Data Processing Agreement
Public DPA summary for School Plans. Last updated: September 2026. An executed school-specific DPA is required before production student-data use.
1. Applicability
This Data Processing Agreement (DPA) applies to schools that have purchased a School plan and are processing personal data of students, teachers, and staff.
For school-controlled teaching and student data, the school acts as controller and Cross Sword Limited acts as processor. Cross Sword Limited may act as an independent controller for limited business operations such as account administration, contracting, billing, security and legal compliance, as described in the Privacy Policy.
2. Subject Matter & Duration
This DPA covers:
- Processing of curriculum, project, and assessment data
- Storage of student submissions and portfolios
- Teacher and student account data
- Audit logs and activity records
Duration: For the term of the applicable agreement and until school-controlled personal data is returned or deleted in accordance with verified school instructions, legal obligations and the hosting provider's backup lifecycle.
3. Processing Activities
Project Designer processes data for:
- Curriculum planning and storage
- Project delivery and assessment
- User authentication and access control
- School-wide analytics and reporting
- System security and fraud detection
- Compliance with legal obligations
4. Data Security Measures
Project Designer implements:
- HTTPS for data in transit and hosting-provider controls for stored data
- School-scoped row-level access rules and role-aware permissions
- Authenticated server functions for sensitive operations
- Dependency scanning and automated security regression tests
- Restricted student access to assigned, published content and their own work
- Server-side assessment grading and protected answer keys
- Incident investigation and breach-notification procedures
5. Sub-Processors
Project Designer uses the following sub-processors:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Base44 | Application platform, authentication, database, storage and backend functions | As documented in the current sub-processor schedule |
| Stripe | Payment processing | As documented by Stripe for the contracted service |
| Configured AI provider(s) | Optional teacher tools and, when enabled by a school, AI-assisted assessment | As documented in the current sub-processor schedule |
The executed DPA and current sub-processor schedule must identify the providers in use, their purposes, locations and applicable transfer safeguards. Provider terms and data-processing commitments must be verified before school launch.
6. Data Subject Rights
The school and Cross Sword Limited will cooperate on data-subject requests according to their controller/processor roles. Cross Sword Limited will provide reasonable assistance so the controller can meet the applicable statutory timeframe for:
- Access to personal data (GDPR Article 15)
- Correction of inaccurate data (GDPR Article 16)
- Erasure / "right to be forgotten" (GDPR Article 17)
- Restriction of processing (GDPR Article 18)
- Data portability (GDPR Article 20)
- Objection to processing (GDPR Article 21)
7. Data Retention & Deletion
- Active Data: Retained while account is active
- School-Controlled Data: Returned or deleted on verified school instruction, subject to legal restrictions
- Operational Records: Retained only for documented security, support, transaction or legal needs
- Deletion Evidence: The deletion request, scope and completion must be recorded
- Backups: Deletion follows the hosting provider's documented recovery lifecycle and backup data is not used for normal product operation
8. International Transfers
Hosting and sub-processor locations must be stated in the current sub-processor schedule. Where personal data is transferred internationally, the executed DPA must identify an applicable mechanism such as an adequacy decision, Standard Contractual Clauses and, where relevant, the UK Addendum or IDTA, together with any required transfer-risk assessment.
9. Breach Notification
If Cross Sword Limited becomes aware of a personal-data breach affecting school-controlled data, it will notify the school without undue delay and provide available information including:
- Nature of the breach
- Data affected
- Likely consequences
- Measures taken to mitigate harm
Your school is responsible for notifying data subjects and authorities within GDPR timeframes.
10. Audit & Compliance
Cross Sword Limited will make available the information reasonably necessary to demonstrate compliance with the executed DPA and will support agreed audits or security questionnaires subject to appropriate confidentiality, scope and cost controls. Independent reports or certifications will be provided only where they actually exist.
11. Termination
Upon termination of the School plan:
- The school may request return or deletion of school-controlled data
- Available export formats and assistance will be agreed for the service in use
- Operational records are retained only where documented security, contractual or legal needs require them
- Residual backup copies expire under the hosting provider's documented recovery lifecycle
12. Contact
Privacy contact: privacy@projectdesigner.app
For contractual or legal enquiries: legal@projectdesigner.app
