Data Processing Agreement

Last updated: January 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between My Dance School ("Processor", "we", "us") and the dance school subscribing to our services ("Controller", "you"). This DPA governs the processing of personal data in accordance with UK GDPR and the Data Protection Act 2018.

1. Definitions

  • Controller: The dance school that determines the purposes and means of processing personal data
  • Processor: My Dance School, which processes personal data on behalf of the Controller
  • Personal Data: Any information relating to an identified or identifiable natural person
  • Data Subjects: The individuals whose personal data is processed (dancers, parents, staff)
  • Processing: Any operation performed on personal data
  • Sub-processor: A third party engaged by the Processor to process personal data

2. Scope and Purpose of Processing

We process personal data solely to provide the My Dance School platform and services, including:

  • Student and staff management
  • Class scheduling and attendance tracking
  • Parent communication and portal access
  • Payment processing
  • Competition management
  • Media storage and sharing
  • Reporting and analytics

3. Categories of Data Subjects

  • Dancers: Students enrolled at the dance school (including minors)
  • Parents/Guardians: Adults responsible for dancers
  • Staff: Teachers, administrators, and other employees
  • Contacts: Emergency contacts and other authorised individuals

4. Types of Personal Data

  • Identity data: names, dates of birth, photographs
  • Contact data: addresses, phone numbers, email addresses
  • Financial data: payment information (processed by Stripe)
  • Attendance records and class participation
  • Medical information relevant to dance activities
  • Emergency contact details
  • Consent records
  • Competition entries and results

5. Processor Obligations

As Processor, we agree to:

  • Process personal data only on your documented instructions
  • Ensure personnel are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures
  • Assist with data subject requests and regulatory compliance
  • Delete or return all personal data upon termination
  • Make available information necessary to demonstrate compliance
  • Inform you if we believe an instruction infringes data protection law

6. Sub-processors

You authorise us to engage the following sub-processors:

Sub-processorPurposeLocation
Supabase (via Lovable Cloud)Database hosting, authenticationEU/UK
ResendEmail deliveryUSA (with EU SCCs)
StripePayment processingUSA (with EU SCCs)

We will notify you of any intended changes to sub-processors, giving you the opportunity to object.

7. Security Measures

We implement appropriate security measures including:

  • Encryption of data in transit (TLS) and at rest
  • Access controls and authentication
  • Regular security assessments
  • Employee training and confidentiality agreements
  • Incident response procedures
  • Regular backups and disaster recovery

8. Data Breach Notification

In the event of a personal data breach, we will notify you without undue delay and within 72 hours of becoming aware. Notification will include the nature of the breach, categories of data affected, approximate number of data subjects, likely consequences, and measures taken or proposed.

9. Data Subject Requests

We will assist you in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) by providing tools within the platform and reasonable technical assistance. If we receive a request directly, we will refer the data subject to you unless otherwise instructed.

10. Audit Rights

Upon reasonable notice, you may audit our compliance with this DPA. We will provide information and access reasonably necessary for such audits. You may also request third-party audit reports where available.

11. International Transfers

Where personal data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the UK ICO or EU Commission, or transfers to countries with adequate data protection laws.

12. Term and Termination

This DPA remains in effect for the duration of your subscription. Upon termination, we will delete or return all personal data within 30 days, unless retention is required by law. You may request a data export before termination.

13. Liability

Our liability under this DPA is subject to the limitations set out in the Terms of Service. Each party remains responsible for its own compliance with data protection law.

14. Contact

For questions about this Data Processing Agreement, contact our Data Protection Officer:

Email: dpo@mydanceschool.co.uk