Legal

Data Processing Agreement

Last updated: 18 July 2026 · Beta version — outline for schools

This page outlines the terms on which Sendiphany Ltd ("Processor") processes personal data on behalf of a school ("Controller") using the Sendiphany platform, in line with Article 28 UK GDPR. Schools requiring a signed DPA for their records should contact hello@sendiphany.co.uk.

1. Roles

For pupil and parent/carer data entered into Sendiphany, the school is the data controller and determines the purposes and means of processing. Sendiphany acts as a data processor, processing personal data only on the school's documented instructions as given through use of the platform.

2. Subject matter and duration

Processing covers the pupil, parent/carer, and staff-feedback data entered into Sendiphany to manage SEND administration, including EHCP drafting, deadline tracking, and local-authority communication. Processing continues for the duration of the school's subscription and any agreed post-termination retention or export period.

3. Nature and purpose of processing

  • Storage and retrieval of pupil SEND records, including special category health data.
  • AI-assisted drafting of EHCP content, with pupil identifiers pseudonymised before transmission to our AI provider.
  • Collection of parent/carer and staff contributions via secure, token-scoped links.
  • Deadline and safeguarding-alert notifications to authorised school staff.

4. Sub-processors

Sendiphany uses the following categories of sub-processor:

  • Supabase — database hosting and authentication.
  • Anthropic — AI drafting, receiving only pseudonymised content (no direct pupil identifiers).
  • Stripe — payment processing for school subscriptions.
  • Resend — transactional email delivery (deadline reminders, notifications).
  • Vercel — application hosting.

We will notify schools of material changes to this sub-processor list where required by law or contract.

5. Security measures

Data is encrypted in transit and at rest, access is scoped per school via row-level security in the database, and administrative access is restricted and logged. As an early-beta product, our security programme (including formal certification) is still maturing — see our Privacy Policy for related detail.

6. Data subject rights and breach notification

Sendiphany will assist the school in responding to data subject rights requests relating to data processed on the school's behalf, and will notify the school without undue delay on becoming aware of a personal data breach affecting the school's data.

7. International transfers

We aim to keep pupil data within the UK/EEA wherever possible. Where a sub-processor transfers data outside the UK, appropriate safeguards (such as the UK International Data Transfer Addendum or equivalent) are used.

8. Contact us

To request a signed copy of our DPA for your school's records, email hello@sendiphany.co.uk.

This is a beta-stage outline. A fully executable DPA is available on request and will supersede this page ahead of general availability. It does not constitute legal advice.