Data Processing Agreement
Introduction
This is Qlix's standard public Data Processing Agreement. It forms part of the Qlix Terms and Conditions and applies automatically whenever you use the Services to record or process information about students. It is accepted on signup or by continued use after the effective date - you do not need to sign it. If your organisation's procurement process requires a countersigned copy, see Annex A.
Status: Public standard terms. Not legal advice.
Version 1.0 · Effective 23 July 2026
Qlix Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Qlix Terms and Conditions between Qlix Limited and you. It applies automatically whenever you use the Services to record or process information about students, and takes effect when you create an account or continue using the Services after the effective date above.
You do not need to sign it. If your organisation's procurement process requires a countersigned copy, see Annex A.
Background
(A) The Customer and Qlix have entered into the Principal Agreement for the provision of the Services.
(B) In providing the Services, Qlix may process Customer Data on behalf of the Customer. The parties intend this DPA to set out their respective rights and obligations in respect of that processing under Applicable Data Protection Law.
(C) If there is a conflict between this DPA and the Principal Agreement on a matter of data protection, this DPA prevails.
In plain terms
This summary is not part of the agreement, but nothing in the agreement contradicts it.
- You own your data. You decide what to record and why. We only do what you tell us to do with it.
- We never use your data to train AI models. Not lesson content, not student work, not marks. That commitment survives the end of your subscription.
- Everything stays in the UK. Storage, backups, and AI processing all happen in London.
- Student names never reach an AI model. They are swapped for anonymous tokens first.
- No analytics or tracking on students. QlixGo, where students submit work, carries none.
- If something goes wrong we tell you within 24 hours, so you have time to meet your own obligations.
- You can export or delete everything, at any time, without asking us.
1. Definitions
"Applicable Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025, the Privacy and Electronic Communications Regulations 2003, and any successor legislation.
"Customer", "you" means the organisation or individual who has entered into the Principal Agreement with Qlix. Where Qlix is engaged by a school, academy trust or other institution, the Customer is that institution. Where Qlix is used by an independent private tutor, the Customer is the tutor.
"Customer Data" means Personal Data processed by Qlix on the Customer's behalf in connection with the Services, as described in Schedule 1.
"Personal Data", "Special Category Data", "Processing", "Data Subject", "Controller", "Processor", "Personal Data Breach" and "Supervisory Authority" have the meanings given in Applicable Data Protection Law. The Supervisory Authority is the Information Commissioner's Office ("ICO").
"Principal Agreement" means the Qlix Terms and Conditions and any order form or subscription between the parties.
"Qlix", "we" means Qlix Limited, a company incorporated in Hong Kong SAR with company number 74458271, registered office Rooms 1703-1704, 17/F Tung Chiu Commercial Centre, 193 Lockhart Road, Wan Chai, Hong Kong SAR.
"Services" means the Qlix teaching workspace and its modules, including QlixDiary, QlixDocs, QlixDrive, QlixInsights, QlixAI, QlixSocial and QlixGo.
"Sub-processor" means any Processor engaged by Qlix to process Customer Data.
2. Roles of the parties
2.1 Dual roles. Qlix acts in two distinct capacities.
(a) As Processor. In respect of Customer Data - including student personal data, staff data you provide, timetable and class structures, teaching content created in the course of your educational activities, and AI prompts and outputs containing any of the foregoing - you are the Controller and Qlix is the Processor. This DPA governs that processing.
(b) As Controller. In respect of account authentication data, billing and subscription records, product telemetry and error logs, support correspondence, and any QlixSocial profile or publicly shared content an individual user chooses to create, Qlix acts as an independent Controller. That processing is governed by the Qlix Privacy Policy and falls outside this DPA. Qlix will not use data processed in that capacity to circumvent its obligations as Processor.
(c) Default. Where the role in respect of a category of data is unclear, the parties will treat Qlix as Processor and this DPA will apply, pending written agreement otherwise.
2.2 Allocation by data category.
Data Qlix's role Your role Account credentials, authentication logs Controller - Billing and subscription Controller - Product telemetry and error logs Controller - Marketing email to account holders Controller - QlixSocial profile and public content Controller - Staff name and work email you provision Processor Controller Timetable, class and group structure Processor Controller Student name or identifier Processor Controller Student submissions via QlixGo Processor Controller Marks, scores, attainment records Processor Controller Teacher notes on students, including SEN Processor Controller Teaching resources created in the course of your work Processor Controller AI prompts and outputs containing Customer Data Processor Controller 2.3 Independent tutors. If you use Qlix as an independent private tutor, you are the Controller for information about the students you teach, and Qlix is your Processor. You may not have thought of yourself as a data controller - most tutors have not. In practice it means you are responsible for telling students, and where they are under 18 their parents or guardians, what information you keep and why, for keeping it accurate, and for not keeping it longer than you need. The ICO publishes free guidance for sole traders.
2.4 Your warranties. You warrant that you have a lawful basis under Article 6, and where required a condition under Article 9, for all Personal Data you instruct Qlix to process, and that you have provided the necessary privacy information to Data Subjects.
2.5 Ownership. Nothing in this DPA transfers ownership of Customer Data to Qlix.
3. Instructions
3.1 Qlix will process Customer Data only on your documented instructions - including as set out in the Principal Agreement, this DPA, and your configuration and use of the Services - unless required to do otherwise by law, in which case Qlix will inform you before processing unless legally prohibited.
3.2 Qlix will tell you if, in its opinion, an instruction infringes Applicable Data Protection Law.
3.3 Aggregated data. Qlix may generate and process aggregated statistical data derived from use of the Services, such as feature usage counts and performance metrics, for security monitoring, capacity planning and product development - provided it is irreversibly anonymised, cannot be attributed to you, to any Data Subject, or to any identifiable class or cohort, and is not re-identifiable.
3.4 AI and machine learning. Qlix will not use Customer Data - including student submissions, assessment outcomes, teacher notes, teaching content, or AI prompts and outputs - to train, fine-tune, evaluate or otherwise develop any artificial intelligence or machine learning model, whether Qlix's own or a third party's. Qlix contractually prohibits its AI Sub-processors from doing the same. This clause survives termination.
4. Qlix's obligations
4.1 Confidentiality. All persons authorised to process Customer Data are bound by written confidentiality obligations that survive the end of their engagement.
4.2 Security. Qlix implements the technical and organisational measures published at /legal/toms and incorporated into this DPA as Schedule 2. Qlix may update those measures, but will not reduce the overall level of security during the term.
4.3 Data Subject rights. Taking into account the nature of the processing, Qlix will assist you in responding to requests from Data Subjects. The Services provide self-service export and deletion covering most access, rectification, erasure and portability requests. Where Qlix receives a request directly from a Data Subject, it will not respond substantively but will forward it to you within 3 working days.
4.4 Impact assessments. Qlix will provide reasonable assistance with data protection impact assessments and consultations with the ICO, including by maintaining a current DPIA Support Pack.
4.5 Personal Data Breach. Qlix will notify you without undue delay and in any event within 24 hours of becoming aware of a Personal Data Breach affecting Customer Data. An initial notification will be sent within that period even if the investigation is incomplete, with updates as more is known. Notification will be by email to your nominated contact and, where the breach is assessed as high risk, by telephone. Qlix will not notify the ICO or Data Subjects of a breach affecting your data without your prior consent, unless legally required.
4.6 Deletion and return. On termination, or on your earlier written request, Qlix will at your election delete or return Customer Data and delete existing copies:
- you may export Customer Data in-product at any time during the term and for 30 days after termination;
- live Customer Data will be deleted within 30 days of termination or of your written deletion instruction, whichever is earlier;
- backup copies will be deleted in the ordinary backup rotation and in any event within 90 days;
- written confirmation of deletion is available on request;
- these periods do not apply where Qlix is required by law to retain data, in which case Qlix will tell you the legal basis and the retention period.
4.7 AI processing. Where you enable AI features:
- inference is performed via Amazon Bedrock in London, United Kingdom;
- student names and direct identifiers are replaced with pseudonymous tokens before any content is transmitted for inference, and the token mapping is held separately within UK infrastructure and never transmitted;
- you control, at organisation and individual user level, which categories of Customer Data may be included in AI context;
- prompts and outputs are not retained by the AI Sub-processor for training or model improvement;
- AI output is a draft requiring review by a member of your teaching staff. The Services do not make significant decisions based solely on automated processing within the meaning of Articles 22A to 22D UK GDPR.
4.8 Data segregation. Student personal data is held in assessment and markbook records, structurally separate from teaching resources. Sharing and publishing functions operate only on teaching resources. No student record, submission, mark or teacher note can be attached to a shared or published item under any configuration.
4.9 No tracking of students. No analytics, advertising or behavioural tracking technologies operate on QlixGo, the student-facing surface.
5. Sub-processors
5.1 You give general written authorisation for Qlix to engage the Sub-processors listed in Schedule 3 and published on our trust and security page.
5.2 Qlix imposes on each Sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to you for their performance.
5.3 Qlix will give at least 30 days' notice, by email to your registered address or by in-product notice, before adding or replacing a Sub-processor that processes Customer Data - except for emergency security replacements, where notice will be given as soon as practicable. You may object on reasonable data protection grounds within 14 days. If we cannot resolve your objection, you may terminate the affected Services without penalty, and that is your sole remedy for the objection.
6. International transfers
6.1 Qlix stores and processes Customer Data on Amazon Web Services in London, United Kingdom. AI inference is also performed in London, United Kingdom. Customer Data is not stored outside the United Kingdom.
6.2 Qlix Limited is incorporated in Hong Kong SAR. That is the place of incorporation only: no personnel are located there and no access to Customer Data takes place from Hong Kong SAR.
6.3 Qlix personnel are located in the United Kingdom and Thailand. Where personnel in Thailand access Customer Data to investigate a reported fault, that access is a restricted transfer. Thailand is not the subject of a UK adequacy decision; it has a GDPR-modelled statute, the Personal Data Protection Act B.E. 2562 (2019), and a supervisory authority.
6.4 Restricted transfers are made under the UK International Data Transfer Agreement (download the IDTA from the ICO), incorporated on acceptance of this DPA, supported by the Transfer Risk Assessment.
6.5 Qlix applies the following safeguards to access from outside the United Kingdom:
- access restricted to a named list of personnel, available on request;
- least-privilege, need-to-know basis, with multi-factor authentication;
- all production access logged, logs retained 90 days;
- access time-limited and revoked on role change or departure;
- support personnel do not access student personal data other than where necessary to investigate a specific reported issue;
- onward transfer to any third party is prohibited;
- Qlix will notify you of any government or law enforcement request for Customer Data, to the extent legally permitted, and will challenge requests that appear unlawful or overbroad.
7. Your obligations
You will:
7.1 ensure your instructions to Qlix are lawful;
7.2 not use the Services to process Personal Data beyond what they are designed to support;
7.3 manage user access, sharing settings and configuration in line with your own policies;
7.4 provide privacy information to, and handle the rights of, the Data Subjects whose data you enter - including students and, where applicable, their parents or guardians;
7.5 not enter Special Category Data unless you have a lawful basis and an Article 9 condition, and the processing is necessary for your educational purposes;
7.6 instruct your staff that student personal data must not be entered into teaching resources. Student data belongs in assessment and markbook records, which cannot be shared or published. Qlix cannot prevent a user typing text into a resource and is not responsible for student personal data entered contrary to this clause;
7.7 keep a current data protection contact on your account to receive breach notifications and Sub-processor notices.
8. Audit and information
8.1 Qlix maintains and makes available a technical and organisational measures summary, a sub-processor register, a DPIA support pack and a completed security questionnaire. Providing these satisfies Qlix's obligation to make available the information necessary to demonstrate compliance with Article 28.
8.2 Where those documents are genuinely insufficient to address a specific concern, you may request an audit. Audits are limited to once in any 12-month period - unless required following a Personal Data Breach or at the direction of the ICO - require 30 days' notice, must be conducted during business hours under a confidentiality agreement, and are at your cost, save where the audit reveals a material breach of this DPA by Qlix.
8.3 Qlix may satisfy an audit request by providing current certifications and third-party security reports where available.
9. Liability
9.1 Liability under this DPA is subject to the limitations in the Principal Agreement, except that nothing limits liability which cannot be limited under Applicable Data Protection Law.
9.2 Each party remains responsible for its own compliance as Controller or Processor respectively.
10. Changes to this DPA
10.1 Qlix may update this DPA to reflect changes to the Services, to Sub-processors, or to legal requirements.
10.2 Where an update materially reduces the protections available to you or to Data Subjects, Qlix will give at least 30 days' notice by email and in-product before it takes effect. You may terminate the affected Services without penalty during that period.
10.3 Updates required by law or by a Supervisory Authority take effect on the date required, with notice as soon as practicable.
10.4 Every published version of this DPA includes its version number and effective date at the top of this document. Previous versions are available on request from privacy@qlixapp.com.
11. Term
This DPA takes effect when you accept the Principal Agreement or continue using the Services after its effective date, and continues while Qlix processes Customer Data. Clauses which by nature should survive - confidentiality, the AI restriction at 3.4, deletion, liability and audit of residual obligations - survive termination.
12. Governing law
12.1 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over disputes arising from it, without prejudice to the ICO's powers or Data Subjects' rights.
12.2 This applies notwithstanding any different governing law in the Principal Agreement.
13. Contact
Data protection enquiries, rights requests and complaints: privacy@qlixapp.com
Qlix Limited has an establishment in the United Kingdom and is subject to the direct supervision of the Information Commissioner's Office.
SCHEDULE 1 - Details of processing
Subject matter. Provision of the Qlix teaching workspace to your staff and students.
Duration. The term of the Principal Agreement, plus the retention periods at clause 4.6.
Nature. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, display, transmission, alignment, combination, backup, restriction, erasure and destruction.
Purposes. Lesson planning and scheduling; recording and retrieving teaching materials; setting, collecting and marking student work; recording assessment outcomes and learning objective attainment; analysing attainment over time to produce progress and class insight views; recording teacher observations on student progress and support needs; generating draft teaching content using AI on a member of staff's instruction; sharing resources between staff; providing technical support.
Categories of Data Subject. Teaching and support staff; students; administrative staff. Volumes are determined by your use of the Services.
Personal Data - staff. Name; work email; job title and role; department; timetable and teaching allocation; duties and meetings; resources authored; account credentials and authentication metadata; usage logs; support correspondence; QlixSocial profile content where voluntarily created.
Personal Data - students. Name or teacher-assigned identifier; year group; class and group membership; work, answers and files submitted via QlixGo; marks, scores and grades; learning objective attainment; submission timestamps and status; free-text notes recorded by staff.
Special Category Data. SEN information, learning support requirements and health-related notes, where you choose to record them. This is data concerning health under Article 9(1). The Services do not require it; you are responsible for the Article 9 condition.
Evaluation and profiling. The Services evaluate and score students on academic attainment and generate attainment, progress and class insight views automatically from stored evidence. This constitutes profiling under Article 4(4) UK GDPR. No significant decision is made solely by automated means - all outputs are decision support for a member of staff, who reviews and may override them. The Services do not profile students for commercial purposes, use advertising or cross-site tracking identifiers, or predict behaviour, attendance or any characteristic beyond performance on submitted work.
Criminal offence data. None. The Services must not be used to record it.
Not processed. Student contact details; home addresses; telephone numbers; dates of birth; biometric data; precise or real-time device location; student or parent payment data; advertising identifiers.
SCHEDULE 2 - Technical and organisational measures
Incorporated by reference from the Technical and Organisational Measures Summary, as updated from time to time, subject to clause 4.2.
SCHEDULE 3 - Sub-processors
Current register published on our trust and security page. As at the effective date:
Processing Customer Data
Sub-processor Purpose Location Amazon Web Services Hosting, database, storage, backup London, United Kingdom Amazon Bedrock AI inference (pseudonymised content) London, United Kingdom Sentry Application error monitoring EU Featurebase In-app support and help centre EEA (Germany) Mailgun Transactional and service email EU OneSignal Push notification delivery Stored EU, accessed from US Not processing Customer Data
Provider Purpose Location Stripe Payment and subscription processing EU / US Mixpanel Product analytics - staff account identifiers only EU Google Analytics Marketing site and staff application analytics US No Sub-processor receives student personal data other than Amazon Web Services and Amazon Bedrock. No analytics provider operates on QlixGo.
SCHEDULE 4 - International transfers
Data at rest. United Kingdom (Amazon Web Services, London). None outside the UK.
AI inference. United Kingdom (Amazon Bedrock, London), on pseudonymised content.
Personnel access.
Location Purpose Access to student data United Kingdom Engineering, support Where required for support Thailand Technical support Only when investigating a reported issue Hong Kong SAR Place of incorporation only None Transfer mechanism. UK IDTA (download from the ICO), supported by the Transfer Risk Assessment.
ANNEX A - Countersigned copies
Most customers do not need one. Where your procurement process requires a countersigned agreement, email privacy@qlixapp.com with your organisation's legal name and address and we will return a signed copy of this DPA within 5 working days at no charge.
If your organisation requires its own template rather than ours, send it over. We will review it and, where it is a standard education-sector agreement, we will generally sign it.
Qlix Limited · Company number 74458271 · Rooms 1703-1704, 17/F Tung Chiu Commercial Centre, 193 Lockhart Road, Wan Chai, Hong Kong SAR · privacy@qlixapp.com