Data Processing Agreement · LessonSmith
Controller ("you", "Customer"): the school, employer or other organisation on whose behalf personal data is submitted to the Service. Where an individual account holder uses the Support Plan tool, that person enters this Agreement for their school and confirms they are authorised to do so, as Terms of Use Section 6a asks them to. If they are not so authorised, they hold the Customer's obligations under this Agreement themselves.
When it applies: from the moment an account holder first gives the confirmation in Terms of Use Section 6a, or from signature where a school signs a copy of this Agreement on its own paper. Signing changes the named counterparty. It does not change the obligations on either side.
This Agreement forms part of the Terms of Use and is read with the Privacy Policy. On any conflict about personal-data processing, this Agreement controls.
1. Roles & scope
- For personal data the Customer submits, or that we process on the Customer's behalf to provide the Service, the Customer is the Controller and LessonSmith is the Processor (Kenya DPA 2019; GDPR Art. 28; UK GDPR).
- We process that data only on the Customer's documented instructions (the normal use of the Service, this Agreement, and the agreement between us) unless the law requires otherwise, in which case we will tell you first where we are lawfully able to.
- Details of processing (subject matter, duration, nature, purpose, data types, data subjects) are in Annex 1.
2. Our obligations as Processor
We will:
- process only on your documented instructions (Section 1);
- ensure persons authorised to process are bound by confidentiality;
- implement the security measures in Annex 2 (Kenya DPA 2019; GDPR Art. 32);
- respect the conditions in Section 4 for engaging sub-processors;
- assist you, taking into account the nature of the processing, to respond to data-subject requests (access, correction, deletion, portability, objection) and to meet your security, breach-notification, impact-assessment and prior-consultation duties;
- at your choice, delete or return all personal data at the end of services and delete existing copies, unless the law requires retention (Section 7);
- make available the information needed to demonstrate compliance, and allow for and contribute to audits (Section 8).
3. Customer obligations
You warrant that you have a lawful basis and any required notices and consents to provide the personal data to us, and that your instructions are lawful.
Learner data, general rule. Outside the Support Plan tool you agree not to submit learners' or children's personal data into the Service. Your users describe classes in general terms instead (see Privacy Policy Section 13).
The Support Plan tool is the exception, by design. It drafts the individual plan a learner with additional support needs is entitled to (an IEP, an ISP under South Africa's SIAS policy, a SEN Support plan under England's SEND Code of Practice, an ILP, or a Learning Support Plan, depending on your system), so using it necessarily involves data about one learner and about their special educational needs. Where your authorised users use that tool, you warrant that:
- you are the Controller for that data and you permit your users to draft these plans with an external tool;
- you hold the lawful basis and any parental or guardian consent your own law requires, including the conditions for a child's data under Kenya DPA 2019 s.33, Article 9 UK/EU GDPR, POPIA ss.34-35, and, in the United States, FERPA together with the confidentiality provisions of IDEA;
- you have given parents or guardians whatever information your law requires about how your school produces and stores these plans;
- you instruct your users to enter the minimum. The learner's name is optional in the tool, initials are sufficient, and a plan drafted with the name left blank exports with a ruled line to complete by hand.
We do not obtain parental or guardian consent on your behalf and we are not in a position to do so.
If you are an individual account holder rather than a school. You give the warranties in this Section for the school you act for, and you confirm your school permits you to draft these plans with an external tool. If it turns out your school did not permit it, the warranties in this Section are yours, and Section 9 and Terms of Use Section 11a apply to you rather than to the school.
4. Sub-processors
- You give general authorisation for us to engage the sub-processors listed in Annex 3, kept current in Privacy Policy Section 5.
- We impose data-protection terms no less protective than this Agreement on each sub-processor and remain liable for their performance.
- We will give reasonable prior notice of any new or replacement sub-processor, for example by updating the list and emailing the billing contact on your account. You may object on reasonable data-protection grounds within 14 days, and we will work in good faith to address it.
5. International transfers
Some processing happens outside Kenya, the EEA and the UK, for example by US-based AI and hosting providers. Where required, transfers rely on an appropriate safeguard such as Standard Contractual Clauses, the UK IDTA, or adequacy, as offered by the relevant provider. Annex 3 notes each provider's mechanism.
6. Personal-data breaches
We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal-data breach affecting your data. We will include the information you reasonably need to meet your own notification duties to the Office of the Data Protection Commissioner or another supervisory authority, and to data subjects.
7. Return & deletion
On termination, or on your request, we will delete or return your personal data within 30 days and delete remaining copies, except data we must retain by law such as payment or tax records, which stays protected under this Agreement until it is deleted.
8. Audits
We will provide the information reasonably necessary to show compliance with this Agreement. For audits you may accept third-party reports or certifications where they are available. Any on-site audit is once per 12 months, on reasonable notice, during business hours, and subject to confidentiality, at your cost unless a material breach is found.
9. Liability & order of precedence
Each party's liability under this Agreement is subject to the limitation of liability in Terms of Use Section 11, including the paragraph there confirming that a learner and their parent or guardian are not parties to the Terms and keep their own rights in full. If this Agreement conflicts with the Terms on the processing of personal data, this Agreement prevails, as Terms of Use Section 6b provides.
10. Governing law
This Agreement is governed by the laws of Kenya and is read consistently with any mandatory data-protection law of the Customer's jurisdiction, such as the GDPR or the UK GDPR, that applies to the processing.
Annex 1: Details of processing
- Subject matter: providing the LessonSmith lesson-plan, Scheme-of-Work and support-plan service.
- Duration: the term of the subscription plus the retention period in Section 7.
- Nature & purpose: hosting, authentication, AI generation, analytics, billing.
- Data subjects: the Customer's authorised users, meaning teachers and staff; and, where the Support Plan tool is used, the learners who are the subject of a support plan, who are children.
- Categories of data: name, email, authentication identifiers; content inputs and outputs; usage and analytics; technical and log data; payment status metadata.
- Special-category and children's data: where the Support Plan tool is used, for each learner: the name or initials the teacher enters, which is optional and often left blank, the class or grade, the learning area, the categories of need ticked from a fixed list, the teacher's own notes on what the learner can currently do and what they are good at, and a review date. A category of need is health-related, so it is special-category data under GDPR Art. 9, sensitive personal data under Kenya DPA 2019, and special personal information under POPIA. It is prohibited everywhere else in the Service by Section 3.
Annex 2: Technical & organisational measures
Secrets and API keys server-side only; encryption in transit over HTTPS; admin tools restricted to authorised accounts; least-privilege access; logging and error monitoring; vendor due diligence; reasonable backup and incident response.
Encryption at rest is applied in two independent layers. Our database provider encrypts every record it holds with AES-256. Above that, personal data written by the Service is encrypted at the application layer under a key the provider does not hold, so a database copy taken on its own yields ciphertext. That layer covers plan content, schemes of work, the teacher profile, school details and support plans, which is where the special-category data described in Annex 1 sits. The copy held in the data subject's own browser is encrypted under a non-exportable key generated on that device.
These measures do not defend against compromise of the Service itself or of an authenticated session, and are not represented as doing so. They mirror Privacy Policy Section 8.
Annex 3: Authorised sub-processors
The current list is maintained in Privacy Policy Section 5: Clerk, Convex, Polar (which uses Stripe), OpenAI, Google, PostHog, Vercel and Sentry. Each entry gives the provider, its purpose, its location and its transfer mechanism. That list and this annex are kept in sync, with Section 5 as the single source of truth.
Related policies
Terms of Use · Privacy Policy · All legal documents
A school that needs a signed copy on its own paper can ask at legal@lessonsmith.ai.