This Data Processing Agreement (DPA) applies when a school or other organisation (the “Controller”) uses SuperExams to process personal data. It forms part of our Terms of Service. Schools that need a countersigned copy for their records can request one at support@superexams.com.
1.Parties & roles
This DPA is between:
- the Controller — the school or organisation whose staff and students use SuperExams; and
- the Processor — Andreas Photiades, trading as SuperExams (superexams.com), a sole trader based in Cyprus.
The Controller determines the purposes for which student and staff personal data is processed; the Processor processes it on the Controller’s behalf under this DPA. Where a person uses SuperExams as an individual (not through a school), SuperExams is the controller and the Privacy Policy applies instead.
2.Subject-matter & duration
The Processor processes personal data to provide the SuperExams service — exam-practice, progress tracking, class and school management, marking and related features — for as long as the Controller’s account is active, and for a short period afterwards as set out under “Return & deletion” below.
3.Nature & purpose of processing
Processing consists of collecting, storing, organising, displaying and deleting personal data as needed to run the platform: creating accounts, saving progress, running classes and assignments, generating reports, providing AI tutoring and marking, and handling support requests.
4.Categories of data subject
- Students (which may include children);
- Teachers and school staff;
- Parents or guardians, where they are given access.
5.Categories of personal data
- Identity & contact — name, email address;
- Credentials — hashed password, two-factor status;
- Usage & progress — papers viewed, answers, marks, submitted work, activity;
- School data — class membership, role, department;
- Technical data — IP address, basic logs.
The Controller should not submit special-category data (e.g. health data) through free-text fields or AI features, as these are not intended for it.
6.Processor obligations
The Processor shall:
- process personal data only on the Controller’s documented instructions, including this DPA and use of the service;
- ensure people authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational security measures (see “Security measures” below and our Security page);
- assist the Controller, so far as possible, in responding to data-subject requests and in meeting its own security, breach-notification and impact-assessment obligations;
- make available the information needed to demonstrate compliance, and allow for and contribute to reasonable audits;
- not engage another processor (sub-processor) except as set out below.
7.Sub-processors
The Controller authorises the Processor to use the following sub-processors, each bound by data-protection terms consistent with this DPA:
- Vercel — application hosting;
- Neon — managed PostgreSQL database;
- Cloudflare — file storage (R2) and network security;
- Stripe — payment processing;
- Anthropic — AI tutor and marking;
- Google — optional sign-in and transactional email;
- Sentry — error monitoring.
We will give the Controller reasonable notice of any intended change to our sub-processors, giving them the chance to object on reasonable data-protection grounds.
8.International transfers
Some sub-processors process data outside the European Economic Area, including in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) or an adequacy decision.
9.Security measures
The Processor maintains technical and organisational measures appropriate to the risk, including encryption in transit and at rest, hashed passwords, mandatory two-factor authentication for staff accounts, role-based least-privilege access, brute-force protection, audit logging, signature-verified payments and hardened security headers. These are described in full on our Security page, which forms part of this DPA.
10.Personal-data breaches
The Processor shall notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller’s data, and provide the information the Controller reasonably needs to meet its own notification obligations to authorities and data subjects.
11.Return & deletion
On termination, or on the Controller’s written request, the Processor shall delete or return the Controller’s personal data and delete existing copies, unless it is required to retain some data by law (for example, financial records). Backups are cycled out on our providers’ normal schedules.
12.Liability & governing law
This DPA is governed by the laws of the Republic of Cyprus and applies alongside the UK/EU General Data Protection Regulation. It supplements, and where relevant overrides, the Terms of Service in respect of personal data. Nothing in it limits either party’s obligations under applicable data-protection law.
13.Contact
For any question about this DPA, to request a countersigned copy, or to raise a data-protection matter, email support@superexams.com.