Annex to the Terms
Data Processing Agreement
Last updated: 18 September 2026 · v2026-09-23
This agreement sets out how T-place processes student data on your behalf under Article 28 of the GDPR. It forms part of the Terms & Conditions and is accepted with them electronically. If your school needs a signed copy, contact us.
1. Who is responsible for the data
You or your school act as the controller: the party that decides why and how student data is used. In this agreement, “you” means that controller. Polishchuk Mykhailo, the operator of T-place, acts as your processor and handles the data on your behalf.
We are the controller for your account, subscription and use of the service. That processing is covered by the Privacy Policy. This agreement covers the student data we process for you.
2. What this agreement covers
| Topic | Details |
|---|---|
| Service | Hosting lessons, receiving student work, grading answers and showing results. |
| Duration | While your account is open, unless you delete the relevant class or assignment earlier. The deletion terms below apply when processing ends. |
| Processing | Storing, retrieving, displaying and deleting data, and comparing responses with the answers you set. We do not use student data for profiling, advertising, analysis across schools or our own purposes. |
| Data | Student names or nicknames, answers and other submitted text, grades, comments, timestamps, IP addresses and browser details needed to provide the service. |
| People concerned | Your students, including children, and other people named in class lists or calendar entries. |
| Sensitive data | T-place is not designed to process special-category data. Entering it is prohibited by the Terms. |
3. Your instructions
We process student data only on your documented instructions: the Terms, this agreement and your actions in the app, such as creating classes, inviting students, grading and deleting work. We do not sell the data, use it for advertising or train AI models on it.
If the law requires processing beyond your instructions, we will tell you beforehand unless legally prohibited. If we believe an instruction breaches data-protection law, we will notify you and may decline to carry it out.
4. Confidentiality
People authorised to access student data are bound by confidentiality and may access only what their work requires. Access to production systems is limited to the people who operate them.
5. How we protect data
We use security measures appropriate to the risks, as required by Article 32 of the GDPR. These include:
- HTTPS to protect data sent between your browser and T-place.
- Passwords stored as Argon2id hashes rather than readable text.
- Short-lived signed session tokens, regular key rotation and separate student tokens limited to their assignment.
- Separate service databases and network restrictions on access between services.
- Private file storage with signed, time-limited access.
- Google Cloud encryption for stored data.
- Daily encrypted database backups retained for 15 days, with a tested recovery process.
- Continuous monitoring and automatic alerts for failures and unusual activity.
- Separate service identities with only the cloud permissions each service needs.
We review these measures as the service develops. We may replace them with equivalent or stronger safeguards, without reducing the level of protection.
6. Providers that process data for us
You authorise us to engage providers to help process student data. Our provider list describes the services we use and where they operate. Only providers that process student data on our behalf are sub-processors under this agreement.
We require equivalent data-protection obligations in writing from these sub-processors and remain responsible for their performance. We will notify you and update the list at least 30 days before adding or replacing a sub-processor of student data. You may object within that period on reasonable data-protection grounds. If we cannot offer an alternative, you may cancel and receive a refund for the unused subscription period.
7. Requests from students and parents
As controller, you handle requests about student data. The app lets you view submitted work, correct grades and delete sessions together with their student work.
For other requests, email teacher.place.co@gmail.com. We will help locate, correct, export or delete data at no charge and in time for you to meet the applicable response deadline, normally one month. If a student or parent contacts us directly, we will refer them to you and notify you, rather than decide the request ourselves.
8. Data breaches and other assistance
We will notify you of a breach affecting student data without undue delay and within 48 hours of becoming aware of it. We will share what happened, who is affected, likely consequences and the steps taken to address it, with updates as we learn more. You are responsible for any required notification to the supervisory authority; we will provide information to help you meet that duty.
On reasonable request, we will also help with data-protection impact assessments and consultations with your supervisory authority, using the information available to us.
9. Returning and deleting data
Deleting a class or assignment removes its student work from the live system. Contact us to delete an individual submission while keeping the rest.
When you stop using T-place, you may choose to have student data returned or deleted. Email teacher.place.co@gmail.com and we will arrange this within 30 days. We will confirm the scope before proceeding and delete remaining copies after return, unless the law requires us to retain them.
Deleted data is removed from daily backups as they expire, within 15 days.
10. Checking that we meet this agreement
We will provide the information reasonably needed to verify compliance, starting with written answers and available documentation.
If further checks are needed, you may audit us or appoint an independent auditor who is not a competitor and agrees to confidentiality. Give 30 days’ written notice. Audits take place during business hours, without disrupting the service or exposing other customers’ data, and normally no more than once a year. A regulator’s requirement or a confirmed breach may justify additional audits. You pay audit costs; we pay to fix any failures on our part.
11. International data transfers
Student data is stored in the EU. Some providers are based in the US and may access it from there to support the service.
These transfers rely on the European Commission’s Standard Contractual Clauses or, where applicable, the provider’s EU–US Data Privacy Framework certification. You can request copies of the safeguards that apply.
12. Duration, liability and updates
This agreement applies while we process student data for you. Duties that remain relevant afterwards, including confidentiality, deletion and help with outstanding requests, continue to apply.
The liability limits in the Terms & Conditions also apply here, except where data-protection law prevents this. We may update this agreement when the law or service changes and will notify you before material changes take effect.