Data Processing Addendum

Extra clarity for student data.

This Data Processing Addendum explains how Writopus processes student-related personal data on behalf of teachers, schools and academies using the service.

Last updated: 16 July 2026

Before using Writopus with schools

This DPA is a practical starting point. Schools and academies may need a signed version with the final legal holder details and any institution-specific requirements.

1

Roles

For student-related personal data uploaded to Writopus by a teacher, school or academy, the teacher, school or academy is normally the controller. Writopus acts as a processor and processes the data only to provide the requested writing correction and reporting service.

For Writopus account, billing, security and product operations data, Writopus may act as an independent controller as described in the Privacy Policy.

2

Subject matter and duration

Writopus processes student-related data so teachers can correct writing tasks, generate feedback, store progress and produce reports. Processing continues while the teacher account or relevant workspace data remains active, unless deletion is requested or required earlier.

3

Categories of data

Student-related data may include:

  • Student name, surname, initials or internal class identifiers.
  • Class, group, exam level and writing task metadata.
  • Writing prompts, student answers, uploaded files, selected Google Docs text or writing photos.
  • Corrections, marks, comments, inline edits, mistake patterns and reports.

Writopus should not be used to upload special category data, health data, official identity documents or information unrelated to writing correction.

4

Controller instructions

Writopus will process student-related data only according to the documented instructions provided through the service, these terms, the Terms of Use and any written agreement between the parties.

If Writopus believes an instruction infringes applicable data protection law, it may notify the controller and pause the affected processing where appropriate.

5

Confidentiality and security

Writopus applies reasonable technical and organisational measures designed to protect student-related data, including authenticated access, Row Level Security, HTTPS, restricted production access, protected environment variables and provider-level security controls.

Personnel or contractors with access to personal data must be subject to confidentiality obligations.

6

Sub-processors

Writopus uses service providers to operate the product. Current sub-processors may include:

Supabase

Database storage for teacher profiles, student profiles, submissions and reports.

OpenAI

AI processing for corrections, feedback, inline edits and transcription.

Google

Optional Google Picker and Google Docs import selected by the teacher. The selected document text becomes Customer Content in Writopus; Google access tokens are not stored by Writopus for this import flow.

Clerk

Authentication and user session management.

Vercel

Hosting, serverless execution, logs and platform security.

Resend

Transactional email for account notifications and welcome messages.

Writopus may update sub-processors when needed to operate the service. We will take reasonable steps to ensure sub-processors provide appropriate data protection commitments.

7

International transfers

Some sub-processors may process data outside the European Economic Area. Where this occurs, Writopus relies on appropriate safeguards offered by those providers, such as adequacy decisions, Standard Contractual Clauses or equivalent lawful transfer mechanisms.

8

Assistance to controllers

Taking into account the nature of the processing, Writopus will provide reasonable assistance to help controllers respond to data subject requests, security incidents, deletion requests and data protection compliance obligations.

Requests should be sent to hello@writopus.com.

9

Deletion and return of data

Teachers may delete student profiles or submissions inside the product where the feature is available. On termination or account deletion, Writopus will delete or return personal data according to the service functionality, legal retention requirements and reasonable technical limitations.

Account holders can download a machine-readable export from the account menu. A signed account-deletion event triggers removal of personal-workspace data. Academy workspace records remain under the Academy controller's instructions and are pseudonymised so they are no longer linked to the deleted teacher identity. If the deleted teacher was the Academy owner, the workspace is blocked until responsibility is reassigned.

10

Audits and information

Writopus will make reasonable information available to demonstrate compliance with this DPA. Any audit request must be reasonable, proportionate and subject to confidentiality and security requirements.

Need a signed DPA?

Contact Writopus before rolling the product out across a school or academy.

Contact privacy