This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Customer” / “Controller”) and Edunexis Technologies Ltd (“Processor”, “we”) for Switch Manager Pro (the “Services”). It governs our processing of personal data on the Customer’s behalf and is designed to meet Article 28 of the UK GDPR. Where it conflicts with the Terms of Service, this DPA prevails for personal data. A counter-signed copy is available on request.
Contents
- Definitions
- Roles & scope
- Processing on instructions
- Confidentiality
- Security
- Sub-processors
- Data subject rights
- DPIAs & assistance
- Personal data breaches
- Return & deletion
- Audits & information
- International transfers
- Customer obligations
- Liability & term
- Annex 1 — Details of processing
- Annex 2 — Security measures
- Annex 3 — Sub-processors
1. Definitions
Terms such as controller, processor, personal data, processing, personal data breach, data subject and supervisory authority have the meanings given in the UK GDPR and the Data Protection Act 2018 (together, “Data Protection Law”). “Sub-processor” means any third party we engage to process personal data under this DPA.
2. Roles & scope
For personal data processed through the Services, the Customer is the controller and Edunexis Technologies Ltd is the processor. Where the Customer is a multi-academy trust acting for its schools, it does so on their behalf.
Where the Customer is itself a processor — for example an IT partner managing a school’s network — the Customer warrants that it is authorised by the relevant controller to engage us, this DPA applies between the Customer and us as a processor-to-sub-processor agreement, and the Customer passes on to us only instructions that controller has given. The details of the processing are in Annex 1.
3. Processing on documented instructions
We process personal data only on the Customer’s documented instructions (including those in the Terms, this DPA and the Customer’s use and configuration of the Services), unless the law requires otherwise — in which case we will tell the Customer first, unless the law prohibits it. We will promptly tell the Customer if we believe an instruction infringes Data Protection Law.
4. Confidentiality
Everyone we authorise to process the personal data is bound by an appropriate duty of confidentiality and has access only on a need-to-know basis.
5. Security
Taking into account the state of the art, costs, and the nature, scope, context and purposes of processing, and the risks to data subjects, we implement appropriate technical and organisational measures, described in Annex 2.
6. Sub-processors
The Customer gives general authorisation for us to engage the sub-processors in Annex 3. We will:
- impose on each sub-processor, by contract, data protection obligations equivalent to those in this DPA;
- remain fully liable to the Customer for each sub-processor’s performance;
- give the Customer at least 30 days’ notice of any intended addition or replacement, during which the Customer may object on reasonable data-protection grounds; if an objection cannot be resolved, the Customer may terminate the affected Services.
7. Assisting with data subject rights
Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability and objection). If a request is made to us directly, we will forward it to the Customer promptly and will not respond except on the Customer’s instructions.
8. Security, DPIAs & prior consultation
Taking into account the nature of processing and the information available to us, we will assist the Customer with its obligations on security of processing, notification of personal data breaches, data protection impact assessments and prior consultation with the supervisory authority.
9. Personal data breaches
We will notify the Customer without undue delay, and in any event within 24 hours, of becoming aware of a personal data breach affecting the Customer’s personal data. The notification will include, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. We will cooperate with the Customer and take reasonable steps to mitigate it. The Customer, as controller, is responsible for any notification to the ICO and to affected individuals.
10. Return & deletion of data
On termination or expiry of the Services, and at the Customer’s choice, we will return or delete all personal data and delete existing copies, unless the law requires us to keep it. If the Customer wants its configuration backups returned, it should ask us before deletion. Deletion is normally completed within 30 days of termination through our offboarding process, and confirmed in writing. Copies in our database provider’s rolling backups expire on that provider’s backup schedule.
11. Audits & information
We will make available all information necessary to demonstrate compliance with Article 28 of the UK GDPR, and will allow for and contribute to audits, including inspections, by the Customer or an auditor it mandates — on reasonable notice, no more than once a year (unless required by a supervisory authority or following a breach), during business hours, and so as to minimise disruption. We may satisfy audit requests with relevant security documentation and responses to reasonable questionnaires.
12. International transfers
We store and process personal data in the United Kingdom and the EEA. We will not transfer it to a country outside the UK/EEA without a valid transfer mechanism under Data Protection Law (such as UK adequacy regulations, the IDTA or the UK Addendum to the EU SCCs) and the Customer’s instruction. Transfers between the UK and the EEA are covered by adequacy.
13. Customer obligations
The Customer warrants that it has a lawful basis for the processing, has given any required privacy information to data subjects, and that its instructions comply with Data Protection Law. Switch configurations can contain personal data (for example a port description naming a person), so the Customer is responsible for what it and its switches put in them, and for deciding which people and devices to search for.
14. Liability & term
This DPA takes effect when the Customer starts using the Services (or on signature) and continues for as long as we process personal data on the Customer’s behalf. Liability under this DPA is subject to the limitations in the Terms of Service, except where Data Protection Law provides otherwise.
Annex 1 — Details of the processing
| Controller | The Customer (a school, multi-academy trust or other organisation), or — where the Customer is an IT partner — the organisation whose network it manages |
| Processor | Edunexis Technologies Ltd |
| Subject-matter | Provision of Switch Manager Pro, a platform for managing network switches through an agent on the Customer’s own network |
| Duration | For the term of the Services and until data is deleted or returned |
| Nature & purpose | Backing up, comparing and searching switch configurations; planning, approving, scheduling and applying configuration changes; identifying switches and reporting their ports, power (PoE) and neighbours; alerting on changes made outside the Services; finding a device by MAC address when the Customer asks; activating the offline installer |
| Types of personal data | Accounts of the Customer’s users (name, work email address, role) and records of what they requested, approved and changed; the name and a one-way identifier of each computer the offline installer is activated on, and who activated it; the name, address, version and diagnostic logs of the computer running the agent; the content of switch configurations and switch outputs, which can include personal data such as local account usernames, port descriptions naming a person or room, and the MAC or IP addresses of connected devices; a MAC address the Customer searches for, and where it was found. Switch passwords and other secrets are held encrypted. No network traffic content, browsing data or special category data. |
| Categories of data subjects | The Customer’s staff and contractors who use the Services; people whose names or devices appear in the Customer’s switch configurations or in searches the Customer runs (for example staff, pupils or guests) |
| Frequency | Continuous, for the duration of the Services |
Annex 2 — Technical & organisational security measures
- No inbound access: the agent on the Customer’s network connects out over HTTPS; nothing on the internet connects in, and no firewall rule is opened.
- Encryption: TLS in transit; configuration backups, switch logins and other secrets encrypted at rest. A switch login is never placed in the command queue: the agent fetches it for one command and it is deleted as it is served.
- Switch identity: the agent records each switch’s SSH host key on first contact and refuses to log in if a different key answers; clearing that is a deliberate, recorded action.
- Change control: every change is shown as the exact commands before it runs and runs only after a person approves it; what is approved is what runs. The Customer can require a second person to approve. Requests, approvals and results are recorded.
- Data minimisation: MAC address tables are searched on the Customer’s network and only matching lines are returned; the table itself is not collected, and a searched address is masked in the audit record.
- Tenant isolation: every organisation’s data is kept separate by row-level security and organisation-scoped access checks.
- Access control: role-based access; sign-in through the Customer’s Google or Microsoft account, so its own multi-factor policy applies; passwords, where used, are held only as hashes by our authentication provider, with lockout after repeated failures.
- Offline installer: each activation is approved by a signed-in person, bound to one computer and Windows account, and can be revoked; passwords set on site stay on that computer.
- Operations: UK/EEA hosting; secrets held in environment configuration, not in code; input validation; rate limiting; database backups; availability monitoring and alerting.
- Personnel: confidentiality obligations and need-to-know access.
Annex 3 — Authorised sub-processors
The following sub-processors are authorised under this DPA. We will notify Customers of any additions or replacements as set out in section 6, with at least 30 days’ notice and a right to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Fly.io | Application hosting (portal and API) | United Kingdom (London) |
| Supabase | Database (PostgreSQL), including encrypted configuration backups | United Kingdom (London, eu-west-2) |
| Upstash | Rate limiting, short-lived caches and one-time session tickets — no personal data stored | European Economic Area |
| Resend | Transactional and alert email (invitations, password resets, change and backup alerts) | European Economic Area |
| Cloudflare | CDN, web application firewall and DNS; object storage for agent and installer downloads | UK/EEA edge |
| IONOS | Business email (the support mailbox) and the scheduled-task server that starts nightly backups — the latter holds no customer data | United Kingdom / European Economic Area |
| Sentry | Error monitoring — operational error data only | European Economic Area |
| Better Uptime | Availability monitoring of service endpoints — no personal data | European Economic Area |
Acceptance. By entering into the Terms of Service and using Switch Manager Pro, the Customer accepts this DPA. A counter-signed version naming the organisation and signatories is available on request from [email protected].
© 2026 Edunexis Technologies Ltd. Switch Manager Pro is a product of Edunexis Technologies Ltd.