Data Processing Agreement
Between Enrollo (processor) and the customer organisation (controller), for processing governed by UK GDPR Article 28.
Version 1.0 · Effective April 19, 2026
Scope & incorporation
This Data Processing Agreement ("DPA") forms part of the Enrollo Terms of Service and governs Enrollo's processing of Customer Personal Data on behalf of the customer organisation (the "Controller"). By creating an Enrollo account and accepting the Terms of Service, the Controller enters into this DPA without further signature — this aligns with UK GDPR Article 28(9), which permits contracts in electronic form.
If the Controller requires a counter-signed DPA for procurement, email hello@enrollo.io and we will return a signed PDF within one business day.
Definitions
- Customer Personal Data — personal data processed by Enrollo on behalf of the Controller in connection with the Enrollo service. Includes student records, application data, commission records, documents, timeline entries, and team member profiles.
- Sub-processor — any third party engaged by Enrollo to process Customer Personal Data under this DPA.
- Data Subject — a natural person whose personal data is processed, including students, their parents or guardians where recorded, counselors, and org owners.
- Terms not defined here carry the meaning given in UK GDPR.
Processor obligations — UK GDPR Article 28(3)
Enrollo shall process Customer Personal Data only as set out in this DPA and the Terms of Service. The following clauses cover the eight sub-clauses of Article 28(3):
(a) Processing on documented instructions
Enrollo processes Customer Personal Data only on documented instructions from the Controller, including transfers to third countries. The Controller's use of the Enrollo product constitutes ongoing documented instruction. Enrollo will not process data for any other purpose, including our own advertising or model training.
(b) Confidentiality of authorised personnel
All Enrollo personnel authorised to process Customer Personal Data are bound by a written confidentiality obligation, including after termination. Access is granted on a need-to-know basis.
(c) Article 32 security measures
Enrollo implements the technical and organisational measures detailed in the TOMs annex at the end of this document. Encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, and regular restore testing are enforced.
(d) Sub-processor engagement
The Controller provides general authorisation for Enrollo to engage the sub-processors listed at /sub-processors. Enrollo imposes the same data-protection obligations on every sub-processor and remains fully liable for their performance.
Enrollo will give at least 30 days' written notice(via email to the Controller's registered admin) before engaging a new sub-processor or replacing an existing one. The Controller may object on reasonable grounds related to protection of Customer Personal Data; if the objection cannot be resolved within 30 days of the notice, the Controller may terminate the Terms of Service for the affected service with no penalty.
(e) Assisting with data-subject rights
Enrollo provides in-product tools enabling the Controller to meet its Chapter III obligations — in particular, the data export endpoint in Settings → Billing, which produces a full machine-readable export of an agency's records on demand (Article 20 portability). Erasure (Article 17) is available via the account deletion flow.
(f) Assisting with security, breach notification, DPIA
Enrollo assists the Controller in complying with Articles 32 to 36 taking into account the nature of processing and information available to Enrollo. In the event of a personal data breach affecting Customer Personal Data, Enrollo will notify the Controller without undue delay and in any event within 24 hoursof becoming aware — stricter than GDPR Article 33's 72-hour supervisory-authority threshold, so the Controller retains headroom for its own notification. Notification includes the nature of the breach, categories and approximate number of data subjects, likely consequences, and measures taken.
(g) Deletion or return of data
On termination of the Terms of Service, Enrollo retains Customer Personal Data for 90 days in read-only state (to allow re-activation or final export), then deletes all copies within a further 30 days unless retention is required by law. The Controller may request earlier deletion at any time.
(h) Audit and inspection
Enrollo will make available to the Controller, on reasonable written request and no more than once per twelve-month period, information necessary to demonstrate compliance with the obligations in this DPA. This includes the current TOMs, sub-processor list, and recent restore-test results. For enterprise Controllers, on-site audits can be arranged at the requesting party's reasonable cost.
International transfers
Customer Personal Data is stored by default in AWS EU (eu-west-1) via Supabase. Where a sub-processor hosts data outside the UK / EEA (for example, Clerk or Sentry), transfers are made under the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses (SCCs) as applicable, with supplementary measures as recommended by the UK ICO and EDPB.
Term and termination
This DPA takes effect on the Controller's acceptance of the Terms of Service and remains in force for as long as Enrollo processes Customer Personal Data on behalf of the Controller. The deletion provisions in clause (g) survive termination.
Annex 1 — Processing description
- Subject matter — provision of the Enrollo CRM service.
- Duration — for the term of the Terms of Service plus the 120-day retention window.
- Nature and purpose— storage, display, search, aggregation, and export of student records, applications, commissions, documents, communications, and timeline events to support the Controller's agency operations.
- Categories of data subjects — prospective and enrolled students; their parents or guardians where recorded; agency staff members; university contacts where recorded.
- Categories of personal data — contact information, academic history, application status, communication logs, documents (passport, transcripts, test scores, financial sponsor letters), and commission calculations.
- Special categories — none intended, but agencies may upload documents that contain special-category data (e.g. medical certificates for student visa applications). Enrollo treats all uploaded documents at the same elevated access control level.
Annex 2 — Technical & organisational measures (TOMs)
Enrollo maintains the following measures under Article 32. The list is non-exhaustive and may be updated; the current-state version is authoritative.
- Encryption — TLS 1.2+ in transit; AES-256 at rest (platform-provided). Session tokens signed and scoped to the requesting browser.
- Access control — Clerk-managed authentication with 2FA support recommended for owner accounts. Organisation-scoped database queries enforced in the application layer; counselors cannot read rows from another agency.
- Least privilege — Supabase service role key scoped to the Enrollo service account; Clerk session claims restrict per-route access. Sub-processor access limited to what each service requires.
- Audit logging — commission status changes, handovers, document status changes, and permission changes are logged to an immutable timeline entry with actor + timestamp.
- Backups — Supabase Pro point-in-time recovery (7 days) plus daily snapshots retained 30 days. Restore tested quarterly.
- Incident response — severity-classified incident process with 24-hour Controller notification for confirmed breaches. See /security.
- Personnel — all personnel with access to Customer Personal Data are bound by written confidentiality obligations surviving termination.
- Deletion — soft delete with 30-day recovery for applications; 90-day retention + 30-day grace for org-level deletion.
Contact
For DPA queries, sub-processor change objections, or counter-signature requests, email hello@enrollo.io.