Data Processing Agreement

Last updated: 16 May 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Ibdaa Ltd, a company registered in England and Wales under number 11658668 with its registered office at 128 City Road, London, EC1V 2NX, United Kingdom ("Ibdaa", "we", "us", "Processor") and the customer that subscribes to the Tawaasal service (the "School", "you", "Controller") (together, the "Parties").

It governs the processing of Personal Data carried out by Ibdaa on behalf of the School in connection with the Tawaasal platform — the tawaasal.com website, the customer portal, and the Tawaasal mobile applications for iOS and Android (together, the "Service").

This DPA applies whenever Ibdaa processes Personal Data on behalf of the School. It takes effect on the date the School first agrees to the Terms of Service or, where the Parties have signed a separate order form, the date stated on that order form.

1. Definitions

Terms in this DPA capitalised but not defined here have the meaning given to them in the Terms of Service. The following further definitions apply:

2. Roles and scope

For the purposes of this DPA, in respect of School Personal Data the School is the Controller and Ibdaa is the Processor.

This DPA does not apply to Personal Data for which Ibdaa is itself the Controller — including account, billing, and marketing data of the individuals who administer the School's account. That processing is governed by the Privacy Policy.

Details of the processing carried out under this DPA are set out in Annex A.

3. Instructions

Ibdaa shall process School Personal Data only on the documented instructions of the School. The School's instructions are constituted by:

If Ibdaa believes that a School instruction infringes Data Protection Law, it shall inform the School without undue delay. Ibdaa is not obliged to follow an instruction that, in its reasonable view, would cause it to breach applicable law.

4. Personnel and confidentiality

Ibdaa shall ensure that any person it authorises to process School Personal Data:

5. Security

Ibdaa shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing, in particular against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, School Personal Data. The measures Ibdaa has in place are described in Annex C.

The School is responsible for choosing security configurations available within the Service that are appropriate to its risk assessment — including enabling multi-factor authentication for staff accounts, configuring password policies, and managing the assignment of roles and permissions.

6. Sub-processors

The School provides general written authorisation for Ibdaa to engage Sub-processors to process School Personal Data, subject to this clause.

The Sub-processors engaged by Ibdaa as of the effective date of this DPA are listed in Annex B. An up-to-date list is also published in the Privacy Policy and available on request from [email protected].

Ibdaa shall give the School at least 30 days' prior written notice (which may be by email or in-portal notice) of the addition or replacement of any Sub-processor. The School may object to the new Sub-processor on reasonable data-protection grounds within that notice period. If the Parties cannot agree a resolution, the School may, as its sole and exclusive remedy, terminate the affected part of the Service by written notice without further charge.

Ibdaa shall:

7. Data subject rights

Taking into account the nature of the processing, Ibdaa shall assist the School by appropriate technical and organisational measures, insofar as possible, to fulfil the School's obligation to respond to requests from Data Subjects exercising rights under Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection).

The Service provides self-service tools that allow the School to retrieve, correct, export, and delete most School Personal Data without needing to involve Ibdaa.

Where Ibdaa receives a request directly from a Data Subject concerning School Personal Data, it shall not respond to that request (other than to direct the Data Subject to the School) and shall forward the request to the School without undue delay.

8. Personal Data Breaches

Ibdaa shall notify the School without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting School Personal Data. The notification shall include, to the extent then known:

Ibdaa shall take reasonable steps to mitigate the effects of the breach and to assist the School in meeting its own breach-notification obligations under Data Protection Law.

9. Data protection impact assessments and consultations

Ibdaa shall provide reasonable assistance to the School with any data protection impact assessment or prior consultation with a supervisory authority required under Data Protection Law, in each case in relation to processing carried out under this DPA and taking into account the information available to Ibdaa.

10. Audits and inspections

Ibdaa shall make available to the School all information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, conducted by the School or another auditor mandated by the School.

To minimise disruption and protect the security of the Service and the data of other customers, the School shall give Ibdaa at least 30 days' prior written notice of any audit (except where required earlier by a supervisory authority or by law); audits shall take place during normal business hours and shall not unreasonably interfere with Ibdaa's operations. Each Party shall bear its own costs of the audit. Where independent third-party audit reports or certifications are available, Ibdaa may discharge its obligations under this clause by providing copies of those reports.

The School shall not be entitled to access Ibdaa's data centres, source code, or commercially confidential information of other customers.

11. International transfers

Where Ibdaa transfers School Personal Data outside the United Kingdom or the European Economic Area, it shall do so only where an appropriate transfer mechanism is in place. The mechanisms Ibdaa relies on may include the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, an adequacy decision, or another lawful safeguard recognised under applicable Data Protection Law.

The School authorises the transfers necessary for the operation of the Sub-processors listed in Annex B.

12. Return or deletion of data

On expiry or termination of the Service, the School may export its data through the self-service export tools provided in the Service. Ibdaa shall make these tools available for a period of 30 days following expiry or termination.

After that 30-day period, Ibdaa shall delete School Personal Data from its production systems within a further 30 days. Backups containing School Personal Data shall be deleted in the normal course of Ibdaa's backup rotation, within 90 days of the deletion from production systems.

Ibdaa may retain School Personal Data for longer to the extent required by law, in which case Ibdaa shall continue to protect it in accordance with this DPA.

13. Liability

The liability of each Party under or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Terms of Service.

14. Order of precedence

In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail to the extent of the conflict, but only in relation to the processing of Personal Data.

15. Term and termination

This DPA shall remain in force for as long as Ibdaa processes School Personal Data on behalf of the School under the Terms of Service. The obligations in clauses 4 (Personnel and confidentiality), 8 (Personal Data Breaches), 11 (International transfers), 12 (Return or deletion of data), and 13 (Liability) shall survive termination to the extent and for the period necessary.

16. Governing law

This DPA is governed by the laws of England and Wales. Each Party irrevocably submits to the exclusive jurisdiction of the courts of England and Wales in respect of any dispute or claim arising out of or in connection with this DPA.


Annex A — Details of Processing

| | | |---|---| | Subject matter | Provision of the Tawaasal school management Service to the School. | | Duration | For the duration of the Terms of Service, plus the deletion period in clause 12 of this DPA. | | Nature and purpose | Hosting, storing, transmitting, displaying, and otherwise processing School Personal Data so that the School can manage its educational operations through the Service. | | Types of Personal Data | Identification and contact data (names, dates of birth, contact details), enrolment and academic records, attendance and behaviour records, grades and assessment data, homework and submissions (which may include free text, files, images, audio, and video uploaded by users), calendar and timetable data, messages and announcements, authentication and audit data, technical data such as IP addresses and device identifiers. | | Categories of Data Subjects | Students, guardians, teachers, school administrators, school staff, and other individuals whose data the School chooses to enter into the Service. | | Special category data | The Service is not designed for the processing of special category data. The School should not enter special category data (for example, health, religious, or biometric data) into free-text fields except where strictly necessary and where the School has a lawful basis for doing so. |

Annex B — Sub-processors

| Sub-processor | Purpose | Region | |---|---|---| | Stripe, Inc. | Payment processing | United States, with UK and EU representatives | | Google LLC (Firebase Cloud Messaging) | Mobile push notifications | Global Google infrastructure | | Google LLC (Firebase Crashlytics) | Crash and diagnostic reporting for the mobile app | Global Google infrastructure | | Google LLC (Sign in with Google) | Optional social sign-in | Global Google infrastructure | | Apple Inc. (Apple Push Notification service, Sign in with Apple) | iOS push notifications and optional social sign-in | United States | | Cloud infrastructure providers | Hosting, storage, and content delivery | United Kingdom and European Economic Area | | Email and messaging providers | Transactional email and SMS | United Kingdom and European Economic Area |

The current list is also published on the Privacy Policy page and may be obtained from [email protected].

Annex C — Technical and Organisational Measures

Ibdaa applies the following measures, which it may update from time to time, provided that the overall level of security is not materially reduced.

Confidentiality

Integrity

Availability and resilience

Procedures for regularly testing, assessing and evaluating effectiveness

Pseudonymisation and minimisation

Incident response

Sub-processor governance