Legal

Data Processing Agreement

This summary describes the key terms of our Data Processing Agreement (DPA), which forms part of the agreement between [Company legal name] and each Customer.

Last updated September 16, 2026

Subject matter and duration

The DPA governs the processing of personal data by [Company legal name] (the "Processor") on behalf of the Customer (the "Controller") in the course of providing Aula. It applies in addition to our Terms of Service or any signed order form.

The DPA lasts for as long as [Company legal name] processes Customer personal data, which is the term of the Customer's subscription plus any period needed to return or delete the data afterwards.

Nature and purpose of processing

We process Customer personal data only to provide, secure and support the Service, including:

  • hosting and storing course content, files and video;
  • authenticating users and managing roles and permissions;
  • delivering lessons, quizzes, assignments, live classes, discussions, messages and notifications;
  • recording progress, attendance, grades, transcripts and certificates;
  • processing course purchases and payouts through Stripe;
  • sending transactional emails;
  • providing analytics, reports, audit logs, API access and webhooks to the Customer;
  • providing technical support at the Customer's request.

Processing operations include collection, storage, organisation, retrieval, use, transmission, restriction and erasure.

Categories of data subjects and personal data

Data subjects may include the Customer's administrators, teachers and instructors, students and learners (which may include minors), parents and guardians, employees and trainees, and course purchasers.

Personal data may include:

  • identity and contact details, such as name, email address and profile photo;
  • account and authentication data, such as role, SSO identifiers and two-factor settings;
  • learning records, such as enrolments, progress, quiz results, assignments, attendance, grades, report cards and transcripts;
  • communications, such as discussion posts, messages and announcements;
  • live class participation and, where enabled, recordings;
  • purchase records (card data is handled by Stripe);
  • technical data, such as IP address, device information and logs.

The Customer controls what data is uploaded and should avoid uploading special category data unless it has a lawful basis and has assessed the risks.

Processor obligations

[Company legal name] will:

  • process personal data only on the Customer's documented instructions, including those given through the Service configuration, and inform the Customer if an instruction appears to breach data protection law;
  • ensure that personnel with access to personal data are bound by confidentiality;
  • implement appropriate technical and organisational security measures;
  • assist the Customer, taking into account the nature of processing, with data subject requests, data protection impact assessments and prior consultations;
  • make available the information needed to demonstrate compliance with the DPA;
  • not sell Customer personal data or use it for its own purposes, such as advertising.

Sub-processors

The Customer gives general authorisation for [Company legal name] to engage sub-processors. Our current sub-processors include Stripe, Cloudflare (R2 storage), Bunny (Stream video), LiveKit, Resend and our infrastructure hosting providers, plus Zoom where the Customer enables that integration.

We impose data protection obligations on each sub-processor that are no less protective than those in the DPA, and we remain responsible for their performance. We will give the Customer notice before adding or replacing a sub-processor, and the Customer may object on reasonable data protection grounds. If we cannot resolve the objection, the Customer may terminate the affected Service.

Security measures

Our technical and organisational measures include:

  • logical separation of each Customer's data using PostgreSQL row-level security;
  • encryption in transit using TLS;
  • hashed passwords, two-factor authentication and SAML/OIDC single sign-on;
  • role-based access control with granular permissions, and least-privilege access for our staff;
  • audit logging of significant administrative actions;
  • scoped API keys and signed webhooks;
  • secure session handling;
  • backups, monitoring and incident response procedures;
  • vendor due diligence for sub-processors.

We review and update these measures as technology and risks change, without reducing the overall level of protection.

Personal data breach notification

If [Company legal name] becomes aware of a personal data breach affecting Customer personal data, we will notify the Customer without undue delay. Our notice will describe, as far as the information is available, the nature of the breach, the categories and approximate number of individuals and records concerned, the likely consequences, and the measures taken or proposed.

We will take reasonable steps to contain and remedy the breach and will cooperate with the Customer so it can meet its own obligations to notify supervisory authorities and affected individuals.

Audits and information requests

We will make available to the Customer the information reasonably necessary to demonstrate compliance with the DPA, such as security documentation and answers to security questionnaires.

Where that information is not sufficient, the Customer may request an audit, subject to reasonable advance notice, confidentiality obligations, and conditions that avoid disruption to the Service and protect the data of other Customers. Audits are carried out at the Customer's expense unless they reveal a material breach of the DPA.

Return and deletion of data

During the subscription, Customers can export their data using reports, exports and the REST API. When the subscription ends, the Customer may export its data during the period described in its plan or order form.

After that period, [Company legal name] will delete Customer personal data from the production environment, and from backups as they expire on their normal cycle, unless the law requires us to keep it. On request, we will confirm deletion in writing.

Transfers and requesting a signed DPA

Where Customer personal data is transferred outside the EEA or the UK, the DPA incorporates the European Commission's Standard Contractual Clauses and, where relevant, the UK International Data Transfer Addendum.

To request a countersigned copy of the DPA, email privacy@example.com or contact your account team at sales@example.com. Please include your organisation's legal name, address and the email address of the account owner. The DPA is governed by the law specified in it, and otherwise by the laws of [Governing law jurisdiction].