1. Definitions
“Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Sub-processor”, and “Supervisory Authority” have the meanings given in the GDPR. “School Data” means the Personal Data uploaded to the Kampus platform by or on behalf of the School.
2. Roles
The School is the Controller of School Data. Kampus is the Processor, processing School Data only on the documented instructions of the School. Where a Sub-processor is engaged, Kampus remains fully responsible for its acts and omissions.
3. Documented instructions
Kampus will process School Data only to deliver the Kampus platform, to comply with documented School instructions, and to meet legal obligations to which Kampus is subject. If a legal requirement conflicts with the School's instructions, Kampus will inform the School before processing, unless that law prohibits such notification on public-interest grounds.
4. Categories of data and data subjects
- Categories of Data Subjects: students, parents or guardians, school staff, applicants, visitors, and other individuals whose data the School chooses to upload.
- Types of Personal Data: identity and contact details; academic and attendance records; billing, payment, and financial data; employment, salary, and leave records; photographs and documents the School chooses to upload; system logs and usage data.
- Special categories: the platform can hold special categories of data (for example, health notes, faith-based attendance) where the School chooses to record them. The School is responsible for establishing the legal basis to process such data and for limiting access appropriately.
5. Security of processing
Kampus implements technical and organisational measures appropriate to the risk, including: encryption of Personal Data in transit (TLS 1.2 or higher) and at rest; role-based access controls with least-privilege defaults; centralised audit logging of access and administrative actions; segregation of School data by campus; hardened production environments with monitored access; vulnerability management and patch processes; business continuity and disaster recovery testing; and regular staff training on data protection and security.
6. Sub-processors
Kampus engages Sub-processors to host, transmit, back up, and support the platform. A current list is maintained at our sub-processor page (or supplied on request) and is updated at least 30 days before a new Sub-processor is engaged. Schools may object to a new Sub-processor on reasonable grounds related to data protection; if we cannot accommodate the objection, the School may terminate the affected services and receive a pro-rata refund of pre-paid fees.
7. International transfers
School Data is stored in the region the School chooses at signup. Where School Data is transferred outside the European Economic Area, the United Kingdom, or another jurisdiction that restricts such transfers, Kampus relies on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or other safeguards recognised by the relevant Supervisory Authority, supplemented by a transfer impact assessment and, where required, additional technical and organisational measures.
8. Data Subject rights
Kampus will, taking into account the nature of the processing, assist the School by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under applicable data protection law. If Kampus receives a request directly from a Data Subject relating to School Data, Kampus will forward the request to the School without undue delay.
9. Personal Data breaches
Kampus will notify the School without undue delay, and in any case within 48 hours, after becoming aware of a Personal Data Breach affecting School Data. The notification will include the information required by Article 33(3) GDPR to the extent available, and will be updated as the investigation develops.
10. Deletion and return
On termination of the agreement, Kampus will, at the School's choice, delete or return all School Data, and delete any existing copies, unless retention is required by applicable law. The deletion timeline is described in our Privacy Policy.
11. Audits
Kampus will make available to the School all information necessary to demonstrate compliance with this DPA, and allow audits, including inspections, conducted by the School or an auditor mandated by the School, with reasonable prior notice and subject to confidentiality and security obligations.
12. Governing law
This DPA is governed by the laws of the registered office of the Kampus entity. The Parties will work in good faith to resolve any dispute, and may escalate to mediation before formal proceedings, where appropriate.
13. Contact
The data protection contact at Kampus is reachable at privacy@kampus.appwith “DPA” in the subject line.