top of page

Data Processing Agreement

Effective Date: 13 July 2026

This Data Processing Agreement ("Agreement") forms part of the agreement between Boundary Review ("Processor") and the subscribing school, academy or multi-academy trust ("Controller") for the provision of the Boundary Review service.

This Agreement reflects the requirements of Article 28 of the UK General Data Protection Regulation (UK GDPR).

 

1. Parties

Data Controller

The subscribing school, academy or multi-academy trust using Boundary Review.

The Controller determines the purposes and means of processing personal data.

Data Processor

Boundary Review

Email: info@boundaryreview.co.uk

Boundary Review processes personal data solely on behalf of the Controller.

 

2. Purpose of Processing

Boundary Review provides software designed to assist schools in identifying examination review opportunities, recording review decisions and managing examination review workflows.

Personal data is processed only for the purposes of providing this service.

Boundary Review will never use customer data for advertising, profiling or commercial marketing.

 

3. Categories of Data

Depending upon how the service is used, the following information may be processed:

Staff Data

  • Name

  • Email address

  • User account details

  • Job role

  • Login activity

  • System audit logs

Pupil Data

  • Candidate identifier

  • Candidate number

  • Examination entries

  • Subject information

  • Raw examination marks

  • Grade boundaries

  • Review recommendations

  • Review decisions

  • Review outcomes

Boundary Review does not require special category personal data unless supplied by the Controller.

 

4. Categories of Data Subjects

The data subjects may include:

  • Pupils

  • Teaching staff

  • Exams Officers

  • School leaders

  • Trust staff

 

5. Duration

This Agreement remains in force for as long as Boundary Review processes personal data on behalf of the Controller.

 

6. Processor Obligations

Boundary Review shall:

  • Process personal data only on documented instructions from the Controller.

  • Ensure that authorised persons processing data are subject to confidentiality obligations.

  • Implement appropriate technical and organisational security measures.

  • Assist the Controller in complying with UK GDPR where reasonably requested.

  • Notify the Controller without undue delay following confirmation of a personal data breach affecting Controller data.

  • Delete or return personal data upon termination of the service where requested, unless retention is required by law.

 

7. Security Measures

Boundary Review maintains appropriate technical and organisational measures including:

  • Google Workspace Enterprise security controls.

  • Encryption of data in transit.

  • Encryption of data at rest.

  • Multi-factor authentication (MFA) for administrator accounts.

  • HTTPS encrypted communications.

  • Strong password policies.

  • Restricted administrative access.

  • Google Drive version history.

  • Automated monthly backup copies of customer spreadsheets using Google Apps Script.

  • Secure storage within Google Workspace.

  • Ongoing review of access permissions.

  • Regular software and security updates.

 

8. Confidentiality

Boundary Review shall ensure that anyone authorised to process personal data:

  • Is subject to an appropriate duty of confidentiality.

  • Processes data only where necessary to deliver the service.

 

9. Sub-processors

Boundary Review currently uses the following sub-processors:

Sub-processorPurpose

Google WorkspaceSecure cloud storage, spreadsheets, email and automation

WixWebsite hosting

Google AnalyticsWebsite usage analytics

Boundary Review will ensure all sub-processors provide appropriate safeguards consistent with UK GDPR.

Boundary Review will notify customers where additional sub-processors are introduced that materially affect data processing.

 

10. International Transfers

Where data is transferred outside the United Kingdom, Boundary Review will ensure appropriate safeguards are in place in accordance with UK GDPR.

 

11. Assistance to the Controller

Boundary Review shall provide reasonable assistance where required to help the Controller meet obligations relating to:

  • Data subject requests.

  • Security obligations.

  • Personal data breaches.

  • Data protection impact assessments (where relevant).

 

12. Personal Data Breaches

Boundary Review shall notify the Controller without undue delay after becoming aware of a confirmed personal data breach affecting Controller data.

The notification will include, where available:

  • Nature of the breach.

  • Categories of data affected.

  • Likely consequences.

  • Measures taken or proposed to address the breach.

 

13. Audit Rights

Upon reasonable written notice, the Controller may request information demonstrating Boundary Review's compliance with this Agreement.

Boundary Review may satisfy such requests by providing documentation including:

  • Privacy Policy.

  • Information Security Policy.

  • This Data Processing Agreement.

  • Responses to reasonable security questionnaires.

Where further assurance is required, audit arrangements shall be agreed in advance and carried out in a manner that does not compromise the security or confidentiality of other customers.

 

14. Return and Deletion of Data

Upon termination of the service, and subject to any legal obligations, Boundary Review shall, at the Controller's choice:

  • Return customer data; or

  • Securely delete customer data.

Backup copies retained solely for disaster recovery purposes will be deleted in accordance with Boundary Review's retention procedures.

 

15. Liability

Each party's liability under this Agreement shall be governed by the underlying service agreement unless otherwise required by law.

 

16. Governing Law

This Agreement shall be governed by the laws of England and Wales.

Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

 

Contact

Boundary Review

Email: info@boundaryreview.co.uk

Questions regarding this Agreement may be sent to the above email address.

bottom of page