Data protection

Processor terms for uploaded marks

Draft, not in forceDraft. These terms are not yet in force and no real data is accepted until they are. They will be published in full, and dated, before the intake opens.

Draft. Text fingerprint 38bca289f489. An upload records the fingerprint of the terms it accepted, so the text a college agreed to can always be matched.

Who the parties are

These terms are between the college, as controller, and ResitLens ("we" and "us"), as processor. ResitLens is the trading name of a UK sole trader. The college can reach us through the contact page.

Subject matter, duration, nature and purpose

The college (the controller) instructs this service (the processor) to process marks it uploads in order to produce a ranked teaching plan, group lists and a decision record, and for nothing else.

Processing begins at upload and ends when the data is deleted, on request or at the end of the retention period below, whichever comes first. These terms last as long as any uploaded data is held.

Types of data and categories of data subject

Data subjects: the college's students, and the member of college staff who uploads.

Types of data: marks per question part; the pseudonymous student IDs the college chose; the college name; and one work email address for notices about the upload. No special category data is processed, and none should be uploaded.

The data subjects may include people under 18. No profile is built about any individual, no decision is taken automatically, and the data is never used for marketing or to train any model.

Our instructions

We process only on the college's documented instructions, of which these terms and the upload itself are the record, unless we are required to do otherwise by law, in which case we will tell the college first unless the law forbids it.

We will tell the college immediately if we consider an instruction infringes data protection law.

Uploaded marks are stored and processed only in the United Kingdom and the European Economic Area. If our hosting provider needs to reach them from anywhere else, for example to support its own systems, that access is covered by the safeguards for international transfers in its data processing terms. Uploaded marks are stored in the United Kingdom. The application that builds the pages runs in the Netherlands, because our hosting provider does not offer a United Kingdom location for it; marks pass through it while a page is built and are not stored there.

Our own operational record

Alongside the processing above, we keep a small record of how the service is used, as controller in our own right: when an upload was made or refused and why, whether it was declared a whole teaching group, whether the work address belongs to a college, and which version of these terms was accepted.

It holds no marks and no student IDs, it is used for nothing but our own count of use, and it is deleted with the upload.

Confidentiality

Everyone we authorise to process the data is bound by a duty of confidence, and access is limited to those who need it to provide the service.

Security

Data is encrypted in transit and at rest. Access is restricted to what serving the page requires, the database is not reachable from any browser, and the service holds no key that could re-identify a student.

We will tell the college about any breach affecting its data without undue delay, with the information the college needs to meet its own obligations.

Sub-processors

Google Cloud (Google Cloud EMEA Limited) provides application hosting and the database, under the Google Cloud Data Processing Addendum and its published sub-processor list, which are incorporated here by reference. The database is located in the United Kingdom; the application runs in the Netherlands.

The college gives general authorisation for this sub-processor. We will give 30 days' notice before adding or replacing a sub-processor of our own, and the college may object and terminate if it does not accept the change. The hosting provider gives at least 30 days' notice of changes to its own sub-processors; we forward each notice to the college within two working days, with the same right to object. Every sub-processor is bound by data protection terms that meet Article 28 of the UK GDPR.

Helping the college meet its obligations

We will help the college respond to a data subject exercising any right, and help with its security, breach notification and impact assessment duties, taking into account what we hold and what we can see. In practice a request usually resolves to a deletion or an export, both of which we do on request.

Retention, deletion and return

Uploaded marks and the pages built from them are deleted 12 months after upload, or sooner on request.

Deletion on request covers the marks, the plan and the record together, and is done rather than queued. The hosting provider then completes deletion from its own systems within its published maximum of 180 days. The college can also delete a plan itself from the plan page.

At the end of these terms the college may choose deletion or return: the marks, the plan and the record are exportable as CSV at any time from the plan page, and we will delete everything after the export unless the college asks otherwise.

Audit and information

We will make available the information needed to show these obligations are met, and answer a written security questionnaire within 30 days. The college may audit on 30 days' written notice, at its own cost, not more than once a year unless a breach or a regulator requires it.

This service ingests marks and its own independently written paper metadata. It never reproduces an exam paper or a mark scheme, and never imports an exam board's analyser labels. Where the college supplies its own topic list, it confirms at upload that the labels are its own, and that confirmation is recorded with the upload.

Governing law

These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.