Legal
GDPR compliance
How Aula helps schools, training providers and creators meet their obligations under the GDPR, and how individuals can exercise their rights.
Last updated September 16, 2026
Our commitment
The General Data Protection Regulation (GDPR) and the UK GDPR set strict rules for handling personal data of people in the European Economic Area and the United Kingdom. [Company legal name] designs Aula so that Customers can meet these rules when they run their academies, and applies the same principles to its own processing: lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.
This page is a summary. The binding terms are in our Terms of Service, Privacy Policy and Data Processing Agreement.
Controller and processor roles
- Customers are controllers of the personal data of their learners, teachers, parents and staff. They decide which data is collected, which features are enabled and how long data is kept.
- [Company legal name] is a processor for that data. We process it only on the Customer's documented instructions, as set out in our Data Processing Agreement.
- [Company legal name] is a controller for its own business data, such as Customer account owners, billing contacts, sales leads and website visitors.
Because schools and similar organisations may enrol children, Customers are responsible for establishing a lawful basis and any parental consent required for minors. Aula supports this with parent accounts linked to student accounts and role-based access.
Lawful bases for processing
For processing where we are the controller, we rely on:
- Contract: to provide the Service to Customers and manage their accounts and subscriptions.
- Legitimate interests: to secure the platform, prevent fraud and abuse, maintain audit logs, improve the Service and communicate with business contacts. We balance these interests against individuals' rights.
- Legal obligation: to keep financial records and respond to lawful requests.
- Consent: for optional marketing communications and non-essential cookies, which can be withdrawn at any time.
For data in Customer academies, the Customer determines the lawful basis, for example contract, public task for public schools, legitimate interests or consent.
Data subject rights
Individuals have the right to access, rectify and erase their personal data, to restrict or object to processing, to data portability, to withdraw consent, and not to be subject to decisions based solely on automated processing that significantly affect them. Aula does not make such decisions about learners.
Aula helps Customers respond to requests:
- admins can view, update and remove user accounts and their associated learning records;
- learning data such as grades, transcripts and progress can be exported through reports and the REST API;
- users can update their own profile details and language preferences;
- audit logs help Customers show who accessed or changed data and when.
When we receive a request that relates to a Customer academy, we forward it to that Customer and assist them as their processor.
Sub-processors
We use a limited number of carefully selected sub-processors, each bound by written data protection terms:
- Stripe for subscription billing, course checkout and instructor payouts;
- Cloudflare R2 for file and attachment storage;
- Bunny Stream for video hosting and adaptive streaming;
- LiveKit for in-browser live classes;
- Resend for transactional email;
- our infrastructure hosting providers for application servers, databases and caches.
Zoom processes data only for Customers who enable the Zoom integration. Identity providers such as Google, GitHub, Microsoft or a Customer's own SAML/OIDC provider are chosen by the Customer or user. We give Customers advance notice of new sub-processors and an opportunity to object, as described in the Data Processing Agreement.
International data transfers
Some sub-processors may process data outside the EEA or the UK. Where this happens, we rely on an adequacy decision or put in place the European Commission's Standard Contractual Clauses and, for UK data, the International Data Transfer Addendum. We assess transfers and apply supplementary measures such as encryption in transit where appropriate.
Security and privacy by design
Aula is built with data protection in mind:
- every tenant's data is isolated in the database with PostgreSQL row-level security;
- access is governed by roles (owner, admin, teacher, student, parent) with granular permissions;
- two-factor authentication and SAML/OIDC single sign-on are available;
- data is encrypted in transit, and passwords are stored only as secure hashes;
- audit logs record significant administrative actions;
- API keys and webhooks let Customers integrate without sharing user credentials.
If a personal data breach affects Customer data, we notify the affected Customers without undue delay so they can meet their own notification duties.
How to exercise your rights
- Learners, parents and teachers: contact the school or organisation that runs your academy. They control your data and can act on your request directly in Aula.
- Customers and website visitors: email privacy@example.com with your request and the email address linked to your account.
- Customers needing a DPA: request one from privacy@example.com or sales@example.com.
We may need to verify your identity before acting. We respond within the time limits required by the GDPR. You also have the right to lodge a complaint with a supervisory authority in the country where you live or work. Our postal address is [Company legal name], [Registered office address].