Note for review. This addendum follows the structure of a standard Article 28 processor agreement and reflects how the platform actually operates. Have it reviewed by a data protection solicitor, and confirm the audit and liability provisions align with your insurance, before publishing.
1. Scope and roles
This addendum applies whenever we process personal data on your behalf in providing the admitAI platform. It supplements our Terms of Service and takes precedence over them on any data protection matter.
- You are the controller. You determine why and how student personal data is processed. You decide what to upload, who to share it with, and how long to keep it.
- We are the processor. We process it only on your documented instructions.
- Where we act as controller in our own right — for your staff account data, billing and our own security logging — our Privacy Policy governs instead.
"UK GDPR", "personal data", "processing", "data subject", "controller" and "processor" carry the meanings given in the UK GDPR and the Data Protection Act 2018.
2. Processing details
The subject matter, duration, nature, purpose, categories of data and categories of data subject are set out in Annex A. Your use of the platform in accordance with its documentation constitutes your documented instructions.
3. Our obligations
We will:
- Process personal data only on your documented instructions, including on international transfers, unless required otherwise by law — in which case we tell you first, unless the law prohibits that on important grounds of public interest.
- Tell you promptly if we consider an instruction infringes data protection law. We may suspend the instruction until it is resolved.
- Implement and maintain the technical and organisational measures in Annex B.
- Ensure everyone authorised to process the data is bound by confidentiality.
- Assist you with data subject requests, security obligations, breach notification, and impact assessments, as set out below.
- Not use your data to train artificial intelligence models, ours or any third party's, and ensure the same restriction is imposed contractually on any AI sub-processor.
- Not sell, rent or disclose personal data to any third party except as this addendum permits.
4. Your obligations
You will:
- Ensure you have a valid lawful basis for the personal data you upload, and an appropriate Article 9 condition for any special category data.
- Provide your students with the privacy information they are entitled to, including that a software processor is involved.
- Ensure the data you upload is accurate and limited to what is necessary.
- Configure retention settings, user permissions and integrations appropriately for your obligations.
- Respond to your own data subjects in the first instance — they are your data subjects, not ours.
- Not upload personal data you have no need to process. In particular, do not upload documents outside the categories in Annex A without telling us first, so we can confirm the safeguards are adequate.
5. Personnel
Access to customer personal data by our staff is granted on a least-privilege basis, only where needed to provide support or maintain the service, and is logged. All personnel are subject to written confidentiality obligations that survive the end of their engagement, and receive data protection training appropriate to their role.
We do not access customer data for any purpose other than providing, securing and supporting the service. Where support requires access to your workspace, it is logged and available to you in your audit trail.
6. Security measures
We implement appropriate technical and organisational measures under Article 32, having regard to the state of the art, cost of implementation, and the nature and risk of the processing. The measures are described in Annex B. We may update them, provided the level of protection is not reduced.
We recognise that the data in this platform is unusually sensitive — passports, bank statements, immigration history — and that a breach would cause real harm to individual students, not merely commercial inconvenience to you. Our measures are set accordingly.
7. Sub-processors
You give general authorisation for us to engage sub-processors. Our current list is published at admitai.io/sub-processors and forms part of this addendum.
- We will give at least 30 days' notice by email before adding or replacing a sub-processor.
- You may object on reasonable data protection grounds within that period. We will work with you to find an alternative. If we cannot, you may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees.
- Every sub-processor is engaged under a written contract imposing obligations equivalent to those in this addendum.
- We remain fully liable to you for our sub-processors' performance.
You can subscribe to sub-processor change notifications at privacy@admitai.io.
8. Data subject requests
The platform provides self-service tools for you to access, correct, export and delete student records without needing us. Where a request cannot be handled through those tools, we will assist you, taking into account the nature of the processing.
- Erasure requests you action in the platform are executed within 24 hours, including for uploaded documents.
- If a data subject contacts us directly, we will not respond substantively. We will refer them to you and tell you within 3 business days.
- Assistance with individual requests is provided at no charge unless the volume becomes manifestly excessive, in which case we will discuss reasonable costs with you before incurring them.
9. Personal data breach
We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data. Our notification will include, so far as we know it at the time:
- The nature of the breach, including the categories and approximate number of data subjects and records affected.
- The likely consequences.
- The measures taken or proposed to address it and mitigate harm.
- A contact point for further information.
Where we do not have complete information within 72 hours, we will give you what we have and follow up in phases rather than waiting. We will assist you with your own notifications to the ICO and to affected data subjects. We will not notify a regulator or data subject on your behalf without your instruction, since that is your decision as controller.
10. Impact assessments and prior consultation
We will provide reasonable assistance with any data protection impact assessment or prior consultation with the ICO relating to your use of the platform. We maintain standard documentation — security overview, data flow description and sub-processor list — which we will share on request to support your assessment.
11. International transfers
Customer personal data is hosted in the United Kingdom and the European Economic Area. Where a sub-processor requires a transfer outside the UK, we rely on:
- UK adequacy regulations, where they apply to the destination; or
- The International Data Transfer Addendum to the EU Standard Contractual Clauses, or the IDTA, supported by a documented transfer risk assessment.
The transfer mechanism for each sub-processor is recorded on our sub-processors page. Where you require an alternative mechanism, tell us and we will discuss what is achievable.
12. Audit rights
We will make available the information necessary to demonstrate our compliance with Article 28, and allow for and contribute to audits.
- In the first instance we will provide our security documentation and respond to a reasonable security questionnaire, at no charge, once per year.
- Where that is genuinely insufficient, you may conduct an on-site or remote audit on 30 days' notice, no more than once in any 12-month period, during business hours, subject to confidentiality and without unreasonable disruption to our operations. A regulator may audit at any time on request.
- You bear your own audit costs. We bear ours, unless the audit reveals material non-compliance on our part, in which case we bear both and remediate at our expense.
We are a small company and do not yet hold ISO 27001 or SOC 2 certification. We would rather say that plainly than imply otherwise. We will tell you honestly what we do and do not have in place if you ask.
13. Return and deletion
On termination, at your choice, we will return or delete all personal data we process for you.
- You retain full export access for 30 days after the agreement ends.
- We delete live data within 30 days of that window closing.
- Encrypted backups cycle out on a rolling 35-day schedule; deleted data is not restored into live systems during that period.
- We may retain data where UK law requires it, for as long as required, and it stays subject to this addendum's protections.
- We will certify deletion in writing on request.
14. Liability
The liability provisions in our Terms of Service apply to this addendum. Nothing in this addendum limits either party's liability to a data subject or a regulator under UK GDPR, or excludes liability that cannot lawfully be excluded.
Annex A — Details of processing
| Subject matter | Provision of the admitAI platform for managing student recruitment and university admissions |
| Duration | The term of the agreement, plus the deletion periods in section 13 |
| Nature of processing | Collection, storage, organisation, structuring, retrieval, analysis, AI-assisted generation of drafts and assessments, transmission to universities and connected services, erasure |
| Purpose | Enabling the Customer to assess, advise, apply on behalf of, and support students through the admissions and visa process |
| Categories of data subject | Prospective and enrolled students; the Customer's staff and counsellors; sub-agents engaged by the Customer; parents, guardians and financial sponsors where the Customer records them |
| Categories of personal data | Identity and contact details; passport and immigration data; academic history and transcripts; English language test results; financial evidence and sponsor documentation; application, offer and enrolment records; communications between student and agency; portal and platform usage records |
| Special category data | May be present where a student discloses health information relevant to a visa or support need, or where documents reveal religious or ethnic origin. The Customer determines whether such data is uploaded and is responsible for the Article 9 condition |
| Criminal offence data | May be present where immigration history includes a prior refusal or a declared offence. Processed under the Customer's Schedule 1 condition |
| Frequency | Continuous for the duration of the agreement |
Annex B — Technical and organisational measures
Encryption and data protection
- AES-256 encryption at rest for all databases, uploaded documents and backups.
- TLS 1.2 or above for all data in transit, with HTTP Strict Transport Security enforced.
- Passwords stored only as salted hashes. Student portal access uses single-use magic links tied to a verified email or phone number, with no stored student password.
Access control
- Logically isolated database per customer tenant. No shared tables across customers.
- Role-based access control, with counsellors scoped to their assigned caseload.
- Least-privilege administrative access for our own staff, logged and reviewed.
- Multi-factor authentication available for agency accounts and required for our administrative access.
Monitoring and resilience
- Immutable audit logging of every record view, upload, release, export and deletion, retained 12 months.
- Automated encrypted backups on a rolling 35-day cycle, with documented restoration procedures.
- Infrastructure monitoring with alerting on anomalous access patterns.
- Documented incident response procedure with defined escalation and a 72-hour notification commitment.
Development and organisational
- Code review before deployment to production; dependency vulnerability scanning.
- Separate development, staging and production environments. Production personal data is not used in development or testing.
- Written confidentiality obligations and data protection training for all personnel with access.
- Documented sub-processor assessment before engagement.
- Data minimisation in AI processing — only the fields required for a task are transmitted, and AI providers are contractually barred from retaining or training on customer content.
To request our current security overview or complete a vendor assessment, write to security@admitai.io.