Data Processing Agreement
Last updated: 16 May 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Ibdaa Ltd, a company registered in England and Wales under number 11658668 with its registered office at 128 City Road, London, EC1V 2NX, United Kingdom ("Ibdaa", "we", "us", "Processor") and the customer that subscribes to the Tawaasal service (the "School", "you", "Controller") (together, the "Parties").
It governs the processing of Personal Data carried out by Ibdaa on behalf of the School in connection with the Tawaasal platform — the tawaasal.com website, the customer portal, and the Tawaasal mobile applications for iOS and Android (together, the "Service").
This DPA applies whenever Ibdaa processes Personal Data on behalf of the School. It takes effect on the date the School first agrees to the Terms of Service or, where the Parties have signed a separate order form, the date stated on that order form.
1. Definitions
Terms in this DPA capitalised but not defined here have the meaning given to them in the Terms of Service. The following further definitions apply:
- "Data Protection Law" means the UK General Data Protection Regulation as it forms part of UK domestic law (the UK GDPR), the UK Data Protection Act 2018, the EU General Data Protection Regulation (Regulation (EU) 2016/679, the EU GDPR) where applicable, the Saudi Personal Data Protection Law (PDPL), the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and any other data protection or privacy law applicable to a Party's processing of Personal Data under this DPA.
- "Personal Data", "Controller", "Processor", "Sub-processor", "Data Subject", "Processing" and "Personal Data Breach" have the meanings given to them in the UK GDPR.
- "School Personal Data" means Personal Data processed by Ibdaa on behalf of the School in the course of providing the Service.
- "Sub-processor" means a third party engaged by Ibdaa to process School Personal Data.
2. Roles and scope
For the purposes of this DPA, in respect of School Personal Data the School is the Controller and Ibdaa is the Processor.
This DPA does not apply to Personal Data for which Ibdaa is itself the Controller — including account, billing, and marketing data of the individuals who administer the School's account. That processing is governed by the Privacy Policy.
Details of the processing carried out under this DPA are set out in Annex A.
3. Instructions
Ibdaa shall process School Personal Data only on the documented instructions of the School. The School's instructions are constituted by:
- this DPA;
- the Terms of Service and any order form;
- the configuration choices the School makes within the Service; and
- any further instructions the School gives in writing, provided they are consistent with the Service and Data Protection Law.
If Ibdaa believes that a School instruction infringes Data Protection Law, it shall inform the School without undue delay. Ibdaa is not obliged to follow an instruction that, in its reasonable view, would cause it to breach applicable law.
4. Personnel and confidentiality
Ibdaa shall ensure that any person it authorises to process School Personal Data:
- is subject to a binding duty of confidentiality;
- is given access only on a need-to-know basis;
- has received appropriate training on the protection of Personal Data; and
- is supervised in accordance with Ibdaa's security policies.
5. Security
Ibdaa shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing, in particular against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, School Personal Data. The measures Ibdaa has in place are described in Annex C.
The School is responsible for choosing security configurations available within the Service that are appropriate to its risk assessment — including enabling multi-factor authentication for staff accounts, configuring password policies, and managing the assignment of roles and permissions.
6. Sub-processors
The School provides general written authorisation for Ibdaa to engage Sub-processors to process School Personal Data, subject to this clause.
The Sub-processors engaged by Ibdaa as of the effective date of this DPA are listed in Annex B. An up-to-date list is also published in the Privacy Policy and available on request from [email protected].
Ibdaa shall give the School at least 30 days' prior written notice (which may be by email or in-portal notice) of the addition or replacement of any Sub-processor. The School may object to the new Sub-processor on reasonable data-protection grounds within that notice period. If the Parties cannot agree a resolution, the School may, as its sole and exclusive remedy, terminate the affected part of the Service by written notice without further charge.
Ibdaa shall:
- enter into a written contract with each Sub-processor that imposes data-protection obligations equivalent in substance to those in this DPA; and
- remain liable to the School for the acts and omissions of its Sub-processors to the same extent as for its own acts and omissions.
7. Data subject rights
Taking into account the nature of the processing, Ibdaa shall assist the School by appropriate technical and organisational measures, insofar as possible, to fulfil the School's obligation to respond to requests from Data Subjects exercising rights under Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection).
The Service provides self-service tools that allow the School to retrieve, correct, export, and delete most School Personal Data without needing to involve Ibdaa.
Where Ibdaa receives a request directly from a Data Subject concerning School Personal Data, it shall not respond to that request (other than to direct the Data Subject to the School) and shall forward the request to the School without undue delay.
8. Personal Data Breaches
Ibdaa shall notify the School without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting School Personal Data. The notification shall include, to the extent then known:
- the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address the breach and mitigate its possible adverse effects; and
- contact details from which further information can be obtained.
Ibdaa shall take reasonable steps to mitigate the effects of the breach and to assist the School in meeting its own breach-notification obligations under Data Protection Law.
9. Data protection impact assessments and consultations
Ibdaa shall provide reasonable assistance to the School with any data protection impact assessment or prior consultation with a supervisory authority required under Data Protection Law, in each case in relation to processing carried out under this DPA and taking into account the information available to Ibdaa.
10. Audits and inspections
Ibdaa shall make available to the School all information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, conducted by the School or another auditor mandated by the School.
To minimise disruption and protect the security of the Service and the data of other customers, the School shall give Ibdaa at least 30 days' prior written notice of any audit (except where required earlier by a supervisory authority or by law); audits shall take place during normal business hours and shall not unreasonably interfere with Ibdaa's operations. Each Party shall bear its own costs of the audit. Where independent third-party audit reports or certifications are available, Ibdaa may discharge its obligations under this clause by providing copies of those reports.
The School shall not be entitled to access Ibdaa's data centres, source code, or commercially confidential information of other customers.
11. International transfers
Where Ibdaa transfers School Personal Data outside the United Kingdom or the European Economic Area, it shall do so only where an appropriate transfer mechanism is in place. The mechanisms Ibdaa relies on may include the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, an adequacy decision, or another lawful safeguard recognised under applicable Data Protection Law.
The School authorises the transfers necessary for the operation of the Sub-processors listed in Annex B.
12. Return or deletion of data
On expiry or termination of the Service, the School may export its data through the self-service export tools provided in the Service. Ibdaa shall make these tools available for a period of 30 days following expiry or termination.
After that 30-day period, Ibdaa shall delete School Personal Data from its production systems within a further 30 days. Backups containing School Personal Data shall be deleted in the normal course of Ibdaa's backup rotation, within 90 days of the deletion from production systems.
Ibdaa may retain School Personal Data for longer to the extent required by law, in which case Ibdaa shall continue to protect it in accordance with this DPA.
13. Liability
The liability of each Party under or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Terms of Service.
14. Order of precedence
In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail to the extent of the conflict, but only in relation to the processing of Personal Data.
15. Term and termination
This DPA shall remain in force for as long as Ibdaa processes School Personal Data on behalf of the School under the Terms of Service. The obligations in clauses 4 (Personnel and confidentiality), 8 (Personal Data Breaches), 11 (International transfers), 12 (Return or deletion of data), and 13 (Liability) shall survive termination to the extent and for the period necessary.
16. Governing law
This DPA is governed by the laws of England and Wales. Each Party irrevocably submits to the exclusive jurisdiction of the courts of England and Wales in respect of any dispute or claim arising out of or in connection with this DPA.
Annex A — Details of Processing
| | | |---|---| | Subject matter | Provision of the Tawaasal school management Service to the School. | | Duration | For the duration of the Terms of Service, plus the deletion period in clause 12 of this DPA. | | Nature and purpose | Hosting, storing, transmitting, displaying, and otherwise processing School Personal Data so that the School can manage its educational operations through the Service. | | Types of Personal Data | Identification and contact data (names, dates of birth, contact details), enrolment and academic records, attendance and behaviour records, grades and assessment data, homework and submissions (which may include free text, files, images, audio, and video uploaded by users), calendar and timetable data, messages and announcements, authentication and audit data, technical data such as IP addresses and device identifiers. | | Categories of Data Subjects | Students, guardians, teachers, school administrators, school staff, and other individuals whose data the School chooses to enter into the Service. | | Special category data | The Service is not designed for the processing of special category data. The School should not enter special category data (for example, health, religious, or biometric data) into free-text fields except where strictly necessary and where the School has a lawful basis for doing so. |
Annex B — Sub-processors
| Sub-processor | Purpose | Region | |---|---|---| | Stripe, Inc. | Payment processing | United States, with UK and EU representatives | | Google LLC (Firebase Cloud Messaging) | Mobile push notifications | Global Google infrastructure | | Google LLC (Firebase Crashlytics) | Crash and diagnostic reporting for the mobile app | Global Google infrastructure | | Google LLC (Sign in with Google) | Optional social sign-in | Global Google infrastructure | | Apple Inc. (Apple Push Notification service, Sign in with Apple) | iOS push notifications and optional social sign-in | United States | | Cloud infrastructure providers | Hosting, storage, and content delivery | United Kingdom and European Economic Area | | Email and messaging providers | Transactional email and SMS | United Kingdom and European Economic Area |
The current list is also published on the Privacy Policy page and may be obtained from [email protected].
Annex C — Technical and Organisational Measures
Ibdaa applies the following measures, which it may update from time to time, provided that the overall level of security is not materially reduced.
Confidentiality
- Role-based access control with the principle of least privilege
- Multi-factor authentication for all administrator and staff accounts
- Unique user accounts and prohibition on credential sharing
- Personnel bound by confidentiality obligations and trained on data protection
- Background checks for personnel with access to production systems, where permitted by law
Integrity
- AES-256 encryption for Personal Data at rest
- TLS 1.3 encryption for Personal Data in transit
- Cryptographic separation of tenants at the application layer
- Change management and code review for changes to production systems
- Logging of administrative actions and security-sensitive events
Availability and resilience
- Automated daily backups with geo-redundancy
- Documented disaster recovery and incident response procedures
- Monitoring and alerting on availability and performance
Procedures for regularly testing, assessing and evaluating effectiveness
- Periodic vulnerability assessments and penetration testing
- Annual review of policies and procedures
- Security training for all personnel on induction and annually
Pseudonymisation and minimisation
- Identifiers used in logs and analytics where direct identification is not necessary
- Configurable retention rules within the Service so the School can apply data minimisation
Incident response
- Documented incident response process with defined roles
- 24-hour internal escalation for suspected Personal Data Breaches
- Breach notification to the School within 72 hours of awareness
Sub-processor governance
- Risk-based selection and onboarding of Sub-processors
- Written contracts with data-protection terms equivalent in substance to this DPA
- Periodic review of Sub-processor compliance