Data Processing Agreement
Effective Date: 13 July 2026
This Data Processing Agreement ("Agreement") forms part of the agreement between Boundary Review ("Processor") and the subscribing school, academy or multi-academy trust ("Controller") for the provision of the Boundary Review service.
This Agreement reflects the requirements of Article 28 of the UK General Data Protection Regulation (UK GDPR).
1. Parties
Data Controller
The subscribing school, academy or multi-academy trust using Boundary Review.
The Controller determines the purposes and means of processing personal data.
Data Processor
Boundary Review
Email: info@boundaryreview.co.uk
Boundary Review processes personal data solely on behalf of the Controller.
2. Purpose of Processing
Boundary Review provides software designed to assist schools in identifying examination review opportunities, recording review decisions and managing examination review workflows.
Personal data is processed only for the purposes of providing this service.
Boundary Review will never use customer data for advertising, profiling or commercial marketing.
3. Categories of Data
Depending upon how the service is used, the following information may be processed:
Staff Data
-
Name
-
Email address
-
User account details
-
Job role
-
Login activity
-
System audit logs
Pupil Data
-
Candidate identifier
-
Candidate number
-
Examination entries
-
Subject information
-
Raw examination marks
-
Grade boundaries
-
Review recommendations
-
Review decisions
-
Review outcomes
Boundary Review does not require special category personal data unless supplied by the Controller.
4. Categories of Data Subjects
The data subjects may include:
-
Pupils
-
Teaching staff
-
Exams Officers
-
School leaders
-
Trust staff
5. Duration
This Agreement remains in force for as long as Boundary Review processes personal data on behalf of the Controller.
6. Processor Obligations
Boundary Review shall:
-
Process personal data only on documented instructions from the Controller.
-
Ensure that authorised persons processing data are subject to confidentiality obligations.
-
Implement appropriate technical and organisational security measures.
-
Assist the Controller in complying with UK GDPR where reasonably requested.
-
Notify the Controller without undue delay following confirmation of a personal data breach affecting Controller data.
-
Delete or return personal data upon termination of the service where requested, unless retention is required by law.
7. Security Measures
Boundary Review maintains appropriate technical and organisational measures including:
-
Google Workspace Enterprise security controls.
-
Encryption of data in transit.
-
Encryption of data at rest.
-
Multi-factor authentication (MFA) for administrator accounts.
-
HTTPS encrypted communications.
-
Strong password policies.
-
Restricted administrative access.
-
Google Drive version history.
-
Automated monthly backup copies of customer spreadsheets using Google Apps Script.
-
Secure storage within Google Workspace.
-
Ongoing review of access permissions.
-
Regular software and security updates.
8. Confidentiality
Boundary Review shall ensure that anyone authorised to process personal data:
-
Is subject to an appropriate duty of confidentiality.
-
Processes data only where necessary to deliver the service.
9. Sub-processors
Boundary Review currently uses the following sub-processors:
Sub-processorPurpose
Google WorkspaceSecure cloud storage, spreadsheets, email and automation
WixWebsite hosting
Google AnalyticsWebsite usage analytics
Boundary Review will ensure all sub-processors provide appropriate safeguards consistent with UK GDPR.
Boundary Review will notify customers where additional sub-processors are introduced that materially affect data processing.
10. International Transfers
Where data is transferred outside the United Kingdom, Boundary Review will ensure appropriate safeguards are in place in accordance with UK GDPR.
11. Assistance to the Controller
Boundary Review shall provide reasonable assistance where required to help the Controller meet obligations relating to:
-
Data subject requests.
-
Security obligations.
-
Personal data breaches.
-
Data protection impact assessments (where relevant).
12. Personal Data Breaches
Boundary Review shall notify the Controller without undue delay after becoming aware of a confirmed personal data breach affecting Controller data.
The notification will include, where available:
-
Nature of the breach.
-
Categories of data affected.
-
Likely consequences.
-
Measures taken or proposed to address the breach.
13. Audit Rights
Upon reasonable written notice, the Controller may request information demonstrating Boundary Review's compliance with this Agreement.
Boundary Review may satisfy such requests by providing documentation including:
-
Privacy Policy.
-
Information Security Policy.
-
This Data Processing Agreement.
-
Responses to reasonable security questionnaires.
Where further assurance is required, audit arrangements shall be agreed in advance and carried out in a manner that does not compromise the security or confidentiality of other customers.
14. Return and Deletion of Data
Upon termination of the service, and subject to any legal obligations, Boundary Review shall, at the Controller's choice:
-
Return customer data; or
-
Securely delete customer data.
Backup copies retained solely for disaster recovery purposes will be deleted in accordance with Boundary Review's retention procedures.
15. Liability
Each party's liability under this Agreement shall be governed by the underlying service agreement unless otherwise required by law.
16. Governing Law
This Agreement shall be governed by the laws of England and Wales.
Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.
Contact
Boundary Review
Email: info@boundaryreview.co.uk
Questions regarding this Agreement may be sent to the above email address.
