Data Processing Agreement
Where we process candidate personal data on your instructions, UK GDPR Article 28 requires a written contract. These are those terms. They apply automatically to every organisation account and form part of the agreement between us.
1.Roles and scope
You are the controller. You decide why candidate data is processed and for how long. We are the processor. We act only on your documented instructions.
Your use of the platform in the ordinary way — enrolling candidates, opening sittings, enabling supervision, issuing certificates — constitutes your documented instructions. Anything beyond that must be in writing.
We remain an independent controller for our own business data: the contact details of your administrators, our billing records, and the security logs we keep to protect the platform. That processing is governed by our Privacy Policy.
2.Subject matter, duration, nature and purpose
- Subject matter
- Provision of an online examination and assessment platform.
- Duration
- For the term of the agreement, plus the retention window that follows termination.
- Nature and purpose
- Hosting, storage, transmission, analysis and deletion of candidate data for the purpose of delivering assessments, grading them, issuing results and certificates, and maintaining an integrity record.
- Categories of data subject
- Candidates enrolled by you, and your own staff who hold accounts — administrators, invigilators and examiners.
3.Categories of personal data
- Identifiers: name, email address, organisation, candidate reference.
- Account data: password hash, sessions, devices, sign-in times and IP addresses.
- Assessment data: enrolments, bookings, attempts, answers, timings, results, certificates.
- Preference data: locale and timezone.
Special category data (UK GDPR Article 9)
- Identity document images captured at check-in.
- Facial images captured at check-in and during a supervised sitting.
- Biometric face templates derived from those images and used to identify the candidate.
Biometric data used for identification is special category data. You must have an Article 9 condition for it before enabling identity check-in or facial supervision — normally explicit consent — and you must inform candidates in advance. We provide the supervision notice and record that it was shown; that supports your accountability but does not discharge it.
Where your candidates include children, or where you process data revealing health (for example a reasonable adjustment), tell us so we can agree any additional measures.
4.Our obligations
We will:
- Process personal data only on your documented instructions, including for transfers, unless we are required to do otherwise by law — in which case we will tell you first, unless the law forbids it.
- Ensure everyone authorised to process the data is under a duty of confidence.
- Take the technical and organisational measures required by Article 32, as described in section 5.
- Respect the conditions in section 6 for engaging a sub-processor.
- Help you respond to data subject requests, taking account of the nature of the processing.
- Help you with your obligations under Articles 32 to 36 — security, breach notification and data protection impact assessments.
- At your choice, delete or return the personal data at the end of the service, and delete existing copies unless the law requires us to keep them.
- Make available the information needed to demonstrate compliance, and allow and contribute to audits under section 8.
We will tell you if, in our opinion, an instruction you give infringes data protection law. We are not obliged to act on it while that is unresolved.
5.Security measures
The measures in place include:
- Encryption in transit (TLS) for all traffic, and encryption at rest for stored data and backups.
- Passwords stored as salted scrypt hashes and never recoverable.
- Session security using rotating refresh-token families with reuse detection, so a stolen token invalidates its family.
- Tenant separation enforced at the database layer: a query without an organisation context is a hard error, not an unfiltered result.
- Role-based access control over 99 discrete permission keys, so access is granted by capability rather than by job title.
- Least-privilege, named administrative access for our staff, with multi-factor authentication required.
- An immutable audit trail behind a transactional outbox, so a recorded event cannot describe a change that was rolled back.
- Backups taken and restore-tested on the schedule in the Service Level Agreement.
- Documented internal information security, access control and incident response policies, reviewed at least annually.
6.Sub-processors
You give general authorisation for us to engage sub-processors. Each is bound by written terms no less protective than these, and we remain fully liable to you for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Infrastructure hosting and storage | Germany / EU |
| Microsoft Ireland Operations Ltd | Outbound email delivery (Microsoft 365 / Graph) | EU, with global support access |
We will give at least 30 days notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period; if we cannot resolve your objection, you may terminate the affected service without penalty and receive a pro-rata refund.
To be notified of changes, subscribe at info@xamina.io.
7.International transfers
Candidate data is hosted in the EU. Where a sub-processor processes personal data outside the UK or EEA, the transfer is made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism, supported by a transfer risk assessment we will share on request.
8.Audit
- We will provide our security documentation, policies and any third-party reports we hold, on request, under NDA.
- Where that is not enough to demonstrate compliance, you may audit us — or appoint an independent auditor who is not our competitor — on 30 days written notice, no more than once a year, during business hours, without unreasonable disruption.
- A regulator may audit at any time, and we will co-operate fully.
- You bear your own audit costs. We bear ours unless the audit finds a material breach by us, in which case we bear both.
9.Personal data breach
We will notify you without undue delay, and in any event within 24 hours of becoming aware of a personal data breach affecting your data.
The notification will include, as far as we know it at the time:
- The nature of the breach, and the categories and approximate number of data subjects and records affected.
- The likely consequences.
- The measures taken or proposed, including any mitigation.
- A contact point for more information.
We will not delay an initial notification in order to complete our investigation. A partial notification within the window beats a complete one after your own 72-hour regulatory deadline has passed.
Reporting to the ICO and to affected candidates is your decision as controller. We will support it and will not make it for you.
10.Return and deletion
On termination, you may export your data through the platform. After 30 days we delete it, including from backups within the backup rotation cycle. Where the law requires us to retain something, we will tell you what and why, and will keep it only for as long as required. We will certify deletion in writing on request.
Questions about this document go to info@xamina.io. If anything here conflicts with a signed agreement between us, the signed agreement wins.