Data processing agreement
Version 2026-08-27 · Effective 27 August 2026
This page summarises the standard Data Processing Agreement between Syba LLC and schools subscribing to SchoolRota. It applies alongside the Terms of service whenever we process personal data on your behalf. A signed copy on your own paper, or countersigned on ours, is available from hello@schoolrota.com.
Roles
You are the controller for staff personal data in your portal. We are the processor, and act only on your documented instructions. Using the service, and configuring it as you choose, constitutes those instructions. We will tell you if an instruction appears to breach applicable data protection law.
Scope of processing
- Subject matter: provision of duty rota, lesson cover, and related operational software.
- Duration: the term of your subscription, plus the retention periods below.
- Nature and purpose: hosting, storage, retrieval, generation of rotas and cover proposals, notification, export, backup, and support.
- Categories of data subject: your staff, contractors, and supply staff.
- Categories of personal data: identity and contact details, employment role, working patterns, availability and absence, duty and cover assignments, authentication data, and audit records.
- Special category data: not required and not requested. You should not upload it, and the Acceptable Use Policy prohibits it.
Our obligations
- Process personal data only for the purposes above and not for our own purposes.
- Keep personal data confidential, and ensure staff with access are bound by confidentiality and trained.
- Apply appropriate technical and organisational measures, described on our security page, including tenant isolation, role-based access, encryption in transit and at rest, audit logging, and tested backups.
- Limit access to the minimum number of personnel needed for support and operations, and log that access.
- Not use your data to train AI models, and not sell or share it for advertising.
Sub-processors
You give general authorisation for us to appoint sub-processors. The current list, with purpose and hosting location, is on our sub-processors page. Each is engaged under terms no less protective than these, and we remain responsible for their performance. We publish additions before they begin processing and notify account owners of material changes, giving you 30 days to raise a reasonable objection.
Security incidents
We notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data. Notification includes the nature of the breach, categories and approximate numbers affected where known, likely consequences, and the measures taken. We assist you with your own notification duties. Report suspected incidents to security@schoolrota.com.
Data subject requests
Portal admins can search, correct, export, and delete staff records directly, which covers most requests. If a request reaches us instead, we will not respond to it substantively, will refer the individual to you, and will tell you promptly. We provide reasonable assistance at no charge for requests within scope.
International transfers
All production customer data is currently hosted in the United Kingdom (London), whichever country your school is in. Support access from the United Arab Emirates, and transfers to sub-processors outside the UK or EEA, are covered by the UK International Data Transfer Addendum or EU standard contractual clauses as applicable, together with a transfer risk assessment we can share on request.
Audit and assistance
We provide our security documentation, Cyber Essentials certification, and answers to reasonable due diligence questionnaires. We support your DPIA where the service is in scope. On-site or third-party audit is available once per year on reasonable notice where required by law or your regulator, at your cost, subject to confidentiality and without disrupting other customers.
Return and deletion
- You can export your data at any time during the subscription, and for 30 days after termination. Where we terminated for unlawful activity or a security risk, we provide the export to a named senior officer of your organisation instead of restoring general portal access.
- We delete personal data from live systems within 60 days of the end of that window. Residual copies in encrypted backups are overwritten as those backups age out of our rolling backup cycle, and are not restored or otherwise processed in the meantime.
- We keep a minimal administrative record of the account after deletion: the school name, the subscription, and the administrative actions we took, including the dates of suspension, closure, and deletion, and which of our staff carried them out. It contains no Customer Data, and we keep it to meet legal and accounting obligations and to establish or defend legal claims.
- We may retain data where required by law, in which case we keep it confidential and process it only for that purpose.
- Written confirmation of deletion is available on request.
Liability
Liability under this agreement is subject to the limitations in the Terms of service, except where applicable data protection law does not permit that.
Requesting a signed copy
Email hello@schoolrota.com with your school name and the name of the signatory, and we will return a countersigned DPA. We can also review a DPA on your own template.