# GDPR Data Processing Addendum

### EU / EEA / UK — GDPR Article 28 Addendum to the Data Processing Agreement

> **Template notice.** This is a starting template, not legal advice. Have it
> reviewed by qualified legal counsel before you send or sign it. Replace every
> `[BRACKETED]` placeholder. This Addendum supplements the base Data Processing
> Agreement (COPPA & FERPA aligned); where the two conflict on EU/EEA/UK personal
> data, this Addendum controls.

---

This GDPR Data Processing Addendum (the "Addendum") is entered into as of
**[EFFECTIVE DATE]** and forms part of the Data Processing Agreement between:

- **Processor:** [YOUR LEGAL COMPANY NAME], operator of the [PRODUCT NAME]
  math-learning platform ("Processor," "we," "us"); and
- **Controller:** **[CONTROLLER LEGAL NAME]** (the school, district, or
  organisation) ("Controller," "you").

It applies whenever the Processor processes personal data protected by
Regulation (EU) 2016/679 ("GDPR") or the UK GDPR on the Controller's behalf.

---

## 1. Roles

1.1 The Controller is the **controller** and the Processor is the **processor**
for the personal data processed under the Agreement. For direct family
(self-serve) accounts with no school involved, [YOUR LEGAL COMPANY NAME] is the
**controller** and this Addendum's processor obligations are read as its own
first-party commitments.

1.2 The Processor processes personal data only on the Controller's documented
instructions, including the Agreement itself, unless required by law (in which
case it informs the Controller first, where legally permitted).

## 2. Subject Matter, Duration, Nature and Purpose (Art. 28(3))

- **Subject matter:** provision of an adaptive mathematics learning platform.
- **Duration:** the term of the Agreement plus the retention periods in Section 6.
- **Nature and purpose:** hosting, storage, and processing of student learning
  data to deliver and improve instruction.
- **Types of data:** first name, display name, grade level, learning activity
  (attempts, mastery, progress); for family accounts, the managing adult's email.
- **Categories of data subjects:** students (including children) and the
  parents/guardians/teachers who manage their accounts.
- **Special-category data:** none is intentionally processed.

## 3. Processor Obligations (Art. 28(3)(a)–(h))

The Processor will:

- (a) process personal data only on documented instructions, including for
  international transfers, unless required by law;
- (b) ensure persons authorised to process the data are under confidentiality
  obligations;
- (c) implement the technical and organisational measures in Section 5;
- (d) engage subprocessors only under Section 4;
- (e) assist the Controller, by appropriate measures, to respond to data-subject
  rights requests (access, rectification, erasure, restriction, portability,
  objection) — see Section 7;
- (f) assist the Controller with security, breach notification, DPIAs, and prior
  consultation (Arts. 32–36);
- (g) at the Controller's choice, delete or return all personal data at the end
  of the services and delete existing copies unless retention is required by law;
- (h) make available information necessary to demonstrate compliance and allow
  for and contribute to audits, including inspections.

## 4. Subprocessors (Art. 28(2), (4))

4.1 The Controller grants **general authorisation** for the Processor to engage
subprocessors. The current list is published at **https://konessancemath.com/subprocessors**
and currently includes hosting, database, email, payment, bot-protection, AI, and
computation providers.

4.2 The Processor will inform the Controller of intended changes (addition or
replacement of a subprocessor) with a reasonable opportunity to object, and will
impose data-protection obligations on each subprocessor equivalent to this
Addendum. The Processor remains liable for its subprocessors.

## 5. Security (Art. 32)

The Processor maintains technical and organisational measures including:
encryption in transit (TLS) and at rest via a managed database; row-level access
controls scoping each user to their own records; least-privilege administrative
access; rate limiting and automated bot protection on authentication; and use of
reputable cloud infrastructure. Measures are reviewed and updated as risks evolve.

## 6. Retention and Deletion

- Active accounts: retained while in use.
- Inactive student accounts: automatically deleted after **24 months** of
  inactivity.
- Support-chat transcripts: automatically deleted **90 days** after the last
  message.
- On termination or Controller request: deleted or returned within **30**
  days, and subprocessors directed to do the same, except where retention is
  legally required.

## 7. Data-Subject Rights (Arts. 12–22)

7.1 The platform provides self-service **data export** (access and portability)
and **account deletion** (erasure) for signed-in account holders. For
school-managed students, the Controller directs rectification and erasure; the
Processor provides tooling and assistance.

7.2 The Processor forwards any data-subject request it receives directly to the
Controller without undue delay and does not respond itself except on the
Controller's instruction.

## 8. International Transfers (Arts. 44–49)

8.1 Where the Processor or a subprocessor processes personal data outside the
EU/EEA or UK, the transfer is protected by an appropriate safeguard, primarily
the European Commission's **Standard Contractual Clauses (2021/914)** and, for UK
data, the **UK International Data Transfer Addendum** to those Clauses, which are
incorporated by reference.

8.2 Module Two (controller-to-processor) of the SCCs applies between the Controller
and the Processor. The SCC Annexes are populated by the corresponding parts of
this Addendum, which are incorporated as those Annexes: **Annex I.A (List of
Parties)** by Section 1 and the Signatures block; **Annex I.B (Description of
Transfer)** by Section 2; **Annex I.C (Competent Supervisory Authority)** by the
Controller's lead/local supervisory authority as identified in the Signatures
block; **Annex II (Technical and Organisational Measures)** by Section 5; and
**Annex III (List of Subprocessors)** by Section 4 and the list published at
https://konessancemath.com/subprocessors. The optional **docking clause (Clause
7)** applies; **audit** is governed by Section 10; and the **governing law and
forum** for Clauses 17–18 are those of the Controller's EU/EEA Member State
(or, for UK transfers under the UK IDTA, the law of England and Wales).

8.3 The Processor will make available transfer-impact information on request and
will implement supplementary measures where required.

8.4 **Transactional email routing.** For data subjects in the EEA/UK, the
Processor dispatches transactional email (e.g. account and support messages)
through its email subprocessor's **EU region (Ireland, eu-west-1)**. Data
subjects should note that the email subprocessor stores certain email metadata
and delivery logs in the **United States** regardless of the sending region;
that onward transfer is covered by the safeguards in this Section 8 (SCCs / UK
IDTA) and the subprocessor's own data-processing terms. The Processor minimises
the personal data contained in email payloads (for example, using a chosen
display name rather than a legal name, and not including a date of birth) to
limit what is transferred and stored. This is **not** a representation that
email data never leaves the EEA/UK.

## 9. Breach Notification (Art. 33)

9.1 The Processor will notify the Controller **without undue delay** and no later
than **48 hours** after becoming aware of a personal-data breach, providing the
information the Controller needs to meet its own 72-hour supervisory-authority
notification duty under Article 33. See the Breach-Response Runbook.

## 10. Audit and Records (Arts. 28(3)(h), 30)

10.1 The Processor maintains records of processing activities and will, on
reasonable notice and subject to confidentiality, provide information and support
audits necessary to demonstrate compliance.

## 11. Data Protection Contacts

- **Controller contact / DPO:** **[CONTROLLER DPO NAME / EMAIL]**
- **Processor contact / DPO:** **[PROCESSOR DPO NAME / EMAIL]**
- **Processor EU representative (Art. 27), if applicable:** **[EU REP NAME /
  ADDRESS]**
- **Processor UK representative (Art. 27 UK GDPR), if applicable:** **[UK REP
  NAME / ADDRESS]**

---

## Signatures

**Processor — [YOUR LEGAL COMPANY NAME]**

- Signature: ______________________________
- Name: **[NAME]**  · Title: **[TITLE]**  · Date: **[DATE]**

**Controller — [CONTROLLER LEGAL NAME]**

- Signature: ______________________________
- Name: **[NAME]**  · Title: **[TITLE]**  · Date: **[DATE]**
