Article 30 UK GDPR - effective 25 August 2026
This is AgentChamp Ltd's record of processing activities. It covers both roles: controller (family accounts, adult accounts, billing, marketing) and processor (school pupils' data, processed on the school's instructions).
It exists because Article 30 requires it, and because the ICO's June 2026 *Edtech examined* audit found that close to 90% of the edtech providers it examined had records with material gaps - most often around international transfers, retention, and secondary uses of children's data for analytics or AI. Those three are addressed explicitly below.
Controller / processor: AgentChamp Ltd, company number 17176256, 1434 London Road, Leigh-on-Sea, Essex, England, SS9 2UL. ICO registration ZC230270. Data protection contact: the Data Protection Lead, privacy@agentchamp.co.uk. No statutory DPO is required at our current scale (Article 37 assessed).
Controller: each school that registers. Instrument: the AgentChamp Data Processing Agreement, accepted at registration and version-stamped in the consent audit record.
| Article 30(2) field | Record |
|---|---|
| Categories of processing | Hosting and storage of pupil accounts and reading records; delivery of the reading programme (stories, narration, quizzes, vocabulary, rewards); progress analytics for school staff and linked guardians; automated reading-level placement; credential management; security logging; automated retention and deletion |
| Categories of data subjects | Pupils; the school's teaching and administrative staff |
| Categories of personal data | Pupils: name, year group, class, generated username, internal non-routable email identifier, login code and PIN (encrypted), optional gender, optional additional-reading-support marker (Article 9), and reading activity. Staff: name, email, role, job title, class assignments, authentication logs including IP and browser identifier |
| Special categories | The additional-reading-support marker only. Treated as Article 9 data; the school holds the condition. No diagnosis, condition, EHCP detail or health record is collected |
| Recipients (sub-processors) | Google Cloud (hosting, UK); Microsoft Azure Speech (narration, UK); ElevenLabs (audio synthesis, US); Resend (staff email, US). Stripe is not involved in school pupil data |
| Third-country transfers | No pupil personal data leaves the UK. ElevenLabs receives published text only (SCCs + UK Addendum); Resend receives a staff member's name and email (SCCs + UK Addendum); Google's US parent holds a UK-US Data Bridge certification, with data at rest region-pinned to London |
| Retention | Pupils: 365 days after leaving roll or going inactive, then a 90-day erasure grace period, both enforced by daily automated jobs. A live family subscription pauses the clock and is re-evaluated daily. Staff: not deleted on a timer; removed by explicit action, then the same 90-day purge. Consent audit record: event retained permanently as evidence, identifying elements (IP, browser identifier) erased after 6 years. Logs 30 days. Backups 30 days |
| Security measures | See security-measures.md - summarised in DPA Annex B |
Secondary uses: none. School Data is not used for product development, market research, behavioural analytics, anonymisation for reuse, or the training, fine-tuning or evaluation of any AI model. This is stated as a contractual obligation in the DPA, not only as a policy.
| Field | Record |
|---|---|
| Purpose | Deliver the reading programme to a child at home |
| Lawful basis | Article 6(1)(a) - consent of the holder of parental responsibility (Article 8; readers are under 13). Article 9(2)(a) explicit consent where the additional-reading-support marker is recorded |
| Data subjects | Children aged approximately 5–13 registered by a parent, guardian or tutor |
| Personal data | As for school pupils, without school or class |
| Recipients | Google Cloud, ElevenLabs, Microsoft Azure Speech (as above) |
| Transfers | None of the child's personal data |
| Retention | 365 days of inactivity, then 90-day erasure grace period |
| Field | Record |
|---|---|
| Purpose | Operate the account: registration, authentication, account administration, support |
| Lawful basis | Article 6(1)(b) - contract |
| Personal data | Name, email, role, school affiliation, job title, family code, password hash, authentication logs |
| Recipients | Google Cloud (hosting); Resend (service email) |
| Transfers | Resend, US - SCCs + UK Addendum |
| Retention | Not deleted on a timer. Unverified registrations deleted after 24 hours. Deleted accounts purged after 90 days |
| Field | Record |
|---|---|
| Purpose | Take payment; meet accounting obligations |
| Lawful basis | Article 6(1)(b) contract for the transaction; Article 6(1)(c) legal obligation for the records |
| Personal data | Paying adult's email, opaque account reference, subscription status, transaction amount/currency/status. No card data - it goes from the payer's browser to Stripe |
| Recipients | Stripe |
| Transfers | Stripe, EU/US - UK Extension to the Data Privacy Framework, UK Addendum as fallback |
| Retention | As required for accounting; payment-provider payload reduced to a bare summary after 180 days, and redacted immediately on erasure of the associated account |
| Field | Record |
|---|---|
| Purpose | Send newsletters and news about reading challenges to adults who asked for them |
| Lawful basis | Article 6(1)(a) consent; PECR regulation 22 |
| Data subjects | Adults only. Never children - children have no reachable email address |
| Personal data | Name, email, opt-in timestamp, the policy version consented under, opt-out timestamp |
| Recipients | Resend |
| Retention | For as long as the account exists or consent is withdrawn; both directions recorded in the consent audit record as evidence |
| Note | The consent machinery is live; no marketing email has yet been sent. There is no bulk-send path in the product |
| Field | Record |
|---|---|
| Purpose | Keep accounts safe, detect and investigate abuse, rate-limit attacks |
| Lawful basis | Article 6(1)(f) - legitimate interests. Assessed: the interest is account security; the processing is limited to what security requires; the impact on individuals is minimal and to their benefit |
| Personal data | IP address, browser identifier, timestamps, account identifier. Identifiers are masked or hashed in routine application logs |
| Retention | Logs 30 days. Rate-limit counters are ephemeral |
| Field | Record |
|---|---|
| Purpose | Evidence that consent was obtained and that erasure requests were honoured |
| Lawful basis | Article 6(1)(c) legal obligation, supported by Article 17(3)(b) and (e) for retention after erasure |
| Personal data | Actor and subject identifiers, action, document version, IP address, browser identifier, timestamp |
| Retention | The event is permanent evidence. IP address and browser identifier are erased after 6 years by an automated job. Rows are append-only, enforced by a database trigger |
| Field | Record |
|---|---|
| Purpose | Produce reading material |
| Personal data involved | None. Generation runs offline from content parameters an adult chose - theme, reading level, style. Speech synthesis receives published text. No user identifier is present in any request |
| Recipients | Google Cloud Vertex AI (Gemini, Imagen, Anthropic Claude via Model Garden); ElevenLabs; Microsoft Azure Speech; Google Cloud Text-to-Speech |
| Note | Recorded here for completeness precisely because it is where an edtech provider most often slips into being an undeclared controller. It does not involve personal data, and no children's data trains any model. See ai-and-childrens-data.md |
Recorded explicitly, because a record that only lists activities cannot answer the question a school actually asks:
This record is reviewed whenever a new processing activity, sub-processor or data category is introduced - before it goes live - and in any event annually. A structural test in the codebase asserts that every third-party origin the application may contact appears in the Sub-Processor Inventory, so the supply-chain half of this record cannot drift silently.
Last reviewed: 25 August 2026.
AgentChamp keeps you signed in and remembers your reading settings using cookies and browser storage. What we store, in full.