Data Processing Agreement

For schools · Last updated: 6 September 2026

This sets out how we handle personal data when a school uses GCSE Tutor with its pupils. It is written to meet Article 28 of the UK GDPR. A signed copy is available on request from privacy@gcsetutor.app.

The short version

We hold a pupil's email address, and counters showing how much they have studied. We do not store anything a pupil writes. There is no conversation history in our database, in the browser, or anywhere else — questions and answers are processed and then gone.

That means we cannot hand you a transcript, because there isn't one. It also means there is very little for us to lose.

1. Roles

The school is the data controller. It decides which pupils use the service and why.

GCSE Tutor (Lucian Paduraru, sole trader, South Yorkshire, UK) is the data processor, acting only on the school's documented instructions. We are registered with the Information Commissioner's Office.

2. Subject matter, duration, nature and purpose

  • Subject matter — providing an online GCSE revision service to pupils the school enrols.
  • Duration — for as long as the school's account is active, plus the retention periods in section 7.
  • Nature — storage of account and progress data; transient processing of questions and answers to generate a tutoring response.
  • Purpose — nothing but delivering the service. We do not profile pupils, sell data, or use it for advertising.

3. Categories of data subject

Pupils enrolled by the school, and staff members given an account to oversee them.

4. Personal data processed

Stored:

  • Email address, and the time of each sign-in.
  • Progress counters — XP, level, streak, last study date, and per subject: questions asked, practice sets completed, XP earned. Numbers only.
  • Subscription status — plan and expiry. Card details are never seen by us; they go directly to Stripe.

Processed but not stored:

  • Questions and answers. A pupil's message is sent to our tutoring server, used to generate a reply, and not written to any database or file. It is held in the browser tab only while the lesson is open and is gone when the page is closed or refreshed.
  • Browser type, for anonymous visitors before sign-up, used to count free questions. The IP address is combined with it, hashed, and discarded — we keep the hash, not the address.

We do not ask for, and have no field for, a pupil's name, date of birth, address, phone number, photograph, SEN status, or any special category data.

5. Sub-processors

We use these, and no others:

  • Supabase — database and authentication. The project runs in AWS eu-central-2, which is Zurich, Switzerland.
  • Vercel — serves the website.
  • Cloudflare — DNS and the secure tunnel to our tutoring server.
  • Stripe — payments. They are a controller in their own right for card data.
  • Resend — account emails such as receipts and password resets.

Nothing a pupil writes is sent to OpenAI, Google, Anthropic or any other AI provider, and nothing is used to train any model.

We will tell the school before adding or replacing a sub-processor, and the school may object.

6. Security measures

  • All traffic over HTTPS/TLS.
  • Passwords stored only as hashes, by Supabase; we never see them.
  • Row-level security on every table, so one account cannot read another's data.
  • The tutoring server is not exposed to the internet directly; it is reached through an authenticated tunnel.
  • Access to production data is limited to the sole trader named above.
  • The strongest measure is architectural: because conversations are never written down, a breach of our database cannot expose anything a pupil wrote.

7. Retention and deletion

  • Questions and answers — not retained at all.
  • Every account and its progress data is deleted on 30 June each year, at the end of the exam season, whether or not anyone asks. Nothing is carried into the next exam year. Accounts with a subscription still running on that date are deleted when it ends instead. This is automatic, not a promise to remember: it runs as a scheduled job in the database.
  • On the school's written request we delete all pupil accounts and progress data within 30 days and confirm in writing. This is a term we are offering, not a statutory deadline.
  • A pupil can delete their own account from inside the app at any time. It is removed from our database, not merely deactivated, and any subscription attached to it is cancelled at the same time.
  • Payment records are kept for 7 years, as UK tax law requires.
  • Anonymous free-question counters are kept for 12 months, then deleted.
  • One item survives a deletion, and we would rather state it than have you find it. The 48-hour free trial is available once per email address, so when an account is deleted we keep a one-way hash of that address — nothing else, no name and no history. It cannot be reversed into an address, it is unreadable outside our server, and it is used for one purpose only: refusing a second free trial to the same address. It is cleared with everything else in the 30 June deletion.

8. Assisting the school

We will help the school meet its own obligations: responding to a pupil's or parent's subject access, rectification, erasure or portability request within one month, which is the period UK GDPR allows, and sooner where we can; and providing the information needed for a Data Protection Impact Assessment.

9. Personal data breaches

We will notify the school without undue delay after becoming aware of a breach affecting its pupils, with what we know at that point, and keep it updated as we learn more. That is the standard UK GDPR sets for a processor. The school, as controller, then has 72 hours to report onward to the ICO if it decides it must; we will provide whatever it needs to make that decision.

10. International transfers

Everything a pupil writes is processed in the United Kingdom, on our own hardware in Barnsley, South Yorkshire. It is not sent abroad and it is not sent to any third-party AI provider.

Account data — the email address, sign-in times and progress counters — is held by Supabase in Zurich, Switzerland (AWS eu-central-2). That is a transfer to a third country and it needs no additional safeguard: Switzerland holds a UK adequacy decision, and since 1 September 2023 its own revised Federal Act on Data Protection is aligned with the GDPR. Where any other sub-processor transfers data outside the UK it does so under the UK International Data Transfer Addendum or an adequacy decision.

We will not move processing to a new country without telling the school first. This paragraph said "hosted in the EU" until 15 September 2026, which was wrong — Switzerland is not in the EU — and it is corrected here rather than quietly.

11. Audit

The school may ask for evidence that we are meeting this agreement, and we will answer in writing within 30 days. For a small supplier this is a conversation and a document, not a site visit — we would rather say that plainly than imply an audit programme we do not have.

12. End of the agreement

When the school stops using the service we delete all pupil personal data within 30 days, or return it first if the school asks. Nothing is retained for our own purposes.

Questions, or a countersigned copy: privacy@gcsetutor.app · Privacy policy