Legal

Data Processing Agreement

Mr G Education Ltd · Effective 26 July 2026 · Version 1.0

In short

This agreement governs how we handle personal data on your organisation's behalf: you are the controller, we are your processor. It forms part of our Terms of Service automatically — no signature needed — and sets out our obligations, our sub-processors, and the security measures we maintain. If your procurement process needs a countersigned copy, email us.

1. Parties, scope and incorporation

This Data Processing Agreement ("DPA") is between Mr G Education Ltd (trading as "Moodly"), registered in England and Wales, company number 14557194, ICO registration ZB526873 ("Moodly", the "Processor"), and the organisation that uses Moodly Surveys under our Terms of Service (the "Customer", the "Controller").

This DPA is incorporated into and forms part of the Terms of Service. It applies whenever Moodly processes personal data on the Customer's behalf in providing Moodly Surveys ("Customer Personal Data"). For data protection matters it takes precedence over the rest of the Terms.

Where the Customer is itself a processor for another controller (for example a trust or group administering the Service for its member organisations), the Customer warrants that its controller has authorised these terms and the sub-processors in Annex 3, and Moodly acts as sub-processor.

2. Definitions and roles

"Data Protection Laws" means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, each as amended, and, where applicable to the processing, the EU GDPR. "Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the UK GDPR.

  • The Customer is the controller of Customer Personal Data: it decides who is on its roster, what its surveys ask, which identity mode each survey uses, and how results are used.
  • Moodly is the processor: we process Customer Personal Data only to provide, secure and support the Service.
  • For data where Moodly decides the purposes and means — accounts and billing relationships, website analytics, our own correspondence — Moodly is an independent controller and our Privacy Policy applies instead of this DPA.
Anonymous responses. The Service is engineered so that responses on anonymous surveys (the default) are stored with no name, email address or account identifier, enforced by server-side security rules. Data that identifies no one is not personal data. However, to the extent any survey response nonetheless contains or constitutes personal data — for example free-text answers in which a respondent identifies themself, or responses on surveys using an identified mode — it is Customer Personal Data protected by this DPA.

3. Processing on documented instructions

Moodly will process Customer Personal Data only on the Customer's documented instructions, including regarding international transfers, unless required to do otherwise by law applicable to Moodly — in which case Moodly will inform the Customer of that legal requirement before processing, unless the law prohibits doing so on important grounds of public interest.

The Customer's complete instructions are: the Terms of Service, this DPA, and the Customer's configuration and use of the Service's features (for example publishing a survey, setting its identity mode and audience, enabling a public link, importing a roster, requesting an export, or deleting data). Additional instructions require written agreement.

Moodly will inform the Customer without undue delay if, in its opinion, an instruction infringes Data Protection Laws — though the Customer remains responsible for the lawfulness of its instructions.

4. Customer responsibilities

  • Establish and document a lawful basis for the personal data it submits to the Service, including adding participants to its roster.
  • Provide data subjects (participants, and where relevant parents) with the transparency information Data Protection Laws require.
  • Choose survey content, identity modes and audiences appropriately — including satisfying an Article 9 UK GDPR condition where a survey deliberately collects special category data in identified form (see Annex 1).
  • Keep its portal access levels appropriate and its Portal Users' sign-in accounts secure.
  • Not instruct Moodly to process personal data of children younger than the Service is designed for (see the Privacy Policy).

5. Moodly's obligations

Confidentiality

Moodly ensures that every person it authorises to process Customer Personal Data is bound by a contractual or statutory duty of confidentiality, and accesses it only as needed to provide, secure or support the Service.

Security (Article 32)

Moodly implements and maintains appropriate technical and organisational measures to protect Customer Personal Data, taking into account the state of the art, costs, and the nature, scope, context and purposes of processing — including as a minimum the measures in Annex 2. Moodly may update those measures provided the protection they afford does not materially decrease.

Assistance with data subject rights

Taking into account the nature of the processing, Moodly will assist the Customer by appropriate technical and organisational measures — including the Service's built-in roster management, exports and deletion tools — in fulfilling the Customer's obligation to respond to data subject requests. If a data subject contacts Moodly directly about Customer Personal Data, Moodly will refer them to the Customer without undue delay and will not respond substantively except as legally required.

Assistance is necessarily limited by the Service's anonymity design: responses on anonymous surveys cannot be attributed to a data subject by either party, so access, rectification and erasure cannot be applied to them individually. Both parties agree this is a privacy-protective feature of the processing, not a failure to assist.

Assistance with security, breaches, DPIAs and consultations

Taking into account the nature of the processing and the information available to it, Moodly will assist the Customer in complying with its obligations under Articles 32 to 36 UK GDPR (security, breach notification, data protection impact assessments and prior consultation), and will provide reasonable information to support a Customer DPIA concerning the Service.

6. Sub-processors

The Customer gives general written authorisation for Moodly to engage the sub-processors listed in Annex 3. Moodly will: impose on each sub-processor data protection obligations materially equivalent to this DPA; remain fully liable to the Customer for the sub-processor's performance; and keep Annex 3 up to date on this page.

Moodly will give organisation admins at least 30 days' notice (by email or prominent notice in the portal) before adding or replacing a sub-processor that processes Customer Personal Data. If the Customer has reasonable data protection grounds to object, the parties will discuss in good faith; if the objection cannot be resolved, the Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused period.

7. International transfers

Customer Personal Data at rest — rosters, surveys, responses, completion records — is stored in Google Cloud's London (europe-west2) region.

Where a sub-processor in Annex 3 processes personal data outside the UK, Moodly ensures a valid transfer mechanism under Data Protection Laws: UK adequacy regulations (including for the EEA), the UK Extension to the EU–US Data Privacy Framework for certified recipients, or the ICO's International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, together with any supplementary measures required. Moodly will provide details of the mechanism relied on for any sub-processor on request.

8. Personal data breach

Moodly will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, so far as then known: the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point — with updates as more becomes known.

Moodly will take prompt steps to contain and remediate the breach and will reasonably cooperate with the Customer's own notification obligations. Moodly's notification is not an admission of fault. The Customer is responsible for notifying its supervisory authority and data subjects where required.

9. Deletion and return of data

  • During the subscription, the Customer controls its data directly: admins can remove participants (removal deletes the roster record immediately), and the built-in CSV exports and reports provide return of data in a structured, commonly used, machine-readable format at any time.
  • On termination or expiry, at the Customer's choice Moodly will delete or return Customer Personal Data. An organisation owner can use the self-service deletion tool at any time, which permanently and irreversibly deletes the organisation's roster, surveys, responses and completion records immediately; otherwise Moodly will delete Customer Personal Data within 30 days of a written request following termination, and will confirm deletion in writing on request.
  • Deletion does not apply to data Moodly must retain under applicable law (for example billing and tax records, retained for the statutory period and then deleted) or to residual copies in encrypted backups, which are cycled out in the ordinary course and remain protected by this DPA until then.
  • Responses on anonymous surveys contain no identifiers and are outside the scope of return; they are deleted with the organisation.

10. Information and audit

Moodly will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR — starting with this DPA, its annexes, and the security documentation of the infrastructure providers in Annex 3 (for example Google Cloud's ISO 27001 and SOC 2 reports, available under their compliance programmes).

Where that information is insufficient to demonstrate compliance, Moodly will allow for and contribute to audits, including inspections, conducted by the Customer or its mandated auditor (not a Moodly competitor), subject to: at least 30 days' written notice; at most one audit in any 12-month period except after a personal data breach or where a supervisory authority requires more; reasonable scope agreed in advance; confidentiality undertakings; no access to other customers' data; and the Customer bearing its own costs. Audits of shared cloud infrastructure are satisfied by the providers' third-party certifications and reports.

11. Liability, term and general

  • This DPA takes effect when the Customer first uses the Service and continues until Moodly stops processing Customer Personal Data in accordance with section 9.
  • Each party's liability under this DPA is subject to the exclusions and cap in the Terms of Service, except where Data Protection Laws do not permit liability to be limited.
  • Each party is responsible for the administrative fines and compensation attributable to its own breach of Data Protection Laws, as allocated by Articles 82 and 83 UK GDPR.
  • This DPA is governed by the law of England and Wales, in line with the Terms of Service.
  • If your procurement process requires a countersigned copy of this DPA, or your trust or group needs specific terms, contact info@moodly.education.

Annex 1 — Details of processing

Subject matterProvision of the Moodly Surveys platform: survey authoring, distribution, answering, aggregation, reporting and export.
DurationThe term of the Customer's use of the Service, plus the deletion periods in section 9.
Nature and purposesHosting and storage; authentication; sending sign-in and service emails; collecting, aggregating and displaying survey responses; producing reports and exports; AI-assisted survey drafting where used; service support and security.
Categories of data subjectsParticipants added to the Customer's roster (for example students aged 13+, staff, employees, volunteers, members); Portal Users; public respondents (who are always anonymous by design).
Categories of personal dataRoster data: name, email address, role, optional group/segment (such as year group or team), portal access level. Sign-in data: hashed single-use tokens, identity-provider name and email for SSO. Survey responses: answer content plus role and group labels; on identified-mode surveys only, the respondent's name and participant record reference. Completion records (who completed which survey, stored separately from answers). Support correspondence.
Special category dataNot required by the Service, and never linked to an identifiable person on anonymous surveys. Where the Customer chooses to run identified-mode surveys asking about wellbeing, health or similar matters, the responses may include special category data — the Customer is responsible for its Article 9 UK GDPR condition for doing so.
FrequencyContinuous, for the duration of the subscription.

Annex 2 — Technical and organisational security measures

  • Encryption. All data encrypted in transit (TLS 1.2+) and at rest (provider-managed encryption on Google Cloud).
  • Data residency. Customer Personal Data stored in Google Cloud's London (europe-west2) region, with provider-managed redundancy.
  • Anonymity enforcement. Server-side database security rules reject any attempt to store identity (user ID, email, name or roster reference) with a response on an anonymous survey; identified-mode responses may carry only the authenticated respondent's own verified identity — identity can be omitted or truthful, never invented.
  • Separation of concerns. Completion records (who finished) are stored separately from responses (what was said) with no join key between them.
  • Access control. Role-based access within each organisation (viewer/editor/admin/owner) enforced by security rules and server-side checks on every privileged route; organisation owners are protected against lockout and unauthorised demotion.
  • Authentication. Passwordless magic links — single-use, 30-minute expiry, stored only as SHA-256 hashes — or Google/Microsoft single sign-on with provider-asserted identity; roster removal revokes sign-in immediately.
  • Tenant isolation. Each organisation's data lives under its own tenant root, with cross-tenant access impossible under the security rules; privileged operations run only in server-side routes using least-privilege service credentials.
  • Public link protections. Public survey links carry no personal credentials; submissions are validated against the survey's own questions, capped per survey and per month, rate-limited by IP, and optionally gated by bot protection.
  • Small-cohort protection. Configurable minimum group size below which group-filtered results are hidden, preventing small groups being read as individuals.
  • Payment security. Card payments processed by Stripe (PCI DSS Level 1); card numbers never reach Moodly's systems.
  • Software lifecycle. Version-controlled code, review before release, separated test and production environments, and dependency monitoring.
  • Personnel. Access to production data restricted to those who need it to run or support the Service, under confidentiality obligations.
  • Resilience. Provider-managed infrastructure redundancy and backups, with restoration procedures; self-service export so Customers can retain their own copies.

Annex 3 — Authorised sub-processors

Moodly engages the following sub-processors to process Customer Personal Data. This list is kept current on this page; changes follow the notice process in section 6.

Sub-processorProcessingLocationTransfer safeguard
Google Cloud EMEA Ltd / Google LLC (Firebase)Cloud hosting, database, authenticationUK (London, europe-west2) primary; some supporting services EU/USUK adequacy (EEA); UK Extension to the EU–US Data Privacy Framework / SCCs with UK Addendum
Stripe Payments Europe Ltd / Stripe Inc.Subscription billing and payments (billing contact details)EU / USUK adequacy (EEA); UK-approved transfer mechanisms
Resend Inc.Transactional email delivery (sign-in links, service notices — recipient name and email)USSCCs with UK Addendum / IDTA
Anthropic PBCAI survey drafting (editor prompts, survey drafts, organisation name, terminology and group labels — never responses or rosters); API inputs not used for model trainingUSUK Extension to the EU–US Data Privacy Framework / SCCs with UK Addendum
OpenAI / Microsoft Azure OpenAIAlternative AI drafting provider — engaged only where configured for the Customer, same data scope as aboveEU / USUK-approved transfer mechanisms
Cloudflare Inc.Turnstile bot protection on public survey links (IP address and browser signals) — engaged only where the Customer enables itGlobalUK Extension to the EU–US Data Privacy Framework / SCCs with UK Addendum

Google LLC and Microsoft Corporation additionally act as independent identity providers where a Portal User chooses "Sign in with Google/Microsoft"; in that role they are not sub-processors of Moodly.

Mr G Education Ltd (trading as Moodly) · Registered in England and Wales, company number 14557194 · ICO registration ZB526873 · info@moodly.education