Data Processing Agreement
Last updated: 12 August 2026
This Data Processing Agreement ("DPA") forms part of the Makatib.App Terms of Service between the madrassa, or the person or organisation operating it, accepting those terms ("Customer" or "Controller") and Project Paced Ltd ("Project Paced" or "Processor"). It applies where Project Paced processes personal data for the Customer in providing Makatib.App.
1. Roles, Customer status and interpretation
The Customer is controller of student, guardian, staff, attendance, education, messaging and fee records it places in the service. Project Paced is its processor for that Customer Data. Each party remains independently responsible for processing for which it is a controller, as described in the privacy policy.
The Customer may take any lawful form. It may be an unincorporated association or mosque committee, a registered charity, a company, or an individual teaching in their own name. Nothing in this DPA assumes a particular structure. A Customer who is an individual enters this DPA in the course of a business or profession and not as a consumer, and carries the controller obligations set out here personally. Where the Customer is an individual, that person’s own account, billing and support details are also processed by Project Paced as a controller in its own right under the privacy policy, not as a processor under this DPA.
"Data Protection Law" means the UK GDPR, Data Protection Act 2018 and applicable PECR requirements, and UK GDPR terms have their statutory meanings. Where the Customer is established in the European Economic Area, or its processing is otherwise subject to Regulation (EU) 2016/679, references in this DPA to the UK GDPR are read as references to the EU GDPR and references to the Information Commissioner’s Office are read as references to the Customer’s competent supervisory authority. This DPA is written to UK and EU standards only. A Customer established elsewhere is responsible for satisfying itself that these terms meet the requirements applying to it, and Project Paced makes no representation that they do.
2. Processing instructions
Project Paced will process Customer Data only on the Customer's documented instructions, including these terms, the Customer's configured use of the service and written support requests, unless UK law requires otherwise. If legally permitted, Project Paced will tell the Customer before legally required processing. Project Paced will notify the Customer if it reasonably believes an instruction infringes Data Protection Law and may pause the affected processing while the parties resolve it.
3. Details of processing
| Subject and duration | Hosting and operating Makatib.App for the subscription term, plus the controlled return/deletion period in section 11. |
|---|---|
| Nature and purpose | Storage, organisation, retrieval, transmission, support, backup, security, messaging, invoice/payment record keeping and deletion needed to provide the service. |
| People | Students (mainly children), guardians, staff, volunteers and Customer contacts. Where the Customer runs an application form, this also includes prospective students and the family members who apply on their behalf, who are not yet in any relationship with the Customer. |
| Data | Identity and contact data; classes and relationships; attendance, tasks, educational and Quran progress; messages and attachments; invoices, adjustments, payment outcomes and audit/security data; a student's home address. Where the Customer runs an application form: the applicant's details, home address and prior learning, the applying family's contact details and an emergency contact. If the Customer switches the option on, it also includes health information about the child. |
| Special-category data | Religious belief. Records may reveal religious belief or participation in religious education. The Customer must document both an Article 6 lawful basis and an Article 9 condition before instructing this processing. Which Article 9 condition is available depends on what the Customer is: the Article 9(2)(d) condition is open only to a foundation, association or other not-for-profit body with a religious aim, so a madrassa operated for profit, or by an individual in their own name, cannot rely on it and will usually need explicit consent under Article 9(2)(a) or another condition, with any associated UK policy-document requirement met. The Customer should take its own advice on which applies to it. Health. The Customer may switch on health questions on its application form and record allergies, medical conditions, medication and additional needs against a student. The purpose is a narrow one: so that the adults caring for a child know about a condition or allergy that could affect them, and are prepared for it while the child is in their care. It is not a medical record and must not be used to decide whether a child is offered a place. The Customer should ask only for what meets that need. This is a separate Article 9 category from religious belief, and the Article 9(2)(d) not-for-profit condition does not extend to it: a condition covering religious data does not cover health data. These questions are off by default. Switching them on is an instruction to process health data, and the Customer must first identify its own Article 9 condition for doing so. This will commonly be explicit consent under Article 9(2)(a), or Article 9(2)(c) vital interests for a genuine emergency. The Customer must also meet any associated UK policy-document requirement. Project Paced provides a consent tick-box and records when it was ticked and against which version of the wording; that is evidence for the Customer's decision, not a substitute for making one. |
4. Customer obligations
The Customer will ensure its instructions and use are lawful; provide required notices; maintain appropriate Article 6 and, where relevant, Article 9 grounds; limit data to what is necessary; keep guardian/student relationships and permissions accurate; and handle controller decisions on rights, retention, safeguarding, fees and refunds.
Where the Customer runs an application form, it is additionally responsible for what that form asks, for the notice families see before submitting it, and for deciding whether to collect health information at all. A form that is open to the public can be reached by anyone with the link, so the Customer should ask only for what it needs at the application stage, and should close or regenerate its link when an intake ends. Unsuccessful applications are marked for deletion 90 days after the decision unless the Customer instructs otherwise.
The Customer confirms that it has the legal capacity and authority to enter this DPA and to give the instructions it gives. Where the Customer is an individual, these obligations are that individual’s own; they do not pass to a mosque, committee or madrassa that person teaches for unless that body is itself the Customer under a separate acceptance of the Terms.
5. Confidentiality and personnel
Project Paced will limit Customer Data access to authorised people who need it to provide, secure or support the service. They will be bound by confidentiality obligations and receive appropriate data-protection and security instruction.
6. Security
Project Paced will maintain technical and organisational measures appropriate to the risk, including tenant isolation, role-based access, database row-level security, encryption in transit and provider encryption at rest, secrets management, logging, backups, vulnerability and dependency management, incident handling and access removal. Measures may evolve without materially reducing overall protection. Further detail is available to Customers under appropriate confidentiality where disclosure would not weaken security.
7. Sub-processors
The Customer gives general written authorisation for the providers on the sub-processor list. Project Paced will impose data-protection obligations providing materially equivalent protection, remain responsible for their processing under this DPA, and give reasonable advance notice of a new or replacement sub-processor. A Customer may object on reasonable data-protection grounds during the notified period; the parties will seek a practical solution, failing which either may end the affected service.
8. International transfers
Project Paced will not make a restricted transfer of Customer Data without a lawful mechanism. Depending on the destination and provider, this may be UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to EU Standard Contractual Clauses, together with the required transfer risk assessment and supplementary measures. Current locations and mechanisms are recorded on the sub-processor list and in Project Paced's vendor register.
Where the Customer is established outside the United Kingdom, putting Customer Data into the service may itself be a transfer out of the Customer’s own jurisdiction. In that direction the Customer is the exporter and is responsible for the lawful mechanism for it. Project Paced will provide the information about hosting locations and sub-processors that the Customer reasonably needs in order to make that assessment.
9. Rights and compliance assistance
Taking account of the processing and information available, Project Paced will provide reasonable assistance with data-subject requests, security duties, breach assessment, DPIAs, prior consultation and regulator enquiries. If Project Paced receives a request relating to Customer Data, it will direct it to the Customer and will not answer on the Customer's behalf unless instructed or legally required.
10. Personal-data breaches
Project Paced will notify the Customer without undue delay after becoming aware of a personal-data breach affecting its Customer Data. As information becomes available, the notice will describe the nature and likely consequences, affected data and people, containment/remediation and a contact point. Notification is not an admission of fault. The Customer remains responsible for deciding whether and how to notify the ICO, or whichever supervisory authority is competent for it, and affected people.
11. Return, export, deletion and legal holds
Acceptance of the current Terms and this DPA by an authorised Customer administrator is a versioned, documented standing instruction for the published inactivity schedule; no separate settings-page instruction is required. Under that instruction, only an unpaid onboarding, beta or trial account may be suspended after 90 days without activity and deleted after a further 30-day recovery/export window and notices. A sign-in, reactivation, documented extension or applicable legal hold stops that automated path. Paid and active accounts require a separate termination instruction.
During the service and offboarding window, the Customer may request a reasonable export. On termination, Project Paced will delete or return Customer Data according to the Customer's documented choice and the published offboarding process, including backup expiry, unless law requires retention. The Customer may instruct longer retention for its accounting or legal obligations; those instructions, scope and end date must be documented. A valid legal hold pauses deletion only for affected records. Data retained after service access ends is isolated from ordinary product use and deleted when the obligation or hold ends.
Customer Data covered by export and deletion includes teaching materials uploaded to the private resource library, their metadata, audience records and sharing history. The Customer remains responsible for ensuring uploaded material is appropriately licensed and does not contain unnecessary personal data.
12. Evidence and audits
Project Paced will provide information reasonably necessary to demonstrate Article 28 compliance. Audits should normally use current policies, questionnaires, independent reports and remote evidence first. If those are insufficient, the Customer may conduct one proportionate audit a year on reasonable notice during business hours, subject to confidentiality, security and other customers' rights. Additional audits may follow a material breach or regulator request. The Customer bears its audit costs unless the audit identifies a material breach by Project Paced.
13. Priority, liability and contact
If this DPA conflicts with the Terms on personal-data processing, this DPA controls. The Terms' liability and governing-law provisions apply to this DPA to the extent permitted by law. Data-protection contacts and instructions should be sent to privacy@makatib.app.