Bytewise
Policy

Data Processing Agreement.

Version 2 · 2026-07-17

What and who is Nimbyx: Nimbyx Limited (“Nimbyx”) is the company that owns and operates Bytewise, and provides software and services for schools and other educational establishments. We operate solely in the United Kingdom.

What and who is Bytewise: Bytewise is the school-meals ordering, allergen-management and payments platform owned and operated by Nimbyx.

This Data Processing Agreement forms part of the Bytewise Service Agreement between the School and Nimbyx, and sets out how Nimbyx processes personal data on the School’s behalf.

1. Parties

1.1 The Controller: the School, multi-academy trust or local authority named in the Service Agreement (the “School”).

1.2 The Processor: Nimbyx Limited, a company registered in England and Wales (company number 17288718), registered office Rose House, Old Sawmill Place, Bell Lane, Little Chalfont, Amersham, Buckinghamshire, HP6 6FA (“Nimbyx”, “we”), registered with the Information Commissioner’s Office under reference ZC196580.

1.3 This Data Processing Agreement (“DPA”) forms part of, and is subject to, the agreement between the School and Nimbyx for the provision of the Bytewise service (the “Service Agreement”). Where they conflict on data protection matters, this DPA prevails.

2. Definitions

2.1 “Data Protection Law” means the UK GDPR, the Data Protection Act 2018, and all other data protection laws applicable in the United Kingdom, as amended.

2.2 “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Special Category Data”, “Processing” and “Personal Data Breach” have the meanings given in Data Protection Law.

2.3 “School Personal Data” means the Personal Data processed by Nimbyx on behalf of the School under the Service Agreement, as described in Annex A.

2.4 “Sub-processor” means any processor engaged by Nimbyx to process School Personal Data.

3. Roles and scope

3.1 The parties acknowledge that, for the School Personal Data, the School is the Controller and Nimbyx is the Processor. This includes pupils’ allergen and dietary (health) information and, where the School approves the relevant Wonde permission, pupils’ medical records read from the School’s MIS, each of which is Special Category Data under Article 9 of the UK GDPR; the School determines the lawful basis for that processing (schools typically rely on legal obligation, public task and, in an emergency, vital interests) and provides the corresponding privacy information to data subjects.

3.2 Nimbyx processes School Personal Data only to provide the Bytewise service and only as set out in this DPA and the Service Agreement. Nimbyx is an independent Controller only for limited data it determines the purposes of (for example the direct account relationship with guardians, and its own service administration and security), which is governed by the Nimbyx Privacy Notice, not this DPA.

4. Processor obligations

Nimbyx shall, in respect of School Personal Data:

4.1 Documented instructions. Process it only on the School’s documented instructions (including this DPA and the Service Agreement), unless required by law, in which case Nimbyx will inform the School first unless the law prohibits it. Nimbyx will tell the School if, in its opinion, an instruction infringes Data Protection Law.

4.2 Confidentiality. Ensure that persons authorised to process the data are bound by an appropriate duty of confidentiality.

4.3 Security. Implement appropriate technical and organisational measures under Article 32 of the UK GDPR, as described in Annex B.

4.4 Sub-processors. The School gives general written authorisation for Nimbyx to engage the Sub-processors listed in Annex C. Nimbyx will impose data-protection obligations on each Sub-processor no less onerous than those in this DPA, and remains liable for their acts and omissions. Nimbyx will give the School at least 30 days’ notice of any intended addition or replacement of a Sub-processor, during which the School may object on reasonable data-protection grounds.

4.5 Assisting with data-subject rights. Taking into account the nature of the processing, assist the School by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability and objection). Where Bytewise provides self-service tools, the School may use these directly.

4.6 Assisting with compliance. Assist the School in ensuring compliance with its obligations under Articles 32–36 (security, breach notification, and data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to Nimbyx.

4.7 Breach notification. Notify the School without undue delay after becoming aware of a Personal Data Breach affecting School Personal Data, and provide the School with the information it reasonably needs to meet its own breach-notification obligations (including under Articles 33–34).

4.8 Deletion or return. At the end of the provision of the services relating to processing, at the School’s choice, delete or return all School Personal Data and delete existing copies, unless Data Protection Law requires storage. Nimbyx’s standard position is set out in the retention section of its Privacy Notice and in Annex A.

4.9 Audits and information. Make available to the School all information necessary to demonstrate compliance with its obligations as a Processor under Article 28 of the UK GDPR, and allow for and contribute to audits, including inspections, conducted by the School or an auditor it mandates, on reasonable prior notice and subject to appropriate confidentiality.

5. International transfers

5.1 School Personal Data is hosted and processed primarily in the United Kingdom. Nimbyx will not transfer School Personal Data outside the UK except where an appropriate safeguard under Data Protection Law is in place.

5.2 The transfers outside the UK are: (a) transactional email via Resend (United States), covered by the UK Extension to the EU-US Data Privacy Framework; and (b) application monitoring via Laravel Nightwatch, where data is hosted in the EU (an adequate jurisdiction) and any access by its US-based operator is covered by the UK IDTA and Standard Contractual Clauses in the Laravel DPA.

6. General

6.1 Term. This DPA takes effect on the start of the Service Agreement and continues while Nimbyx processes School Personal Data.

6.2 Liability. Liability under this DPA is subject to the limitations and exclusions of liability in the Service Agreement.

6.3 Governing law. This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of its courts.


Annex A — Details of the processing

Item Detail
Subject matter Provision of the Bytewise cashless catering, meal-ordering, allergen-management and guardian-communication service.
Duration The term of the Service Agreement, plus the retention periods below.
Nature and purpose Collecting, storing, organising, displaying and communicating pupil, guardian and staff data to operate school meals safely (including allergen checks), manage payments/wallets, and communicate with guardians. Where the School approves the relevant Wonde permissions: displaying pupil medical records, read-only, to authorised staff to help them support and safeguard pupils; and displaying pupil photographs to authorised staff solely to confirm a pupil’s identity at the point of service (never published, and never used for automated or biometric recognition).
Types of Personal Data Pupil: name, date of birth, year group, UPN and MIS identifiers, Free School Meal / Pupil Premium eligibility, allergen and dietary (health) information [Special Category], meal selections and spend history; where the School approves the relevant Wonde permissions, medical records from the School’s MIS [Special Category] and photograph. Guardian: name, email, telephone, home address, relationship and parental-responsibility status, account credentials. Staff: name, work email, role. Technical: IP address and device/browser information.
Special Category Data Pupils’ allergen and dietary (health) information and, where the School approves the relevant Wonde permission, pupils’ medical records from the School’s MIS (Article 9).
Categories of Data Subject Pupils, parents/carers/guardians, and school staff.
Retention Pupil and guardian data deleted or anonymised within 12 months of the pupil leaving or the account being closed by the School; payment/transaction records kept 6 years (tax/audit); audit logs up to 7 years; or as otherwise instructed by the School.

Annex B — Technical and organisational measures (Article 32)

  • Data residency: core application and database hosted in the United Kingdom (London region).
  • Encryption in transit: TLS 1.2/1.3 for all connections.
  • Encryption at rest: AES-256 across the database, storage and backups.
  • Application-layer encryption: pupil identity fields and free-text allergen notes, and guardian contact details, are additionally encrypted at the application layer.
  • Access control: role-based, least-privilege access; multi-factor authentication available for administrative access; per-school data segregation; guardians see only their own children.
  • Auditing: an append-only audit trail of significant actions (including allergen changes) for security, safeguarding and accountability.
  • Passwords: hashed, never stored in the clear.
  • Resilience & recovery: managed, encrypted database backups with point-in-time recovery.
  • Sub-processor controls: contractual data-protection terms flowed down to all Sub-processors.
  • Data minimisation & logging hygiene: no personal data written to application logs.

Annex C — Sub-processors

Sub-processor Purpose Location / transfer
Laravel Cloud (Laravel Holdings Inc.) on Amazon Web Services Platform hosting and compute UK (London / eu-west-2)
Neon Managed PostgreSQL database UK (eu-west-2)
Cloudflare File storage (R2), content delivery and web-application firewall EU jurisdiction
Resend (Plus Five Five, Inc.) Transactional and notification email US — UK Extension to the EU-US Data Privacy Framework
Wonde Secure sync of pupil and guardian data from the School’s MIS, including, where the School approves it, pupil medical records and photographs UK
Worldpay Card and online payment processing (Bytewise Pay) UK/EU
Laravel Nightwatch (Laravel Holdings Inc.) Application performance monitoring and error diagnostics EU — US operator, under Laravel DPA

The current authoritative list is maintained in the Sub-processor DPA register; Nimbyx will notify the School of changes as set out in clause 4.4.


Related policies

This Data Processing Agreement should be read alongside our other Nimbyx and Bytewise policies, each available on the Nimbyx website: our Privacy Notice; the Bytewise Terms of Use; the Bytewise Terms & Conditions for Guardians; and our Cookie Policy.

Acceptance

This Agreement is entered into on behalf of the School by a representative with authority to bind it, who confirms that authority and their acceptance in Bytewise (for example when first setting up the School’s area). It takes effect on that acceptance and continues while Nimbyx processes School Personal Data. Where the School prefers, it may instead be signed by an authorised representative of each party.

Contact usA Nimbyx product · © 2026 Bytewise