TeachAid Data Processing Agreement
This Data Processing Agreement (“DPA”) is an addendum to the legal Agreement between the Customer (“Controller”) and TeachAid (“Processor”) for your use of TeachAid's Services.
Definitions
-
Customer Personal Data: All Personal Data processed by TeachAid on behalf of the Customer.
-
Data Protection Law: Includes but is not limited to:
-
General Data Protection Regulation (GDPR);
-
UK Data Protection Act 2018;
-
Applicable U.S. state privacy laws (e.g., FERPA, SOPIPA, and COPPA).
-
-
Sensitive Data: Includes personal identifiers, biometric data, and other special categories under GDPR.
-
Sub-Processor: An entity engaged by TeachAid to process Customer Personal Data.
-
Standard Contractual Clauses (SCCs): European Commission-approved clauses for international data transfers.
Roles and Responsibilities
-
The Customer is the Controller and determines the purpose of processing.
-
TeachAid is the Processor and processes data on behalf of the Customer for the purposes outlined in Annex A.
-
TeachAid will:
-
Only process Customer Personal Data per documented instructions.
-
Notify the Customer if any instructions appear non-compliant with Data Protection Laws.
-
-
The Customer shall:
-
Ensure all data is collected lawfully.
-
Provide necessary notifications and obtain required consents.
-
-
TeachAid does not accept liability for Sensitive Data supplied in violation of this agreement.
Security
TeachAid shall:
-
Implement appropriate technical and organizational measures per Article 32 of GDPR, including:
-
Data encryption at rest and in transit.
-
Access controls and regular security training for personnel.
-
-
Maintain up-to-date security policies and ensure they are regularly audited.
-
Ensure all personnel authorized to process data are bound by confidentiality.
Security Incidents and Notification
-
TeachAid will:
-
Notify the Customer of any Personal Data Breach without undue delay, within 24 hours where feasible.
-
Cooperate with the Customer in fulfilling legal notification obligations.
-
-
Such notification will include:
-
The nature of the breach.
-
Steps taken to mitigate risks.
-
Recommendations for the Customer.
-
Cooperation and Assistance
TeachAid will assist the Customer with:
-
Responding to Data Subject rights requests under applicable law.
-
Conducting data protection impact assessments (DPIAs).
-
Complying with obligations for supervisory authority consultations.
-
Any assistance provided beyond routine operations may incur additional costs.
Audit Rights
-
TeachAid will:
-
Provide necessary documentation to demonstrate compliance.
-
Allow for audits and inspections, subject to reasonable notice.
-
-
Audits are limited to one per year unless required due to legal obligations.
-
Costs of such audits are borne by the Customer unless non-compliance is identified.
Use of Sub-Processors
-
TeachAid may engage Sub-Processors and will:
-
Ensure Sub-Processors meet equivalent data protection standards.
-
Notify Customers of any new Sub-Processors, allowing a 15-day objection period.
-
-
Current Sub-Processors are listed in the Annex.
International Transfers
-
TeachAid will:
-
Use SCCs for any transfers outside of the EU/EEA.
-
Ensure Sub-Processors adhere to similar safeguards for international data transfers.
-
-
TeachAid ensures compliance with U.S.-EU Privacy Shield requirements or equivalent frameworks, where applicable.
Data Retention and Deletion
-
Upon termination, TeachAid will:
-
Delete or return all Customer Personal Data per Customer instructions.
-
Retain backup data only as required by applicable law or legitimate legal needs.
-
-
Deletion requests must comply with TeachAid’s retention policies and timelines.
Annex A – Details of Data Processing
-
Processor: TeachAid.
-
Controller: The Customer.
-
Nature of Processing: Delivery of educational services, including curriculum management and analytics.
-
Categories of Data Subjects: Students, teachers, and administrative users.
-
Data Types: Email addresses, names, grades, curriculum plans, and activity logs.
Annex B – Security Measures
TeachAid’s security measures include but are not limited to:
-
Encryption: AES-256 for data at rest and TLS for data in transit.
-
Access Control: Role-based access with multi-factor authentication.
-
Monitoring: Real-time threat detection systems.
-
Incident Management: Comprehensive incident response plans.