Data Processing Agreement (UK GDPR Article 28)
1. Parties
Controller: [School / Trust name], [registered address] ("Controller", "you", "School")
Processor: IANTZ LIMITED (company number 13777598), 3 Princes Court, Royal Way, Loughborough, Leicestershire, LE11 5XR, United Kingdom, trading as Payments by iAntz ("Processor", "we", "iAntz")
2. Background
The Controller wishes to use the Payments by iAntz platform and related services. In providing those services, the Processor will process personal data on behalf of the Controller. This Agreement sets out the obligations of the parties under UK GDPR and the Data Protection Act 2018.
3. Definitions
Terms used in this Agreement have the meanings given in UK GDPR unless otherwise defined. "Personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings in the UK GDPR.
"Services" means the Payments by iAntz software platform, support, and related services provided under the contract between the parties.
"Sub-processor" means any third party engaged by the Processor to process personal data on behalf of the Controller.
4. Subject matter, duration, nature, and purpose
| Item | Details |
|---|---|
| Subject matter | Provision of school payments, communications, and related administration services via the iAntz platform |
| Duration | For the term of the Services agreement, plus any post-termination period required for deletion, anonymisation, or legal retention |
| Nature of processing | Collection, storage, organisation, retrieval, use, disclosure by transmission, alignment, restriction, erasure, and anonymisation |
| Purpose | Enabling school fee and payment collection, wallet management, parent-school communications, MIS synchronisation (where enabled), reporting, refunds, and service operation |
5. Types of personal data and categories of data subjects
| Data subjects | Categories of personal data (indicative) |
|---|---|
| School staff | Name, email, phone, role, authentication data, usage logs, communications sent via the platform |
| Parents / guardians | Name, email, phone, address (where provided), payment metadata, transaction history, linked children, communications, authentication data |
| Pupils / students | Name, year group, class, MIS identifiers, wallet balances, payment items, photos (from MIS where synced), dietary/safeguarding data where entered by the school |
| Other carers / collectors | Name, contact details, relationship to child, collection pass data where used |
See the Data Inventory document in this pack for a fuller breakdown with retention and location.
6. Processor obligations
The Processor shall:
- Process personal data only on documented instructions from the Controller, including regarding transfers, unless required by UK law (in which case the Processor shall inform the Controller unless prohibited by law).
- Ensure persons authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational measures as described in the Security & Certifications Summary and at iantz.com/security.
- Not engage another processor without the Controller's prior written authorisation, subject to clause 7.
- Assist the Controller, taking into account the nature of processing, in responding to data subject requests.
- Assist the Controller with security, breach notification, DPIAs, and prior consultation obligations, insofar as possible.
- At the Controller's choice, delete or return personal data at the end of provision of Services, subject to legal retention requirements.
- Make available information necessary to demonstrate compliance and allow audits, subject to reasonable notice and confidentiality safeguards.
- Immediately inform the Controller if an instruction infringes UK GDPR or the Data Protection Act 2018.
7. Sub-processors
The Controller provides general written authorisation for the Processor to engage Sub-processors listed in the Sub-processor List (included in this data protection pack and updated from time to time at iantz.com/security).
The Processor shall:
- Impose data protection obligations on Sub-processors that are no less protective than this Agreement.
- Remain liable to the Controller for Sub-processor performance.
- Notify the Controller of intended changes to Sub-processors (additions or replacements) with reasonable notice, giving the Controller opportunity to object on reasonable data protection grounds.
8. International transfers
Personal data is primarily processed in the United Kingdom. Where processing involves a transfer outside the UK, the Processor shall ensure appropriate safeguards are in place, such as UK International Data Transfer Agreement (IDTA), UK Addendum to EU SCCs, or an adequacy regulation, as applicable.
9. Personal data breaches
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and provide information reasonably required for the Controller to meet its obligations under UK GDPR Articles 33 and 34.
10. Data subject rights
The Processor shall assist the Controller in fulfilling data subject rights requests. Parents and staff may exercise certain rights in-app (data export and account deletion). See the Data Subject Rights Process document in this pack.
11. Deletion and return
On termination of Services, the Processor shall, at the Controller's election, delete or return personal data within a reasonable period, except where UK law requires retention (for example, financial records for 7 years). Where deletion is not possible, the Processor shall anonymise personal data where appropriate.
12. Audit and information
Upon reasonable written request, the Processor shall provide information reasonably necessary to demonstrate compliance with this Agreement. The Processor may satisfy audit requests through third-party certifications and security documentation, rather than intrusive on-site access, except where required by law or regulator.
13. Liability
Liability under this Agreement is subject to the limitation and indemnity provisions in the main Services contract between the parties, except where liability cannot be limited by law.
14. Order of precedence
If there is a conflict between this Agreement and the main Services contract regarding data protection, this Agreement prevails. If there is a conflict between this Agreement and UK GDPR, UK GDPR prevails.
15. Contact
Processor data protection contact: [email protected]
ICO registration (Processor): ZC093007
General enquiries: [email protected] · 01509 462745
Signatures
| For the Controller | For the Processor (IANTZ LIMITED) |
| Name: | Name: |
| Title: | Title: |
| Date: | Date: |
| Signature: | Signature: |