Back to trust pack
Trust pack document

Data Processing Agreement (Template)

Controller-processor terms template for school procurement and legal review.

Outleap Data Processing Agreement (School Template)

Status: Approved baseline template for contracting. School-specific fields and legal review are still required before signature.

1. Parties

  • Controller (School): [School legal entity name]
  • Processor (Supplier): Outleap Limited (Company No. 14277395), 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE
  • ICO registration: ZB393894
  • Processor representative: Jesse Merrigan (Director and named data protection contact, supported by Outleap's documented governance and review process). General/supplier contact: hello@outleap.io. Privacy and data-rights contact: info@outleap.io
  • Effective date: [YYYY-MM-DD]

2. Services in Scope

This DPA covers personal data processed by Outleap to provide the current first-school rollout of the Outleap destinations workflow. The processing in scope today comprises: the Evidence Bank, the UCAS three-question statement workflow, advisory AI feedback on statements visible to staff through normal product views, school oversight tools (cohort visibility, at-risk flags, and school setup metadata), and CV/application workspaces where enabled for the School's rollout. Automated safeguarding alert delivery, staff routing and review holds are not active in the launch product. Reference Studio and Opportunity Radar are coming September 2026 and are not part of current processing unless activated by written agreement before activation.

3. Roles and Instructions

  1. The School acts as Controller and determines the educational purpose and lawful basis for processing.
  2. Outleap acts as Processor and processes personal data only on the School's documented instructions, unless required by law.
  3. Outleap will promptly notify the School if an instruction appears to conflict with UK GDPR obligations.

4. Categories of Data and Data Subjects

  • Data subjects: students, teachers, school administrators.
  • Core identifiers: name, school email address, user ID, school ID, role.
  • Education workflow data: evidence entries, statement draft text, submitted statement snapshots, feedback drafts and published feedback, submission status, and CV/application records where enabled for the School. (Reference workflow records relate to Reference Studio, coming September 2026, and are not currently processed unless activated by written agreement.)
  • Operational metadata: course progress, timestamps, audit events, role-based access events.
  • Special category data: may be processed where the School chooses to include extenuating-circumstances or other special category information in authorised workflows (for example contextual or welfare detail in a statement). Such processing remains under the School's instructions and is subject to role-scoped access, safeguarding controls, and the School's lawful basis and Article 9 condition.

5. Security and Confidentiality Controls

Outleap applies technical and organisational measures appropriate to the service, including:

  • Role-based access control and school-level tenant scoping.
  • Authentication controls using Firebase Authentication.
  • Encryption in transit (HTTPS/TLS) and encryption at rest on managed cloud services.
  • Audit logging for administrative and operational actions.
  • Logging policy to avoid student statement text and AI output content in application logs.
  • Least-privilege access for runtime service accounts and infrastructure components.

Personnel with access to personal data are bound by confidentiality obligations.

6. Subprocessors (Current/Planned)

Outleap uses the following subprocessors for platform delivery.

Subprocessor Service purpose Typical data processed Hosting/processing location notes
Google Cloud / Firebase (Google) Hosting, API runtime, auth, database, task queue, storage of platform records Account data, workflow metadata, statement/feedback records, audit logs Configured for UK/EU-oriented regions (europe-west2, europe-west4) for core workloads
Vertex AI (Google) AI-assisted feedback and drafting support where enabled Relevant student-provided content and the minimum workflow context needed to provide the requested support UK/EU Google Cloud regions
Amazon Web Services (Amazon Bedrock) AI-assisted feedback and drafting support where enabled Relevant student-provided content and the minimum workflow context needed to provide the requested support Supported EU AWS regions
Postmark (designated transactional email provider) Transactional email delivery (login links, reminders, notifications) Recipient email address, message metadata, delivery events US-based provider; transfer safeguards (UK IDTA or UK Addendum to SCCs) apply, to be confirmed in signed contract schedule

Outleap remains responsible for subprocessor compliance and will maintain an up-to-date subprocessor list for customers. The current list and data-flow description form part of the trust pack.

7. International Transfers

Outleap aims to keep customer workloads in UK/EU-hosted infrastructure. Some service providers may process personal data in EU regions outside the UK. The signed contract schedule must record the applicable UK adequacy basis or other appropriate safeguard. If personal data is transferred elsewhere outside the UK, Outleap will use an appropriate transfer mechanism (for example a UK IDTA or UK Addendum to SCCs) and provide supporting documentation on request.

8. Data Subject Rights Support

Outleap will provide reasonable assistance to the School in responding to data subject rights requests (access, rectification, erasure, restriction, portability, objection), subject to identity and role verification.

9. Personal Data Breach Process

Outleap will notify the School without undue delay, and in any event within 72 hours of confirming a personal data breach affecting School data, and provide known details on:

  • nature and likely impact,
  • categories/approximate volume affected,
  • containment and remediation steps,
  • ongoing update cadence.

10. Retention and Deletion

Retention periods and deletion controls are defined in the approved retention schedule (see data-retention-policy-template.md). On contract termination, Outleap will support data export/handover and then delete or return personal data, except where legal obligations require retention.

11. Audit and Assurance

On reasonable notice, Outleap will provide information needed to demonstrate compliance with this DPA, including policy documentation and control evidence appropriate to the service risk profile.

12. Annex A: Processing Details

  • Subject matter: operation of the current first-school rollout of the Outleap destinations workflow.
  • Nature of processing: collection, storage, access control, role-scoped display, advisory AI feedback generation and delivery, reminder/notification operations, operational support handoff where required, and CV/application workspaces where enabled for the School.
  • Purpose: support school-led evidence capture, UCAS three-question statement drafting, advisory AI feedback that staff can see, CV/application support where enabled, and cohort progress management. Reference Studio and Opportunity Radar are coming September 2026 and would be added to this purpose by written agreement before processing begins.
  • Duration: for the term of the service agreement plus agreed retention/deletion windows.

13. Annex B: Contact Points

  • School privacy contact: [Name, role, email]
  • Outleap privacy contact: Jesse Merrigan, Director, info@outleap.io — supported by Outleap's documented data-protection governance and review process.
  • Outleap general/supplier contact: hello@outleap.io
  • Data Protection Officer: Outleap has not appointed a statutory DPO. A DPO is not required under UK GDPR Article 37 given the scale of processing. The named data-protection contact is the Director.
  • Breach notification email: info@outleap.io

14. Signatures

School (Controller)

  • Name:
  • Role:
  • Signature:
  • Date:

Outleap Limited (Processor)

  • Name: Jesse Merrigan
  • Role: Director
  • Signature:
  • Date:

This is a template document. School-specific fields require completion and legal review before use. For questions, contact hello@outleap.io.

For data, IT and DPOs

Need a walkthrough of this document?

We can walk your procurement and governance team through the trust pack and answer school-specific questions.

Book a trust review