1. Scope and duration
The processing covers use of ReMarkAble to receive pupil work, transcribe it, generate curriculum-aligned assessment suggestions, allow authorised staff to review and release feedback, and produce class or school reports. It lasts for the school’s account term and the limited return, deletion and legal-retention periods stated below.
2. Processing details
| Item | Description |
|---|---|
| Data subjects | Pupils, students, teachers, school leaders, administrators and invited staff. |
| Personal data | Names or school identifiers, email addresses where accounts are used, class membership, uploaded work, handwriting images, OCR text, marks, grades, feedback, audit records and technical identifiers. |
| Special-category data | Only where the Controller deliberately enables an agreed feature, such as pupil-characteristic reporting. This may include SEND or health-related indicators. It must not be enabled until the Controller has established an Article 6 lawful basis, an Article 9 condition and any required DPIA. |
| Operations | Collection, storage, organisation, retrieval, transmission to authorised subprocessors, AI analysis, reporting, export, restriction, redaction and deletion. |
| Purpose | Formative assessment, teacher moderation, feedback, educational reporting, service security and support. |
3. Documented instructions
ReMarkAble will process Controller Data only on documented instructions contained in this agreement, the service agreement, configured product settings and written support requests, unless UK law requires otherwise. If law permits, ReMarkAble will tell the Controller before carrying out a legally required instruction.
ReMarkAble will promptly tell the Controller if an instruction appears to infringe applicable data-protection law. The Controller remains responsible for the lawfulness, accuracy and proportionality of the data it submits and for providing privacy information to pupils, parents and staff.
4. Confidentiality and security
ReMarkAble will ensure that people authorised to process Controller Data are subject to confidentiality obligations.
- Access is role-based and restricted to authorised users and support personnel with a business need.
- Data is encrypted in transit and protected by the hosting providers’ encryption-at-rest controls.
- Production access, errors and administrative activity are logged proportionately.
- Uploaded work is not used to train public or third-party foundation models.
- Security controls are reviewed when the service, risk profile or supply chain changes.
5. Subprocessors
The Controller gives general written authorisation for the subprocessors below. ReMarkAble will impose equivalent data-protection obligations on each subprocessor and remains responsible for their performance of those obligations.
| Subprocessor | Purpose | Processing location | School data |
|---|---|---|---|
| Supabase, Inc. | Authentication, database and encrypted file storage | United States / selected project region | Account, roster, uploaded work and assessment data |
| OpenAI, L.L.C. | OCR, mark-scheme retrieval and AI assessment | United States and configured service regions | Submitted images or text and generated assessment output |
| Vercel Inc. | Application hosting and delivery | Global infrastructure, including the United States | Network, request and application data |
| Functional Software, Inc. (Sentry) | Error monitoring | European Union | Diagnostic and technical event data; default PII collection is disabled |
| Resend, Inc. | Transactional email | United States | Recipient address, message metadata and service email content |
| HubSpot, Inc. | School relationship and support management | United States / European Union | School staff contact and account-event data; pupil work is not sent |
| Stripe Payments UK Ltd and affiliates | Payments for applicable subscriptions | United Kingdom, European Union and United States | Customer and transaction data; ReMarkAble does not receive full card details |
ReMarkAble will give reasonable advance notice of a material new subprocessor through the school account or registered administrative email. The Controller may raise a reasonable data-protection objection before the change takes effect. If no reasonable resolution is available, either party may end the affected service.
6. International transfers
Where Controller Data is transferred outside the United Kingdom, ReMarkAble will use an applicable UK adequacy regulation or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment and supplementary measures where required.
7. Assistance and incidents
- ReMarkAble will provide reasonable assistance with access, rectification, erasure, restriction, portability and objection requests relating to Controller Data.
- ReMarkAble will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller Data and provide available information needed for the Controller’s assessment and notifications.
- ReMarkAble will reasonably assist with security obligations, DPIAs and prior consultation, taking account of the nature of the processing and information available to it.
- Requests and incidents should be sent to dpo@remarkableai.co.uk.
8. Return, deletion and retention
During the account term the Controller can export pupil assessment records through the available school tools or request assistance. On termination, ReMarkAble will, at the Controller’s choice, return available Controller Data and delete or irreversibly de-identify remaining copies within 30 days, except data that must be retained by law or in secure backups awaiting ordinary rotation. Any retained copy remains protected and is used only for that legal purpose.
While an account remains active, identifiable uploaded work and detailed feedback are retained for no longer than 12 months unless a shorter school instruction applies. Financial records and demonstrably anonymised aggregate statistics follow separate legal or operational schedules.
9. Audit and compliance information
ReMarkAble will make available information reasonably necessary to demonstrate compliance with Article 28. The Controller may audit compliance no more than once annually, and additionally following a material incident or credible compliance concern, on reasonable notice and subject to confidentiality, security and proportionality safeguards. Current independent reports may be used where they provide adequate assurance.
10. Technical and organisational measures
- Authentication and role-based authorisation for school, staff, pupil and administrative functions.
- Database row-level access policies and service-side checks for school and pupil records.
- TLS for data in transit and supplier-managed encryption at rest for production databases and object storage.
- File-type, size and magic-byte validation before submitted images enter the assessment pipeline.
- Consent-gated optional tracking, restricted diagnostic collection and separation of pupil identity from analytics user IDs.
- Logging, error monitoring, stage-aware processing records and restricted administrative tools used to investigate failures and security events.
- Dependency, code-review, testing and deployment controls proportionate to the change and risk.
- Documented incident escalation, rights-request assistance, retention review and secure deletion or de-identification procedures.
These measures may be replaced by controls that provide an equivalent or higher level of protection. ReMarkAble will not materially reduce the overall security of the service during the account term.
11. Liability, precedence and governing law
Liability is governed by the main service agreement, subject to liabilities that cannot lawfully be excluded. If this DPA conflicts with the main agreement on protection of Controller Data, this DPA prevails. English law governs this DPA and the courts of England and Wales have jurisdiction.