← Back to data protection pack

Data Processing Agreement (UK GDPR Article 28)

Payments by iAntz · IANTZ LIMITED · Version July 2026 · For school procurement and DPIA due diligence

This is iAntz's standard-form Data Processing Agreement. It is provided for due diligence and DPIA purposes. Execution occurs when your school enters into a contract with IANTZ LIMITED or signs an order form that incorporates these terms by reference.

1. Parties

Controller: [School / Trust name], [registered address] ("Controller", "you", "School")

Processor: IANTZ LIMITED (company number 13777598), 3 Princes Court, Royal Way, Loughborough, Leicestershire, LE11 5XR, United Kingdom, trading as Payments by iAntz ("Processor", "we", "iAntz")

2. Background

The Controller wishes to use the Payments by iAntz platform and related services. In providing those services, the Processor will process personal data on behalf of the Controller. This Agreement sets out the obligations of the parties under UK GDPR and the Data Protection Act 2018.

3. Definitions

Terms used in this Agreement have the meanings given in UK GDPR unless otherwise defined. "Personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings in the UK GDPR.

"Services" means the Payments by iAntz software platform, support, and related services provided under the contract between the parties.

"Sub-processor" means any third party engaged by the Processor to process personal data on behalf of the Controller.

4. Subject matter, duration, nature, and purpose

ItemDetails
Subject matterProvision of school payments, communications, and related administration services via the iAntz platform
DurationFor the term of the Services agreement, plus any post-termination period required for deletion, anonymisation, or legal retention
Nature of processingCollection, storage, organisation, retrieval, use, disclosure by transmission, alignment, restriction, erasure, and anonymisation
PurposeEnabling school fee and payment collection, wallet management, parent-school communications, MIS synchronisation (where enabled), reporting, refunds, and service operation

5. Types of personal data and categories of data subjects

Data subjectsCategories of personal data (indicative)
School staffName, email, phone, role, authentication data, usage logs, communications sent via the platform
Parents / guardiansName, email, phone, address (where provided), payment metadata, transaction history, linked children, communications, authentication data
Pupils / studentsName, year group, class, MIS identifiers, wallet balances, payment items, photos (from MIS where synced), dietary/safeguarding data where entered by the school
Other carers / collectorsName, contact details, relationship to child, collection pass data where used

See the Data Inventory document in this pack for a fuller breakdown with retention and location.

6. Processor obligations

The Processor shall:

  1. Process personal data only on documented instructions from the Controller, including regarding transfers, unless required by UK law (in which case the Processor shall inform the Controller unless prohibited by law).
  2. Ensure persons authorised to process personal data are bound by confidentiality.
  3. Implement appropriate technical and organisational measures as described in the Security & Certifications Summary and at iantz.com/security.
  4. Not engage another processor without the Controller's prior written authorisation, subject to clause 7.
  5. Assist the Controller, taking into account the nature of processing, in responding to data subject requests.
  6. Assist the Controller with security, breach notification, DPIAs, and prior consultation obligations, insofar as possible.
  7. At the Controller's choice, delete or return personal data at the end of provision of Services, subject to legal retention requirements.
  8. Make available information necessary to demonstrate compliance and allow audits, subject to reasonable notice and confidentiality safeguards.
  9. Immediately inform the Controller if an instruction infringes UK GDPR or the Data Protection Act 2018.

7. Sub-processors

The Controller provides general written authorisation for the Processor to engage Sub-processors listed in the Sub-processor List (included in this data protection pack and updated from time to time at iantz.com/security).

The Processor shall:

8. International transfers

Personal data is primarily processed in the United Kingdom. Where processing involves a transfer outside the UK, the Processor shall ensure appropriate safeguards are in place, such as UK International Data Transfer Agreement (IDTA), UK Addendum to EU SCCs, or an adequacy regulation, as applicable.

9. Personal data breaches

The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and provide information reasonably required for the Controller to meet its obligations under UK GDPR Articles 33 and 34.

10. Data subject rights

The Processor shall assist the Controller in fulfilling data subject rights requests. Parents and staff may exercise certain rights in-app (data export and account deletion). See the Data Subject Rights Process document in this pack.

11. Deletion and return

On termination of Services, the Processor shall, at the Controller's election, delete or return personal data within a reasonable period, except where UK law requires retention (for example, financial records for 7 years). Where deletion is not possible, the Processor shall anonymise personal data where appropriate.

12. Audit and information

Upon reasonable written request, the Processor shall provide information reasonably necessary to demonstrate compliance with this Agreement. The Processor may satisfy audit requests through third-party certifications and security documentation, rather than intrusive on-site access, except where required by law or regulator.

13. Liability

Liability under this Agreement is subject to the limitation and indemnity provisions in the main Services contract between the parties, except where liability cannot be limited by law.

14. Order of precedence

If there is a conflict between this Agreement and the main Services contract regarding data protection, this Agreement prevails. If there is a conflict between this Agreement and UK GDPR, UK GDPR prevails.

15. Contact

Processor data protection contact: [email protected]
ICO registration (Processor): ZC093007
General enquiries: [email protected] · 01509 462745

Signatures

For the ControllerFor the Processor (IANTZ LIMITED)
Name:  Name:  
Title:  Title:  
Date:  Date:  
Signature:  Signature: