Trust & safety
Data protection
Last updated: [PLACEHOLDER — publish date]
This page summarises how UniDoodle handles data protection for individual users and organisation customers. Read alongside our Privacy Policy.
Roles
For direct sign-ups UniDoodle is the data controller. For students added by a school or organisation, that organisation is the controller and UniDoodle acts as processor.
Data Processing Agreement
Organisations can request our standard DPA (including subprocessor list and international transfer terms) from privacy@unidoodle.com. [PLACEHOLDER — link to signed DPA template].
Data subject requests
Individuals can exercise access, rectification, deletion, portability and objection rights by emailing privacy@unidoodle.com. We aim to respond within 30 days.
Breach notification
We will notify affected controllers without undue delay and no later than 72 hours after becoming aware of a personal data breach, as required by GDPR Art. 33.
This is a working draft. Items marked [PLACEHOLDER] must be reviewed and completed by the UniDoodle team (and its legal advisers) before general availability.

