Data Processing Agreement

GDPR Article 28 Compliant Agreement between Elevate Solutions (Processor) and Educational Institutions (Controllers)

Last updated: September 29, 2026

This Data Processing Agreement ("DPA") forms part of the contract between the Customer (the "Controller") and Elevate Solutions (the "Processor") for the provision of educational platform services. This DPA reflects the parties' agreement with regard to the processing of Personal Data in accordance with the requirements of Data Protection Laws.

Binding Agreement

By using Elevate Skills Academy services, the Controller agrees to the terms of this DPA. This agreement is legally binding and enforceable under GDPR Article 28.

1. Definitions

"Controller" means the educational institution (school, university, or organization) that determines the purposes and means of processing Personal Data.

"Processor" means Elevate Solutions, which processes Personal Data on behalf of the Controller.

"Data Protection Laws" means all applicable laws relating to data protection and privacy including GDPR, CCPA, PDPA, and other relevant regulations.

"Personal Data" means any information relating to an identified or identifiable natural person processed through Elevate Skills Academy services.

"Processing" has the meaning given in GDPR Article 4(2).

"Sub-processor" means any third party appointed by the Processor to process Personal Data.

2. Scope and Purpose of Processing

2.1 Subject Matter

The Processor will process Personal Data as necessary to provide the educational simulation platform services to the Controller, including student data management, progress tracking, and reporting.

2.2 Duration

Processing will continue for the duration of the service agreement and for a reasonable period thereafter as required for data deletion or return.

2.3 Nature and Purpose

The processing is for the following purposes:

  • Providing educational simulation platform access
  • Student account management and authentication
  • Tracking student progress and performance
  • Generating educational reports and analytics
  • Teacher administrative functions
  • Platform maintenance and technical support

2.4 Types of Personal Data

  • Student names and contact information
  • Teacher and administrator names and contact information
  • School/organization details
  • Account credentials (encrypted)
  • Student performance data and learning outcomes
  • Usage and interaction data
  • Technical data (IP addresses, device information)

2.5 Categories of Data Subjects

  • Students (including minors)
  • Teachers and educators
  • School administrators
  • Parent/guardian contacts (where applicable)

3. Processor Obligations

3.1 Processing Instructions

The Processor shall process Personal Data only on documented instructions from the Controller, unless required to do so by law. The Processor shall immediately inform the Controller if it believes an instruction violates Data Protection Laws.

3.2 Confidentiality

The Processor shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

3.3 No Onward Transfer

The Processor shall not transfer Personal Data outside the EEA without prior written consent from the Controller and appropriate safeguards in place (Standard Contractual Clauses or adequacy decisions).

3.4 Assistance to Controller

The Processor shall, taking into account the nature of processing, assist the Controller by appropriate technical and organizational measures in:

  • Fulfilling Controller's obligation to respond to data subject requests
  • Ensuring compliance with data security obligations
  • Conducting Data Protection Impact Assessments
  • Consulting with supervisory authorities

4. Security of Processing

The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

Encryption:

Pseudonymization and encryption of Personal Data both in transit (TLS 1.3) and at rest (AES-256)

Confidentiality:

Ensuring ongoing confidentiality through access controls, authentication, and authorization mechanisms

Integrity and Availability:

Ensuring ongoing integrity and availability of processing systems and services through redundancy and backups

Resilience:

Ability to restore availability and access to Personal Data in a timely manner in the event of incident

Testing and Evaluation:

Regular testing, assessment, and evaluation of effectiveness of technical and organizational measures (annual penetration testing, quarterly security audits)

Incident Response:

Documented incident response and breach notification procedures

5. Use of Sub-processors

5.1 General Authorization

The Controller provides general authorization for the Processor to engage Sub-processors for specific processing activities. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-processors, giving the Controller the opportunity to object within 30 days.

5.2 Current Sub-processors

Sub-processorServiceLocation
Amazon Web Services (AWS)Cloud hostingEU (Frankfurt)
Google Cloud PlatformAnalytics servicesEU (Belgium)
SendGridEmail deliveryEU

5.3 Sub-processor Obligations

The Processor shall impose the same data protection obligations on Sub-processors as set out in this DPA, and remain fully liable to the Controller for the performance of Sub-processor obligations.

6. Personal Data Breach Notification

The Processor shall notify the Controller without undue delay (and in any event within 24 hours) after becoming aware of a Personal Data Breach affecting the Controller's Personal Data.

Breach Notification Must Include:

  • Description of the nature of the Personal Data Breach
  • Categories and approximate number of data subjects affected
  • Categories and approximate number of Personal Data records affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate potential adverse effects
  • Name and contact details of the Processor's data protection officer or contact point

The Processor shall cooperate with the Controller and provide reasonable assistance as necessary to enable the Controller to comply with its obligations under Data Protection Laws regarding breach notification to supervisory authorities and data subjects.

7. Assistance with Data Subject Rights

The Processor shall, taking into account the nature of processing, assist the Controller by implementing appropriate technical and organizational measures to fulfill the Controller's obligations to respond to requests from data subjects exercising their rights under Data Protection Laws, including:

Right of access (Article 15 GDPR)
Right to rectification (Article 16 GDPR)
Right to erasure (Article 17 GDPR)
Right to restriction (Article 18 GDPR)
Right to data portability (Article 20 GDPR)
Right to object (Article 21 GDPR)

The Processor shall forward any data subject requests received directly to the Controller without delay and shall not respond to such requests except on documented instructions from the Controller or as required by law.

8. Deletion or Return of Personal Data

At the choice of the Controller, the Processor shall delete or return all Personal Data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless applicable law requires storage of Personal Data.

Timeline and Process:

  • The Controller must request deletion or return within 30 days of service termination
  • The Processor will complete deletion or return within 60 days of the request
  • Deletion will be certified with a written confirmation
  • Backup copies will be securely deleted within 90 days
  • Personal Data required for legal compliance will be retained only as long as legally mandated

9. Audit and Inspection Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with obligations under this DPA and Data Protection Laws.

Annual Audits:

The Processor conducts annual third-party security audits (SOC 2 Type II) and makes summary reports available to Controllers upon request.

Controller Audits:

The Controller may conduct audits and inspections with 30 days' prior written notice, no more than once per year unless required by supervisory authority or in case of suspected breach.

Costs:

Controller bears the costs of Controller-initiated audits. Processor provides annual audit reports at no additional cost.

10. Liability and Indemnification

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the main service agreement between the parties.

GDPR Article 82 Liability

Under GDPR Article 82, the Processor shall be liable for damage caused by processing only where it has not complied with obligations specifically directed to processors or where it has acted outside or contrary to lawful instructions of the Controller. The Processor is exempt from liability if it proves it is not in any way responsible for the event giving rise to the damage.

11. Term and Termination

This DPA shall remain in effect for as long as the Processor processes Personal Data on behalf of the Controller, and shall automatically terminate upon cessation of all processing and deletion or return of all Personal Data.

Either party may terminate this DPA if the other party breaches any material term and fails to remedy such breach within 30 days of written notice.

Contact Information

For questions regarding this Data Processing Agreement or data protection matters:

Processor: Elevate Solutions

Address: 522 S Hunt Club Blvd #360, Apopka, FL 32703, USA

Data Protection Officer: info@elevateskillsacademy.com

DPA Inquiries: info@elevateskillsacademy.com

EU Representative: For GDPR-related DPA inquiries from the EU, contact us at info@elevateskillsacademy.com

Related Policies