Data Processing Agreement

Public DPA summary for School Plans. Last updated: September 2026. An executed school-specific DPA is required before production student-data use.

1. Applicability

This Data Processing Agreement (DPA) applies to schools that have purchased a School plan and are processing personal data of students, teachers, and staff.

For school-controlled teaching and student data, the school acts as controller and Cross Sword Limited acts as processor. Cross Sword Limited may act as an independent controller for limited business operations such as account administration, contracting, billing, security and legal compliance, as described in the Privacy Policy.

2. Subject Matter & Duration

This DPA covers:

  • Processing of curriculum, project, and assessment data
  • Storage of student submissions and portfolios
  • Teacher and student account data
  • Audit logs and activity records

Duration: For the term of the applicable agreement and until school-controlled personal data is returned or deleted in accordance with verified school instructions, legal obligations and the hosting provider's backup lifecycle.

3. Processing Activities

Project Designer processes data for:

  • Curriculum planning and storage
  • Project delivery and assessment
  • User authentication and access control
  • School-wide analytics and reporting
  • System security and fraud detection
  • Compliance with legal obligations

4. Data Security Measures

Project Designer implements:

  • HTTPS for data in transit and hosting-provider controls for stored data
  • School-scoped row-level access rules and role-aware permissions
  • Authenticated server functions for sensitive operations
  • Dependency scanning and automated security regression tests
  • Restricted student access to assigned, published content and their own work
  • Server-side assessment grading and protected answer keys
  • Incident investigation and breach-notification procedures

5. Sub-Processors

Project Designer uses the following sub-processors:

Sub-ProcessorPurposeLocation
Base44Application platform, authentication, database, storage and backend functionsAs documented in the current sub-processor schedule
StripePayment processingAs documented by Stripe for the contracted service
Configured AI provider(s)Optional teacher tools and, when enabled by a school, AI-assisted assessmentAs documented in the current sub-processor schedule

The executed DPA and current sub-processor schedule must identify the providers in use, their purposes, locations and applicable transfer safeguards. Provider terms and data-processing commitments must be verified before school launch.

6. Data Subject Rights

The school and Cross Sword Limited will cooperate on data-subject requests according to their controller/processor roles. Cross Sword Limited will provide reasonable assistance so the controller can meet the applicable statutory timeframe for:

  • Access to personal data (GDPR Article 15)
  • Correction of inaccurate data (GDPR Article 16)
  • Erasure / "right to be forgotten" (GDPR Article 17)
  • Restriction of processing (GDPR Article 18)
  • Data portability (GDPR Article 20)
  • Objection to processing (GDPR Article 21)

7. Data Retention & Deletion

  • Active Data: Retained while account is active
  • School-Controlled Data: Returned or deleted on verified school instruction, subject to legal restrictions
  • Operational Records: Retained only for documented security, support, transaction or legal needs
  • Deletion Evidence: The deletion request, scope and completion must be recorded
  • Backups: Deletion follows the hosting provider's documented recovery lifecycle and backup data is not used for normal product operation

8. International Transfers

Hosting and sub-processor locations must be stated in the current sub-processor schedule. Where personal data is transferred internationally, the executed DPA must identify an applicable mechanism such as an adequacy decision, Standard Contractual Clauses and, where relevant, the UK Addendum or IDTA, together with any required transfer-risk assessment.

9. Breach Notification

If Cross Sword Limited becomes aware of a personal-data breach affecting school-controlled data, it will notify the school without undue delay and provide available information including:

  • Nature of the breach
  • Data affected
  • Likely consequences
  • Measures taken to mitigate harm

Your school is responsible for notifying data subjects and authorities within GDPR timeframes.

10. Audit & Compliance

Cross Sword Limited will make available the information reasonably necessary to demonstrate compliance with the executed DPA and will support agreed audits or security questionnaires subject to appropriate confidentiality, scope and cost controls. Independent reports or certifications will be provided only where they actually exist.

11. Termination

Upon termination of the School plan:

  • The school may request return or deletion of school-controlled data
  • Available export formats and assistance will be agreed for the service in use
  • Operational records are retained only where documented security, contractual or legal needs require them
  • Residual backup copies expire under the hosting provider's documented recovery lifecycle

12. Contact

Privacy contact: privacy@projectdesigner.app

For contractual or legal enquiries: legal@projectdesigner.app

Project Designer

Purpose-built curriculum planning for IB Design teachers.

© 2026 Project Designer. All rights reserved.

Built for IB Design Technology educators worldwide.

This work/product/service has been developed independently from and is not endorsed by the International Baccalaureate Organization. International Baccalaureate, Baccalauréat International, Bachillerato Internacional and IB are registered trademarks owned by the International Baccalaureate Organization.

Cookie Consent

We use cookies to improve your experience. Essential cookies are always active. You can customize your preferences or .