IN-TOUCH SCHOOLS
CONNECT. LEARN. MANAGE.

School Data Protection & Processing Agreement — Framework

Provides a commercial and privacy framework for agreements between In-Touch Schools and schools using the platform.

Founder draft: Version 0.1. Legal review is required before production use.

1. Purpose

This framework should form the basis of a separate signed agreement with each school. It is not a substitute for a negotiated data protection agreement.

2. Roles

The parties should document which party is the Responsible Party for each processing activity and the circumstances in which In-Touch Schools acts as an Operator or otherwise processes information on behalf of the school.

3. Processing instructions

In-Touch Schools should process School Data only on documented instructions and for agreed service purposes, subject to applicable law.

4. Confidentiality

Personnel and contractors with access to School Data should be bound by confidentiality obligations appropriate to their role.

5. Security

The provider should maintain reasonable technical and organisational safeguards, including access control, authentication, encryption, logging, vulnerability management, backups and incident response appropriate to the risk.

6. Sub-processors / Operators

Third-party service providers should be identified through a controlled supplier process and bound by written obligations appropriate to the information they process.

7. Security incidents

The parties should define prompt escalation from an Operator to the Responsible Party and cooperate with investigation, mitigation and legally required notifications.

8. Data subject requests

The parties should define how access, correction, deletion, objection and related requests will be received, verified, allocated and completed.

9. Data return and deletion

At contract termination, the parties should define how School Data is returned, migrated, retained for lawful purposes, deleted and removed from active systems and backups according to the agreed retention schedule.

10. Audit and assurance

The agreement should provide proportionate mechanisms for security assurance, compliance evidence and review of material risks.

11. International transfers

Where processing occurs outside South Africa, the parties should document the relevant transfer safeguards and responsibilities.

12. Commercial terms

Licensing, fees, service levels, support, implementation, migration and liability should be addressed in the commercial agreement rather than left solely to this framework.