Data Processing Agreement
Version 1.3 — September 2026
1. Parties and purpose
This agreement is between Nelochem Ltd, a company registered in England and Wales under company number 17387331, trading as DanceMate, whose registered office is 20 Patten Close, Marks Tey, Colchester, Essex, CO6 1ND, United Kingdom (the "Processor", "we", "us") and the subscribing dance school identified at signup or in the signature block below (the "Controller", "you").
It governs our processing of School Personal Data — personal data you store in DanceMate about your students, parents and guardians, contacts, event attendees, exam candidates and staff. This agreement forms part of the Terms of Service (section 9) and binds us and every subscribing school from signup, whether or not it is signed — the optional signature block below simply gives your school an executed copy for its records, and does not change the terms. If this agreement and the summary in section 9 of the Terms of Service ever differ, this agreement prevails. The DanceMate business transferred from Chris Burrell (sole trader) to Nelochem Ltd as described in section 1 of the Terms of Service, and this agreement transferred with it on the same terms.
2. Definitions
"UK GDPR", "personal data", "processing", "data subject", "controller", "processor" and "personal data breach" have the meanings given in the UK General Data Protection Regulation and the Data Protection Act 2018. A "sub-processor" is a third party we engage to process School Personal Data on your behalf.
3. Subject matter, duration, nature and purpose
The details required by Article 28(3) UK GDPR — what is processed, about whom, for how long and why — are set out in Annex A. In short: we host and process your school's administrative records for the sole purpose of providing the DanceMate service to you, for as long as you subscribe plus the wind-down period in clause 8.
4. Our obligations as your processor
We will:
- Follow your instructions. We process School Personal Data only on your documented instructions — including with regard to any transfer of School Personal Data outside the UK. Your use of the service constitutes those instructions, and anything further can be agreed with us in writing by email — unless UK law requires us to process otherwise, in which case we will tell you first (unless that law prevents it). We will tell you immediately if we believe an instruction from you would breach data protection law.
- Keep it confidential. We ensure every person authorised to process School Personal Data is bound by a duty of confidentiality.
- Keep it secure. We implement and maintain the technical and organisational measures in Annex C, and keep them under review, taking account of the state of the art and the risks of the processing (Article 32 UK GDPR).
- Use only approved sub-processors. We use only the sub-processors listed in Annex B, which you authorise by entering this agreement. We impose data-protection obligations equivalent to this agreement on each of them by written contract, and remain fully responsible to you for their performance. We will email you at least 30 days before adding or replacing a sub-processor — except an emergency replacement needed to keep the service secure or running, which we will tell you about promptly afterwards. Your right to object — and to cancel with a refund of the unused part of anything you have paid — applies equally to an emergency replacement once we tell you about it. If you reasonably object on data-protection grounds and we cannot resolve your objection, you may cancel your subscription and we will refund the unused part of anything you have paid.
- Help you with rights requests. Taking account of the nature of the processing, we assist you with appropriate measures — including the export, correction and deletion tools in the service — in fulfilling your obligation to respond to data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection). If a data subject contacts us directly, we will pass the request to you without undue delay rather than answer it ourselves.
- Help you with your own compliance. Taking account of the nature of the processing and the information available to us, we assist you with your obligations on security, personal data breach notification to the ICO and to affected people, and data protection impact assessments (Articles 32–36 UK GDPR).
- Tell you about breaches. We notify you without undue delay after becoming aware of a personal data breach affecting School Personal Data, with enough information for you to meet your own notification duties, and we cooperate with you in addressing it.
- Delete or return the data at the end. As set out in clause 8.
- Demonstrate compliance. As set out in clause 9.
5. Your obligations as controller
You confirm that: you have a lawful basis for the School Personal Data you store in DanceMate (including children's data) and have provided any privacy information your students, parents and staff are entitled to; your instructions to us will comply with data protection law; you will keep the data you enter accurate; and you will manage your school's access sensibly — who you add as staff, what access you give them, and removing people when they leave.
6. International transfers
School Personal Data is stored in the United Kingdom (Annex B). Where a sub-processor's operations involve access from, or processing in, a country outside the UK without an adequacy decision, the transfer is protected by safeguards approved under UK GDPR — standard contractual clauses with the UK International Data Transfer Addendum, as identified in Annex B. By entering this agreement you authorise the transfers described in Annex B, each protected by the safeguard identified there. We will not otherwise transfer School Personal Data outside the UK except on your documented instructions: any new transfer — including a change in where an existing sub-processor processes the data — will be notified to you on the same 30-days'-notice-and-objection basis as a sub-processor change under clause 4, and made only once a safeguard approved under UK GDPR is in place. Copies of the relevant safeguards are available on request.
7. Children's data
We recognise that School Personal Data routinely includes children's information (names, dates of birth, grades, attendance). You are the controller of it and decide what is recorded; we apply the same protections in this agreement to all School Personal Data, and we never use children's data for any purpose beyond providing the service to you.
8. Deletion and return
At the end of your subscription, at your choice we delete the School Personal Data or return it to you in a portable format (and then delete it). If you express no choice, we keep it for up to 12 months so you can come back with everything intact, then delete it — no later than 12 months after the end. At any time you can ask us to delete it sooner and we will do so within 30 days, unless UK law requires us to keep specific data (in which case we will tell you what and why).
Deletion removes data from our live systems. Residual copies can persist in database backups (encrypted at rest by our database provider) for a short further period before being overwritten in the normal backup cycle; backups are used only for disaster recovery, and if one ever had to be restored, we would re-delete the data.
9. Information and audits
We make available to you the information reasonably necessary to demonstrate our compliance with this agreement — including answering your security and data-protection questionnaires — and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate (provided the auditor is not a competitor of ours and agrees to reasonable confidentiality obligations). We may first satisfy an audit by providing documentation and certifications from us and our sub-processors; anything further is at your reasonable cost, at most once in any 12 months — except where a further audit is prompted by a personal data breach affecting School Personal Data or required by the ICO — on 30 days' written notice, and conducted in a way that does not put other schools' data at risk.
10. Liability
This agreement is part of your subscription agreement with us, and the exclusions and cap in section 11 of the Terms of Service apply to it. Nothing in this clause limits a data subject's own rights, or either party's liability where data protection law does not allow it to be limited.
11. Term and changes
This agreement applies from the moment you sign up and lasts until we have completed deletion or return under clause 8. If we update it, the change process in section 12 of the Terms of Service applies — at least 30 days' email notice for anything that materially affects your rights, with the option to cancel first. The version and date at the top of this page always identify the current text; we archive every published version and will re-supply the version your school signed on request.
12. Governing law
This agreement is governed by the law of England and Wales, and the courts of England and Wales have jurisdiction, on the same basis as section 14 of the Terms of Service.
Signatures
This agreement already binds both of us through your subscription — signatures are optional, for schools whose own records need a signed copy. The version executed is the one shown at the top of this page: 1.3 — September 2026.
Signed for the school (Controller)
Signed for DanceMate (Processor)
Chris Burrell
Director, for and on behalf of Nelochem Ltd, trading as DanceMate
Annex A — Details of the processing
| Subject matter | Hosting and processing of the Controller's school-administration records in the DanceMate service. |
|---|---|
| Duration | The subscription term, plus the deletion/return period in clause 8. |
| Nature and purpose | Storage, retrieval, display, transmission (including sending emails and notifications at the Controller's request), backup and deletion — solely to provide the DanceMate service to the Controller. |
| Types of personal data | Names; email addresses and phone numbers; dates of birth and ages; dance grades, exam entries, results and fees; attendance records; event and ticket details; staff names, email addresses and login credentials; device push-notification subscriptions. |
| Categories of data subjects | The Controller's students (including children), parents and guardians, contacts, event attendees and ticket buyers, exam candidates, and staff. |
| Special category data | Not requested by the service, and the Controller should not store special category data (such as health information) in free-text fields. If special category data is nonetheless stored, this agreement applies to it in full, and the Controller is responsible for ensuring a condition under Article 9 UK GDPR applies. |
Annex B — Authorised sub-processors
| Sub-processor | Role | Location of data | Transfer safeguard |
|---|---|---|---|
| Neon | Database storage of all School Personal Data | United Kingdom (AWS London, eu-west-2). Neon is US-headquartered. | Any access from outside the UK (e.g. support) is covered by standard contractual clauses with the UK addendum under Neon's data processing agreement. |
| Vercel | Application hosting; processes requests in transit | Some request processing on servers in the USA | Standard contractual clauses with the UK addendum. |
| Resend | Email delivery (recipient addresses and message content) | USA-based provider | Standard contractual clauses with the UK addendum under Resend's data processing agreement. |
| Anthropic | AI assistance for our support and operations: processing the text of messages your school sends to support, and related operational records (your school's name and subscription state), so routine requests can be understood and handled promptly. It does not receive the records your school stores about its students, and API inputs and outputs are not used to train Anthropic's models. | USA-based provider | Standard contractual clauses with the UK addendum under Anthropic's data processing addendum. |
| OpenAI | Text-to-speech only, for our own internal back-office assistant: it converts that assistant's written summaries into spoken audio so we can hear them. Those summaries can mention a school's name, quote part of a message the school sent to support, or describe a school's subscription state — the same operational records listed for Anthropic above, read aloud instead of written down. It receives nothing else, and in particular no student records and no contact details. It is never used by schools or their pupils, and API inputs and outputs are not used to train OpenAI's models. Audio is generated on the fly and not retained by us. | USA-based provider | Standard contractual clauses with the UK addendum under OpenAI's data processing addendum. |
Anthropic was added to this list on 4 September 2026, before any subscribed school's data predated this version — so no clause 4.6 notice period applied. OpenAI was added on 8 September 2026 on the same footing, for the text-to-speech role described above; its description was widened the same day (version 1.3) to say plainly that a spoken summary can carry a school's subscription state, which the written summaries alongside it already could. Future additions or replacements will be notified as clause 4.6 describes.
Our Privacy Policy also mentions Stripe and YouTube for completeness, but neither processes School Personal Data on your behalf: Stripe handles your school's own billing (as its own controller), and YouTube is contacted by the viewer's own browser when a video is played. They are therefore not sub-processors under this agreement. Likewise, push notifications are delivered via the push service built into each user's own browser (Google, Apple or Mozilla), with message content encrypted end to end so the push service cannot read it — those services are not sub-processors either.
Annex C — Technical and organisational security measures
- All data in transit encrypted with HTTPS/TLS; strict transport security (HSTS) enforced.
- Each school's data is isolated by the application on every request — no school can access another's data.
- Access control: a school-chosen access code for the owner, and individual email-and-password staff logins with passwords stored only as salted hashes, with per-member access levels and revocation.
- Brute-force lockouts on every sign-in path, with security logging of failed attempts (purged after 90 days).
- Database credentials restricted to the application and never exposed to the browser; least-privilege configuration.
- Data stored in a UK data centre with automated backups, encrypted at rest by our database provider.
- Automated retention purges of security and activity logs; school data deleted after the periods in clause 8.
- Hardened HTTP security headers, including a content security policy, on every page.
- Regular structured security reviews of the codebase, with findings tracked to resolution.
← Back to DanceMate