Parties and scope
This Data Processing Agreement ("DPA") forms part of the agreement between the subscribing education institution ("Controller") and Academqo, with registered office at de Winterstraat 30, 5703XW in Helmond, the Netherlands. registered under KvK: 98051997, VAT: NL005306680B37 ("Processor" or "Academqo").
This DPA applies where Academqo processes personal data on behalf of the Controller through the Service.
Subject matter and duration
Processor provides education institution management software. Processor processes personal data on behalf of Controller for the duration of the subscription and until deletion or return obligations are fulfilled, subject to the retention terms in the Privacy Policy and this DPA.
Nature and purpose of processing
Processing is limited to hosting, storing, organising, transmitting, securing, and otherwise handling personal data as necessary to provide the Service, support users, maintain security, and comply with Processor's legal obligations.
Categories of data and data subjects
Depending on Controller's use of the Service, processing may concern:
- Data subjects: institution administrators, teachers, students, applicants, and other users invited by Controller
- Categories of data: identification and contact data, account and role data, educational records, schedules, enrollments, assignments, submissions, communications, files, and technical usage data
Controller is responsible for ensuring that personal data uploaded to the Service is collected and used lawfully.
Controller obligations
Controller shall:
- determine the purposes and means of processing for institution-controlled data
- provide appropriate privacy notices to data subjects
- ensure a lawful basis exists for processing, including where student or minor data is involved
- ensure instructions to Processor comply with applicable data protection law
- respond to data subject requests where Controller is responsible, except where Processor is required to assist under this DPA
Processor obligations
Processor shall:
- process personal data only on documented instructions from Controller, including through use of the Service and documented support requests, unless required by law
- ensure personnel authorised to process personal data are bound by confidentiality obligations
- implement appropriate technical and organisational security measures
- assist Controller, taking into account the nature of processing, with data subject requests, security incidents, and data protection impact assessments where reasonably required
- delete or return personal data upon termination of the Service, subject to legal retention requirements and the retention schedule in the Privacy Policy
- make available information reasonably necessary to demonstrate compliance with Article 28 GDPR
Processor may refuse instructions that violate applicable law or materially compromise platform security or other customers.
Sub-processors
Controller provides general authorisation for Processor to engage sub-processors necessary to provide the Service. Current sub-processors are listed in the Privacy Policy.
Processor will inform Controller of intended changes to sub-processors and provide an opportunity to object on reasonable grounds relating to data protection. If Controller reasonably objects and the parties cannot resolve the objection, Controller may terminate the affected Service.
Processor remains responsible for sub-processor performance of data protection obligations.
Security measures
Processor maintains measures appropriate to the risk, which may include access controls, tenant isolation, encryption in transit, logging, backup procedures, and incident response processes.
Personal data breaches
Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller personal data and provide information reasonably available to assist Controller in meeting breach notification obligations.
Data subject requests
Where Processor receives a request directly from a data subject relating to Controller personal data, Processor will promptly inform the data subject to contact Controller unless Processor is legally permitted and able to respond on Controller's behalf.
Processor will provide reasonable assistance to Controller in responding to data subject requests, taking into account the nature of processing and information available to Processor.
Audits and information
Upon reasonable written request, Processor will provide information necessary to demonstrate compliance with this DPA and allow audits mandated by applicable law, subject to confidentiality, security, and operational constraints. Routine audits may be conducted no more than once per year unless required by a supervisory authority or following a material security incident.
International transfers
Processor uses EU-region hosting where possible. Where personal data is transferred outside the EEA, Processor will ensure appropriate safeguards such as Standard Contractual Clauses or other lawful mechanisms.
Deletion and return
Upon termination of the Service, Controller may export available data during any applicable access period. Thereafter, Processor will delete or anonymise Controller personal data within 90 days, except where retention is required by law, for accounting records, security logs, or limited backup retention.
Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service, except where liability cannot be limited under applicable law.
Order of precedence
If there is a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails to the extent of the conflict.
Contact
For DPA enquiries: privacy@academqo.com