UK GDPR Article 28
Data processing agreement
Between your organisation and The Code Guy Ltd. Print it, or send it back signed.
Version 1.0, 23 September 2026. Subject to final legal review.
Parties
| The Controller | The organisation named in the signature block below, referred to as "you". |
|---|---|
| The Processor | The Code Guy Ltd, a company registered in England and Wales under number 09407392, whose registered office is The Old Byre, 15 Redgates Lane, Sewards End, Saffron Walden, CB10 2LW, referred to as "we" and "us". The Code Guy Ltd produces the Forest School App and is registered with the Information Commissioner's Office under ZB286164. |
1. What this agreement is
This agreement sets out the terms on which we process personal data on your behalf when you use the Forest School App, and it is the written contract required by Article 28(3) of the UK GDPR. It forms part of our Terms of service. Where this agreement and the Terms of service conflict on a matter of data protection, this agreement wins.
1.1 Definitions
"UK GDPR", "personal data", "special category data", "processing", "controller", "processor", "personal data breach" and "data subject" have the meanings given in the UK GDPR and the Data Protection Act 2018. "Data protection law" means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, as amended. "Your data" means the personal data described in Annex 1 that we process on your behalf. "Service" means the Forest School App: the web application, the field app, and the interfaces between them.
1.2 Roles
You are the controller of your data and we are your processor. You are responsible for having a lawful basis for the personal data you enter, for the fairness and accuracy of it, and for the information you give to the children, families and staff it concerns. We are separately the controller of your staff's account records and your billing records, which are described in our privacy policy and are not covered by this agreement.
2. Our obligations
We will:
- Process only on your instructions. We process your data only on your documented instructions, which are this agreement, the Terms of service and your use of the features of the service, including any instruction about transfers to a third country. Where the law requires us to process your data otherwise, we will tell you before we do unless the law forbids us from telling you.
- Tell you if an instruction is unlawful. If we believe an instruction you give infringes data protection law, we will tell you.
- Keep it confidential. Everyone we authorise to process your data is bound by a duty of confidence, and only those who need access to run and support the service have it. Access is reviewed at least quarterly.
- Keep it secure. We apply the technical and organisational measures in Annex 3, which meet Article 32, and we review them at least annually and after any material change to the service.
- Use sub-processors only on these terms. You give us general authorisation to use the sub-processors listed in Annex 2. Each is engaged under a written contract imposing obligations no less protective than these, and we remain fully liable to you for their performance. We will give you at least 30 days' notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds; if we cannot resolve your objection you may terminate the affected part of the service without penalty and receive a refund of any fee paid for the unused period.
- Help you answer people. Taking into account the nature of the processing, we will help you meet your duties to data subjects. The service itself lets an owner export a single child's whole record, export the whole organisation, and erase a child's record, without needing us. Where you do need us, we will respond within 10 working days. If a data subject comes to us directly about your data, we will not answer them substantively; we will tell them to come to you and will tell you.
- Help you with Articles 32 to 36. We will help you keep the processing secure, notify breaches, and carry out data protection impact assessments and any prior consultation, taking into account the nature of the processing and the information available to us. A ready-made impact assessment for this service is published at /procurement/dpia.
- Tell you about a breach. We will notify you without undue delay, and in any event within 24 hours, of becoming aware of a personal data breach affecting your data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. We will give you further information as we learn it, and we will not tell a supervisory authority or a data subject about a breach of your data on your behalf unless you ask us to or the law requires it of us.
- Delete or return it. On the end of the service we will, at your choice, delete your data or return it to you. You can export your data yourself at any time while your account is open. Unless you tell us otherwise, we delete an organisation's data within 30 days of the account closing, except where the law requires either of us to keep a record for longer, in which case we keep only that record, only for as long as the law requires, and continue to protect it under this agreement. Backups are overwritten on the rolling 35-day cycle described in Annex 3.
- Show you. We will make available the information needed to show we meet these obligations, and allow and contribute to an audit, including an inspection, by you or an auditor you appoint. An audit may be carried out once in any 12-month period, on 30 days' written notice, during business hours, without unreasonable disruption, and subject to confidentiality. We may satisfy an audit request with our current certification and the published pack at /procurement where that reasonably answers it. An audit following a personal data breach affecting your data is not subject to the once a year limit.
3. International transfers
Your data is stored in the United Kingdom. Where a sub-processor in Annex 2 processes personal data outside the UK, that transfer is covered by UK adequacy regulations or by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. We will not make a new transfer outside the UK without a valid transfer mechanism in place.
4. Liability, term and general
This agreement starts when you first use the service and continues for as long as we process your data. The limitations and exclusions of liability in the Terms of service apply to this agreement, except that nothing in either limits a liability that cannot lawfully be limited, including a party's liability for a fine or a claim arising from its own breach of data protection law. This agreement is governed by the law of England and Wales and the courts of England and Wales have exclusive jurisdiction.
Annex 1: the processing
| Subject matter | Running forest school sessions: planning, registers, risk-benefit assessments, observations, incidents, medication, bookings, and safeguarding records. |
|---|---|
| Duration | For as long as your account is open, plus the deletion period in clause 2.9. |
| Nature | Collection, recording, organisation, storage, retrieval, use, transmission to people you authorise, erasure and destruction, by automated means. |
| Purpose | Providing the service to you, and nothing else. We do not use your data to train models, to advertise, to profile, or to build any product. |
| Categories of data subject | Children and young people attending your sessions; their parents, carers and emergency contacts; your staff, volunteers and helpers; people who book a place; practitioners attending a training event you run. |
| Categories of personal data |
Children: name, preferred name, date of birth, photograph, group,
attendance, observations and development notes, consents (photography,
participation, off-site, first aid, sun cream, walking home), field notes, and the
answers given on your booking form. Parents and carers: name, relationship, phone number, email address, whether they may collect, and their messages to you. Staff and volunteers: name, email address, role, DBS and first aid status and the certificates you attach, qualifications, policy and risk assessment sign-offs. Bookings and payments: payer name and email address, amounts, references. Card details are never passed to us. |
| Special category and criminal offence data |
Health: allergies, medical conditions, medication, dietary needs,
care plan notes, SEND and EHCP notes, medication administered, accident and
incident records. Safeguarding: concerns raised about a child, including disclosures, categories, actions and referrals. Held in a separate store, readable only by a Designated Safeguarding Lead you name. Criminal offence data: the existence, date, number and status of a DBS check on a member of staff. |
Annex 2: authorised sub-processors
As at the date of this agreement. The current list is always at /procurement.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Hosting: application, database, media store | UK South |
| Microsoft Application Insights | Error and performance monitoring | Azure, EU/UK |
| Amazon Web Services (SES) | Service and notification email | EU (Ireland) |
| Stripe Payments Europe / Stripe Inc. | Subscription billing and hosted checkout | UK / EU, with onward transfer safeguards |
| PostHog (EU Cloud) | Cookieless product analytics, identifiers masked | EU |
| Norwegian Meteorological Institute | Session weather forecast from site coordinates | Norway (UK adequacy) |
| postcodes.io | Site postcode to coordinates | United Kingdom |
| OpenStreetMap Foundation | Map tiles on the site map | EU |
| unpkg (Cloudflare) | Serving the map library to the browser | Global content network |
| Google (Analytics) and Ahrefs | Public marketing website analytics only. No access to your data | EU/US, SCCs where applicable |
| YouTube (no-cookie) and Vimeo | Playing a video embedded in a shared activity idea | EU/US, SCCs |
Annex 3: technical and organisational measures
Separation
Every read and write in the service carries the organisation's identity and is filtered by it at a single point in the code, which also stamps the organisation onto anything written. There is no query path that spans organisations except one, reserved to the operator tier described below, which cannot return a child's record.
Access control
Permissions are granted per organisation and per person, and are checked as claims rather than job titles. A change to someone's role or their removal takes effect on an open browser session within five minutes and on a field-app session at its next request to the server. Password minimum length is ten characters; an account locks for fifteen minutes after ten failed attempts; sign-in, password reset and code entry are rate limited per address.
Safeguarding
Safeguarding concerns are held in a separate store from children's records and are readable only by a person the organisation has granted the Designated Safeguarding Lead role. That grant is separate from every other permission, so an owner or administrator who is not a DSL has no access. Three independent checks enforce it: the page, the endpoint, and the storage layer. Every read and write is written to an insert-only access log naming the person, the concern and the time. Concerns appear in no export, no PDF, no email and no operator view.
Operator access
Our own operational view returns organisations, subscriptions, staff names and aggregate counts only, because the code behind it has no method that returns a child's record or a medical detail. Support sessions that view the service as one of your staff are time-boxed, require a written reason, and are recorded page by page. The Designated Safeguarding Lead permission is always stripped from such a session, whoever it is signed in as.
Encryption
HTTPS only, TLS 1.2 minimum, HSTS for one year including subdomains. Azure platform encryption at rest on the database and the media store. Field-app credentials are held in the device's own secure storage, and the field app is excluded from Google's automatic Android backup.
Media
Photographs and documents are held in a private Azure Blob Storage container with anonymous access disabled, under non-guessable names, and are never served from a public address. Every request goes through the application, which checks the reader's permission and, for a photo, the photo consent of every child in the frame. Signed-in responses carrying a child's file are marked not to be stored by the browser.
Uploads
Files are identified by their contents rather than their name or declared type, are limited to an allow-list, and scalable vector graphics are never served inline.
Backup and resilience
Continuous point-in-time backup of the database, restorable to any moment in the last 35 days, with a written restore runbook. The media store keeps three copies within the UK region, and a deleted photograph or document is recoverable for 30 days. Both halves of your data are recoverable, not only the records half.
Assurance
Cyber Essentials, certificate 2db8b10a-6085-42aa-8561-cd67537f51f1, scope the whole organisation, certified 29 July 2026 and due for recertification 29 July 2027. Every route reachable without a sign-in is listed in a reviewed file and the build fails when a new one appears. An automated test suite runs before every deployment and an unauthenticated probe runs against the live site after it, checking that no route carrying a child's data answers. Dependencies are scanned for known vulnerabilities. A written release checklist and a quarterly infrastructure review cover firewall rules, storage settings, access review and key rotation.
Logging and minimisation
Children's names, dates of birth, medical text and safeguarding text are excluded from application logs, analytics and error reports by policy and by review at every release. Product analytics runs cookieless with identifiers masked. Records are erased through a single documented routine that cascades across sessions, observations, photographs and bookings.
Signatures
Signed for and on behalf of the parties.
The Controller
Organisation Name Position Signature DateThe Processor: The Code Guy Ltd
Name Position Signature DateSend the signed copy to dpo@thecodeguy.co.uk and we will countersign and return it.