Terms used in this DPA have the same meaning as in the UK GDPR, EU GDPR and the Swiss FADP. "Personal Data", "Controller", "Processor", "Processing", "Data Subject" and "Personal Data Breach" are used as defined in those instruments.
2.1. Controller
The School is the Controller. It determines the purposes and means of Processing personal data and is responsible for establishing a lawful basis and obtaining any necessary consents.
2.2. Processor
ATL Portfolio is the Processor. We Process personal data only on documented instructions from the School, as set out in this DPA and the Platform's Terms of Service.
We Process personal data only for the following purposes:
- Providing and maintaining the ATL Portfolio Platform for the School.
- Enabling students to document and reflect on ATL evidence.
- Enabling teachers and coordinators to assess, feedback and report on ATL development.
- Generating reports and analytics within the School's own data.
- Operating, securing and improving the Platform.
We do not Process personal data for our own purposes, for advertising, or for training public AI models on School data.
- Identification data: name and school email address.
- Profile data: programme, year group, class, role.
- Educational content: ATL evidence, reflections, self-assessments, media uploads.
- Assessment data: proficiency levels, teacher feedback, reports.
- Billing data (administrators only): billing contact and transaction records.
- Students enrolled in the School's IB programmes.
- Teachers and coordinators employed by the School.
- School administrators and billing contacts.
Taking into account the state of the art and the risks, we implement appropriate technical and organisational measures, including:
- Encryption in transit (HTTPS / TLS) and encryption at rest.
- Role-based access control and row-level security at the database layer.
- School data isolation — no cross-school access.
- Domain-based authentication and session token expiry.
- Principle of least privilege for platform staff access.
- Regular dependency updates and security patching.
Personnel with access to personal data are bound by confidentiality obligations and only granted access where necessary for their role. Platform-level access is restricted to operational support and is never used to share data between Schools.
We engage the following categories of sub-processor to deliver the Platform:
| Hosting & database | Base44 platform / Supabase on AWS-backed infrastructure |
|---|---|
| Payment processing | Stripe (school billing data only) |
| Transactional email | Resend |
| AI features | Third-party AI model provider (non-identifying context; no student names) |
A full, current sub-processor list is available on request. We will notify Schools of any new sub-processor before it begins processing School data, giving the School the right to object.
Data is stored in the United Kingdom. The Platform is hosted on the Base44 platform using AWS-backed infrastructure (Supabase) in the UK. Where data is transferred outside the UK, EU or Switzerland, appropriate safeguards (such as Standard Contractual Clauses and, where relevant, the UK International Data Transfer Agreement) are put in place.
- Active School data is retained for the duration of the subscription.
- Deleted user data is anonymised or removed within 30 days of request.
- Backups are retained for a limited technical recovery period (30 days).
- Billing records are retained as required by applicable financial regulation.
We assist the School in fulfilling its obligations to respond to data subject requests, including:
- Subject Access Requests (Article 15) — we provide the School with the relevant data within 30 days.
- Rectification and erasure — we action verified requests from the School promptly.
- Data portability — we provide data export in a portable format on request.
- Breach notification to authorities and data subjects — see section 12.
If a Personal Data Breach affecting School data is confirmed, we will:
- Notify the School without undue delay and within 72 hours.
- Provide the nature of the breach, the data affected, the likely consequences and the measures taken.
- Assist the School in meeting any obligation to notify the supervisory authority and affected data subjects.
- Document the breach and the remediation steps.
The School may, on reasonable notice, request information necessary to demonstrate our compliance with this DPA. On-site audits are available by arrangement, subject to confidentiality, and may be conducted by the School or a mandated independent auditor.
On termination of the subscription, at the School's choice, we will either return the School's data in a portable format or delete it. Deletion is completed within 30 days, with residual backup copies removed within the backup retention cycle.
Questions about compliance?
Our data protection team is ready to help IT managers, DPOs and procurement leads review ATL Portfolio for your school.
