — marking and classification

Google LLC / Google Cloud EMEA Ltd

EU with possible US transit

Google Cloud DPA + Gemini API terms

Google's Cloud Data Processing Addendum and Google Cloud sub-processor list are incorporated by reference.

22. Annex B — Technical and organisational measures

Authentication. Microsoft school sign-in only for pupils and teachers, restricted to school domains enabled in advance via a Firestore allowlist and a beforeUserCreated blocking function. The student-or-teacher role is set by the server at account creation from a list agreed with the School, and cannot be chosen or changed by the person signing in. A separate email-and-password route exists for Shuttle Learning staff and demonstration accounts only and is not used by pupils. The Google sign-in provider is disabled.

Firestore Security Rules. Deny-all client writes on grading and summary collections; reads scoped to the authenticated user and their class. The anonymous statistics collections are neither client-readable nor client-writable.

Server-side grading. All writes to grading and summary collections are performed server-side via the Google Admin SDK.

Rate limits and input caps. 30 submissions per minute and 200 per day per user; submissions capped at 8,000 characters.

Secret management. GEMINI_API_KEY and other secrets held in Google Secret Manager, never in client code.

Multi-factor authentication. Enforced on all developer and admin accounts.

Data minimisation. Submitted source code is deleted at the point of marking (24-hour exception on marking failure). Pupil email addresses are not written to system logs.

Backups and resilience. Daily backups retained for 7 days then overwritten; point-in-time recovery is off; backups are used only to restore the service after a failure and never to reinstate deleted data.

Monitoring and logging. Cloud Logging captures account identifiers, lessonId, questionId and counts. Pupil work and pupil email addresses are never logged.

Encryption. HTTPS in transit and encryption at rest across Google Cloud services.

Data residency. Storage and compute pinned to EU regions.

Incident response. Documented breach procedure feeding the 24-hour notification in Section 12.

Note: Firebase App Check (reCAPTCHA attestation) was considered and has not been enabled. Earlier versions of this DPA listed it; that statement was inaccurate and has been removed.

23. How this DPA is recorded as accepted

When a member of school staff with delegated authority ticks the "I accept" box during onboarding, Shuttle Learning records the school's acceptance against this version of the DPA: the school name, the name and role of the person who accepted, the email address used, the timestamp, and the DPA version number. That record is the School's countersignature for the purposes of UK GDPR Article 28(9). A counter-signed Word or PDF version, recording the same details, is available on request to support@shuttlelearning.com.


Logo

All trademarks, logos and brand names are the property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, trademarks and brands does not imply endorsement.


Follow us on:

Icon
Icon
Icon
Icon
Icon

Support@shuttlelearning.com

Logo

All trademarks, logos and brand names are the property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, trademarks and brands does not imply endorsement.


Follow us on:

Icon
Icon
Icon
Icon
Icon

Support@shuttlelearning.com

Logo

All trademarks, logos and brand names are the property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, trademarks and brands does not imply endorsement.


Follow us on:

Icon
Icon
Icon
Icon
Icon

Support@shuttlelearning.com