Corrected against the deployed system on 7 September 2026; still awaiting legal review. Annex B now describes the measures actually in place, including the ones that fall short of what an earlier draft claimed. Outstanding: review by a data protection solicitor, confirmation that each sub-processor agreement is executed, and our insurance position.
1. Scope and roles
This addendum applies whenever we process personal data on your behalf in providing the admitAI platform. It supplements our Terms of Service and takes precedence over them on any data protection matter.
- You are the controller. You determine why and how student personal data is processed. You decide what to upload, who to share it with, and how long to keep it.
- We are the processor. We process it only on your documented instructions.
- Where we act as controller in our own right — for your staff account data, billing and our own security logging — our Privacy Policy governs instead.
"UK GDPR", "personal data", "processing", "data subject", "controller" and "processor" carry the meanings given in the UK GDPR and the Data Protection Act 2018.
2. Processing details
The subject matter, duration, nature, purpose, categories of data and categories of data subject are set out in Annex A. Your use of the platform in accordance with its documentation constitutes your documented instructions.
3. Our obligations
We will:
- Process personal data only on your documented instructions, including on international transfers, unless required otherwise by law — in which case we tell you first, unless the law prohibits that on important grounds of public interest.
- Tell you promptly if we consider an instruction infringes data protection law. We may suspend the instruction until it is resolved.
- Implement and maintain the technical and organisational measures in Annex B.
- Ensure everyone authorised to process the data is bound by confidentiality.
- Assist you with data subject requests, security obligations, breach notification, and impact assessments, as set out below.
- Not use your data to train artificial intelligence models, ours or any third party's, and ensure the same restriction is imposed contractually on any AI sub-processor.
- Not sell, rent or disclose personal data to any third party except as this addendum permits.
4. Your obligations
You will:
- Ensure you have a valid lawful basis for the personal data you upload, and an appropriate Article 9 condition for any special category data.
- Provide your students with the privacy information they are entitled to, including that a software processor is involved.
- Ensure the data you upload is accurate and limited to what is necessary.
- Configure retention settings, user permissions and integrations appropriately for your obligations.
- Respond to your own data subjects in the first instance — they are your data subjects, not ours.
- Not upload personal data you have no need to process. In particular, do not upload documents outside the categories in Annex A without telling us first, so we can confirm the safeguards are adequate.
5. Personnel
Access to customer personal data by our staff is granted on a least-privilege basis, only where needed to provide support or maintain the service, and is logged. All personnel are subject to written confidentiality obligations that survive the end of their engagement, and receive data protection training appropriate to their role.
We do not access customer data for any purpose other than providing, securing and supporting the service. Where support requires access to your workspace, it is logged and available to you in your audit trail.
6. Security measures
We implement appropriate technical and organisational measures under Article 32, having regard to the state of the art, cost of implementation, and the nature and risk of the processing. The measures are described in Annex B. We may update them, provided the level of protection is not reduced.
We recognise that the data in this platform is unusually sensitive — passports, bank statements, immigration history — and that a breach would cause real harm to individual students, not merely commercial inconvenience to you. Our measures are set accordingly.
7. Sub-processors
You give general authorisation for us to engage sub-processors. Our current list is published at admitai.co.uk/sub-processors and forms part of this addendum.
- We will give at least 30 days' notice by email before adding or replacing a sub-processor.
- You may object on reasonable data protection grounds within that period. We will work with you to find an alternative. If we cannot, you may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees.
- Every sub-processor is engaged under a written contract imposing obligations equivalent to those in this addendum.
- We remain fully liable to you for our sub-processors' performance.
You can subscribe to sub-processor change notifications at privacy@admitai.co.uk.
8. Data subject requests
The platform lets you access and correct student records directly. Self-service export and erasure are not yet built — deleting a student moves it to a trash view, and there is no bulk export. Until those ship, ask us and we will produce or erase the data for you, at no charge, within the timescales below.
- Deleting a student moves the record to a trash view. From there an agency owner can erase it permanently, which removes the uploaded files from disk as well as the record, and reports back anything it could not remove rather than claiming a clean erasure. A structured export of everything held about one student is available to any agency member, in JSON, with authenticated download links for each document.
- If a data subject contacts us directly, we will not respond substantively. We will refer them to you and tell you within 3 business days.
- Assistance with individual requests is provided at no charge unless the volume becomes manifestly excessive, in which case we will discuss reasonable costs with you before incurring them.
9. Personal data breach
We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data. Our notification will include, so far as we know it at the time:
- The nature of the breach, including the categories and approximate number of data subjects and records affected.
- The likely consequences.
- The measures taken or proposed to address it and mitigate harm.
- A contact point for further information.
Where we do not have complete information within 72 hours, we will give you what we have and follow up in phases rather than waiting. We will assist you with your own notifications to the ICO and to affected data subjects. We will not notify a regulator or data subject on your behalf without your instruction, since that is your decision as controller.
10. Impact assessments and prior consultation
We will provide reasonable assistance with any data protection impact assessment or prior consultation with the ICO relating to your use of the platform. We maintain standard documentation — security overview, data flow description and sub-processor list — which we will share on request to support your assessment.
11. International transfers
Our application servers, and the uploaded documents stored on them, are in London. Our database is in the United States, so the structured personal data it holds is transferred outside the UK. An earlier version of this addendum said all customer personal data was hosted in the UK and the EEA; that was incorrect. We are deciding between migrating the database to a UK or EU region and documenting the transfer properly. For that transfer, and wherever else a sub-processor requires one, we rely on:
- UK adequacy regulations, where they apply to the destination; or
- The International Data Transfer Addendum to the EU Standard Contractual Clauses, or the IDTA, supported by a documented transfer risk assessment.
The transfer position for each sub-processor is recorded on our sub-processors page, which marks the ones where we have not yet confirmed an executed agreement. Where you require an alternative mechanism, tell us and we will discuss what is achievable.
12. Audit rights
We will make available the information necessary to demonstrate our compliance with Article 28, and allow for and contribute to audits.
- In the first instance we will provide our security documentation and respond to a reasonable security questionnaire, at no charge, once per year.
- Where that is genuinely insufficient, you may conduct an on-site or remote audit on 30 days' notice, no more than once in any 12-month period, during business hours, subject to confidentiality and without unreasonable disruption to our operations. A regulator may audit at any time on request.
- You bear your own audit costs. We bear ours, unless the audit reveals material non-compliance on our part, in which case we bear both and remediate at our expense.
We are a small company and do not yet hold ISO 27001 or SOC 2 certification. We would rather say that plainly than imply otherwise. We will tell you honestly what we do and do not have in place if you ask.
13. Return and deletion
On termination, at your choice, we will return or delete all personal data we process for you.
- You retain access for 30 days after the agreement ends, and we will produce an export for you on request within that window.
- We delete live data within 30 days of that window closing. Done by hand today, not by a scheduled job — and we will confirm the deletion to you in writing.
- Encrypted backups cycle out on our database provider's retention schedule; deleted data is not restored into live systems during that period.
- We may retain data where UK law requires it, for as long as required, and it stays subject to this addendum's protections.
- We will certify deletion in writing on request.
14. Liability
The liability provisions in our Terms of Service apply to this addendum. Nothing in this addendum limits either party's liability to a data subject or a regulator under UK GDPR, or excludes liability that cannot lawfully be excluded.
Annex A — Details of processing
| Subject matter | Provision of the admitAI platform for managing student recruitment and university admissions |
| Duration | The term of the agreement, plus the deletion periods in section 13 |
| Nature of processing | Collection, storage, organisation, structuring, retrieval, analysis, AI-assisted generation of drafts and assessments, transmission to universities and connected services, erasure |
| Purpose | Enabling the Customer to assess, advise, apply on behalf of, and support students through the admissions and visa process |
| Categories of data subject | Prospective and enrolled students; the Customer's staff and counsellors; sub-agents engaged by the Customer; parents, guardians and financial sponsors where the Customer records them |
| Categories of personal data | Identity and contact details; passport and immigration data; academic history and transcripts; English language test results; financial evidence and sponsor documentation; application, offer and enrolment records; communications between student and agency; portal and platform usage records |
| Special category data | May be present where a student discloses health information relevant to a visa or support need, or where documents reveal religious or ethnic origin. The Customer determines whether such data is uploaded and is responsible for the Article 9 condition |
| Criminal offence data | May be present where immigration history includes a prior refusal or a declared offence. Processed under the Customer's Schedule 1 condition |
| Frequency | Continuous for the duration of the agreement |
Annex B — Technical and organisational measures
Encryption and data protection
- Encryption at rest as provided by our database and server hosts for all databases, uploaded documents and backups. We do not add an application-layer encryption of our own on top of it.
- TLS 1.2 or above for all data in transit, with HTTP Strict Transport Security enforced.
- Account passwords stored only as bcrypt hashes, for staff and students alike. Students receive a single-use, time-limited link to a verified address in order to set that password, and to reset it. A student's own UCAS password was previously stored as typed. We have stopped storing it, cleared what had been collected, and the field is being removed from the schema entirely — nothing in the platform ever used it, and our Terms say we will not submit to UCAS on a student's behalf.
Access control
- Logical tenant isolation with scoped access controls designed to prevent cross-customer access.
- Role-based access control, with counsellors scoped to their assigned caseload.
- Least-privilege administrative access for our own staff, logged and reviewed.
- Multi-factor authentication is available for agency accounts, using any standard authenticator app. It is opt-in per person rather than mandatory, and enrolment only takes effect once a code from the app has been verified — so a half-finished setup can never lock anyone out. Ten single-use recovery codes are issued at enrolment. We do not yet require it for all staff, and say so rather than implying a policy we have not set.
Monitoring and resilience
- Append-only logging of changes to a student record — who changed what, when, and from what to what, distinguishing staff from student edits, with sensitive values recorded as changed but not copied. Every view and download of a document is logged too, with the reader, the time and the address, in a table that deliberately holds no foreign key so the record survives the erasure of the document and of the student. Two honest limits: the log is append-only by convention rather than by database grant, and it is not yet retention-bounded.
- Automated encrypted backups held by our database provider on their retention cycle. Restoration has not been rehearsed end to end; we will say so if you ask.
- Infrastructure monitoring with alerting on anomalous access patterns.
- Documented incident response procedure with defined escalation and a 72-hour notification commitment.
Development and organisational
- Code review before deployment to production; dependency vulnerability scanning.
- Separate development, staging and production environments. Production personal data is not used in development or testing.
- Written confidentiality obligations and data protection training for all personnel with access.
- Documented sub-processor assessment before engagement.
- Data minimisation in AI processing — only the fields required for a task are transmitted, and AI providers are contractually barred from retaining or training on customer content.
To request our current security overview or complete a vendor assessment, write to security@admitai.co.uk.