← Back

Data Processing Agreement

Between Learning Lens (Processor) and the data controller named below

Effective date: August 2026 — Version 2.3

1. Parties

Data Controller: The local authority responsible for the subscribing school, or the school itself where it is an independent data controller ("the Controller").

Data Processor: Jamie Scobie, trading as Learning Lens, based in Scotland, ICO registration ZC200575 ("the Processor").

Signing. Where the local authority is the Controller, this Agreement must be signed by an authorised officer of the authority. A headteacher's signature binds the Controller only where the school is itself the Controller, or where the authority has delegated that signing authority in writing.

This Agreement supplements the Learning Lens Terms of Service and sets out the terms on which the Processor will process personal data on behalf of the Controller in accordance with UK GDPR and the Data Protection Act 2018.

2. Scope of Processing

2.1 Subject Matter and Purpose

The Processor processes personal data for the purpose of providing the Learning Lens platform, specifically: capturing and analysing classroom observation data, generating reports and analytics to inform school self-evaluation under HGIOS4 (or equivalent national framework where configured), and supporting related professional dialogue.

2.2 Categories of Data Subjects

  • Teaching and support staff at the Controller's school (observers and observed teachers)
  • School leaders and administrators

No pupil data is processed under the current Classroom module. If future modules processing pupil data are activated, this Agreement will be updated accordingly.

2.3 Types of Personal Data

  • Staff names and email addresses
  • Professional role and department
  • Observation records: observer name, teacher name, pedagogical practices observed, descriptive evidence of observed teaching practices, free-text professional feedback
  • Aggregated analytics and report outputs derived from observation records

No ratings, grades, or quantitative scores of individual teachers are produced or processed.

2.4 Duration

Processing will continue for the duration of the Controller's subscription to Learning Lens, plus a retention period of 90 days following termination to allow for data export.

3. Processor Obligations

  1. Process personal data only on documented instructions from the Controller, unless required to do so by law.

  2. Ensure that persons authorised to process personal data are subject to confidentiality obligations.

  3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

    • Encryption of data in transit and at rest
    • Database-level Row Level Security enforcing school-by-school data isolation
    • Role-based access controls within the application
    • Regular security updates to application dependencies
    • Access logging for any direct database access by Processor staff

    The Processor enforces school-by-school data isolation through PostgreSQL Row Level Security policies on all tables containing school data. Teacher-private data (including personal reflections) is isolated at the single-user level, enforced by database policy with no administrative override. Teacher data write permissions are constrained at the column level through PostgreSQL grants, preventing any client-side code (including authenticated user sessions) from modifying observer-generated observation records. These controls are independently auditable and documented in the Processor's Architecture document, available on request.

  4. Not engage another processor (sub-processor) without prior written authorisation from the Controller. The current authorised sub-processors are listed in Schedule 1 of this Agreement. The Processor will inform the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object.

  5. Assist the Controller, insofar as is possible, in fulfilling the Controller's obligations to respond to data subject access requests and other data subject rights under UK GDPR.

  6. Assist the Controller in ensuring compliance with obligations relating to security, breach notification, Data Protection Impact Assessments, and prior consultation with the ICO, taking into account the nature of processing and the information available to the Processor.

  7. At the Controller's choice, delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies unless applicable law requires storage.

  8. Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this Agreement, and allow for and contribute to audits and inspections conducted by the Controller or another auditor mandated by the Controller.

4. Breach Notification

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach. The notification will include:

  1. A description of the nature of the breach, including the categories and approximate number of data subjects and records affected
  2. The name and contact details of the Processor's data protection contact
  3. A description of the likely consequences of the breach
  4. A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects

The Processor will cooperate with the Controller and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of the breach.

5. Sub-Processors

The Controller authorises the use of the following sub-processors:

Sub-ProcessorServiceData ProcessedLocation
Supabase Inc.Database hosting and authenticationAll school and observation data stored in Learning LensAWS EU (Frankfurt)
Vercel Inc.Application hostingStatic site assets only (no personal data in cached assets). No personal data is processed by Vercel — the application communicates directly with SupabaseGlobal CDN (public assets)
Google LLC (Google Workspace)Business email and document handling for correspondence with the ControllerCorrespondence with the ControllerGoogle's global infrastructure under UK SCCs and Data Privacy Framework certification
Vercel Inc. (Vercel Analytics)Aggregate page-view analyticsNo personal data, no cookiesVercel's global infrastructure
Functional Software, Inc. d/b/a SentryApplication error reporting (diagnostic reports when the application encounters a fault)Technical diagnostic data only: the error type and message, a stack trace of Learning Lens application code, browser and operating system version, language setting, and the paths of the page on which the fault occurred and the page navigated from. Those paths may contain a record identifier (for example a visit reference) but never a query string, URL fragment, or free-text content. No user identifier, name, email address or IP address is attached to the report; no cookies, no request or response content, and no observation data are transmittedSentry EU region (Frankfurt, Germany)

The Processor will ensure that any sub-processor agreement imposes data protection obligations no less onerous than those set out in this Agreement.

6. Data Transfers

The Processor processes personal data in AWS eu-central-1 (Frankfurt, Germany) under its agreement with Supabase Inc. Transfers of personal data from the United Kingdom to the European Economic Area take place under the European Commission's adequacy decision for the United Kingdom and the UK's corresponding adequacy regulations for EU member states, together providing a lawful basis for the transfer under Article 45 UK GDPR.

The Processor will not transfer personal data outside the United Kingdom or the European Economic Area without the prior written consent of the Controller and without ensuring appropriate safeguards are in place (such as UK International Data Transfer Agreement or an adequacy decision).

Error reporting. Diagnostic reports generated when the application encounters a fault are processed by Functional Software, Inc. d/b/a Sentry in its EU region, where data at rest is held in Frankfurt, Germany. The Processor has selected the EU region specifically so that this data remains within the EEA. Sentry is a US-incorporated company, and its Data Processing Addendum incorporates the European Commission's Standard Contractual Clauses (Module 2, controller-to-processor) together with the UK International Data Transfer Addendum, which provide the safeguards required for any access from outside the EEA. The content of these reports is limited to the technical diagnostic data described in Section 5; observation data, free-text content, account identifiers and credentials are excluded at source by the application's configuration.

Ancillary service providers. The Processor uses Google Workspace (Google LLC) for business email and document handling in connection with the service. Personal data processed through email correspondence with the Controller is handled in accordance with Google's own data protection terms, which incorporate UK Standard Contractual Clauses and Google's Data Privacy Framework certification. This processing is incidental to the core service.

7. Controller Obligations

  1. The Controller is responsible for ensuring that its processing of personal data through Learning Lens has a valid lawful basis under UK GDPR.
  2. The Controller is responsible for informing data subjects (staff members) about the processing of their personal data through the Controller's own staff privacy notice.
  3. The Controller is responsible for managing User accounts and access permissions within Learning Lens, including revoking access for staff who leave.
  4. The Controller will not instruct the Processor to process data in a manner that would infringe UK GDPR.

8. Liability and Indemnity

Each party is liable for damage caused by processing that infringes UK GDPR, in accordance with Article 82. The Processor is liable only to the extent that it has not complied with obligations specifically directed to processors under UK GDPR or has acted outside or contrary to the lawful instructions of the Controller.

9. Term and Termination

This Agreement comes into effect on the date the Controller's subscription to Learning Lens is activated and remains in effect for the duration of the subscription, including any post-termination retention period. On termination, the Processor will delete or return all personal data in accordance with the Terms of Service unless applicable law requires continued storage.

10. Governing Law

This Agreement is governed by and construed in accordance with the laws of Scotland. Any disputes will be subject to the exclusive jurisdiction of the Scottish courts.

Schedule 1: Authorised Sub-Processors

As at the date of this Agreement:

Sub-ProcessorRegistered AddressServiceData Location
Supabase Inc.970 Toa Payoh North #07-04, Singapore 318992 (HQ: San Francisco, CA, USA)Managed PostgreSQL database, authentication, Row Level SecurityAWS eu-central-1 (Frankfurt)
Vercel Inc.440 N Barranca Ave #4133, Covina, CA 91723, USAStatic site hosting (global CDN, cached public marketing assets only — no personal data is processed by Vercel)Global CDN (public assets)
Google LLC (Google Workspace)1600 Amphitheatre Parkway, Mountain View, CA 94043, USABusiness email and document handling for correspondence with the ControllerGoogle's global infrastructure under UK SCCs and Data Privacy Framework certification
Vercel Inc. (Vercel Analytics)440 N Barranca Ave #4133, Covina, CA 91723, USACookieless aggregate page-view analytics (no personal data, no cookies)Vercel's global infrastructure
Functional Software, Inc. d/b/a Sentry45 Fremont Street, 8th Floor, San Francisco, CA 94105, USAApplication error reporting — technical diagnostic data only, with user identifiers, credentials, request content and observation data excluded at source (see Section 5)Sentry EU region (Frankfurt, Germany), under Standard Contractual Clauses and the UK International Data Transfer Addendum