← Compliance packDocument 2 of 8
🐾 PAWSTEPS · PETS ON THE GREEN LTD

Data Processing Agreement

UK GDPR Article 28 · between the School (Controller) and Pets on the Green Ltd (Processor)
Status: Draft template for negotiation and signature. Have this reviewed by your data protection adviser or solicitor before signing. It is not legal advice. Where a school has its own preferred DPA, PawSteps is willing to review and countersign it.

Parties

ControllerThe subscribing school or academy trust: ________________________ (completed per school at signing)
ProcessorPets on the Green Ltd (trading as PawSteps), Company No. 16721467, Pets on the Green Ltd, 4 Redvers Road, Warlingham, Surrey, CR6 9HN, Warlingham, Surrey
Effective date13 July 2026 — coterminous with the PawSteps site-licence agreement

1. Subject matter & duration

The Processor processes personal data on behalf of the Controller solely to deliver the PawSteps platform under the site licence, for the duration of that licence and any wind-down period defined in clause 9.

2. Nature & purpose of processing

Provision of curriculum-linked learning, wellbeing activities, SEND resources and (where enabled) progress and EHCP evidence tools to the Controller’s pupils and staff.

3. Categories of data & data subjects

Data subjectsCategories of personal data
PupilsFirst name/nickname, age band, learning activity, progress data, and (where the school enables it) wellbeing and SEND/EHCP evidence (special category)
StaffName, work email, role, account credentials

4. Obligations of the Processor

  1. Process personal data only on the Controller’s documented instructions, including for transfers, unless required by law (and then only after notice where lawful).
  2. Ensure persons authorised to process are bound by confidentiality.
  3. Implement appropriate technical and organisational measures (clause 6) per Article 32.
  4. Not engage a sub-processor without prior specific or general written authorisation, and impose equivalent data-protection terms on any sub-processor (clause 5).
  5. Assist the Controller, by appropriate measures, in responding to data-subject rights requests.
  6. Assist the Controller in ensuring compliance with Articles 32–36 (security, breach notification, DPIAs, prior consultation).
  7. Notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach.
  8. At the Controller’s choice, delete or return all personal data at the end of the services and delete existing copies unless retention is required by law.
  9. Make available all information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, by the Controller or its auditor.

5. Sub-processors

The Controller provides general authorisation for the Processor to use the sub-processors listed below. The Processor will give 30 days’ notice of any intended change, allowing the Controller to object.

Sub-processorServiceLocation
Netlify (web hosting) and Supabase (database, EU/London region)UK cloud hostingUnited Kingdom
Resend (transactional email)Transactional email & supportUK/EU
Stripe Payments UK LtdSubscription payments (no card data stored by PawSteps)UK/EU

6. Security measures (Article 32)

Encryption in transit (TLS) and at rest; role-based access control and least privilege; multi-factor authentication for administrative access; UK-based hosting; regular backups; logging and monitoring; secure software development practices; staff confidentiality and data-protection training. On-device storage is used for the wellbeing journal to minimise data held by the Processor.

7. International transfers

Personal data is hosted in the United Kingdom. No transfers outside the UK are made without an appropriate safeguard under UK GDPR (e.g. adequacy or the IDTA) and prior notice to the Controller.

8. Breach notification

On becoming aware of a personal data breach the Processor will notify the Controller’s named contact ________________________ (completed per school at signing) without undue delay, providing the nature of the breach, likely consequences and measures taken, to support the Controller’s 72-hour ICO obligation.

9. Return & deletion

On termination, the Processor will, at the Controller’s option, return or securely delete all personal data within 30 days, and confirm deletion in writing, save where law requires retention.

10. Liability & governing law

This Agreement is governed by the laws of England and Wales. Liability is as set out in the underlying site-licence agreement.

Signatures

For the Controller (School/Trust)
Name / role
Signature & date
For the Processor (Pets on the Green Ltd)
Ciera O’Rourke, Director
Signature & date