Data Processing Agreement
Version: August 2026
between
the customer using eDoer under a Service Agreement
(“Controller”)
and
Education4All GmbH
Registered office: Hildesheim, Germany
Registered with the commercial register of the Local Court of Hildesheim under HRB 210458
as operator of the “eDoer” learning platform
(“Processor”)
Controller and Processor together referred to as the “Parties”.
This Data Processing Agreement (“DPA”) forms part of the Service Agreement between the Parties.
eDoer is the learning platform and related services operated by Education4All GmbH. In this agreement, references to eDoer describe the Platform and, where legal responsibility is concerned, Education4All GmbH as its operator.
1. Subject Matter and Duration
1.1 This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the provision of the eDoer learning platform.
1.2 This DPA applies only to personal data processed by eDoer strictly on behalf of the Controller.
1.3 Processing activities performed by eDoer as an independent controller (see Section 5.4) are not subject to this DPA.
1.4 The Processor provides a multi-tenant learning management platform (“eDoer”) enabling the Controller to:
- Create and manage organizations
- Register and manage users
- Create and manage learning paths, modules, and courses
- Deliver assessments and evaluations
- Issue certificates
- Enable communication within the organization
- Provide in-app notifications and transactional notification email
- Store educational content and related materials
- Configure AI-assisted features, including organization knowledge base files and learner background documents where enabled
- Enable approved third-party document imports where enabled
The Processor processes personal data solely to provide these services.
1.5 Processing shall take place for the duration of the Service Agreement.
Upon termination of the Agreement, personal data shall be deleted or returned in accordance with the provisions of the DPA, unless statutory retention obligations apply.
2. Nature and Purpose of Processing
2.1 Processing is carried out primarily by automated means within secured server infrastructure and may include:
- Collection
- Recording
- Organization and structuring
- Storage
- Retrieval and consultation
- Limited transmission to authorized sub-processors
- AI-based processing where enabled by the Controller
- Import from approved third-party document sources where enabled
- Deletion or anonymization
Processing is limited to what is necessary for the provision of the services.
2.2 The Processor processes personal data for the purpose of:
- Providing and maintaining the learning platform
- Enabling course management and delivery
- Processing assessments and learning progress
- Generating certificates
- Facilitating communication within the organization
- Providing recipient-specific notifications, moderation communications, and transactional notification email
- Storing and organizing educational and reference materials
- Supporting AI-assisted features configured by the Controller, including organization knowledge base files and learner background documents where enabled
- Supporting approved third-party document imports where enabled
- Providing technical support
The data processor does not process personal data for its own marketing purposes or for its own commercial gain. Processing is limited to what is necessary for the provision of the services.
The Processor shall process personal data only on documented instructions from the Controller.
If the Processor considers that an instruction infringes the GDPR or other applicable Union or Member State data-protection law, it shall immediately inform the Controller and may suspend the affected processing until the instruction is confirmed, amended, or withdrawn.
3. Categories of Data Subjects
- Learners (students)
- Teachers / curators
- Organization administrators
- Other authorized users designated by the Controller
4. Categories of Personal Data
Data processing may involve personal data, a list of the used categories can be found in Annex I.1.
The Services do not require special categories of data under Article 9 GDPR. Such data may nevertheless appear in free text, messages, attachments, learner background documents, imported files, or AI inputs. The Controller shall not submit or authorize such data unless it has documented an Article 9 condition, the purpose, affected features, access restrictions, retention, and any required DPIA. The Processor shall process permitted special-category data only on documented instructions and with the safeguards in Annex II.
5. Roles of the Parties
5.1 The Controller determines the purposes and means of processing educational data within the platform.
5.2 The Processor processes personal data exclusively on behalf of the Controller pursuant to Article 28 GDPR.
5.3 The Parties classify each processing activity according to their actual determination of its purposes and essential means. The Parties do not intend joint controllership for the processing described in Annex I; if they jointly determine a separate activity, they shall conclude and make available the essence of an Article 26 arrangement before that activity begins.
5.4 eDoer acts as an independent controller only for distinct processing whose purposes and essential means it determines, including account and tenant security, fraud and abuse prevention, system stability and infrastructure monitoring, consent-based browser telemetry, consent and contract evidence, organization subscription billing, statutory financial administration, mandatory platform communications, and legal compliance. Such processing is governed by eDoer’s Privacy Policy and controller RoPA and is outside this DPA.
5.5 Where Marketplace Services are enabled, eDoer acts as an independent controller for the marketplace purposes it independently determines, including platform commissions, reconciliation, platform security, fraud and loss prevention, platform audit records, and statutory financial administration. Seller, Stripe, and eDoer roles for onboarding, checkout, payment, refunds, disputes, and compliance are determined per activity under the applicable agreements and actual allocation of purposes and essential means. Any processor or joint-controller activity must be documented before activation.
5.6 Learning-path enrollment, access, progress, assessment, and certification data arising after a marketplace purchase remain processed on the Controller’s documented instructions under this DPA. A marketplace purchase reference and entitlement status may be linked to the learner record solely to grant, suspend, restore, or revoke the corresponding access.
5.7 Where a notification or transactional email is generated from educational or organizational activity controlled by the Controller, eDoer processes the notification content and delivery data on the Controller’s documented instructions. Processing by eDoer for its own account security, billing, legal obligations, fraud prevention, or mandatory platform administration remains outside this DPA and is described in the Privacy Policy.
5.8 The Controller is responsible for establishing a lawful basis and, where applicable, an Article 9 condition; providing Articles 13 and 14 information; determining lawful retention and access; ensuring the accuracy and proportionality of instructions; managing permissions; and completing any required DPIA or prior consultation.
5.9 Where Users may be minors, the Controller shall document the applicable authorization, age-appropriate transparency, safeguarding, and feature-configuration requirements. eDoer remains responsible for these obligations for processing in which it acts as controller.
6. AI-Assisted Features
6.1 The platform may use AI services to support educational features, including:
- Learning path generation
- Educational content generation and assistance
- Exam generation
- Retrieval and grounding based on organization knowledge base files
- Personalized assistance using learner background documents where enabled
6.2 AI services process only data that the Controller or an authorized user elects to make available for AI functionality, which may include:
- Learning path metadata
- Educational content created by the Controller
- Organization-designated knowledge base files
- Learner background documents uploaded where enabled
- Voluntarily submitted free-text prompts
- User-submitted attachments
6.3 The Processor does not intentionally transmit learner performance data, assessment results, progress tracking data, or platform account identifiers as separate structured AI inputs. However, such data may be contained in content, files, prompts, attachments, or background documents intentionally submitted by the Controller or an authorized user for AI processing.
6.4 The Processor implements data-minimization measures and does not solicit special-category data for AI processing. The Controller remains responsible for determining whether submitted AI input contains personal data, including special-category data, whether the submission is lawful and necessary, and whether a DPIA is required. The Processor shall provide information reasonably necessary for that assessment and shall not use submitted data for independent model training under the applicable enterprise/API terms.
6.5 Where approved document-source integrations such as e.g. Roxtra are enabled by platform-level administration and the Controller, the Processor may process the connecting user’s integration username and encrypted credential material to authenticate with the third-party source, search documents, and import selected files into eDoer.
6.6 Imported third-party files are stored in eDoer and thereafter processed like other files uploaded to the platform under the Controller’s instructions.
6.7 Third-party source systems designated by the Controller for search and import are not sub-processors engaged by the Processor unless expressly listed in Annex III.
7. Sub-Processors
7.1 The Controller authorizes the Processor to engage sub-processors.
7.2 Sub-processors may include:
- Cloud hosting providers
- Object storage providers
- Email service providers
- Infrastructure and security providers
- AI service providers (e.g., OpenAI, Google Cloud/Gemini)
- Automated data-gathering providers used on demand for approved source-import and preprocessing flows (currently Decodo for certain YouTube metadata and transcript requests)
7.3 The Processor shall:
- Enter into written agreements with sub-processors in accordance with Article 28 GDPR
- Impose by written contract the same data-protection obligations required by Article 28(3) GDPR, including documented instructions, confidentiality, security, assistance, deletion or return, and audit support,
- Remain fully liable for sub-processor’s performance
7.4 Enterprise AI agreements prohibit the use of submitted data for model training where applicable.
7.5 The Processor shall provide at least 30 days’ prior notice of an intended addition or replacement of a sub-processor where reasonably practicable. The Controller may object during that period on reasonable data-protection grounds. The Parties shall seek a practicable resolution; if none is available, the Controller may terminate the affected Service before the change takes effect. Emergency security or availability changes may occur on shorter notice, with reasons provided without undue delay.
8. International Transfers
8.1 Where personal data is transferred outside the EU/EEA, the Processor ensures appropriate safeguards under Chapter V GDPR.
8.2 Primary processing by a sub-processor in the EU/EEA is not treated as a third-country transfer. Where personal data is transferred onward outside the EU/EEA, the applicable safeguards may include the European Commission Standard Contractual Clauses and the EU-US Data Privacy Framework where available and applicable.
- Standard Contractual Clauses apply where required for an onward third-country transfer.
- The EU-US Data Privacy Framework will be used where available and legally applicable.
Further details can be found in Annex III.
8.3 The Processor maintains and documents a Transfer Impact Assessment.
9. Security Measures
The Processor implements appropriate technical and organizational measures, including:
- Encrypted transmission (TLS)
- Role-based access control
- Organization-level data isolation through architecture
- Logging of administrative access
- Encryption of stored third-party integration credentials
- Incident response procedures
A summary of technical and organizational measures is attached as Annex II.
10. Data Subject Rights
- The Processor shall assist the Controller in responding to requests under Articles 15–22 GDPR.
- The Controller remains responsible for responding to such requests.
11. Personal Data Breach
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA and shall provide available information necessary for Articles 33 and 34 GDPR, including the nature of the breach, affected data and data-subject categories, approximate scale where known, likely consequences, mitigation, and a contact point. Information may be supplied in phases as the investigation progresses. The Processor shall document the incident, preserve relevant evidence, cooperate with the Controller, and assist with obligations under Articles 32–36 GDPR, including DPIAs and prior consultation.
12. Deletion and Return of Data
Upon termination of the Service Agreement, the Processor shall:
- At the Controller’s choice, delete or return personal data and delete remaining copies, unless applicable law requires continued storage
- Retain data only where legally required
Personal data remaining in backups shall be isolated from ordinary use, protected, and deleted on the documented backup lifecycle. If deletion is temporarily impossible, the Processor shall continue to apply this DPA and process the data only for restoration, security, or a documented legal requirement.
12.1 Unless the Controller gives a lawful documented instruction requiring earlier deletion, or applicable law requires longer storage, the Processor applies the following standard technical retention schedule to personal data processed under this DPA:
- Soft-deleted AI conversations and their associated messages, generation-job records, and usage records are permanently removed after a recovery period of up to 30 days.
- Completed AI generation-job records and per-call token-usage records are retained for 90 days.
- Temporary generated-image output expires after 1 hour and is removed with its temporary job record by scheduled cleanup.
- Derived AI indexes and necessary source mappings are retained while the underlying source exists. Deletion of the source triggers removal from the retrieval system; failed or delayed removals are remediated so deletion is completed within 30 days. Completed removal-job metadata is retained for 90 days.
- Rotated AI service log files are retained for no more than 14 days and may be deleted sooner through size-based rotation. Other processor-side operational logs containing Controller personal data are retained for no more than 90 days unless a shorter operational period applies.
- Expired verification tokens are removed 30 days after expiry; read or seen notifications after 90 days; unread and unseen notifications after 180 days; terminal notification-email delivery records after 180 days; and consent audit records and the minimal completed user-erasure audit ledger after 730 days.
12.2 The database retention process runs once per day and once when the privacy worker starts. AI-service cleanup runs at shorter intervals to enforce temporary-image and AI-record expiry. These schedules do not delay a valid data subject or Controller deletion instruction where earlier deletion is required and technically possible.
12.3 Encrypted database backups are created daily and retained for 7 days on a rolling basis. Deleted data is not restored to ordinary use. Before a restored backup serves production traffic, applicable deletion records are reapplied. A documented legal hold or statutory obligation may suspend deletion only for the affected data and required period, with access restricted accordingly.
13. Audit Rights
13.1 The Processor shall make available information necessary to demonstrate compliance with Article 28 GDPR and this DPA.
13.2 Audits, including inspections, carried out by the Controller or an independent auditor mandated by it shall be permitted on reasonable notice and in an appropriate and proportionate manner that protects confidentiality, security, and other customers’ data.
13.3 Current independent audit reports or certifications may be used to satisfy reasonable audit requirements where they provide sufficient relevant assurance, without limiting the Controller’s rights where additional verification is required.
14. Liability
Liability is governed by the Service Agreement and Article 82 GDPR.
Annex I – Processing Description
This Annex forms part of the Data Processing Addendum between the Parties.
1. Categories of Personal Data
The processing may involve the following categories:
1.1 Identification and Account Data
- Name
- Email address
- User role
- Organizational affiliation
1.2 Educational Data
- Enrollment information
- Learning progress
- Assessment results
- Submitted assignments
- Completion status
1.3 Certification Data
- Name
- Grade or completion status
- Date of issuance
1.4 Communication Data
-
Topics and messages within path, curator-only, and direct-conversation scopes
-
Replies, mentions, reactions, attachments, topic participants and scope, and read-state timestamps
-
Reports, reporter identity, report reason, shared-thread choice, status, moderation action and actor, and related timestamps
-
Where a reporter elects to share a thread, the relevant discussion may become accessible to an otherwise authorized moderator for review of the pending report
1.5 Files and Reference Materials
- Uploaded files
- Organization knowledge base files and related reference materials where enabled
- Learner background documents where enabled
- Imported files from approved third-party document sources where enabled
1.6 Optional Integration Data
- Third-party document-source username for each user
- Encrypted credential material required to authenticate and import files
- Import metadata and logs
- External source URLs, YouTube video or playlist identifiers, language preferences, and retrieved public metadata or transcript content where Decodo-assisted import or preprocessing is used
1.7 Technical Data
- Timestamps
- Log information necessary for system operation
- IP address (where technically required)
Special-category data is not required but may appear in User-submitted or imported content. The Controller shall identify the applicable Article 9 GDPR condition and documented instructions before authorizing such processing. The Processor applies role-based access, tenant isolation, encrypted transport, support-access controls, minimization, deletion instructions, and the other measures in Annex II.
1.8 Marketplace-Derived Learning Access Data (where enabled)
-
Learner user identifier
-
Purchased learning path and access-entitlement status
-
Purchase reference and fulfillment, suspension, or revocation timestamps
-
No payment-card, bank-account, or seller-verification documents are intentionally stored in the educational learner record
1.9 Notification and Email Delivery Data
- Recipient user and Organization identifiers; event type and category; activity-derived payload and context; destination; and created, updated, read, seen, and deletion timestamps
- Notification-email category preferences and whether optional email is enabled
- Scheduled delivery time, delivery status and skip reason, attempt count, provider message identifier, reconciliation key, acceptance, sent, skipped and failed timestamps, and error information
- Email sender and recipient, subject, text and HTML body, and attachments where applicable
2. Instruction Limitation
The Processor shall process personal data exclusively on documented instructions of the Controller and shall not determine the purposes or essential means of processing under this Annex.
Annex II – Technical and Organizational Measures
This Annex describes the technical and organizational measures implemented by the Processor to ensure an appropriate level of security.
1. Organizational Measures
1.1 Governance and Responsibility
- Clear internal allocation of data protection responsibilities
- Management oversight of data protection compliance
- Documented privacy and security policies
- Access to production systems limited to authorized personnel only
1.2 Confidentiality Obligations
- All personnel are bound by confidentiality agreements
- Access to personal data restricted on a need-to-know basis
- Role-based access management enforced
1.3 Training and Awareness
- Staff involved in development and operations receive data protection and security awareness training
- Developers are instructed in data minimization principles, especially for AI integrations and third-party document imports
2. Access Control
2.1 Logical Access Control
- Role-Based Access Control (RBAC)
- Authentication required for all administrative actions
- Strong password requirements
- Password hashing using industry-standard algorithms (e.g., bcrypt/argon2)
2.2 Administrative Access
- Administrative access limited to authorized personnel
- Super-admin access only for:
- Technical troubleshooting
- Security investigation
- Documented support requests
- Administrative actions are logged
- Access subject to internal approval procedures where applicable
3. Infrastructure Security
3.1 Hosting Environment
- Application, file storage, and database servers are hosted on infrastructure provided by Hetzner in EU data center locations
- Firewalls restrict unnecessary inbound connections
- Database servers are not publicly exposed
3.2 Network Security
- All external communication encrypted via TLS (HTTPS)
- Application traffic routed through Cloudflare proxy
- DDoS mitigation and traffic filtering enabled
- Secure DNS configuration
3.3 Database Security
- Database access restricted to application layer
- No public database endpoints
- Access credentials stored securely using environment variables
- Regular updates and patching of system software
4. Data Isolation (Multi-Tenant Architecture)
- Strict organization-level data separation enforced at application layer
- Authorization checks implemented on all data access endpoints
- No cross-organization data access is permitted except for documented, authorized, time-limited support or security access described in this DPA
- AI requests are tenant-isolated (no cross-tenant data mixing)
5. Encryption
- TLS 1.2+ enforced for all external traffic
- Encrypted API communication with sub-processors (OpenAI, Google Cloud, and Amazon Simple Email Service (Amazon SES))
- Third-party integration credentials stored in encrypted form
- Signed or time-limited file URLs used for non-public file access where applicable
6. Backup and Recovery
-
Daily automated database backups
-
Rolling backup retention of 7 days
-
Secure storage of backup files
-
Backup access restricted to authorized personnel
-
Documented restoration and continuity procedures
-
Periodic validation that backups required for recovery can be restored
-
Protected deletion of backups after the 7-day lifecycle
-
Reapplication of applicable deletion records before a restored backup serves production traffic
7. Logging and Monitoring
-
Application error logging enabled
-
Security-relevant events logged
-
Administrative access logged
-
Rotated AI service file logs retained for no more than 14 days, subject to earlier size-based rotation
-
Other processor-side operational logs containing Controller personal data retained for no more than 90 days unless a shorter period applies
-
Logs protected against unauthorized modification
-
Documented incident classification, escalation, containment, evidence preservation, and post-incident review
-
Risk-based review and testing of the effectiveness of technical and organizational measures
-
Periodic access review, vulnerability remediation, and security-update processes
8. Development and Testing Controls
- Development and production environments logically separated
- AI analytics disabled in development environments
- Test data does not intentionally contain production personal data
- Deployment processes controlled
9. Data Minimization in AI Processing
- AI processing is limited to:
- Educational content
- Learning path metadata
- Examination texts
- Voluntarily submitted free-text requests
- No intentional transmission of:
- Learner performance data
- Assessment results
- Account identifiers
- Special categories of personal data
- Enterprise AI agreements prohibit, where applicable, the use of submitted data for model training.
- AI processing takes place exclusively on a request-response basis (no bulk data export).
10. Physical Security
- Physical security is managed by the infrastructure providers actually used for the Services, including Hetzner, Cloudflare, and the AWS entities supporting Amazon SES in Europe (Frankfurt), as identified in the current sub-processor register
- Providers maintain industry-standard physical access controls
11. Regular Review
- Technical and organizational measures reviewed periodically
- Adjusted based on:
- Risk assessment
- Infrastructure changes
- Regulatory developments
Annex III – List of Sub-Processors
The subprocessors are listed below under the following subheadings:
- Address
- Service
- Location
- Transfer mechanism
OpenAI Ireland Ltd.
- 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland
- AI-assisted content processing and generation
- European Union (primary processing entity); possible transfer to US affiliates
- Standard Contractual Clauses (SCC) and EU-US Data Privacy Framework (DPF)
Google Cloud (Google LLC / Google Ireland Ltd.)
- Gordon House, Barrow Street, Dublin 4, Ireland
- AI services (Gemini)
- European Union
- Standard Contractual Clauses (SCC) and EU-US Data Privacy Framework (DPF)
Hetzner Online GmbH / Hetzner Finland Oy
- Industriestr. 25; 91710 Gunzenhausen; Germany
- Application, object storage, and database hosting
- Germany / Finland (EU)
- Not applicable
Cloudflare, Inc.
- 101 Townsend Street, San Francisco, California, 94107-1934, USA
- Reverse Proxy, Content Delivery Network (CDN), DDoS-Protection, TLS-termination
- European Union / USA
- Standard Contractual Clauses (SCC) and EU-US Data Privacy Framework (DPF), if applicable
Amazon Web Services EMEA SARL
- 38 Avenue John F. Kennedy, L-1855 Luxembourg. AWS infrastructure affiliates and subprocessors are governed by the current AWS DPA and AWS subprocessor list; the relevant Frankfurt infrastructure entity is identified there where applicable.
- Transactional and notification email delivery through Amazon Simple Email Service (Amazon SES)
- Europe (Frankfurt), Germany (eu-central-1)
- Standard Contractual Clauses (SCC) and EU-US Data Privacy Framework (DPF), provided data is transferred to a third country
Decodo (UAB “Data troops”)
- Švitrigailos str. 34, Vilnius, Lithuania
- On-demand Web Scraping API used for certain YouTube playlist, video metadata, and transcript retrieval flows
- Lithuania (EU); request routing may involve infrastructure or requested public sources in other countries depending on the target and service configuration
- Not applicable for processing in Lithuania; Standard Contractual Clauses or another lawful Chapter V safeguard apply where required for onward transfers
Whereby AS
- Gate 1 no. 107, 6700 Måløy, Norway
- Video chatting support
- Norway (European Economic Area)
- Not applicable
