Milepost
Data Processing Agreement
Last updated 12 August 2026.
A note on this document: we've published this ahead of formal legal sign-off, prepared in good faith to meet UK transparency requirements while a full legal review is completed. It may be updated as that review concludes. Questions or concerns: admin@teachingmrallen.com.
This is our standard Data Processing Agreement (“DPA”), incorporated by reference into our Terms and Conditions. It applies between Teaching Mr Allen Limited (“Milepost”, the “Processor”) and each school or organisation using the Service (the “Customer”, the “Controller”). A signed, customer-specific copy naming your school and confirming the details below is completed when you sign up -- contact support@milepost.fit for a copy.
1. Definitions
- Applicable Data Protection Laws means UK GDPR and the Data Protection Act 2018, and, to the extent applicable to the Customer's own data protection obligations, Malaysia's Personal Data Protection Act 2010.
- Personal Data, Processing, Controller, Processor, Data Subject, and Personal Data Breach have the meanings given in UK GDPR.
- Sub-processor means any third party engaged by the Processor to process Personal Data in providing the Service.
2. Subject matter, duration, nature and purpose
Set out in Schedule 1 below. This DPA applies for as long as the Processor processes Personal Data on the Controller's behalf under the Principal Agreement (our Terms and Conditions and the Customer's Order).
3. Controller and Processor roles
In relation to Personal Data processed via the Service, the Customer is the Controller and Milepost is the Processor. The Customer is solely responsible for the accuracy, quality, and legality of the Personal Data it submits and for having a lawful basis to process it, including any Personal Data relating to students, who may be children.
4. Processor obligations
The Processor shall:
- process Personal Data only on the Controller's documented instructions, unless required to do otherwise by law, in which case it will inform the Controller before processing unless prohibited from doing so;
- ensure that persons authorised to process Personal Data are subject to a duty of confidentiality;
- implement appropriate technical and organisational measures as set out in Schedule 2;
- not engage a Sub-processor without the Controller's general written authorisation (given via Schedule 3 and this DPA), and inform the Controller of any intended changes with an opportunity to object;
- assist the Controller, by appropriate technical and organisational measures, to respond to Data Subjects exercising their rights under Applicable Data Protection Laws;
- assist the Controller in ensuring compliance with its obligations relating to security, breach notification, and data protection impact assessments;
- at the Controller's choice, delete or return all Personal Data at the end of the provision of Services, and delete existing copies unless retention is required by law; and
- make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits on reasonable notice.
5. Sub-processors
The Controller authorises the Processor to engage the Sub-processors listed in Schedule 3. The Processor will give the Controller at least 30 days' notice of any new or replacement Sub-processor, during which the Controller may object on reasonable data-protection grounds. The Processor remains liable for each Sub-processor's performance of its data protection obligations.
6. International transfers
The Processor's primary Sub-processor (Supabase) hosts the Customer's Personal Data in Singapore. The Processor ensures that any transfer of Personal Data outside the UK is subject to appropriate safeguards recognised under UK GDPR, and will provide details of the relevant mechanism to the Controller on request.
7. Personal Data Breach
The Processor shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data Breach affecting the Controller's Personal Data, and shall cooperate with the Controller's response.
8. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in our Terms and Conditions, except to the extent such limitations are not permitted by Applicable Data Protection Laws.
9. Term and termination
This DPA takes effect on the date the Customer first submits Personal Data to the Service and continues for as long as the Processor processes Personal Data on the Customer's behalf, notwithstanding termination of the Principal Agreement, until such processing ends.
10. Governing law
This DPA is governed by the laws of England and Wales, consistent with our Terms and Conditions.
Schedule 1 -- Details of Processing
Subject matter: Provision of the Milepost staff and student information management platform to the Customer.
Duration: For the term of the Principal Agreement, and thereafter until all Personal Data is deleted or returned per Section 4.
Nature and purpose: Storage, organisation, retrieval, and display of school staff and student administrative data to enable the Customer to manage timetabling, duty rostering, assessment records, pastoral notes, and related school administration.
Categories of Data Subjects: The Customer's staff members, and the Customer's students, including children.
Categories of Personal Data: Staff -- name, contact details, role, timetable, duty assignments, availability status. Students -- name, class, timetable, pastoral/learning-support notes, assessment and gradebook records.
Special category data: Pastoral and learning-support records may include special category data (for example, health-related information) where a school records this for safeguarding purposes.
Schedule 2 -- Technical and Organisational Security Measures
- Role-based access controls within the Service, so staff only see data relevant to their role.
- Encryption of data in transit (HTTPS/TLS).
- Authentication required for all access to the Service; no public access to Customer Data.
- Audit logging of key changes (for example, duty roster and timetable edits, gradebook entries).
Schedule 3 -- Authorised Sub-processors
- Supabase, Inc. -- database and file storage hosting (AWS ap-southeast-1, Singapore).
- Render Services, Inc. -- application hosting.
Schedule 4 -- Customer Details
Completed with the school's legal name, address, and data protection contact when this DPA is executed.
