DPIA Support Pack
Nature of the processing activities
|
How will the data be collected? |
Data will be collected through the following methods: 1. Student data via Wonde integration: We run a script that connects to the school's Management Information System (MIS) through Wonde's API. This occurs once at project initiation with explicit user consent, and can be repeated upon request by the school. Schools can disable the Wonde integration at any time; data sharing via Wonde only occurs with the school's explicit consent, and schools retain control over MIS integration throughout the relationship. 2. Student data via manual upload: Schools can alternatively upload student information as CSV files or input student details individually through our platform interface. 3. Assessment materials uploaded by teachers: Essay and exam content is collected through our secure platform when teachers upload: • Scanned handwritten scripts in PDF format (which we transcribe using our software) • Word documents containing individual essays • Plain text essays via copy/paste functionality 4. Staff registration data: Teacher and administrator information is collected through: • Our account creation/sign-up process for school administrators • Email invitation system where administrators invite additional teachers, who then complete their own registration • Manual account setup by our team (with admin setting their own password) All data collection occurs through our secure web-based platform with appropriate user authentication and consent mechanisms. |
|
How will the data be used and processed to achieve aim? |
The shared personal data will be used and processed as follows to provide automated essay marking and feedback services: Data Processing Workflow: 1. Immediate Identity Separation: Upon transcription, students are issued an anonymising identification code. This identity information is immediately siloed separately from essay content before any external processing begins. Additionally, if students have written their names within essay content, our system automatically detects and removes these personal identifiers. All external AI processing uses only anonymising identifiers - the anonymous-ID-to-student mapping remains exclusively on our servers and is never shared with external LLM providers. 2. Transcription: Handwritten essays are transcribed using a combination of OCR technology and Large Language Models (LLMs) accessed through Portkey, with proprietary algorithms weighing and blending their outputs for accuracy. 3. AI Marking: Anonymised essay content is sent to multiple LLM providers (hosted on Vertex AI, AWS, Google AI Studio, Anthropic, OpenAI, Together AI) via Portkey for marking and feedback generation. Multiple models are used with load balancing and failsafes. 4. Quality Control: LLM outputs are cross-checked by other LLMs for consistency and accuracy. Additional safeguards (Aporia, Patronus) prevent prompt injections and hallucinations. 5. Grade Standardisation: Numeric grades are processed through proprietary in-house algorithms on our servers to align with standardisation materials and correct for known LLM marking variations. 6. Class Feedback Generation: Concatenated (anonymised) class essays and feedback are processed through LLMs to generate whole-class insights and recommendations. Access Controls: • Teachers can only access marking results for essays they have uploaded, unless they have admin privileges, or essays have been manually shared with them by another user • Account-based access with optional SSO and MFA authentication • Optional student list sharing between teachers (administrator consent required) • Internal company access: the CEO, COO, and Chief Developer have database access (via MFA) strictly for troubleshooting purposes only • Customer success staff access limited to troubleshooting purposes • No routine access to student data by company personnel outside of troubleshooting scenarios |
|
Will any student, teacher, assessment or uploaded content be used to train AI models? |
Not without the school's explicit written permission. As set out elsewhere in this document, essay content is anonymised before any AI processing takes place, and the anonymous-ID-to-student mapping is never shared with external LLM providers. This is confirmed contractually: under clause 5.2 of the Platform Terms and Conditions, Top Marks AI may analyse Outputs and other platform usage data to maintain, optimise, bug-fix, and improve the performance of the Platform generally for the benefit of its customers as a whole, but agrees that it will not use Customer data, including student data, for training or improvement purposes without the school's explicit written permission. This is reinforced by Annex A to Schedule 1 (paragraph 3.2), which confirms that Top Marks AI does not process Personal Data for the training, fine-tuning, or improvement of AI models or the Platform without such permission. |
|
Is AI marking advisory only, with teachers retaining final judgement? |
Yes. No score or feedback is passed directly to students by the platform, and teachers retain the ability to review and edit AI-generated feedback before it is exported or shared with students. |
|
How will the data be stored and secured? |
Data Storage Location: • Platform hosted on Render (Frankfurt, Germany) • Primary data storage: MongoDB on AWS infrastructure (Ireland, EU) • Temporary file storage: Amazon S3 (Ireland, EU) • Geographic locations specifically selected for GDPR compliance within EU/EEA Backup Storage: • Automated backup systems via MongoDB subscription tier • Personal data is included in backups as part of operational data • Backups stored within the same AWS Ireland infrastructure • All backup data subject to same encryption and security controls as primary storage Technical Security Measures: • Bank-grade encryption for data at rest and in transit, including HTTPS for all communications • Network firewalls • Role-based access controls (RBAC) applying the principle of least privilege • Multi-factor authentication (MFA) required for all database access • Password protection requirements for user accounts, with optional SSO and MFA available • Regular security audits and continuous risk monitoring of systems • SOC 2 and ISO 27001 controls inherited via AWS Ireland hosting infrastructure • Full audit logging of system access, with timestamps and user identification • Access limited to employees, contractors, and third parties with legitimate business need only Physical and Personnel Controls: • AWS Ireland infrastructure provides physical security controls for data centers • Render (Frankfurt) hosting includes enterprise-grade physical security • Internal access controls: Limited database access to the CEO, COO, Chief Developer, and customer success staff for troubleshooting purposes only • All internal access protected by MFA and audit logging Data Retention and Deletion: • Student assessment data retained based on agreements with educational institutions • Inactive accounts: notification provided before deletion after 24 months of inactivity • Some data retained as required for legal compliance obligations |
|
How is access to personal data restricted and monitored? |
Access to production data is strictly limited to the CEO, COO, Chief Developer, and customer success staff (troubleshooting purposes only), all under mandatory MFA. All such access is logged and monitored, with timestamps and user identification recorded. This is consistent with Annex A (paragraph 3.2(d)) to Schedule 1 of the Platform Terms and Conditions, which limits support, troubleshooting and maintenance access to these named roles. |
|
Has the processor been independently audited or certified for security, and is penetration testing performed? |
Top Marks AI holds Cyber Essentials certification, assessed by IASME under the Willow scheme, covering the full organisation, and is registered with the ICO (reference ZB903015). Top Marks AI's infrastructure runs on AWS Ireland, which holds SOC 2 and ISO 27001 certification; Top Marks AI's own security practices inherit these enterprise-grade standards, but Top Marks AI does not itself hold ISO 27001 certification directly. |
|
Is system access and activity logged, and how long are these logs retained? |
Yes. Comprehensive audit logging tracks all data access, with timestamps and user identification, and all database access is logged. Support communications are logged and retained for 24 months. |
|
How will the data be deleted / disposed of? |
Upon termination of the agreement or upon customer request, Top Marks will, in accordance with paragraph 9 of Schedule 1 (Data Processing Agreement) to the Platform Terms and Conditions: • At the customer's option (provided the customer notifies Top Marks of that option within 60 days of termination), delete or return all personal data in Top Marks's possession that relates to the agreement • Comply with such a request within 30 days of the request • If no specific customer request is made, automatically delete all copies of personal data within 90 days of agreement termination • Exception: Some data may be retained where required by applicable law Secure Disposal: • All data deletion follows secure disposal procedures to ensure data cannot be recovered • Deletion applies to both primary storage (MongoDB on AWS Ireland) and backup systems • Data is permanently removed from all systems and cannot be restored
Backup Data Retention: Personal data stored in automated backups is subject to the same deletion timelines as primary data. Following the initial deletion period, backup data containing personal information is also securely disposed of within the same 90-day timeframe, except where legal retention requirements apply. Right to Deletion: Customers and data subjects can request deletion of their personal data at any time by contacting info@topmarks.ai, and Top Marks will comply with such requests in accordance with applicable data protection laws. |
|
Will the data be shared/disclosed to third parties? |
Sub-Processors That Handle Personal Data: Per section 6 of Annex A to Schedule 1 (Data Processing Agreement) of the Platform Terms and Conditions, Top Marks AI uses the following sub-processors that process personal data: • Render (Render.com) – Platform hosting and infrastructure (EU – Frankfurt, Germany) • MongoDB Atlas – Primary database storage (EU – hosted on AWS infrastructure, Ireland) • Wonde Ltd – MIS integration / retrieval of student and staff data at the school's instruction (UK) • Amplitude – Analytics and usage monitoring (EU hosted) Sub-Processors That Do NOT Handle Personal Data: The following sub-processors are used for AI processing but do not receive personal data (essays are anonymised via the barcode system before processing): • Portkey.ai (AI model brokerage) • Together AI, Anthropic, OpenAI, Google Vertex, Google AI Studio (LLM providers) • AWS Bedrock (AI services) • Google Vision via Google Cloud (OCR processing) • Brevo (communications) • GPTZero, Patronus AI, Aporia (AI safety/guardrails) A full, current sub-processor list is published at topmarks.ai/subprocessors, which is incorporated by reference into paragraph 11 of Schedule 1. Sub-Processor Contracts and Liability: Any sub-processor to handling personal data operates under a contract imposing data protection obligations on that sub-processor equivalent to Top Marks AI’s own obligations under Schedule 1 — covering processing only on documented instructions, appropriate technical and organisational security measures, confidentiality, assistance with data subject rights and breach notification, and deletion or return of data on termination (paragraph 7A of Schedule 1). Changes to Sub-Processors: Top Marks AI will not engage any new sub-processor to process personal data without first obtaining the school's consent (paragraph 7 of Schedule 1). Changes are therefore never made without a school's knowledge, and the consent step is the school's opportunity to raise concerns before a change takes effect. Data Sharing Safeguards: • All sub-processors that handle personal data are bound by appropriate data protection agreements • Data transfers to sub-processors include appropriate safeguards as required by UK/EU data protection laws • Sub-processors are required to implement appropriate technical and organisational security measures • Personal data is only shared with sub-processors to the extent necessary to provide the contracted services No Third-Party Marketing: Personal data is never sold or shared with other companies for third-party marketing purposes without explicit opt-in consent. Top Marks AI may separately send its own marketing communications (for example, about new platform features) where it has appropriate permissions, or in reliance on the 'soft opt-in' where a recipient has previously enquired about or purchased its services; recipients can opt out of these at any time. Educational Institution Access: Schools retain access to their students' grading and feedback data through the platform interface, but this constitutes data controller access rather than third-party sharing. |
|
What types of processing identified as likely high risk are involved? |
Data Breach Risks: • Anonymisation failure: Edge case risk where students include personal identifiers (e.g., signing their name) in assessment responses • Sub-processor breaches: Risk of security incidents at third-party providers (though all are reputable organisations) • Unauthorised access: Mitigated through MFA systems backed by Google/Microsoft infrastructure Individual Rights Limitations: • Students and parents can request data deletion via info@topmarks.ai as outlined in privacy policy • Potential limitations only in cases of legal holds or mandatory retention requirements under applicable law Cross-Border Processing: • Anonymised essay content sent to US-based LLM providers creates minimal residual privacy risk due to robust barcode anonymisation system Mitigation Measures in Place: Technical Safeguards: • Anonymous-ID-to-student mapping system ensuring no personal identifiers reach external AI providers • PII removal during transcription: Automated systems actively identify and strip personal identifiers during the transcription process to address edge cases where students may include names or other identifying information in their responses • Multi-layered AI quality control with cross-checking between different LLM providers • AI safety guardrails (Aporia, Patronus) preventing prompt injections and hallucinations • Bank-grade encryption and MFA-protected access controls Organisational Measures: • Staff training on data protection responsibilities for all personnel with sensitive data access • Comprehensive cyber insurance coverage (Hiscox) including data breach protection • EU-based hosting infrastructure (Frankfurt/Ireland) for GDPR compliance • Contractual safeguards with all sub-processors handling personal data Children's Data Protections: • Under UK GDPR, no additional parental consent is required beyond the school's own basis for processing, as services are contracted through schools acting in their educational capacity • Where the US Children's Online Privacy Protection Act (COPPA) applies (broadly, in respect of US-based students under 13), the school warrants under paragraph 10(a) of Schedule 1 and section 5 of the Subscription Contract that it has obtained, or will obtain, verifiable parental or guardian consent before providing that Student Data to Top Marks AI • Data minimisation practices - only collecting information necessary for assessment marking • Robust anonymisation before any external processing
Incident Response: • Defined procedures for breach notification and containment • Clear escalation paths and regulatory reporting obligations • Regular monitoring of sub-processor compliance and security standards |
|
How and when does Top Marks AI notify a school of a personal data breach? |
Top Marks AI maintains a formal, structured Security Breach Incident Response Plan, with a response team comprising the CEO, COO, Chief Developer, and Customer Success staff, and documented procedures for technical remediation and forensic analysis. The plan covers immediate containment and investigation, impact assessment and remediation steps, notification to affected schools' contacts and DPOs, support for the school's own ICO notification obligations where required, and ongoing progress updates throughout investigation and resolution. Contractually, under paragraph 4 of Schedule 1 to the Platform Terms and Conditions, Top Marks AI is committed to notify the school without undue delay on becoming aware of any loss, damage, destruction, or unauthorised processing or accidental disclosure of personal data, and to provide reasonable assistance with the school's own regulator and data-subject obligations. This is backed operationally by section 4.1 of the Service Level Agreement, under which Top Marks AI will notify the school within 72 hours of becoming aware of a confirmed personal data breach affecting the school's data (or as soon as reasonably practicable where that is not possible), including the nature of the breach, the categories and approximate number of data subjects affected, likely consequences, and the measures taken or proposed. As the school is the Data Controller, the duty to notify the ICO sits with the school; Top Marks AI's role is to support that notification, not to make it directly. |
Scope of processing activities |
|
|
Categories of personal data |
Student Data: • Full name (or student ID as alternative identifier where school opts for this) • Class/year group information (where school explicitly consents to share) • Exam or essay responses, including handwritten responses converted into text • Assessment results and feedback generated by the platform • Email addresses (for notifications) Staff Data: • Full name • Email address • Institution name • Communication records • Account identifiers and login credentials (hashed) • Teacher account identifiers (linking uploaded work to specific teacher accounts) Technical/Usage Data: • Device Information: IP address, browser type, operating system • Usage Data: Pages visited, interactions with platform, time spent on platform • Cookies and tracking technologies for analytics and user experience • Authentication and access logs Metadata: • Submission timestamps (when work is uploaded to the platform) • Teacher-work associations (which teacher uploaded which assessments) • Subject/course information (as provided by schools during upload process) • Barcode/QR code identifiers used to link anonymised assessment content to student identity records held on Top Marks AI's servers • Standardisation and marking scheme references associated with uploaded assessments All data collection is limited to what is necessary for the automated marking and feedback services, with schools maintaining control over what student information they choose to share through Wonde integration or manual uploads. Top Marks AI does not collect or process special category personal data (as defined in Article 9 UK GDPR) or criminal convictions data (Article 10 UK GDPR) as part of its standard service (Annex A, paragraph 4). Where a school believes that assessment content may incidentally contain special category data, it should notify Top Marks AI prior to upload. |
|
Length and frequency of processing |
Processing Duration: • Active processing: Data is processed immediately upon upload, with each essay taking approximately 5 minutes for AI marking and feedback generation • One-time processing: Each essay undergoes a single marking process - once completed, the data moves to static storage Data State After Processing: • At rest: Following initial marking, student essays, grades, and feedback are stored in MongoDB database and remain inactive unless accessed • Periodic access only: Stored data is only reprocessed when: • Users access individual student results and feedback • Teachers request whole class feedback generation (which aggregates previously processed individual feedback) • Teachers make use of the Moderation feature to adjust and regenerate feedback for a student’s response. Retention Periods: • Student assessment data: Retained based on agreements with individual educational institutions (schools determine their own retention requirements) • Staff contact details: Retained for ongoing communication and support unless deletion is requested • Inactive accounts: Automatic deletion after 24 months of inactivity (with prior notification to account holder) • Legal compliance: Some data retained as required by applicable laws No Continuous Processing: • Data is not in constant use or subjected to ongoing automated processing • No background reprocessing or analysis occurs without explicit user action • Platform does not use customer data for training or improvement purposes without the school's explicit written permission (clause 5.2 of the Platform Terms and Conditions) |
|
How long will the data be retained for? |
Standard Retention Periods: • Student assessment data: Retained based on individual agreements with educational institutions (schools determine their own requirements) • Staff contact details: Retained for ongoing communication and support unless deletion is specifically requested • Inactive accounts: Data deleted after 24 months of inactivity with prior notification to account holder Post-Contract Termination: • Customer option for immediate return/deletion: Upon termination, schools can request return or deletion of all personal data within 60 days of contract end • Response timeframe: Top Marks complies with deletion requests within 30 days of the request • Automatic deletion: If no specific request is made, all personal data copies are deleted within 90 days of agreement termination Backup Data Retention: • Same deletion timeline: Personal data in automated backups follows identical retention periods as primary data • 90-day maximum: Backup data containing personal information is securely disposed of within 90 days of termination Legal Retention Exceptions: • Statutory requirements: Some data may be retained longer where required by applicable law • Compliance obligations: Data necessary for legal compliance may be retained beyond standard deletion periods Data Deletion Process: • All data deletion follows secure disposal procedures ensuring data cannot be recovered • Deletion applies to both primary storage (MongoDB) and backup systems • Permanent removal from all systems with no restoration capability Retention Reviews: Retention compliance is reviewed every six months as part of standard operating procedure, with additional reviews triggered by changes to school agreements or regulatory requirements. The annual DPIA review also includes a full assessment of retention policies and their implementation. |
Context of processing |
|
|
What is the lawful basis for processing? |
Top Marks AI's Privacy Policy sets out the lawful basis it relies on for each purpose of processing: • Automated grading services (student names, assessment responses): performance of a contract with educational institutions – Article 6(1)(b) • Communicating with staff about assessment results and updates (staff names, email addresses): legitimate interests – Article 6(1)(f) • Improving and developing the platform (usage data, device information): legitimate interests – Article 6(1)(f) • Security and fraud prevention (IP address, login activity): legitimate interests – Article 6(1)(f) • Complying with legal obligations (any necessary personal data): compliance with a legal obligation – Article 6(1)(c) No consent is relied upon for this core processing. Consent is used separately for the discrete purpose of the initial Wonde MIS connection, as described elsewhere in this document, and schools remain responsible as Data Controller for identifying their own lawful basis (which may include public task) for sharing student and staff data with Top Marks AI in the first place. |
|
What is the relationship with the user/data subject? |
In relation to student and staff personal data processed to provide the Platform, Top Marks AI acts as a Data Processor for the school (the Data Controller), processing personal data solely on behalf of the school and according to the school's instructions to provide automated marking and assessment services (paragraph 2 of Schedule 1 to the Platform Terms and Conditions). |
|
Where can I find your UK GDPR Data Processing Agreement? |
The Data Processing Agreement is set out as Schedule 1 of Top Marks AI's Platform Terms and Conditions (topmarks.ai/terms), which is incorporated into the school's Subscription Contract (section 1.1) and constitutes the written agreement required by Article 28(3) UK GDPR between the school (as controller) and Top Marks AI (as processor). The processing particulars required by Article 28(3) are set out in Annex A to Schedule 1. Standing assurance material available on request includes: the GDPR & Data Protection Pack and the full DPIA (reviewed annually). Cyber Essentials certification and SOC 2 / ISO 27001 certifications inherited via AWS hosting have also been referenced in other Top Marks AI materials, although these are not addressed in the Platform Terms and Conditions, SLA, Privacy Policy, or Subscription Contract template — see the security certification question below. |
|
How much control will the data subject have over the shared personal data? |
Full Data Subject Rights: Data subjects (students, staff, and parents) retain comprehensive control over their personal data: Access and Correction Rights: • Right to request copies of personal data held about them • Right to update inaccurate or incomplete data • Right to restrict processing under certain conditions Deletion Rights: • Right to request data erasure where legally applicable • Can contact Top Marks directly at info@topmarks.ai to exercise deletion rights • Schools can also facilitate deletion requests on behalf of students Objection Rights: • Right to object to processing based on legitimate interests • Right to data portability (receive data in structured format) Parental Rights (for minors): • Parents can request access to or deletion of their child's data by contacting their school or Top Marks directly at info@topmarks.ai • When parents contact Top Marks directly, we immediately notify the relevant school and coordinate the response through the school as data controller • Right to be informed about data processing through school privacy notices Limitations: • Some data may be retained where required for legal compliance • Processing restrictions may apply where data is necessary for contractual obligations or legitimate interests Data subjects can exercise these rights by contacting info@topmarks.ai or through their educational institution. |
|
Are there prior concerns over this type of processing or security flaws? |
No Prior Security Incidents: No prior security concerns or data breaches are documented in company materials. Known Processing Risks Identified and Mitigated: Third-Party Processing: • Risk: Use of multiple LLM providers (Together AI, Bedrock, Vertex, etc.) for AI processing • Mitigation: Anonymisation via barcode system ensures no personal identifiers reach external AI providers Cross-Border Data Transfers: • Risk: Some AI providers are US-based, creating potential cross-border transfer concerns • Mitigation: Only anonymised content is transferred; personal data remains in EU (Ireland/Frankfurt hosting) API and Data Transfer Security: • Risk: Data transmission between platform and sub-processors • Mitigation: Bank-grade encryption for all data in transit and at rest Multi-Source Data Handling: • Risk: Data collection from multiple sources (Wonde integration, CSV uploads, manual entry) • Mitigation: Standardised security protocols apply regardless of data source; consistent encryption and access controls Data Storage Geography: • Identified advantage: All personal data storage maintained within EU jurisdiction (MongoDB on AWS Ireland, Render Frankfurt) • Sub-processors handling personal data: All EU-hosted (Render, MongoDB, Amplitude) Continuous Monitoring: • Regular security audits and risk assessments in place • AI safety guardrails (Aporia, Patronus) to prevent processing vulnerabilities. |
Assess necessity and proportionality
|
How do you support data subject rights? |
Data subjects can exercise their UK GDPR rights by contacting Top Marks directly at info@topmarks.ai. Access Requests: • Provide copies of personal data held about the individual • Respond within statutory timeframes under UK GDPR (Subject Access Requests are fulfilled within 30 days) Correction and Updates: • Update inaccurate or incomplete personal data upon request • Ensure corrections are reflected across all systems Deletion/Erasure: • Process deletion requests where legally applicable • Remove data from both primary storage and backup systems • Complete deletion within 30 days of valid requests Objection and Restriction: • Support individuals who object to processing based on legitimate interests • Implement processing restrictions under appropriate circumstances • Provide data in structured formats for portability requests Parental Rights (for students under 18): • Parents can request access to or deletion of their child's data • Support requests made either directly to Top Marks or through the school School Coordination: • Work with educational institutions to facilitate rights requests • Ensure consistent approach whether requests come directly or via schools Process Limitations: • Some data may be retained where required for legal compliance • Rights may be restricted where processing is necessary for contractual performance All rights requests are handled in accordance with UK GDPR requirements and statutory response timeframes. |
|
How do you safeguard international transfers? |
Primary Data Storage - No International Transfers: All personal data storage is maintained within the UK/EEA: • Platform hosted on Render (Frankfurt, Germany) • Database storage via MongoDB on AWS infrastructure (Ireland) • Sub-processors handling personal data are all EU-hosted (Render, MongoDB, Amplitude) Anonymised Content Processing: For AI processing services, only anonymised content (stripped of personal identifiers) is sent to providers including some US-based services. As no personal data is transferred, international transfer safeguards are not required for this processing. Where any international transfers of personal data are necessary, Top Marks AI implements appropriate safeguards including: • UK's International Data Transfer Agreement (for transfers from the UK) • Approved EU Standard Contractual Clauses (for transfers from the EEA) • Appropriate technical and organisational measures as required by UK/EU data protection law Transfer Summary (from Privacy Policy): • UK: Hosting provider, SaaS tools - Safeguard: Encryption • European Union: SaaS tools (Render, MongoDB on AWS in Ireland, Amplitude) - Safeguard: Encryption • USA: SaaS tools (AI providers) - No personal data transferred Additional Protections: • All transfers require appropriate data protection agreements with recipients • Recipients must implement equivalent security measures • Regular monitoring of transfer compliance and security standards Annex A (section 7) to Schedule 1 confirms in terms that personal data is not transferred to any country outside the UK or EEA in connection with the storage or primary processing of personal data under the Agreement, and lists only Render (Frankfurt), MongoDB Atlas/AWS (Ireland) and Amplitude (EU) as the infrastructure involved in that storage and processing. |
|
What are your incident response commitments? |
• Incident priority targets: P1 (Critical, e.g. platform-wide outage, data loss, security breach) – 2 hour initial response, 8 business hour resolution target; P2 (High) – 4 business hour response, 2 business day resolution target; P3 (Medium) – 1 business day response, 5 business day resolution target; P4 (Low) – 2 business day response, best-efforts resolution. These are targets, not guarantees • Personal data breach notification: within 72 hours of Top Marks AI becoming aware of a confirmed breach (SLA section 4.1) • Data subject requests: acknowledged within 5 business days and fulfilled (or referred to the school as controller) within 30 calendar days (SLA section 4.2) • Data deletion: within 30 days of a written instruction, or within 90 days of licence expiry if no instruction is received (SLA section 4.3) |
|
Document title |
Top Marks AI - DPIA Support Pack |
|
Version |
2.0 |
|
Owner |
Alex Chapman, COO, Top Marks AI Ltd |
|
Review date |
August 2027 |