Data Processing Agreement
Last updated: [Last Updated Date]
Introduction
This Data Processing Agreement ("DPA") forms part of the Platform Terms between [Legal Entity Name] ("we," "us," "the Processor") and the business licensing a hosted instance of [Platform Name] ("you," "the Customer," "the Controller").
It is entered into pursuant to Article 28(3) of Regulation (EU) 2016/679 ("GDPR"), which requires a written contract between a controller and a processor. It applies from the moment your Instance first processes personal data.
Roles. For personal data processed within your Instance, you are the controller and we are the processor. For your own administrative account and for billing you, we act as a controller in our own right; that processing is described in our Privacy Policy and is outside the scope of this DPA.
1. Subject Matter, Duration, Nature and Purpose
- Subject matter: the hosting and operation of your Instance
- Duration: the term of the Platform Terms, plus the retention period in clause 9
- Nature and purpose: storage, retrieval, transmission, backup, and display of personal data so that you can operate your business and deliver products to your End Users, together with the technical support necessary to keep the Instance running
- Type of processing: collection, recording, organisation, storage, retrieval, transmission, erasure, and destruction
2. Categories of Data Subjects
- Your End Users and customers
- Your administrators and staff who use the Instance
- Individuals who submit their details through lead capture, contact, or newsletter forms on your Instance
3. Categories of Personal Data
- Identity: name, email address
- Account: hashed password, role, login timestamps
- Purchase: order history, payment provider customer and transaction identifiers. We do not store payment card numbers, which are handled by your payment provider
- Usage: course and lesson progress, application inputs and outputs, download activity
- Technical: IP address, browser user agent
- Content: files and information uploaded by you or your End Users
4. Special Categories of Data
Neither party intends special categories of personal data within the meaning of Article 9 GDPR, nor personal data relating to criminal convictions and offences within the meaning of Article 10, to be processed under this DPA.
You must not use the Instance to process such data without our prior written agreement, so that appropriate additional safeguards can be put in place first.
5. Our Obligations as Processor
We will:
- Process personal data only on your documented instructions, including as to international transfers, unless required to do otherwise by law, in which case we will inform you before processing unless the law prohibits it. Your use of the Instance, together with the Platform Terms and this DPA, constitutes your documented instructions
- Inform you if, in our opinion, an instruction infringes the GDPR or other applicable data protection law
- Ensure that personnel authorised to process personal data are bound by an appropriate obligation of confidentiality
- Implement and maintain the technical and organisational measures set out in Annex A
- Assist you, taking into account the nature of the processing and the information available to us, in responding to requests from data subjects exercising their rights under Chapter III GDPR
- Assist you in complying with your obligations under Articles 32 to 36 GDPR, including security, breach notification, and data protection impact assessments
- Make available the information necessary to demonstrate compliance with Article 28, as set out in clause 10
Support access. We access personal data within your Instance where necessary to provide support, to investigate faults, and to maintain the service. Such access is limited to what is necessary for the task, and the personnel concerned are bound by confidentiality.
6. Sub-processors
You give general written authorisation for us to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex B.
We will impose on each sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.
We will give at least [Sub-processor Notice] notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the Platform Terms in respect of the affected processing, and we will refund fees prepaid for the unused remainder of the current period.
7. International Transfers
Some sub-processors are established outside the European Economic Area. Where personal data is transferred to such a country in the absence of an adequacy decision under Article 45 GDPR, the transfer takes place on the basis of the Standard Contractual Clauses adopted by the European Commission, which are incorporated into this DPA by reference, together with any supplementary measures required following a transfer impact assessment.
8. Personal Data Breaches
We will notify you without undue delay, and in any event within [Breach Notification Time] of becoming aware of a personal data breach affecting personal data processed under this DPA.
The notification will describe, so far as known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. We will provide further information as it becomes available.
Notifying a supervisory authority or the affected data subjects is your responsibility as controller. We will provide reasonable assistance.
9. Return and Deletion
On termination of the Platform Terms, and at your choice:
- You may request an export of the personal data processed under this DPA within [Export Window] of termination. We will provide it in a structured, commonly used, machine-readable format
- We will delete the personal data, including from backups in the ordinary course of their rotation, within [Deletion Period] of the end of the export window
We may retain personal data where required to do so by law, in particular accounting and invoicing records, for [Retention Exception Period]. Retained data remains subject to this DPA for as long as we hold it.
10. Audit
We will make available to you the information necessary to demonstrate compliance with Article 28 GDPR, in the form of our documentation, our description of technical and organisational measures, and written answers to reasonable questions.
Where that is not sufficient, you may carry out an on-site audit, subject to the following: it is at your cost, on at least 30 days' written notice, no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach, conducted during normal business hours, not conducted during an ongoing security incident, and subject to the auditor accepting confidentiality obligations and not being a competitor of ours.
11. Liability
Liability under this DPA is subject to the limitations and exclusions in the Platform Terms.
12. Order of Precedence
Where this DPA conflicts with the Platform Terms in relation to the processing of personal data, this DPA prevails. Where it conflicts with the Standard Contractual Clauses, those clauses prevail.
Annex A: Technical and Organisational Measures
Measures implemented pursuant to Article 32 GDPR:
Encryption
- Personal data is encrypted in transit using TLS
- Personal data is encrypted at rest at the storage layer
- Credentials and secrets are stored encrypted or hashed, never in plain text
Access control
- Access to production systems is restricted to personnel who require it
- Administrative accounts require multi-factor authentication where the provider supports it
- Access within the application is enforced at the database layer through row-level security, in addition to application-level checks
Resilience
- Backups are taken at [Backup Frequency] and retained for [Backup Retention]
- Restoration from backup is tested periodically
Operational security
- Security patches are applied to the platform and its dependencies on an ongoing basis
- Application and access events are logged
- Incidents are triaged, contained, and recorded, and notified in accordance with clause 8
Organisational
- Personnel with access to personal data are bound by confidentiality obligations
- Sub-processors are bound by written terms no less protective than this DPA
Annex B: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| [Database Provider] | Database, authentication, file storage | [Database Region] |
| [Hosting Provider] | Application hosting | [Hosting Region] |
| [Payment Provider] | Payment processing | [Payment Provider Region] |
| [Email Provider] | Transactional email delivery | [Email Provider Region] |
| [Video Provider] | Video hosting and streaming | [Video Provider Region] |
| [Community Provider] | Community access | [Community Provider Region] |
| [AI Provider] | AI-assisted application features | [AI Provider Region] |
Annex B may be updated by notice under clause 6, without amendment of this DPA.
Contact
Questions and notices under this DPA, including breach notifications, should be sent to [Security Email].
[Legal Entity Name], [Registered Address] [Registration Authority] number [Registration Number]