Data Processing Agreement
Last updated: 24 July 2026
This Data Processing Agreement (‘DPA’) forms part of the agreement between Stepping Through (‘Processor’) and the organisational client (‘Controller’) whenever we process personal data on your behalf, and sets out the Article 28 UK GDPR terms that apply.
1. Definitions
Terms such as ‘personal data’, ‘processing’, ‘controller’, ‘processor’, ‘data subject’ and ‘personal data breach’ have the meanings given in UK GDPR.
2. Subject matter & duration
The Processor processes personal data solely to deliver the coaching, programme, advisory or platform services described in the underlying agreement, for its duration and any documented wind‑down period.
3. Nature & purpose of processing
Storage, retrieval, analysis, transmission and deletion of personal data to run assessments (including PBP), coaching sessions, learning programmes and communications requested by the Controller.
4. Categories of data subjects & personal data
- Data subjects: the Controller’s employees, learners, coachees and nominated stakeholders.
- Personal data: identifiers (name, email, role), assessment responses, session notes, feedback, and any additional data the Controller instructs us to process.
- No special‑category data is processed unless expressly agreed in writing with appropriate safeguards.
5. Processor obligations
- Process personal data only on documented instructions from the Controller.
- Ensure personnel with access are bound by confidentiality.
- Implement appropriate technical and organisational measures under Article 32 UK GDPR (encryption in transit, role‑based access, least‑privilege, backups, logging, vendor review).
- Assist the Controller with data‑subject requests, DPIAs and prior consultations as required.
- Notify the Controller without undue delay — and in any event within 72 hours — of becoming aware of a personal data breach.
6. Sub‑processors
The Controller provides general authorisation for the Processor to engage sub‑processors, including hosting, database, email, analytics and AI providers used to deliver the service. The Processor imposes equivalent data‑protection obligations on each sub‑processor and remains liable for their performance. A current sub‑processor list is available on request.
7. International transfers
Where personal data is transferred outside the UK/EEA, the Processor relies on adequacy decisions or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
8. Audits
Once per year, and on reasonable notice, the Controller may request information reasonably necessary to demonstrate compliance with this DPA, or commission an independent auditor bound by confidentiality, at the Controller’s cost.
9. Return & deletion
On termination the Processor will, at the Controller’s choice, return or securely delete personal data within 30 days, except where retention is required by law.
10. Liability & conflicts
Liability under this DPA is subject to the limitations in the underlying agreement. In the event of conflict, this DPA prevails on data‑protection matters.
11. Contact
For any request under this DPA, contact customerservices@steppingthrough.org.
