Data processing agreement
BugBotLab Ltd · last updated 11 September 2026 · print this page to sign a copy
This agreement is made under Article 28 of the UK GDPR. It forms part of the terms of service and applies automatically to every school that uses BugBot class codes, on any plan, during a trial and during free use. A school that wants a signed copy can fill in the details at the end and send it to info@bugbotlab.com, and we will countersign it.
1. The parties and their roles
The controller is the school, college or other organisation whose teachers use BugBot Teach ("the school"). The processor is BugBotLab Ltd, registered in England and Wales, company number 16669242, registered office 103 Ouseley Road, Wraysbury, Staines-Upon-Thames, TW19 5JJ ("BugBotLab"). The school decides why and how class data is used. BugBotLab processes it only to provide the service. Words such as personal data, processing, data subject and personal data breach have the meanings they have in the UK GDPR and the Data Protection Act 2018.
2. Instructions
BugBotLab processes the school's personal data only on the school's documented instructions. Those instructions are this agreement, the terms of service, and what teachers do in BugBot Teach, such as making a class, sending a hint or deleting a record. If BugBotLab thinks an instruction breaks data protection law, it will tell the school. If the law requires BugBotLab to process the data in another way, it will tell the school first unless the law forbids that.
3. Confidentiality
Only people who need access to run the service can reach the school's data. They are named, bound by confidentiality, and use two-factor authentication.
4. Security
BugBotLab keeps the technical and organisational measures in Schedule 2 in place, and it will not reduce their overall level of protection during the agreement.
5. Sub-processors
The school gives general permission for BugBotLab to use the sub-processors in Schedule 3. BugBotLab will give at least 30 days' notice by email and on this page before adding or replacing one. If the school objects on reasonable data protection grounds and the two cannot agree a solution, the school can end its plan and get a refund of the unused part. BugBotLab puts data protection terms on each sub-processor that are at least as protective as this agreement, and it stays responsible to the school for them.
6. International transfers
Class data is stored in London. Some sign-in data may be processed in the United States by Firebase Authentication. That is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses in Google's data processing terms. BugBotLab will not make any other transfer outside the UK without a lawful safeguard and notice under section 5.
7. Helping the school
- Rights requests. Teachers can view, export and delete student records themselves in BugBot Teach. If a data subject contacts BugBotLab directly, BugBotLab passes the request to the school within 5 working days and helps the school answer it.
- DPIAs and the ICO. BugBotLab provides a pre-filled DPIA template and answers reasonable questions for the school's DPIA or any consultation with the Information Commissioner.
8. Personal data breaches
BugBotLab will tell the school without undue delay, and within 48 hours of becoming aware of a personal data breach affecting the school's data. BugBotLab gives what it knows at the time about what happened, the data and people affected, the likely consequences, and what it is doing about it, and adds details as they become known. That gives the school time to meet its own 72-hour duty to report to the ICO.
9. At the end
The school can export its class data as a spreadsheet from BugBot Teach at any time, and delete it there. When the school asks, or when the retention periods in the privacy notice end, BugBotLab deletes the data within 30 days, unless the law requires it to keep some. Copies in the database provider's own recovery systems are overwritten on the provider's normal schedule. BugBotLab will confirm deletion in writing on request.
10. Audits and information
BugBotLab makes available the information needed to show it meets Article 28. That includes answering the school's security questionnaire once a year, providing this agreement and the documents in Schedule 2, and explaining any change. If the school has good reason to believe that is not enough, BugBotLab will allow an audit by the school or an auditor it appoints, on 30 days' notice, at a reasonable time, and at the school's cost, subject to confidentiality.
11. Liability, length and law
Liability under this agreement follows section 9 of the terms of service, except where the law does not allow that. This agreement lasts as long as BugBotLab processes the school's data. It is governed by the law of England and Wales. If this agreement and the terms of service conflict on data protection, this agreement wins.
Schedule 1: the processing
| Item | Details |
|---|---|
| Subject matter | Providing BugBot Teach: class codes, the live class view, progress, hints, assignments, module locks, custom tasks and mark book exports. |
| Duration | While the school uses class codes, then until deletion under section 9. |
| Nature and purpose | Collecting, storing, displaying and deleting learning activity so teachers can teach and support students. Programs are checked automatically by a simulator. There is no profiling, advertising, sale of data or training of AI models, and no automated decisions with legal or similar effect. |
| Data subjects | Students in the school's classes, usually aged 14 to 19, and the school's teachers. |
| Personal data | Students: nickname, a random identifier, class code, current lesson, task results and attempts, the last program run (up to 4000 characters), the last error message, timestamps. Teachers: email address, display name, sign-in provider, classes, messages and hints. |
| Special category data | None is asked for. Schools should tell students not to type personal details into nicknames or programs. |
Schedule 2: security measures
- All traffic uses HTTPS. Data is encrypted at rest by the database provider.
- Database security rules on every request: a student writes only their own record, a teacher reads only the classes they made (and school admins only their school's classes), and feedback is write-only.
- Teacher sign-in through the school's Google or Microsoft accounts, so the school's own MFA and leaver process apply, or by email and password hashed by Google.
- Students need no account and give no real name. Class codes can be closed, and teachers see every joiner and can delete any record.
- Admin access to the cloud project is limited to named BugBotLab staff, with two-factor authentication.
- Retention runs automatically: inactive classes are deleted after 12 months by a scheduled job.
- Analytics run only with consent, with no advertising features, and never on class data.
- Planned: Cyber Essentials certification. Date to be confirmed.
Schedule 3: sub-processors
| Sub-processor | What for | Where |
|---|---|---|
| Google (Google Cloud and Firebase: Firestore, Authentication, Hosting, Cloud Functions) | Storing class data, sign-in, serving the site, scheduled deletion and problem-report emails | Class data in London (europe-west2); sign-in may be processed in the United States |
| Google Workspace | Email with teachers, including problem reports | Google data centres, under Google's data processing terms |
The front-page waitlist (MailerLite), optional analytics (Google Analytics) and the libraries and fonts the pages load (Cloudflare cdnjs, jsDelivr, Google Fonts) are not used for class data and are listed in the privacy notice.
Signed copy
| For the school | For BugBotLab Ltd | |
|---|---|---|
| Organisation | ___ | BugBotLab Ltd, company number 16669242 |
| Name and role | ___ | Jerome Graves, Director |
| Signature | ___ | ___ |
| Date | ___ | ___ |
