IlmFlow

Data Processing Agreement

Last updated: 9 August 2026 · See also our Terms of Service and Privacy Policy

This is IlmFlow’s standard Data Processing Agreement (DPA) under UK GDPR Article 28(3), setting out how we process personal data on a madrasah’s behalf as its data processor. It applies automatically to every madrasah using the Services, alongside our Terms of Service, no request or separate signature needed, though we’re happy to provide a countersigned copy on request (see Section 15). IlmFlow is a trading name of ILMFLOW LTD, a company registered in England and Wales (company number 17434787).

1. Parties & Definitions

This Data Processing Agreement ("DPA") is between the madrasah or other organisation using IlmFlow ("Controller", "you") and IlmFlow ("Processor", "we", "us"). It applies wherever we process Personal Data on your behalf in connection with the Services described in our Terms of Service.

  • "UK GDPR" means the UK General Data Protection Regulation as it forms part of UK law, together with the Data Protection Act 2018.
  • "Personal Data", "Processing", "Controller", "Processor", "Data Subject" and "Personal Data Breach" have the meanings given in the UK GDPR.
  • "Sub-processor" means any third party a Processor engages to process Personal Data in providing the Services.
  • Capitalised terms not defined here have the meaning given in our Terms of Service or Privacy Policy.

2. Subject Matter, Duration, Nature & Purpose of Processing

We process Personal Data on your behalf for the duration of your subscription to the Services, for the purpose of providing the IlmFlow platform: running your attendance register, Qur’an/Hifz and dua tracking, exams and report cards, fee records, staff records and, where you enable it, UK payroll, and the admin, teacher and parent portals that support those functions.

The nature of the processing is electronic storage, retrieval, organisation, and display of the records you and your Authorized Users enter, plus the specific operations needed to run each feature (for example, calculating a payslip, generating a report card, or sending an absence notification). We do not process this data for our own purposes, and we do not sell it or use it for advertising.

3. Categories of Data Subjects & Types of Personal Data

The categories of Data Subjects and Personal Data are set out in full in Section 3 of our Privacy Policy, and in summary are:

  • Administrators & head teachers: name, email, phone, role, login details.
  • Teachers & other staff: name, contact details, role, classes taught, timesheet data, and, where UK payroll is enabled, tax code, National Insurance number, salary/pay rate, bank details, pension scheme, student/postgraduate loan status, and HMRC Starter Checklist declarations.
  • Students/pupils: name, date of birth, gender, class, address, attendance records, Qur’an/Hifz/dua progress, exam results and report cards, fee records, and a per-madrasah student reference ID.
  • Parents/guardians: name, email, phone, the link to their children’s records, and anything they submit through the parent portal (for example, a chat message or an absence report).

Some madrasahs also record, at their own discretion as Controller, a staff member’s DBS (criminal record check) reference and expiry date and right-to-work/visa status. These are criminal offence data and, in the case of visa/immigration status, may reveal other protected characteristics; we only process them on your documented instructions, for the safeguarding and right-to-work purposes you set. Separately, because IlmFlow is used by Islamic supplementary schools, attendance and progress data recorded against Qur’an or Hifz classes can, by its nature, reveal or suggest a Data Subject’s religious belief, a special category of data under Article 9 UK GDPR. You are responsible, as Controller, for having an appropriate condition under Article 9 or Article 10 UK GDPR (as applicable) for holding this data; we process it only as your instructions direct.

4. Processing Only on Your Instructions

We will only process Personal Data on your documented instructions, including regarding transfers to a country outside the UK, unless we are required to do otherwise by UK or EU law, in which case we will tell you before processing (unless the law prohibits this for important reasons of public interest). Your use of the Services’ ordinary functionality, and any written communication from an Authorized User with account permissions to give it, counts as a documented instruction. If we believe an instruction breaches UK GDPR or other data protection law, we will tell you immediately.

5. Confidentiality

We ensure that anyone we authorise to process Personal Data (including any employee, contractor, or Sub-processor) is subject to a binding duty of confidentiality, whether contractual or statutory, and only processes that data as needed to provide the Services.

6. Security Measures

We take technical and organisational measures appropriate to the risk, as required by Article 32 UK GDPR, including:

  • passwords stored hashed (never as plain text), and account access secured with per-user login credentials;
  • role-based access control within the application, and tenant-scoped data access so one madrasah cannot see another’s records;
  • encryption in transit (HTTPS/TLS) between your browser or device and our servers;
  • particularly sensitive credentials, such as HMRC Gateway passwords used for payroll filing, encrypted at rest;
  • production system and database access restricted to the person operating IlmFlow, used only to build, run, and support the Services;
  • regular software updates to address known security vulnerabilities.

No method of transmission or storage is completely secure, and we do not represent that these measures make a breach impossible. We keep our security measures under review as the Services and known risks develop.

7. Sub-processors

You give us general written authorisation to engage the Sub-processors listed below, each of which processes Personal Data only for the specific purpose stated, and, other than our hosting and email providers, only where the madrasah has enabled the relevant feature:

  • Hosting (all Controller data): our own server infrastructure, physically located in the European Union (currently France).
  • Email delivery (contact details needed to send a message): our email service provider, for transactional and notification email such as absence alerts, invites, and password resets.
  • Stripe (payment and contact details, only where a madrasah connects Stripe): online fee payment processing. Payments go directly to the madrasah’s own connected Stripe account; we do not hold card numbers.
  • HM Revenue & Customs (staff payroll data, only where UK payroll is used): statutory payroll reporting, as legally required of an employer.
  • Anthropic (limited, non-pupil content, only when a teacher uses the AI exam-paper generator or the AI assistant): processes the textbook excerpt/page range chosen, or the assistant conversation, to generate exam questions or an answer.
  • Google (Firebase) (device push tokens, only where push notifications are enabled): delivering push notifications to a madrasah’s or parent’s device.
  • Meta (WhatsApp Cloud API) (phone number and message content, only where a madrasah or visitor uses WhatsApp messaging features): sending and receiving WhatsApp messages.
  • Google (Analytics, Maps) (website visitor and address data, only on public marketing pages, and for Analytics only after cookie consent): website analytics and address autocomplete on enrolment forms.

If we add a new Sub-processor or replace an existing one in a way that materially changes how your Personal Data is processed, we will update this page and give existing customers reasonable notice, in line with Section 16 of our Terms of Service, so you can raise any objection before the change takes effect. We remain responsible to you for each Sub-processor’s performance of its data protection obligations under a written contract that imposes terms no less protective than this DPA.

8. Assisting With Data Subject Rights

Taking into account the nature of the processing, we will provide appropriate technical and organisational measures to help you respond to requests from Data Subjects exercising their rights under UK GDPR Chapter III (for example, access, rectification, erasure, or portability requests), including through the Services’ own export and edit functionality. Where we receive a Data Subject request directly relating to your madrasah’s data, we will pass it to you promptly and will not respond to it ourselves, since you are the Controller.

9. Assisting With Security, Breach Notification & Impact Assessments

Taking into account the nature of the processing and the information available to us, we will help you comply with your own obligations under Articles 32 to 36 UK GDPR, including security of processing, notifying Personal Data Breaches, and, where you ask, providing information reasonably needed for a Data Protection Impact Assessment or prior consultation with the Information Commissioner’s Office.

10. Personal Data Breaches

If we become aware of a Personal Data Breach affecting your Personal Data, we will notify you without undue delay and, where reasonably practicable, within 72 hours of becoming aware of it, and provide the information you reasonably need to meet your own notification duties to the Information Commissioner’s Office and affected individuals. This is in addition to, and does not replace, the breach response commitments in Section 9 of our Privacy Policy.

11. International Transfers

Our own hosting is within the European Union, which UK data protection law treats as offering an adequate level of protection. Where a Sub-processor listed in Section 7 is based, or processes data, outside the UK and EU (for example, in the United States), we rely on the safeguards recognised under UK data protection law for international transfers, such as the UK’s International Data Transfer Addendum, standard contractual clauses, or the provider’s own equivalent commitments, before any Personal Data is transferred there.

12. Audit & Compliance

We will make available to you the information reasonably necessary to demonstrate compliance with this DPA, and allow for, and contribute to, audits or inspections conducted by you or an auditor you mandate, on reasonable prior written notice, no more than once in any 12-month period (except where a regulator or a suspected Personal Data Breach requires otherwise), during business hours, and subject to reasonable confidentiality safeguards for our systems and other customers’ data.

13. Return or Deletion of Data

At your choice, at the end of the provision of the Services relating to processing, we will make your Personal Data available for you to export, and will then delete it, except to the extent UK or EU law requires us to keep it (for example, HMRC’s requirement to retain payroll records for at least three years). This reflects the process already set out in Section 5 of our Terms of Service.

14. Liability

Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in Section 13 of our Terms of Service, which this DPA does not expand.

15. Term & How This DPA Takes Effect

This DPA takes effect automatically, and is incorporated into and forms part of, our Terms of Service, from the point a madrasah begins using the Services, for as long as that agreement continues. No separate signature is required for this DPA to apply. If a madrasah’s own compliance records need a countersigned copy, contact us at hello@ilmflow.co.uk and we will provide one on the same terms set out here. If anything in this DPA conflicts with the Terms of Service on a matter this DPA specifically covers, this DPA takes precedence for that matter; otherwise the Terms of Service apply.

16. Contact

Questions about this DPA, or requests for a countersigned copy? Email hello@ilmflow.co.uk.

This document is a general template and has not yet been reviewed by a solicitor. Because IlmFlow processes children’s and staff data, it should not be relied on as final legal advice until that review is complete.