Published using Google Docs
Lexonic — Data Processing Addendum v2
Updated automatically every 5 minutes

Data Processing Addendum  |  Sound Training for Reading Limited (Lexonic)

DATA PROCESSING ADDENDUM

Sound Training for Reading Limited (trading as Lexonic)

Version 2.0 | Effective June 2026 | Supersedes all previous versions

PART 1 - DATA PROCESSING PROVISIONS

1. Introduction

1.1 In this Addendum, "Processor" refers to Sound Training for Reading Limited (also "Lexonic", "we", "us", or "our") and "Controller" refers to the party identified in the Order Form to which this Data Processing Addendum is attached, or if not attached, refers to the party named at the end of this Addendum (also "you" or "your"). Lexonic and a client shall each be referred to as a "Party" and together as the "Parties".

1.2 This Addendum sets out the additional terms, requirements and conditions on which the Controller shall transfer personal data to the Processor, and on which the Processor shall process such personal data for the purposes of the Agreement. It contains the mandatory clauses required by Article 28 of UK GDPR and any applicable data protection laws in each relevant region for contracts between controllers and processors.

2. Interpretation

The following words and expressions have the following meanings:

Article: An article of the UK GDPR.

Chapter: A chapter of the UK GDPR.

Data Protection Law: All applicable legislation protecting the fundamental rights and freedoms of individuals in relation to their personal data and right to privacy, including but not limited to: (1) UK GDPR; (2) EU GDPR; (3) the Data Protection Act 2018; (4) CCPA / CPRA; (5) the Privacy and Electronic Communications (EC Directive) Regulations 2003; and relevant local privacy laws in the USA, UK, EU, Nordics and globally, each as amended and updated from time to time.

UK GDPR: The retained EU law version of the General Data Protection Regulation (EU) 2016/679, as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (SI 2019/419).

Personal data, data subject, processor, controller, processing, personal data breach, pseudonymisation, special categories of data, supervisory authority: As defined in the applicable Data Protection Laws.

Sub-Processor: Any third party engaged by the Processor to carry out processing activities on the Controller's personal data on the Processor's behalf.

Third Party: Any person, organisation, or entity that is not a Party to this Addendum, and is not a Sub-Processor engaged by the Processor in accordance with section 5 of this Addendum.

3. General

3.1 Part 2 of this Addendum describes the subject matter, duration, nature and purpose of processing and the personal data categories and data subject types in respect of which the Processor may process personal data to fulfil its obligations under the Agreement.

3.2 Whenever the Processor processes personal data on the Controller's behalf:

3.2.1 the Controller shall be the controller and the Processor shall be the processor in respect of such personal data; and

3.2.2 the Processor shall only process such personal data on the Controller's documented instructions (as set out in Part 2 to this Addendum, and including any technical support, maintenance or troubleshooting reasonably necessary to provide the Services), except where required to do otherwise by Data Protection Law, in which case the Processor shall inform the Controller of that legal requirement before processing unless the law prohibits such disclosure on important grounds of public interest.

3.3 The Processor shall inform the Controller upon becoming aware of:

3.3.1 any requirement of applicable law which requires the Processor to process personal data otherwise than on the Controller's documented instructions, unless that law prohibits such disclosure on important grounds of public interest; or

3.3.2 any instruction from the Controller in relation to the processing of personal data which, in the Processor's reasonable opinion, infringes Data Protection Law.

3.4 The Controller shall ensure that it has all necessary and appropriate consents and notices in place to enable the lawful transfer of the shared personal data to the Processor for the duration and purposes of this Agreement.

4. Security

4.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk to the rights and freedoms of natural persons, the Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including (as appropriate):

4.1.1 the pseudonymisation and encryption of personal data;

4.1.2 the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;

4.1.3 the ability to restore the availability and accessibility of personal data in a timely manner in the event of a physical or technical incident;

4.1.4 a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing; and

4.1.5 providing any assistance the Controller reasonably requires in order to implement appropriate technical and organisational measures to protect its personal data.

4.2 In assessing the appropriate level of security, the Processor shall take account of the risks presented by the processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.

4.3 The Processor shall ensure that its employees, and any other persons with access to personal data processed on the Controller's behalf, are made aware of their data protection and security obligations and are subject to binding obligations of confidentiality.

4.4 In accordance with the above requirements:

4.4.1 Only members of the Controller's staff who have been formally nominated by the Controller prior to setup shall be invited to register to use the secure Lexonic Online Service and accept the terms of use. Nominations shall be confirmed at the point of onboarding and a record retained by Lexonic for the duration of the Agreement. The Controller is responsible for notifying Lexonic promptly, and in any event within 5 working days, of any change to Authorised Users, including where a nominated staff member leaves the organisation, changes role, or should no longer have access for any reason. Lexonic shall revoke access upon receipt of such notification. The Controller shall conduct a review of its nominated users at least annually and confirm to Lexonic that the list remains accurate.

4.4.2 Processor staff access is limited to the minimum number of personnel necessary to provide the contracted services and for the minimum time necessary.

4.4.3 Processor staff are governed by Lexonic's data protection and data breach policies.

5. Sub-Processing

5.1 The Controller agrees that Lexonic may use suppliers ("Sub-Processors") to help deliver the Services. This Addendum acts as general authorisation for Lexonic to do so, subject to the conditions in this section 5.

5.2 Lexonic maintains an up-to-date list of its Sub-Processors, identifying for each its name, function and location (the "Sub-Processor List"). The Sub-Processor List is available at https://lexonic.org/legal/subprocessors (or on request from dataprotection@lexonic.org) and is updated by Lexonic in accordance with clause 5.3.

5.3 Before authorising any new Sub-Processor to Process Customer data, Lexonic shall give the Controller at least 30 days' prior notice of the engagement, including the name, location and processing activities of the relevant Sub-Processor. Lexonic shall give such notice both (a) by updating the Sub-Processor List, change notifications sent to subscribers of notification updates and (b) by giving the Controller opportunity to object on reasonable grounds within 14 days. Where the Controller raises such an objection, the Parties shall discuss it in good faith and seek to resolve it; if it cannot be resolved, the Controller may, as its sole remedy, terminate the affected Services without penalty for the unexpired portion of the relevant term, by written notice given before the new Sub-Processor begins Processing Customer data.

5.3.1 Where Lexonic must replace a Sub-Processor at shorter notice for reasons beyond its reasonable control (such as the insolvency of, or a material security or service failure by, an existing Sub-Processor), Lexonic may do so and shall notify the Controller as soon as reasonably practicable, providing the same information and objection rights set out in clause 5.3 as soon as the circumstances allow.

5.4 All Sub-Processors are required to meet the same data protection standards as those Lexonic itself is held to under this Addendum. Lexonic will enter into a written agreement with each Sub-Processor imposing data protection obligations consistent with this Addendum. If a Sub-Processor fails to meet those standards, Lexonic remains responsible to the Controller.

6. Transfer to Third Parties

6.1 The transfer of personal data to any Third Party in any manner is strictly prohibited unless one of the following conditions is met:

6.1.1 the transfer is required by applicable law or by a binding order of a competent court, regulator, or public authority; or

6.1.2 the Processor has obtained the prior explicit written consent of the Controller to that specific transfer.

6.2 Where a legal obligation requires the Processor to transfer personal data to a Third Party, the Processor shall, prior to making that transfer and to the extent permitted by law:

6.2.1 notify the Controller in writing of the requirement, identifying the legal basis, the identity of the Third Party recipient, and the personal data to be transferred; and

6.2.2 provide the Controller with a reasonable opportunity to seek legal advice or to challenge the requirement before the transfer is made.

6.3 Where prior notification is not possible because the applicable law prohibits it (for example, in connection with a law enforcement investigation), the Processor shall notify the Controller as soon as it is lawfully permitted to do so.

6.4 In all cases, any transfer to a Third Party under this section shall be limited to the minimum personal data necessary to fulfil the legal requirement or to give effect to the Controller's consent, and shall be subject to appropriate confidentiality undertakings from the recipient.

6.5 For the avoidance of doubt, this section 6 does not apply to Sub-Processors engaged in accordance with section 5, which are governed by the conditions set out in that section.

7. Requests from Data Subjects and Supervisory Authorities

7.1 If a data subject makes a request relating to the exercise of their legal rights in relation to personal data processed under this Addendum, the Processor shall, without undue delay and at no additional charge to the Controller, provide such information and assistance as is reasonably required by the Controller in order to respond to requests for exercising data subject rights under Chapter III of UK GDPR.

8. Personal Data Breaches and Notification

8.1 If the Processor becomes aware of a personal data breach relating to any personal data processed on the Controller's behalf, the Processor shall:

8.1.1 Notify the Controller without undue delay after becoming aware of the breach, and in any event in sufficient time to allow the Controller to meet any notification obligations it may have under applicable Data Protection Law.

8.1.2 provide details of the nature of the breach, the categories and approximate number of data subjects and personal data records affected, the likely consequences of the breach, and the measures taken or proposed to address the breach; and

8.1.3 provide such further information and assistance as the Controller reasonably requires in relation to the breach.

8.2 The Parties acknowledge that, as between them, the Controller is responsible for determining whether a personal data breach is notifiable to the Information Commissioner's Office (ICO) or to affected data subjects, and for making any such notification. The Processor shall not notify the ICO or any data subject of a breach affecting the Controller's personal data unless expressly instructed in writing by the Controller, save where the Processor is independently required to notify a supervisory authority under Data Protection Law in respect of its own obligations. The Processor shall provide all assistance reasonably necessary to enable the Controller to meet its notification obligations within the timeframes required by Data Protection Law, including the 72-hour period under Article 33 of UK GDPR.

9. Privacy Impact Assessments

9.1 Taking into account the nature of the processing and the information available to the Processor, the Processor shall, at no additional charge to the Controller, provide such information and assistance as the Controller reasonably requires in order to:

9.1.1 carry out any data protection impact assessments (under Article 35);

9.1.2 consult with a supervisory authority prior to processing (under Article 36); and/or

9.1.3 meet any obligations under data protection law which derive from the activities described in paragraphs 9.1.1 and 9.1.2 above.

10. Deletion and Return of Data

10.1 Following termination or expiry of the Agreement, or upon the Controller's earlier written request, the Processor shall, at the Controller's election, securely delete or return all personal data processed on the Controller's behalf. The retention periods in Part 2 are maximum default periods that apply only to the extent the Controller has not elected deletion or return under this clause; where the Controller so elects, deletion or return takes precedence over those defaults, save for data the Processor is required by law to retain (such as financial and billing records under clause 10.1.2).:

10.1.1 securely delete all personal data (and any copies of the same) processed on the Controller's behalf; or

10.1.2 return all such personal data to the Controller in a commonly used, machine-readable format, unless the Processor is required by applicable law to retain such data, in which case the Processor shall inform the Controller of that requirement and retain only the minimum data necessary to comply with it.

10.2 Where immediate deletion or return is not technically practicable, the Processor shall do so as soon as reasonably possible and shall in the meantime ensure that appropriate safeguards are in place and that the data is not used for any other purpose.

10.3 The Processor shall provide the Controller with written confirmation of deletion or return within 30 days of completion.

11. International Transfers

11.1 The Processor shall not transfer any of the Controller's personal data to a third country or international organisation without having the Controller's prior written consent to that transfer and one of the following conditions being met:

11.1.1 the United Kingdom government has decided that the relevant country or organisation ensures an adequate level of protection (under Article 45);

11.1.2 appropriate safeguards are in place as set out in Article 46 (including, where applicable, standard contractual clauses); or

11.1.3 one or more of the derogations set out in Article 49 applies.

11.2 Prior to any international transfer, the Processor shall carry out and retain a Transfer Impact Assessment and make this available to the Controller on request.

12. Processing for Marketing Purposes

12.1 The Parties acknowledge that where the Processor processes the business contact details of the Controller's nominated staff (names, job titles, email addresses) to send product updates or marketing relating to Lexonic's own services, it does so as an independent controller, not as a processor under this Addendum. Such processing falls outside the relationship in Section 3 and is governed by Lexonic's own privacy notice and applicable Data Protection Law, including the Privacy and Electronic Communications (EC Directive) Regulations 2003.

12.2 The lawful basis is the Processor's legitimate interests in promoting its services to existing and prospective business customers. Individuals may opt out at any time via consent@lexonic.org or the unsubscribe link in each communication, and the Processor shall give effect to any opt-out without undue delay.

12.3 No student assessment personal data shall be processed for marketing or any related profiling under any circumstances..

13. Children's Personal Data

13.1 Where the Processor processes the personal data of children (data subjects under 18, or such other age as constitutes a child under applicable Data Protection Law) on the Controller's behalf, the Processor shall: (a) process such data only as strictly necessary to provide the Assessment App services, and never for marketing, marketing-related profiling, or any commercial purpose; (b) apply heightened technical and organisational safeguards appropriate to the risks to children, having regard to the ICO's Age Appropriate Design Code (Children's Code) so far as applicable; (c) not disclose children's data to any Sub-Processor or Third Party except under Sections 5 and 6 and subject to equivalent protections; and (d) restrict access to Authorised Users nominated under clause 4.4.1.

14. US Privacy Rights (CCPA / CPRA)

14.1 Where the Controller is subject to the California Consumer Privacy Act (CCPA) and/or the California Privacy Rights Act (CPRA), or other applicable US state privacy laws, the Processor confirms that it:

14.1.1 processes personal data solely for the purposes set out in this Addendum and the Agreement and not for any other commercial purpose;

14.1.2 shall not sell, share, or otherwise disclose personal data to third parties except as permitted under this Addendum and applicable US privacy law;

14.1.3 shall assist the Controller in honouring consumer rights requests (including requests to access, delete, correct or opt out of sale/sharing) within the timeframes required by applicable US law; and

14.1.4 shall notify the Controller if it determines it can no longer meet its obligations under applicable US privacy law.

15. Audits

15.1 The Processor shall, subject to the Controller providing appropriate confidentiality undertakings, make available to the Controller all assistance and information necessary to demonstrate compliance with Article 28, including reasonable cooperation during business hours and upon reasonable notice with audits and/or inspections conducted by or on behalf of the Controller or another auditor mandated by the Controller.

15.2 Nothing in this paragraph 14 shall require the Processor to disclose or permit access to any of its (or any third party's) confidential or commercially sensitive information.

16. Governing Law and Jurisdiction

16.1 This Addendum is governed and construed by the laws of England and Wales.

16.2 Subject to clause 16.3, the Parties submit to the exclusive jurisdiction of the courts of England and Wales for any dispute or claim arising out of or in connection with this Addendum.

16.3 Nothing in 16.1 or 16.2 overrides (a) any mandatory governing law or jurisdiction requirement imposed by Data Protection Law for a particular transfer or processing activity, including the governing-law and forum requirements of any standard contractual clauses or other transfer mechanism under Section 11; or (b) any non-waivable right of a data subject to bring proceedings, or of a supervisory authority to act, under applicable Data Protection Law.

PART 2 - DATA PROCESSING DETAILS

1. Subject-Matter of the Processing

Lexonic processes customer data to deliver contracted products and services. This data comprises information about the purchasing organisation's staff and, for those customers subscribing to products which include the Assessment App, student data. Where applicable, staff contact data may also be processed for product communications in accordance with Section 12 of Part 1 and UK GDPR.

2. Duration of the Processing

Staff and student personal data shall be retained for the period during which services are provided to the purchasing organisation and for the following periods thereafter:

Data Category

Retention Period

Legal Basis

Staff contact and account data

5 years following expiry/termination

Legitimate interests / contractual necessity

Student assessment and progress data

6 months following expiry or termination of the Agreement, unless earlier deletion is requested by the Controller

Contractual necessity

Financial and billing records

6 years

Legal obligation

These are maximum retention periods, subject to the Controller's right to request earlier deletion or return under Section 10 of Part 1. Financial and billing records (6 years) are retained on the basis of a legal obligation and are not subject to earlier deletion.

3. Types of Personal Data to be Processed

In the case of Staff: names, job titles, email addresses, contact telephone numbers, staff feedback.

In the case of Students (where the Controller has subscribed to the Assessment App, as part of Advance and Leap): name, date of birth, progress and assessment data.

4. Nature and Purpose of the Processing

Staff personal data will be processed for the following purposes:

- To assist Lexonic in the provision of services to the purchasing organisation.

- To enable controlled access to data held by Lexonic under its contract with the purchasing organisation.

- To send product updates and marketing communications relating to Lexonic services, subject to the Controller's right to opt out (see Section 12 of Part 1).

Student personal data will be processed for the following purpose:

- To provide progress and assessment data to the purchasing organisation’s Nominated Staff  who access the Lexonic Online Services.

5. Categories of Data Subjects

Employees and students of the purchasing organisation's sites.


Lexonic registered address: Victoria House, Pearson Way, Thornaby, Stockton-On-Tees, TS17 6PT

Company number: 06977154

Data Protection contact: dataprotection@lexonic.org

This document was last updated: June 2026

Version 2.0  |  Effective: June 2026 Page