Last updated: 13 July 2026. The minimal controller and processor agreement required by UK GDPR / EU GDPR Article 28 for the roster feature. Accepted on the Roster tab of the dashboard, before any pupil names are entered, alongside the Teacher Terms.
Between the school on whose behalf a teacher accepts it (the "School", the data controller) and Peter Browne (the "Provider", "we", the data processor). The School determines the purposes and means of processing the roster data; the Provider processes it only on the School's documented instructions, being these terms and the ordinary use of the dashboard.
The teacher's own account data (their email, school name and school email captured at sign-up) is processed by the Provider as an independent controller under its privacy policy, and is outside this DPA.
Subject matter: the class leaderboard roster feature in Divisible Dash. Duration: for as long as the School's teachers use the feature, and until deletion under clause 8. Nature and purpose: storing a short pupil label entered by the teacher and matching it to that pupil's anonymous in-game account so the teacher can see who is who on their own class leaderboard. No profiling, advertising, or automated decision-making.
Personal data: per pupil, a first name and one last initial, and the link to that pupil's anonymous account identifier. Data subjects: pupils at the School whose first name and last initial a teacher enters. The Provider does not collect from pupils, and instructs teachers not to enter, surnames, dates of birth, ages, contact details, or any special category or criminal offence data.
The Provider shall:
The School authorises the Provider to use the sub-processors in Annex 1. The Provider imposes data protection terms on each no less protective than this DPA and remains liable for their performance. The Provider will give the School at least 30 days notice of any intended change of sub-processor, by email or a notice on the dashboard, and the School may object.
Roster data is stored in Google Firebase (Cloud Firestore). Where data is transferred outside the UK or EEA, the transfer relies on the Standard Contractual Clauses that Google includes in its Cloud Data Processing Addendum, which apply automatically to the Firebase services used.
The Provider processes roster data to UK and EU GDPR standards for every School, wherever it is, as a strong common baseline. Each School remains responsible, as controller, for its own local data protection law and for confirming it may lawfully provide the names. Where a School's own country requires a specific basis, that applies in addition: for example a School in the United States may rely on the school-consent basis for educational use under COPPA, and a School in the UK or EEA has the transfer protection in clause 6.
The Provider will notify the School without undue delay after becoming aware of a personal data breach affecting the roster data, and provide the information the School reasonably needs to meet its own obligations.
The Provider retains roster data only while the feature is provided to the School. Roster data is deleted when a teacher deletes the roster row, the class, or the teacher account on the dashboard, or when the School or teacher asks in writing to delete it. On deletion, the pupils' in-game scores remain under their anonymous accounts but are no longer linked by the Provider to any real name. There is no automatic time-based deletion.
Governed by the laws of England and Wales, matching the Teacher Terms, with the courts of England and Wales having non-exclusive jurisdiction.
| Sub-processor | Service |
|---|---|
| Google (Firebase) | Authentication and Cloud Firestore hosting of the class and roster data, and static hosting of the dashboard, under Google's Cloud Data Processing Addendum |