Data protection
Data Processing Agreement
Version 1.0, last updated 8 September 2026
This agreement governs the personal data we process on your Maktab's behalf. It forms part of our terms of service, and accepting those accepts this.
It exists because UK data protection law requires it. Article 28 of the UK GDPR says nobody may process personal data for someone else without a written contract covering specific ground. This is that contract, written to be read rather than to be impressive.
Which of us is which
Your Maktab is the data controller. You decide what is recorded about your students, staff and families, and why.
We are your processor. We hold and handle that information on your instructions, and for no other purpose. We do not sell it, share it for advertising, or use it to train AI models.
For a small amount of information we are the controller in our own right: enquiries made through our website, our own staff records, and the security logs that record sign-in attempts. That is covered by our privacy notice, not by this agreement.
Our instructions
We process personal data only on your documented instructions. Your instructions are the platform as documented, meaning that when a member of your staff uses a feature, that use is your instruction to us.
Anything outside that, such as a bespoke extract, a migration, or work on your behalf that the platform does not do by itself, must be agreed in writing first and may be charged for.
We will also process personal data where UK law requires us to. Where we are permitted to tell you before we do, we will.
If we think an instruction of yours breaches data protection law, we will tell you and we may pause that instruction until it is resolved.
What we process for you
Subject matter and purpose. Running your Maktab: enrolment, registers and attendance, homework, Hifdh, level tests, merits, reports, messaging, fees and payments, staff records and timesheets, and the parent and teacher portals.
Nature of the processing. Storing, organising, retrieving, displaying, transmitting and deleting records, and producing the reports and summaries the platform offers.
Who the data is about. Students, who are children. Their parents and guardians. Your teachers, staff and volunteers. People who apply to join.
What kinds of data. Names, dates of birth, contact details and home addresses. Attendance and lateness. Academic and Hifdh records, level tests, merits and reports. Messages exchanged through the platform. Fees, invoices, payments and balances. Staff hours, roles and pay. Photographs and voice recordings attached to homework.
Special category data. Where you record it: medical conditions, allergies, special educational needs and additional needs, and consent for emergency treatment. This is handled under the same terms as everything else in this agreement, with access controlled by the roles you set.
How long. For as long as your subscription runs, and then for the export window described below.
Confidentiality
Everyone at our end who can access your data is bound by a duty of confidentiality that survives them leaving.
Access is limited to the people who need it to run and support the platform, and it is logged.
Security
We keep appropriate technical and organisational measures in place to protect your data, as Article 32 requires. In practice that means encryption in transit and at rest, access limited by role and logged, tenant isolation enforced at the database, credentials held in managed secret storage, and regular patching.
We do not publish the detail of our security architecture, and we would not expect a supplier of ours to either. If you need assurance beyond this, ask and we will arrange it under a confidentiality agreement.
Security measures change as threats do. We may update them, provided the protection does not drop below what is described here.
Sub-processors
You give us general written authorisation to use sub-processors. The current list is published at themaktabapp.com/sub-processors, with what each one does and the country it does it in.
We will give you at least 30 days notice before adding or replacing one. If you object on reasonable data protection grounds within that period, we will discuss it with you and try to resolve it. If we cannot, you may terminate your subscription and we will refund the unused part of your period.
Every sub-processor is bound by obligations no weaker than these, and we remain fully responsible to you for what they do.
Where your data is processed
The database holding your records is in the United Kingdom.
Some supporting services process data outside the UK, and the sub-processor list says which and where. Where personal data leaves the UK it is transferred under the safeguards UK law provides, using the International Data Transfer Addendum to the EU Standard Contractual Clauses or another lawful mechanism.
Helping you answer people's requests
If a parent, student or member of staff asks to see, correct, delete or export what is held about them, that request is yours to answer. The records are yours and you are the controller.
The platform is built so you can answer without us: you can search, correct and delete records directly, and an owner can export everything the Maktab holds at any time from the admin portal.
Where a request genuinely needs us, we will help, taking into account the nature of the processing and the information available to us. If a request needs substantial work from us beyond the tools the platform already provides, we will agree the scope and cost with you first.
If a request reaches us directly, we will not answer it ourselves. We will pass it to you promptly and let the person know we have done so.
If there is a personal data breach
We will tell you within 24 hours of confirming a breach that affects your data. That is tighter than the 72 hours the law allows us, because you are the one who has to decide whether to notify the Information Commissioner and the families involved, and you need the time.
The 24 hours runs from the point we confirm a breach has occurred and that it affects you, not from the first sign of something unusual. Investigating an alert is not the same as having a breach, and a notification sent before anyone knows what happened helps nobody.
We will tell you what happened, what data was affected, roughly how many people, what we have done, and what we suggest you do. Where we do not yet know something we will say so and follow up rather than delay the first message.
Notifying the Information Commissioner, and the people affected, is your decision and your duty as controller. We will give you what you need to make it.
Assessments and the regulator
We will give you reasonable help with data protection impact assessments and with prior consultation of the Information Commissioner, taking into account the nature of the processing and what we actually know.
That help is limited to information we hold about how the platform processes data. Assessing your own purposes, your lawful basis and your risk appetite is yours to do.
Demonstrating compliance, and audits
We will make available the information you reasonably need to show that we are meeting these obligations. In the first instance that is our written documentation, which usually answers the question.
If it does not, you may audit us once in any 12 month period, on at least 30 days written notice, remotely, during normal business hours, at your own cost, and subject to a confidentiality agreement. An audit must not disrupt the service or expose another customer's data.
More frequent audits are available where a regulator requires one, or following a confirmed breach affecting your data.
What you are responsible for
This section matters, because the most likely thing to go wrong is at your end rather than ours. By accepting this agreement you confirm that:
You have a lawful basis for everything you record in the platform, and where you rely on consent, you have obtained it and can evidence it.
You have given privacy notices to the parents, students and staff whose data you record, telling them what you hold and why.
You have the right consents and conditions for medical, special educational needs and other special category data before you enter it.
You control who has access. Deciding which of your staff get admin rights, what each role can see, and removing people who leave is yours to do. We give you the tools; we cannot know who at your Maktab should hold them.
What you enter is accurate, and you keep it so.
Your instructions to us are lawful.
You will indemnify us against claims, fines and costs arising from any of the above being untrue. This does not touch our own responsibility for our own failures.
Getting your data back, and deletion
An owner can export everything your Maktab holds at any time, from the admin portal, at no charge and without asking us.
When your subscription ends, your data stays exportable for 30 days. After that we delete it from our live systems.
Backups are deleted on their normal cycle rather than opened up and edited, which is standard practice and keeps the backups themselves trustworthy. Data in a backup is not used for anything and is deleted when that backup expires.
We will not withhold your data over a billing dispute, and we do not delete it to make a point.
Where UK law requires us to keep something, we will keep only that, only for as long as required, and we will tell you.
Liability
The liability provisions in our terms of service apply to this agreement, and the cap there is a single cap across both, not one each.
This clause settles responsibility between you and us. It does not and cannot limit what either of us owes a parent, student or member of staff under Article 82, or what the Information Commissioner may do.
Where we are both responsible for the same damage, each of us bears the share that reflects our own part in causing it.
Changes to this agreement
Every version is numbered and dated, and superseded versions stay available so you can see what you accepted and when.
Where a change materially affects you, we give at least 30 days notice and ask the account owner to accept the new version. If you would rather not, you may terminate before it takes effect and we will refund the unused part of your period.
We may make a change without notice where the law requires it, and we will tell you as soon as we have.
General
This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Where this agreement and the terms of service disagree about personal data, this agreement wins.
If a court finds any part unenforceable, the rest continues to apply.
A signed copy is available for Maktabs whose governors or data protection officer need one. Ask us and we will send it.