Data processing agreement
Last updated: 18 August 2026
This is the standard agreement we sign with every member school, published here so your data protection officer can read it before anyone commits to anything. Under UK GDPR Article 28, the school is the data controller for its students' data and Music Tech Studio is the data processor. It is written to match our privacy notice and forms part of the school membership terms.
Signing happens on a one-page cover sheet naming the school, both parties' addresses and the date; the cover sheet incorporates the text below. Email privacy@musictechstudio.co.uk for a signable copy.
The parties
(1) The school named on the cover sheet (the "Controller"), and (2) Mike Lehnert, trading as Music Tech Studio, at the trading address given on the cover sheet, contact privacy@musictechstudio.co.uk (the "Processor").
This Agreement is entered into under Article 28 of the UK GDPR and forms part of the Music Tech Studio school membership between the parties. It applies for as long as the Processor processes personal data on the Controller's behalf.
1. Definitions
"UK GDPR", "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR and the Data Protection Act 2018. "Services" means the Music Tech Studio membership platform for Pearson Edexcel A-Level Music Technology Components 3 and 4, including the student revision platform, teacher dashboard and essay-marking loop.
2. Subject matter, nature and purpose of processing
The Processor provides an online revision and assessment platform. On the Controller's behalf it processes student personal data to: deliver curriculum-aligned learning and retrieval practice; record quiz, assessment and essay work; generate feedback (including automated essay feedback, clause 7); and present progress and exam-readiness information to the student and to the Controller's nominated teacher.
3. Duration
Processing continues for the duration of the school's membership, plus the deletion window in clause 10.
4. Categories of data subjects and personal data
Data subjects: students of the Controller studying A-Level Music Technology (typically aged 16 to 18); the Controller's nominated teacher(s).
Personal data: student name and cohort; email address (optional, account recovery only); grade data (assessment scores, mark history, teacher feedback); essay submissions and audio recordings; quiz responses and retrieval-practice data; a pseudonymous login token; teacher name and school email address.
Special category data: none is requested or required. Students are instructed not to include personal information beyond the set task in free-text and audio submissions.
5. Controller instructions
The Processor processes personal data only on the Controller's documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case the Processor informs the Controller before processing, unless the law prevents this). This Agreement and the use of the Services as designed constitute the Controller's complete instructions.
6. Processor obligations (Article 28(3))
The Processor shall:
- (a) ensure persons authorised to process the data are committed to confidentiality (the Processor is a sole operator; no staff have access);
- (b) implement the technical and organisational measures in Annex 1 (Article 32);
- (c) engage sub-processors only under clause 8;
- (d) taking into account the nature of the processing, assist the Controller in responding to data subject rights requests (access, rectification, erasure, restriction, portability, objection) within 10 working days of a request from the Controller;
- (e) assist the Controller with its Article 32 to 36 obligations (security, breach notification, DPIAs), taking into account the nature of processing and information available to the Processor;
- (f) at the end of the Services, delete or return the personal data per clause 10;
- (g) make available to the Controller the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits per clause 11.
7. Automated essay feedback (Anthropic)
Essay text submitted by students is sent to Anthropic (a US provider) to generate marking feedback against the assessment objectives. Safeguards:
- Submissions are sent for the purpose of generating feedback only, and contain no student identifiers: the transferred payload comprises the exam question, the mark scheme and the response text alone. Students are instructed not to include personal information in their responses.
- Anthropic's Commercial Terms of Service state that Anthropic may not train models on customer content from its services; its Data Processing Addendum is incorporated into those terms by reference and provides for deletion of customer data within 30 days of termination.
- Transfers are covered by the safeguards in clause 9.
8. Sub-processors
The Controller gives general written authorisation to the sub-processors listed below, as also published in the privacy notice:
| Sub-processor | Location | Purpose |
|---|---|---|
| Vercel | Frankfurt, EU | Hosting |
| Supabase | EU region | Database and authentication |
| PostHog | Frankfurt, EU | Analytics, consent-only, tied to pseudonymous token |
| Resend | US (clause 9) | Email delivery: teacher sign-in links, grade and feedback notifications |
| Anthropic | US (clause 9) | Automated essay feedback (clause 7) |
The Processor shall give the Controller at least 30 days' written notice of any intended addition or replacement, during which the Controller may object on reasonable data-protection grounds. The Processor imposes data-protection obligations on each sub-processor equivalent to those in this Agreement and remains liable for their performance.
9. International transfers
Personal data is hosted in the EU (UK adequacy applies). Two sub-processors process data in the United States, each under safeguards recognised by UK GDPR:
- Anthropic (clause 7): its Data Processing Addendum incorporates the EU Standard Contractual Clauses and the ICO's UK Addendum.
- Resend (email delivery, which may include student names and grade information in notification emails): its Data Processing Agreement incorporates the EU Standard Contractual Clauses and the UK Addendum, and Resend is certified under the EU-US Data Privacy Framework.
No other sub-processor receives personal data outside the UK/EU.
10. Return and deletion
Student data remains available for the duration of the student's A-Level studies. Within 12 months of a student leaving (or on earlier written instruction from the Controller), the Processor deletes the student's personal data. On termination of the membership, the Controller may request return (portable export) or deletion of all student data; deletion is completed within 90 days and confirmed in writing on request. Any residual copies in encrypted system backups are overwritten in the ordinary course of the backup cycle and are not restored except for disaster recovery.
11. Audit
The Processor answers reasonable written information requests within 15 working days. Where these are insufficient, the Controller (or an appointed auditor, not a competitor of the Processor) may audit compliance with this Agreement on 30 days' written notice, at most once in any 12-month period, during normal hours, without access to other schools' data.
12. Personal data breach
The Processor notifies the Controller without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Controller's data, with sufficient information for the Controller to meet its Article 33 and 34 obligations, and cooperates in remediation.
13. Liability and general
Each party's liability under this Agreement is subject to the liability provisions of the membership terms; in any event, and except for liability that cannot be excluded by law, each party's total liability under this Agreement is limited to the fees paid under the membership in the 12 months preceding the claim. If any provision conflicts with the membership terms on data-protection matters, this Agreement prevails. This Agreement is governed by the law of England and Wales.
Annex 1: technical and organisational measures
- All traffic encrypted in transit (TLS); data encrypted at rest by Supabase.
- Database access governed by row-level security; no permissive public policies.
- Students authenticate by private per-student secret-token links: no student passwords, no student email addresses required, nothing for students to register.
- Teacher access by magic-link email to a school address; no shared logins.
- Analytics only with consent, keyed to the pseudonymous token, never to names.
- EU-region hosting and database (Frankfurt / EU).
- Single named operator (Mike Lehnert); no third-party staff access.
- API routes require authentication; error responses do not leak internal detail.
The questions DPOs ask
Not part of the agreement: straight answers to the questions data protection officers ask us.
"Student work goes to a US AI provider?" Yes, essay text only, to generate feedback referenced to the assessment objectives. The payload carries no student identifiers at all: the exam question, the mark scheme and the response text, verified against the marking code. Anthropic's terms prohibit training on it. Database and hosting stay in the EU.
"Who else sees the data?" Nobody. Sole operator, no advertisers, no resale; the sub-processor list above is the whole of it.
"What happens when a student leaves?" Deleted within 12 months, earlier on instruction; portable export available.
"Under-18s?" The platform is designed for it: no student accounts, no student emails, token links distributed by the teacher.