For schools & trusts
Data protection & DPA
Schools and trusts need to know exactly where pupil data sits before they commission support. This is our position, and we will sign your DPA or provide ours.
Last updated: August 2026
Controller and processor roles
For enquiries made through this website, Neu Road Ltd is the controller. For pupil data shared once support is commissioned, the school or trust is the controller and Neu Road Ltd is the processor, acting only on documented instructions under a written agreement (UK GDPR Article 28).
What we process for schools
Pupil first name and year group, SEND needs and relevant provision detail, session notes and progress records, and named staff contact details. We ask schools not to share more than the support requires.
Sub-processors
- Cloud hosting and database (UK/EEA regions)
- Transactional email delivery
- Scheduling for introduction calls
We give notice of any change to sub-processors and will provide the current list on request.
Security measures
Encryption in transit and at rest, role-based access limited to the practitioner and named staff involved, enhanced DBS and safeguarding training for every practitioner, access reviews on offboarding, and breach notification to the controller without undue delay and within 72 hours of becoming aware.
Data subject requests and audits
We assist controllers with access, rectification and erasure requests, DPIAs, and reasonable audits. On termination we return or securely delete pupil data at the controller's choice, subject to safeguarding retention duties.
Request a DPA
Email team@neu-road.org with "DPA request" and your setting's name. We can sign your standard agreement or send ours, alongside our safeguarding policy and insurance certificates.