Back to policies

Data Processing Agreement

Processor terms for schools and organisations using EduInsight.

Published
4 May 2026
Last updated
5 January 2026
Next review
5 January 2026
Version
Version 1

Roles and scope

Schools, trusts, local authorities, federations and other customer organisations normally act as controller for the personal data they upload or generate in EduInsight. EduInsight acts as processor when providing the platform and related support services, except where it acts as controller for its own account, billing, security and service administration records.

The processing covers account administration, staff and group management, observations, learning walks, feedback workflows, templates, reports, PDF exports, billing administration, support and security operations.

EduInsight processes customer personal data only on documented customer instructions, including instructions given through platform configuration and authorised user actions.

Processor commitments

EduInsight maintains appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage.

EduInsight ensures personnel with access to customer data are subject to confidentiality obligations and only access data where necessary for their role.

EduInsight will assist customers, taking into account the nature of processing, with reasonable requests relating to data subject rights, security, deletion, return of data and compliance evidence.

Subprocessors

EduInsight may use subprocessors for hosting, database services, file storage, authentication, directory integrations, email delivery, payment processing, analytics necessary for service operation and support tooling.

Subprocessors must support the delivery, security or administration of the service and must be subject to appropriate contractual safeguards.

Where international transfers are relevant, EduInsight uses appropriate safeguards such as adequacy arrangements or approved contractual mechanisms.

Deletion and return

At the end of service, customers may request export, deletion or return of customer data, subject to legal, security, backup and accounting retention requirements.

Backup deletion may follow the normal backup lifecycle rather than immediate physical deletion from every backup copy.

DPA questions can be sent to privacy@eduinsightobserve.com.

Security note

These public policies intentionally use general security descriptions. We do not publish exact infrastructure providers, deployment locations, internal routes or implementation-level operational details.

This policy is reviewed regularly to ensure compliance.

Back to policies
Data Processing Agreement | EduInsight Observe | EduInsight Observe