Skip to content
  • There are no suggestions because the search field is empty.

DPIA Support Pack

Nature of the processing activities

How will the data be collected?

Data will be collected through the following methods:

1. Student data via Wonde integration: We run a script that connects to the school's Management Information System (MIS) through Wonde's API. This occurs once at project initiation with explicit user consent, and can be repeated upon request by the school. Schools can disable the Wonde integration at any time; data sharing via Wonde only occurs with the school's explicit consent, and schools retain control over MIS integration throughout the relationship.

2. Student data via manual upload: Schools can alternatively upload student information as CSV files or input student details individually through our platform interface.

3. Assessment materials uploaded by teachers: Essay and exam content is collected through our secure platform when teachers upload:

Scanned handwritten scripts in PDF format (which we transcribe using our software)

Word documents containing individual essays

Plain text essays via copy/paste functionality

4. Staff registration data: Teacher and administrator information is collected through:

Our account creation/sign-up process for school administrators Email invitation system where administrators invite additional teachers, who then complete their own registration

Manual account setup by our team (with admin setting their own password)

All data collection occurs through our secure web-based platform with appropriate user authentication and consent mechanisms.

How will the data be used and processed to achieve aim?

The shared personal data will be used and processed as follows to provide automated essay marking and feedback services:

Data Processing Workflow:

1. Immediate Identity Separation: Upon transcription, students are issued an anonymising identification code. This identity information is immediately siloed separately from essay content before any external processing begins. Additionally, if students have written their names within essay content, our system automatically detects and removes these personal identifiers. All external AI processing uses only anonymising identifiers - the anonymous-ID-to-student mapping 

remains exclusively on our servers and is never shared with external LLM providers.

2. Transcription: Handwritten essays are transcribed using a combination of OCR technology and Large Language Models (LLMs) accessed through Portkey, with proprietary algorithms weighing and blending their outputs for accuracy.

3. AI Marking: Anonymised essay content is sent to multiple LLM providers (hosted on Vertex AI, AWS, Google AI Studio, Anthropic, OpenAI, Together AI) via Portkey for marking and feedback

generation. Multiple models are used with load balancing and failsafes.

4. Quality Control: LLM outputs are cross-checked by other LLMs for consistency and accuracy. Additional safeguards (Aporia, Patronus) prevent prompt injections and hallucinations.

5. Grade Standardisation: Numeric grades are processed through proprietary in-house algorithms on our servers to align with

standardisation materials and correct for known LLM marking variations.

6. Class Feedback Generation: Concatenated (anonymised) class essays and feedback are processed through LLMs to generate whole-class insights and recommendations.

Access Controls:

Teachers can only access marking results for essays they have uploaded, unless they have admin privileges, or essays have been manually shared with them by another user

Account-based access with optional SSO and MFA authentication Optional student list sharing between teachers (administrator consent required)

Internal company access: the CEO, COO, and Chief Developer have database access (via MFA) strictly for troubleshooting purposes only Customer success staff access limited to troubleshooting purposes No routine access to student data by company personnel outside of troubleshooting scenarios


Will any student, teacher,

assessment or uploaded content be used to train AI models?

Not without the school's explicit written permission. As set out elsewhere in this document, essay content is anonymised before any AI processing takes place, and the anonymous-ID-to-student mapping is never shared with external LLM providers.

This is confirmed contractually: under clause 5.2 of the Platform Terms and Conditions, Top Marks AI may analyse Outputs and other platform usage data to maintain, optimise, bug-fix, and improve the performance of the Platform generally for the benefit of its customers as a whole, but agrees that it will not use Customer data, including student data, for training or improvement purposes without the school's explicit written permission. This is reinforced by Annex A to Schedule 1 (paragraph 3.2), which confirms that Top Marks AI does not process Personal Data for the training, fine-tuning, or improvement of AI models or the Platform without such permission.


Is AI marking advisory only, with teachers retaining final judgement?

Yes. No score or feedback is passed directly to students by the platform, and teachers retain the ability to review and edit AI-generated feedback before it is exported or shared with students.

How will the data be stored and secured?

Data Storage Location:

Platform hosted on Render (Frankfurt, Germany)

Primary data storage: MongoDB on AWS infrastructure (Ireland, EU) Temporary file storage: Amazon S3 (Ireland, EU)

Geographic locations specifically selected for GDPR compliance within EU/EEA

Backup Storage:

Automated backup systems via MongoDB subscription tier Personal data is included in backups as part of operational data Backups stored within the same AWS Ireland infrastructure All backup data subject to same encryption and security controls as primary storage

Technical Security Measures:

Bank-grade encryption for data at rest and in transit, including HTTPS for all communications

Network firewalls

Role-based access controls (RBAC) applying the principle of least privilege

Multi-factor authentication (MFA) required for all database access Password protection requirements for user accounts, with optional SSO and MFA available

Regular security audits and continuous risk monitoring of systems SOC 2 and ISO 27001 controls inherited via AWS Ireland hosting infrastructure

Full audit logging of system access, with timestamps and user identification

Access limited to employees, contractors, and third parties with legitimate business need only

Physical and Personnel Controls:

AWS Ireland infrastructure provides physical security controls for data centers

Render (Frankfurt) hosting includes enterprise-grade physical security Internal access controls: Limited database access to the CEO, COO, Chief Developer, and customer success staff for troubleshooting purposes only 

All internal access protected by MFA and audit logging

Data Retention and Deletion:

Student assessment data retained based on agreements with educational institutions

Inactive accounts: notification provided before deletion after 24 months of inactivity

Some data retained as required for legal compliance obligations



How is access to personal data restricted and monitored?

Access to production data is strictly limited to the CEO, COO, Chief Developer, and customer success staff (troubleshooting purposes only), all under mandatory MFA. All such access is logged and monitored, with timestamps and user identification recorded. This is consistent with Annex A (paragraph 3.2(d)) to Schedule 1 of the Platform Terms and Conditions, which limits support, troubleshooting and maintenance access to these named roles.

Has the processor been

independently audited or certified for security, and is penetration testing performed?

Top Marks AI holds Cyber Essentials certification, assessed by IASME under the Willow scheme, covering the full organisation, and is registered with the ICO (reference ZB903015). Top Marks AI's infrastructure runs on AWS Ireland, which holds SOC 2 and ISO 27001 certification; Top Marks AI's own security practices inherit these enterprise-grade standards, but Top Marks AI does not itself hold ISO 27001 certification directly.

Is system access and activity logged, and how long are these logs

retained?

Yes. Comprehensive audit logging tracks all data access, with timestamps and user identification, and all database access is logged. Support communications are logged and retained for 24 months.

How will the data be deleted / disposed of?

Upon termination of the agreement or upon customer request, Top Marks will, in accordance with paragraph 9 of Schedule 1 (Data Processing Agreement) to the Platform Terms and Conditions:

At the customer's option (provided the customer notifies Top Marks of that option within 60 days of termination), delete or return all

personal data in Top Marks's possession that relates to the

agreement

Comply with such a request within 30 days of the request

If no specific customer request is made, automatically delete all copies of personal data within 90 days of agreement termination Exception: Some data may be retained where required by applicable law

Secure Disposal:

All data deletion follows secure disposal procedures to ensure data cannot be recovered

Deletion applies to both primary storage (MongoDB on AWS Ireland) and backup systems

Data is permanently removed from all systems and cannot be restored

 

Backup Data Retention:

Personal data stored in automated backups is subject to the same deletion timelines as primary data. Following the initial deletion period, backup data containing personal information is also securely disposed of within the same 90-day timeframe, except where legal retention requirements apply.

Right to Deletion:

Customers and data subjects can request deletion of their personal data at any time by contacting info@topmarks.ai, and Top Marks will comply with such requests in accordance with applicable data protection laws.


Will the data be shared/disclosed to third parties?

Sub-Processors That Handle Personal Data:

Per section 6 of Annex A to Schedule 1 (Data Processing Agreement) of the Platform Terms and Conditions, Top Marks AI uses the following sub-processors that process personal data:

Render (Render.com) – Platform hosting and infrastructure (EU – Frankfurt, Germany)

MongoDB Atlas – Primary database storage (EU – hosted on AWS infrastructure, Ireland)

Wonde Ltd – MIS integration / retrieval of student and staff data at the school's instruction (UK)

Amplitude – Analytics and usage monitoring (EU hosted)

Sub-Processors That Do NOT Handle Personal Data:

The following sub-processors are used for AI processing but do not receive personal data (essays are anonymised via the barcode system before processing):

Portkey.ai (AI model brokerage)

Together AI, Anthropic, OpenAI, Google Vertex, Google AI Studio (LLM providers)

AWS Bedrock (AI services)

Google Vision via Google Cloud (OCR processing)

Brevo (communications)

GPTZero, Patronus AI, Aporia (AI safety/guardrails)

A full, current sub-processor list is published at topmarks.ai/subprocessors, which is incorporated by reference into paragraph 11 of Schedule 1.

Sub-Processor Contracts and Liability:

Any sub-processor to handling personal data operates under a contract imposing data protection obligations on that sub-processor equivalent to Top Marks AI’s own obligations under Schedule 1 — covering processing only on documented instructions, appropriate technical and organisational security measures, confidentiality, assistance with data subject rights and breach notification, and deletion or return of data on termination (paragraph 7A of Schedule 1).

Changes to Sub-Processors:

Top Marks AI will not engage any new sub-processor to process personal data without first obtaining the school's consent (paragraph 7 of Schedule 1). Changes are therefore never made without a school's knowledge, and the consent step is the school's opportunity to raise concerns before a change takes effect.

Data Sharing Safeguards:

All sub-processors that handle personal data are bound by appropriate data protection agreements

Data transfers to sub-processors include appropriate safeguards as required by UK/EU data protection laws

Sub-processors are required to implement appropriate technical and organisational security measures

Personal data is only shared with sub-processors to the extent necessary to provide the contracted services

No Third-Party Marketing:

Personal data is never sold or shared with other companies for third-party marketing purposes without explicit opt-in consent. Top Marks AI may separately send its own marketing communications (for example, about new platform features) where it has appropriate permissions, or in reliance on the 'soft opt-in' where a recipient has previously enquired about or purchased its services; recipients can opt out of these at any time.

Educational Institution Access:

Schools retain access to their students' grading and feedback data through the platform interface, but this constitutes data controller access rather than third-party sharing.



What types of processing identified as likely high risk are involved?

Data Breach Risks:

Anonymisation failure: Edge case risk where students include personal identifiers (e.g., signing their name) in assessment responses

Sub-processor breaches: Risk of security incidents at third-party providers (though all are reputable organisations)

Unauthorised access: Mitigated through MFA systems backed by Google/Microsoft infrastructure

Individual Rights Limitations:

Students and parents can request data deletion via info@topmarks.ai as outlined in privacy policy

Potential limitations only in cases of legal holds or mandatory retention requirements under applicable law

Cross-Border Processing:

Anonymised essay content sent to US-based LLM providers creates minimal residual privacy risk due to robust barcode anonymisation system

Mitigation Measures in Place:

Technical Safeguards:

Anonymous-ID-to-student mapping system ensuring no personal identifiers reach external AI providers

PII removal during transcription: Automated systems actively identify and strip personal identifiers during the transcription process to address edge cases where students may include names or other identifying information in their responses

Multi-layered AI quality control with cross-checking between different LLM providers

AI safety guardrails (Aporia, Patronus) preventing prompt injections and hallucinations

Bank-grade encryption and MFA-protected access controls

Organisational Measures:

Staff training on data protection responsibilities for all personnel with sensitive data access

Comprehensive cyber insurance coverage (Hiscox) including data breach protection

EU-based hosting infrastructure (Frankfurt/Ireland) for GDPR compliance

Contractual safeguards with all sub-processors handling personal data

Children's Data Protections:

Under UK GDPR, no additional parental consent is required beyond the school's own basis for processing, as services are contracted through schools acting in their educational capacity

Where the US Children's Online Privacy Protection Act (COPPA) applies (broadly, in respect of US-based students under 13), the school warrants under paragraph 10(a) of Schedule 1 and section 5 of the Subscription Contract that it has obtained, or will obtain, verifiable parental or guardian consent before providing that Student Data to Top Marks AI

Data minimisation practices - only collecting information necessary for assessment marking

Robust anonymisation before any external processing

 

Incident Response:

Defined procedures for breach notification and containment Clear escalation paths and regulatory reporting obligations Regular monitoring of sub-processor compliance and security standards


 

How and when does Top Marks AI notify a school of a personal data breach?

Top Marks AI maintains a formal, structured Security Breach Incident Response Plan, with a response team comprising the CEO, COO, Chief Developer, and Customer Success staff, and documented procedures for technical remediation and forensic analysis. The plan covers immediate containment and investigation, impact assessment and remediation steps, notification to affected schools' contacts and DPOs, support for the school's own ICO notification obligations where required, and ongoing progress updates throughout investigation and resolution.

Contractually, under paragraph 4 of Schedule 1 to the Platform Terms and Conditions, Top Marks AI is committed to notify the school without undue delay on becoming aware of any loss, damage, destruction, or unauthorised processing or accidental disclosure of personal data, and to provide reasonable assistance with the school's own regulator and data-subject obligations. This is backed operationally by section 4.1 of the Service Level Agreement, under which Top Marks AI will notify the school within 72 hours of becoming aware of a confirmed personal data breach affecting the school's data (or as soon as reasonably practicable where that is not possible), including the nature of the breach, the categories and approximate number of data subjects affected, likely consequences, and the measures taken or proposed.

As the school is the Data Controller, the duty to notify the ICO sits with the school; Top Marks AI's role is to support that notification, not to make it directly.

Scope of processing activities

Categories of personal data

Student Data:

Full name (or student ID as alternative identifier where school opts for this)

Class/year group information (where school explicitly consents to share)

Exam or essay responses, including handwritten responses converted into text

Assessment results and feedback generated by the platform Email addresses (for notifications)

Staff Data:

Full name

Email address

Institution name

Communication records

Account identifiers and login credentials (hashed)

Teacher account identifiers (linking uploaded work to specific teacher accounts)

Technical/Usage Data:

Device Information: IP address, browser type, operating system Usage Data: Pages visited, interactions with platform, time spent on platform

Cookies and tracking technologies for analytics and user experience Authentication and access logs

Metadata:

Submission timestamps (when work is uploaded to the platform) Teacher-work associations (which teacher uploaded which assessments)

Subject/course information (as provided by schools during upload process)

Barcode/QR code identifiers used to link anonymised assessment content to student identity records held on Top Marks AI's servers Standardisation and marking scheme references associated with uploaded assessments

All data collection is limited to what is necessary for the automated marking and feedback services, with schools maintaining control over what student information they choose to share through Wonde integration or manual uploads.

Top Marks AI does not collect or process special category personal data (as defined in Article 9 UK GDPR) or criminal convictions data (Article 10 UK GDPR) as part of its standard service (Annex A, paragraph 4). Where a school believes that assessment content may incidentally contain special category data, it should notify Top Marks AI prior to upload.


Length and frequency of processing

Processing Duration:

Active processing: Data is processed immediately upon upload, with each essay taking approximately 5 minutes for AI marking and feedback generation

One-time processing: Each essay undergoes a single marking process - once completed, the data moves to static storage

Data State After Processing:

At rest: Following initial marking, student essays, grades, and feedback are stored in MongoDB database and remain inactive unless accessed

Periodic access only: Stored data is only reprocessed when: Users access individual student results and feedback

Teachers request whole class feedback generation (which aggregates previously processed individual feedback)

• Teachers make use of the Moderation feature to adjust and regenerate feedback for a student’s response.

Retention Periods:

Student assessment data: Retained based on agreements with individual educational institutions (schools determine their own retention requirements)

Staff contact details: Retained for ongoing communication and support unless deletion is requested

Inactive accounts: Automatic deletion after 24 months of inactivity (with prior notification to account holder)

Legal compliance: Some data retained as required by applicable laws

No Continuous Processing:

Data is not in constant use or subjected to ongoing automated processing

No background reprocessing or analysis occurs without explicit user action

Platform does not use customer data for training or improvement purposes without the school's explicit written permission (clause 5.2 of the Platform Terms and Conditions)


How long will the data be retained for?

Standard Retention Periods:

Student assessment data: Retained based on individual agreements with educational institutions (schools determine their own requirements)

Staff contact details: Retained for ongoing communication and support unless deletion is specifically requested

Inactive accounts: Data deleted after 24 months of inactivity with prior notification to account holder

Post-Contract Termination:

Customer option for immediate return/deletion: Upon termination, schools can request return or deletion of all personal data within 60 days of contract end

Response timeframe: Top Marks complies with deletion requests within 30 days of the request

Automatic deletion: If no specific request is made, all personal data copies are deleted within 90 days of agreement termination

Backup Data Retention:

Same deletion timeline: Personal data in automated backups follows identical retention periods as primary data

90-day maximum: Backup data containing personal information is securely disposed of within 90 days of termination

Legal Retention Exceptions:

Statutory requirements: Some data may be retained longer where required by applicable law

Compliance obligations: Data necessary for legal compliance may be retained beyond standard deletion periods

Data Deletion Process:

All data deletion follows secure disposal procedures ensuring data cannot be recovered

Deletion applies to both primary storage (MongoDB) and backup systems

Permanent removal from all systems with no restoration capability

Retention Reviews:

Retention compliance is reviewed every six months as part of standard operating procedure, with additional reviews triggered by changes to school agreements or regulatory requirements. The annual DPIA review also includes a full assessment of retention policies and their implementation.


Context of processing

What is the lawful basis for

processing?

Top Marks AI's Privacy Policy sets out the lawful basis it relies on for each purpose of processing:

Automated grading services (student names, assessment responses): performance of a contract with educational institutions – Article 6(1)(b)

Communicating with staff about assessment results and updates (staff names, email addresses): legitimate interests – Article 6(1)(f) Improving and developing the platform (usage data, device information): legitimate interests – Article 6(1)(f)

Security and fraud prevention (IP address, login activity): legitimate interests – Article 6(1)(f)

Complying with legal obligations (any necessary personal data): compliance with a legal obligation – Article 6(1)(c)

No consent is relied upon for this core processing. Consent is used separately for the discrete purpose of the initial Wonde MIS connection, as described elsewhere in this document, and schools remain responsible as Data Controller for identifying their own lawful basis (which may include public task) for sharing student and staff data with Top Marks AI in the first place.

What is the relationship with the user/data subject?

In relation to student and staff personal data processed to provide the Platform, Top Marks AI acts as a Data Processor for the school (the Data Controller), processing personal data solely on behalf of the school and according to the school's instructions to provide automated marking and assessment services (paragraph 2 of Schedule 1 to the Platform Terms and Conditions).


Where can I find your UK GDPR Data Processing Agreement?

The Data Processing Agreement is set out as Schedule 1 of Top Marks AI's Platform Terms and Conditions (topmarks.ai/terms), which is incorporated into the school's Subscription Contract (section 1.1) and constitutes the written agreement required by Article 28(3) UK GDPR between the school (as controller) and Top Marks AI (as processor). The processing particulars required by Article 28(3) are set out in Annex A to Schedule 1.

Standing assurance material available on request includes: the GDPR & Data Protection Pack and the full DPIA (reviewed annually). Cyber Essentials certification and SOC 2 / ISO 27001 certifications inherited via AWS hosting have also been referenced in other Top Marks AI materials, although these are not addressed in the Platform Terms and Conditions, SLA, Privacy Policy, or Subscription Contract template — see the security certification question below.

How much control will the data subject have over the shared

personal data?

Full Data Subject Rights:

Data subjects (students, staff, and parents) retain comprehensive control over their personal data:

Access and Correction Rights:

Right to request copies of personal data held about them Right to update inaccurate or incomplete data

Right to restrict processing under certain conditions

Deletion Rights:

Right to request data erasure where legally applicable

Can contact Top Marks directly at info@topmarks.ai to exercise deletion rights Schools can also facilitate deletion requests on behalf of students

Objection Rights:

Right to object to processing based on legitimate interests Right to data portability (receive data in structured format)

Parental Rights (for minors):

Parents can request access to or deletion of their child's data by contacting their school or Top Marks directly at info@topmarks.ai When parents contact Top Marks directly, we immediately notify the relevant school and coordinate the response through the school as data controller

Right to be informed about data processing through school privacy notices

Limitations:

Some data may be retained where required for legal compliance 

Processing restrictions may apply where data is necessary for contractual obligations or legitimate interests

Data subjects can exercise these rights by contacting info@topmarks.ai or through their educational institution.


Are there prior concerns over this type of processing or security flaws?

No Prior Security Incidents:

No prior security concerns or data breaches are documented in company materials.

Known Processing Risks Identified and Mitigated:

Third-Party Processing:

Risk: Use of multiple LLM providers (Together AI, Bedrock, Vertex, etc.) for AI processing

Mitigation: Anonymisation via barcode system ensures no personal identifiers reach external AI providers

Cross-Border Data Transfers:

Risk: Some AI providers are US-based, creating potential cross-border transfer concerns

Mitigation: Only anonymised content is transferred; personal data remains in EU (Ireland/Frankfurt hosting)

API and Data Transfer Security:

Risk: Data transmission between platform and sub-processors Mitigation: Bank-grade encryption for all data in transit and at rest

Multi-Source Data Handling:

Risk: Data collection from multiple sources (Wonde integration, CSV uploads, manual entry)

Mitigation: Standardised security protocols apply regardless of data source; consistent encryption and access controls

Data Storage Geography:

Identified advantage: All personal data storage maintained within EU jurisdiction (MongoDB on AWS Ireland, Render Frankfurt)

Sub-processors handling personal data: All EU-hosted (Render, MongoDB, Amplitude)

Continuous Monitoring:

Regular security audits and risk assessments in place

AI safety guardrails (Aporia, Patronus) to prevent processing vulnerabilities.

Assess necessity and proportionality


How do you support data subject rights?

Data subjects can exercise their UK GDPR rights by contacting Top Marks directly at info@topmarks.ai.

Access Requests:

Provide copies of personal data held about the individual Respond within statutory timeframes under UK GDPR (Subject Access Requests are fulfilled within 30 days)

Correction and Updates:

Update inaccurate or incomplete personal data upon request Ensure corrections are reflected across all systems

Deletion/Erasure:

Process deletion requests where legally applicable

Remove data from both primary storage and backup systems Complete deletion within 30 days of valid requests

Objection and Restriction:

Support individuals who object to processing based on legitimate interests

Implement processing restrictions under appropriate circumstances Provide data in structured formats for portability requests

Parental Rights (for students under 18):

Parents can request access to or deletion of their child's data Support requests made either directly to Top Marks or through the school

School Coordination:

Work with educational institutions to facilitate rights requests Ensure consistent approach whether requests come directly or via schools

Process Limitations:

Some data may be retained where required for legal compliance Rights may be restricted where processing is necessary for contractual performance

All rights requests are handled in accordance with UK GDPR requirements and statutory response timeframes.

How do you safeguard international transfers?

Primary Data Storage - No International Transfers:

All personal data storage is maintained within the UK/EEA:

Platform hosted on Render (Frankfurt, Germany)

Database storage via MongoDB on AWS infrastructure (Ireland)

Sub-processors handling personal data are all EU-hosted (Render, MongoDB, Amplitude)

Anonymised Content Processing:

For AI processing services, only anonymised content (stripped of personal identifiers) is sent to providers including some US-based services. As no personal data is transferred, international transfer safeguards are not required for this processing.

Where any international transfers of personal data are necessary, Top Marks AI implements appropriate safeguards including:

UK's International Data Transfer Agreement (for transfers from the UK)

Approved EU Standard Contractual Clauses (for transfers from the EEA)

Appropriate technical and organisational measures as required by UK/EU data protection law

Transfer Summary (from Privacy Policy):

UK: Hosting provider, SaaS tools - Safeguard: Encryption

European Union: SaaS tools (Render, MongoDB on AWS in Ireland, Amplitude) - Safeguard: Encryption

USA: SaaS tools (AI providers) - No personal data transferred

Additional Protections:

All transfers require appropriate data protection agreements with recipients

Recipients must implement equivalent security measures Regular monitoring of transfer compliance and security standards

Annex A (section 7) to Schedule 1 confirms in terms that personal data is not transferred to any country outside the UK or EEA in connection with the storage or primary processing of personal data under the Agreement, and lists only Render (Frankfurt), MongoDB Atlas/AWS (Ireland) and Amplitude (EU) as the infrastructure involved in that storage and processing.


What are your incident response commitments?

Incident priority targets: P1 (Critical, e.g. platform-wide outage, data loss, security breach) – 2 hour initial response, 8 business hour resolution target; P2 (High) – 4 business hour response, 2 business day resolution target; P3 (Medium) – 1 business day response, 5 business day resolution target; P4 (Low) – 2 business day response, best-efforts resolution. These are targets, not guarantees

Personal data breach notification: within 72 hours of Top Marks AI becoming aware of a confirmed breach (SLA section 4.1)

Data subject requests: acknowledged within 5 business days and fulfilled (or referred to the school as controller) within 30 calendar days (SLA section 4.2)

Data deletion: within 30 days of a written instruction, or within 90 days of licence expiry if no instruction is received (SLA section 4.3)

Document title

Top Marks AI - DPIA Support Pack

Version

2.0

Owner

Alex Chapman, COO, Top Marks AI Ltd

Review date

August 2027