Data Processing Addendum (DPA)
(GDPR Article 28, UK GDPR, and U.S. State Privacy Terms)
Last Updated: September 4, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other applicable agreement (“Agreement”) between CourseDeck (“Processor” or Service Provider) and the entity identified as the customer (“Customer” or Controller).
This DPA applies to the extent CourseDeck processes Personal Data on behalf of the Customer in connection with the CourseDeck SaaS platform. It is intended to address contractual requirements applicable to processor/service-provider relationships under the EU GDPR, UK GDPR, and applicable U.S. state privacy laws.
1. Definitions
Capitalized terms not otherwise defined herein have the meanings given in the Agreement, GDPR, or applicable data protection laws.
- Controller: The Customer determining the purposes and means of Processing.
- Processor: CourseDeck, processing Personal Data on behalf of the Controller.
- Service Provider: As defined under applicable U.S. state privacy laws, including the CCPA/CPRA where applicable.
- Personal Data: Any information relating to an identified or identifiable individual.
- Customer Personal Data: Personal Data that CourseDeck Processes on behalf of the Customer in connection with the Service. Customer Personal Data does not include Personal Data for which CourseDeck acts as an independent Controller.
- Processing: Any operation performed on Personal Data.
- Sub-processor: Any third party engaged by CourseDeck to process Personal Data on behalf of the Customer.
2. Scope, Subject Matter, and Duration of Processing
2.1 Subject Matter
Provision of the CourseDeck SaaS platform and related services.
2.2 Duration
Processing for the duration of the Agreement, plus any period required for lawful data retention.
2.3 Nature and Purpose
Processing activities may include:
- Hosting, storage, and retrieval of data
- Authentication and access management
- Enrollment data collection and student record management
- Scheduling, attendance, reporting, and analytics
- Communication delivery (emails, notifications)
- Technical support and system maintenance
2.4 Categories of Data Subjects
- Customer administrators and staff
- Teachers and employees
- Students (including minors)
- Parents or guardians
- Adult learners or other authorized registrants where applicable
2.5 Categories of Personal Data
- Identifiers (name, email address, student ID)
- Educational and attendance records
- Performance and progress data
- Parent or guardian contact information
- Date of birth or age-related information where required for enrollment
- Health, medical, or other enrollment-related information submitted by or for the Customer
- Technical logs and usage metadata
3. Roles and Compliance Responsibilities
3.1 Customer (Controller)
The Customer represents and warrants that:
- It has a valid legal basis for Processing Customer Personal Data.
- It provides any legally required privacy notices.
- It obtains parental, guardian, or other authorization for minors’ data where required by applicable law.
- It complies with applicable data protection laws in connection with its use of the Service.
- It is responsible for determining the Personal Data it chooses to collect or Process through the Service, the purposes of such Processing, and whether any optional, sensitive, health-related, or minor-related information is necessary and appropriate for its use of the Service.
- It is responsible for the legality, accuracy, quality, and appropriateness of its instructions and configurations and shall not instruct CourseDeck to Process Customer Personal Data in a manner that violates applicable law.
3.2 CourseDeck (Processor / Service Provider)
CourseDeck shall:
- Process Customer Personal Data only on documented instructions from the Customer, except where Processing is required by applicable law. Where legally permitted, CourseDeck will inform the Customer of that legal requirement before carrying out such Processing.
- Process Customer Personal Data only as necessary to provide and support the Service or as otherwise permitted by the Agreement and applicable law.
- Notify the Customer if an instruction violates applicable law where required.
4. Confidentiality
CourseDeck ensures that:
- Personnel authorized to process Personal Data are subject to confidentiality obligations.
- Access to Personal Data is limited to personnel with a legitimate need to know.
5. Technical and Organizational Security Measures
CourseDeck implements appropriate technical and organizational measures designed to protect Personal Data, taking into account the nature, scope, context, and purposes of the Processing and the risks to individuals, as required by applicable data protection law. Where the GDPR or UK GDPR applies, CourseDeck will implement appropriate measures consistent with Article 32. Depending on the relevant system and service, these measures may include:
- Role-based and least-privilege access controls
- Logical segregation of Customer data within multi-tenant environments
- Secure transmission of data using industry-standard security protocols
- Security logging and monitoring appropriate to the relevant systems and services
- Security controls provided by CourseDeck’s hosting, database, storage, and other infrastructure providers
These measures are reviewed and updated as appropriate in light of the nature of the Service and applicable risks.
6. Sub-processors
6.1 Authorization
The Customer grants general authorization for CourseDeck to engage Sub-processors.
CourseDeck will provide reasonable notice of an intended addition or replacement of a Sub-processor that Processes Customer Personal Data where required by applicable law or the Agreement. The Customer may raise a reasonable, documented objection based specifically on data-protection grounds.
CourseDeck will use commercially reasonable efforts to address a valid objection. If the parties cannot reasonably resolve the objection, their respective rights and remedies will be governed by the Agreement.
6.2 Current Sub-processors and Related Service Providers
As of the effective date, CourseDeck may use the following Sub-processors and related third-party providers:
| Function | Provider |
|---|---|
| Hosting & Infrastructure | Vercel |
| Database (Serverless Postgres) | Neon |
| File / Media Storage | UploadThing |
| Email Delivery | Resend |
| Analytics | PostHog |
| Payments | Lemon Squeezy (Merchant of Record) |
Lemon Squeezy acts as Merchant of Record for purchases made through CourseDeck and may process payment-related Personal Data under its applicable terms, privacy policy, and data processing arrangements. Its role for particular processing activities is determined by those arrangements; inclusion in this table does not mean Lemon Squeezy acts as a Sub-processor for every processing activity.
6.3 Sub-processor Obligations
Where CourseDeck engages a Sub-processor to Process Customer Personal Data, CourseDeck will impose the data-protection obligations required by applicable law, including the obligations required under Article 28(4) of the GDPR where applicable to the relevant sub-processing services.
CourseDeck remains responsible to the Customer for the performance of such Sub-processor only to the extent required by applicable law and subject to the liability provisions of the Agreement.
6.4 Compliance Information and Audits
CourseDeck will make available to the Customer information reasonably necessary to demonstrate compliance with its applicable processor obligations under this DPA.
CourseDeck may satisfy such requests in the first instance through relevant certifications, third-party audit reports, security documentation, questionnaires, or other reasonable evidence.
Where a further audit or inspection is required by applicable data protection law and the information already provided is not reasonably sufficient, the Customer may conduct such audit itself or through a qualified independent auditor, subject to reasonable advance notice, confidentiality obligations, CourseDeck’s reasonable security requirements, and scheduling during normal business hours.
Unless required otherwise by applicable law, regulation, a competent supervisory authority, a material security incident affecting Customer Personal Data, or reasonable evidence of material non-compliance, audits will normally be limited to no more than once in any twelve-month period.
Any audit must be limited to systems, records, and information reasonably relevant to the Processing of Customer Personal Data. It must not require access to other customers’ data, source code, trade secrets, credentials, vulnerability information, or systems where such access would create an unreasonable security or confidentiality risk, except to the extent strictly required by applicable law and where no less intrusive means is reasonably available.
The Customer may not perform penetration testing, vulnerability scanning, or other intrusive security testing without CourseDeck’s prior written consent.
The Customer will bear its own audit costs. CourseDeck may charge reasonable costs for assistance beyond its ordinary compliance documentation, except where prohibited by applicable law or where an audit establishes a material breach of this DPA by CourseDeck.
7. International Data Transfers
Personal Data may be processed or accessed outside the EEA or UK.
Where required for transfers of Personal Data subject to the EU GDPR, UK GDPR, or similar transfer restrictions, CourseDeck and its relevant Sub-processors or service providers will use an appropriate lawful transfer mechanism.
8. Assistance with Data Subject Rights
Taking into account the nature of Processing, CourseDeck shall reasonably assist the Customer in fulfilling data subject rights requests as required by applicable law.
CourseDeck shall not respond directly to data subjects regarding Customer Personal Data unless instructed by the Customer or legally required.
9. Personal Data Breach Notification
CourseDeck shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and provide information reasonably necessary for compliance with applicable law.
10. Security, DPIA, and Regulatory Assistance
Taking into account the nature of the Processing and the information available to CourseDeck, CourseDeck shall provide reasonable assistance to the Customer with applicable obligations relating to security of Processing, Personal Data Breach notifications, data protection impact assessments, and prior consultation with supervisory authorities, to the extent required by applicable data protection law.
CourseDeck may provide such assistance through information and standard documentation reasonably available to it. Additional assistance that is not required by applicable law may be subject to a separate agreement and reasonable fees.
11. Data Return and Deletion
During the term of the Agreement, the Customer is responsible for using the export functionality made available through the Service to obtain copies of Customer Personal Data that it wishes to retain.
Upon termination or expiry of the Agreement, CourseDeck will, at the Customer’s choice and to the extent required by applicable data protection law, return or delete Customer Personal Data and delete existing copies, unless applicable law requires retention.
Where reasonably available, return of Customer Personal Data may be satisfied through the standard export functionality provided by the Service. Any additional customized export, migration, or recovery assistance that is not required by applicable law may be subject to separate agreement and reasonable fees.
The Customer should exercise available export or return options before termination or within any post-termination retention period made available under the Agreement. CourseDeck is not required to retain Customer Personal Data indefinitely after termination or to restore data that has been deleted in accordance with its applicable retention and deletion lifecycle.
To the extent immediate deletion from backup or archival systems is not reasonably practicable, residual copies may remain until deleted or overwritten in the ordinary course, subject to appropriate safeguards and without further active Processing except as required for backup, security, disaster recovery, or legal purposes and subject to applicable law.
12. U.S. State Privacy Terms
To the extent CourseDeck Processes Customer Personal Data as a Service Provider, Contractor, Processor, or similar regulated recipient under applicable U.S. state privacy laws:
- CourseDeck will Process Customer Personal Data only for the specific business purposes described in Section 2.3 (Nature and Purpose) of this DPA and as otherwise expressly permitted by applicable law.
- CourseDeck will not sell or share Customer Personal Data as those terms are defined under applicable U.S. state privacy laws.
- CourseDeck will not use Customer Personal Data for cross-context behavioral advertising.
- CourseDeck will not retain, use, or disclose Customer Personal Data outside the direct business relationship with the Customer or for purposes other than the specified purposes of providing and supporting the Service, except as permitted by applicable law.
- CourseDeck will not combine Customer Personal Data with personal information received from or on behalf of another person or collected from CourseDeck’s own interaction with an individual except as permitted by applicable law.
- CourseDeck will provide the level of privacy protection for Customer Personal Data required of CourseDeck in its applicable Service Provider, Contractor, Processor, or similar role under applicable law.
- CourseDeck will provide reasonable assistance to the Customer with applicable consumer rights requests where required by law.
If CourseDeck determines that it can no longer meet applicable legal obligations relating to Customer Personal Data in such role, CourseDeck will notify the Customer as required by applicable law.
The Customer may take reasonable and appropriate steps required by applicable law to help ensure compliant Processing of Customer Personal Data and to stop and remediate unauthorized Processing.
13. Liability
Any liability arising out of or relating to this DPA shall be subject to and governed by the Limitation of Liability and liability caps set forth in the Agreement.
Nothing in this DPA shall be construed to increase CourseDeck’s liability beyond the limits expressly agreed in the Agreement, except where prohibited by applicable law.
14. Data Location and Processing Regions
Unless otherwise agreed in writing, CourseDeck and its service providers may process Personal Data in the United States and other locations in which they operate, subject to applicable legal requirements.
15. Governing Law and Jurisdiction
This DPA is governed by the same law and dispute resolution provisions specified in the Agreement.
16. Third-Party Rights
Except to the extent required by applicable law, no person other than the parties to the Agreement has any right to enforce any term of this DPA, whether under any third-party beneficiary doctrine, the Contracts (Rights of Third Parties) Ordinance (Cap. 623) of Hong Kong where applicable, or otherwise.
17. Order of Precedence
In the event of a conflict between this DPA and the Agreement specifically concerning the Processing of Customer Personal Data, this DPA will prevail only to the extent of that conflict. In all other respects, the Agreement remains in full force and effect.
Nothing in this Section 17 expands the scope of this DPA or overrides the liability provisions in Section 13 or the applicable liability limitations in the Agreement.
Schedule 1 – International Transfer Mechanisms
Where required by applicable data protection law, the parties will use applicable standard contractual clauses, addenda, or other lawful transfer mechanisms for restricted international transfers.
Contact Information
For questions regarding this Data Processing Addendum, please contact: support@mycoursedeck.com