Data processing terms
Last updated 1 October 2026
The commitments we make under UK GDPR to every organisation that uses ISMS.
1. What these terms are
These terms set out how ISMS UK (“we”) processes personal data for each organisation that uses ISMS (“you”). They meet the requirements of Article 28 of the UK GDPR and apply alongside our Service Agreement. If the two ever conflict on data protection, these terms win.
You are the controller of the personal data you put into ISMS. We are your processor.
2. The processing
Purpose: to provide, secure and support the ISMS service you subscribe to. Duration: for as long as you use ISMS, and until the data is deleted when you leave.
Mosques and madrasahs: pupils (often children), parents and guardians, staff and volunteers. Data includes names, contact details, dates of birth, attendance, progress, fees, payments and notes, and may include health or other special category information you choose to record.
Student consultancies: applicants, students, sub-agents and staff. Data includes names, contact details, identity documents such as passports, education history, application progress, and visa and immigration records.
3. Our commitments
We process the data only on your documented instructions, which are your use of ISMS and anything you ask of us in writing. If we believe an instruction breaks data protection law, we will tell you.
Everyone who can access your data for us is bound by confidentiality.
We keep appropriate technical and organisational security measures in place (see below).
We help you respond to people exercising their rights, for example by exporting or correcting their records, and we pass on to you any request we receive directly.
We help you meet your own duties on security, breach reporting and data protection impact assessments, taking into account what we know about the processing.
4. Security measures
Each organisation's data is kept separate at the database level. All connections are encrypted. Passwords are stored only in hashed form. Sign-in supports two-factor authentication, access depends on each person's role, and sensitive actions are recorded in an audit log.
5. Sub-processors
We put the same data protection obligations on every sub-processor as these terms put on us, and we remain responsible to you for their work.
6. International transfers
ISMS is hosted in the United States (US West). That transfer is covered by the standard contractual clauses with the UK International Data Transfer Addendum, which form part of our hosting provider's data processing terms. We will not transfer your data anywhere else outside the UK without equivalent safeguards.
7. Personal data breaches
If we become aware of a breach affecting your data, we will tell you without undue delay and in any case within 48 hours, with what we know about what happened, the data involved and what we are doing about it. That gives you time to meet your own 72-hour duty to report to the ICO.
8. When you leave
We will give you a copy of your data on request, while your subscription is active or when it ends. When it ends, we delete your data within 90 days, unless the law requires us to keep it. Backups are overwritten in their normal cycle.
9. Checking we comply
We will give you the information you reasonably need to show that these terms are being met, and answer your questions about them. To ask anything, email hello@ismsuk.com.
Questions about this page: hello@ismsuk.com · GDPR · Privacy policy · Cookie policy · Data processing terms