Terms for a SaaS product sold to schools

Customer terms for an education technology product sold to schools, colleges and academy trusts, drafted for a fixed fee of £995 in five working days.

Share

Terms for a SaaS product sold to schools

Terms for a SaaS product sold to schools and academy trusts, drafted for how schools buy and what they need, covering who the customer is and how a school contracts, pupil data and the processor terms schools require, children and the design code, safeguarding and staff access, accessibility and public sector duties, the academic year, pricing and payment, and freedom of information. £995, delivered in five working days.

Buy now, £995

Selling software to schools means selling to public bodies that hold children's data, and the terms have to answer the questions a school's data protection officer and business manager will ask before anyone signs: who the contracting entity is, what happens to pupil data, how children are protected in the product, whether the product is accessible, and how the contract fits an academic year and a school budget. The terms should be drafted so that a school can say yes without a negotiation it has no capacity for. I draft those terms for a fixed fee of £995, delivered in five working days.

Who this is for

Education technology businesses in England and Wales selling a SaaS product to maintained schools, academies and multi-academy trusts, independent schools, colleges and local authorities, whether to teachers directly, to school leadership or through procurement frameworks.

What matters in SaaS terms for schools

Who the customer is and how a school contracts

A maintained school contracts through its governing body or its local authority, an academy through the academy trust that runs it, and a multi-academy trust may buy for all its schools under one agreement; the terms should identify the contracting entity, provide for a trust to add schools by order form, and say who may sign. Schools buy under their own procurement rules and, for larger contracts, under the Procurement Act 2023, and the terms should be drafted to fit a school's standard purchasing rather than to fight it.

Pupil data and the processor terms schools require

The school is the controller of pupil and staff data and the supplier is its processor, so the terms must contain the provisions Article 28 of the UK GDPR requires, in a data processing schedule that a data protection officer can read: the data and purposes, security under Article 32, subprocessors and their locations, transfers under Article 46, breach notification in time for the school to meet Article 33, deletion at the end, and no use of pupil data for the supplier's own purposes, including training or advertising. Schools will ask for the supplier's data protection impact assessment inputs, and the terms should commit to providing them.

Children, the design code and the product

A product likely to be used by children is subject to the age appropriate design code issued under section 123 of the Data Protection Act 2018, which sets standards on defaults, profiling, nudging and data minimisation, and the terms should state that the product is designed to the code, describe age ranges and how accounts for pupils are created and controlled by the school, and prohibit advertising and tracking of pupils. Where pupils create content or interact, the terms should provide moderation and reporting tools and the school's controls over them.

Safeguarding, staff access and conduct

The school's safeguarding duties extend to the tools it uses, and the terms should describe the supplier's safeguarding arrangements: which staff can access pupil data, vetting where staff interact with pupils, the school's control over who in the school can see what, and how concerns raised through the product are reported to the school. The supplier should commit to compliance with the school's reasonable policies when on site or interacting with pupils, and the terms should not put the supplier in a safeguarding role it is not equipped for.

Accessibility, public sector duties and freedom of information

Public sector bodies must make their websites and apps accessible under the Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018 and a school's tools form part of that, so the terms should state the accessibility standard the product meets and commit to an accessibility statement; the school must also comply with the Equality Act 2010 for disabled pupils. Schools are subject to the Freedom of Information Act 2000, and the terms should acknowledge that the school may have to disclose the contract and pricing, with the supplier's confidential information identified so that the school can consider exemptions.

The academic year, pricing, payment and exit

Subscriptions should run with the academic year with renewal and notice dates that fit school planning, pricing should be stated per pupil, per school or per trust with VAT, and payment terms should allow for school purchase orders and the thirty-day payment period that public bodies work to; interest under the Late Payment of Commercial Debts (Interest) Act 1998 applies but is rarely the answer. On exit the school needs its data exported in a usable format and deleted after, and the supplier's liability cap should be one a school can accept, drafted with reasonableness under section 11 of the Unfair Contract Terms Act 1977 in mind and no exclusion of the data protection obligations the school cannot delegate.

What it costs

SaaS terms of service, £995. Your standard customer-facing terms. Five working days.

Buying online forms the engagement on payment. The scope is what the saas and technology contracts page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A bespoke contract drafted for how your product is sold, delivered and supported
  • Service levels you can meet, with remedies that are proportionate rather than aspirational
  • A liability position that is defensible and will survive enterprise procurement
  • IP and data provisions that fit together rather than contradicting each other
  • A commercial note on where you will get pushback and what is worth conceding
  • One round of amendments

What is not included

  • Negotiating individual enterprise deals, which I quote separately
  • Advice on the law of jurisdictions outside England and Wales
  • Technical security certification or audit
  • Regulatory advice for regulated sectors such as financial services or health

Questions I am often asked

A school's data protection officer has sent a twenty-question checklist. Will the terms answer it?

That is what the data processing schedule is for: the data, purposes, security, subprocessors, transfers, breach notification and deletion set out in the order DPOs ask. The terms are drafted so that the checklist is answered by pointing at the schedule.

Can we use anonymised pupil data to improve the product?

Only if the terms say so, the anonymisation is real, and the school agrees. Most schools accept aggregated, de-identified usage data for improvement when it is defined; none accept pupil data used for advertising or training without consent.

A multi-academy trust wants one contract for thirty schools. How is that structured?

The trust contracts as the customer with each school added by order form, one data processing schedule, and pricing per school. The terms are drafted with that structure ready.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.