Legal
Data Processing Agreement
Version 1 · in effect from 11 September 2026
Who is who
Where an organisation buys EduQan for its people, that organisation is the controller of its learners' personal data and EduQan is the processor. Where an individual buys a course directly from us, EduQan is the controller. A single person can be both at once — an employee assigned a course by their employer who also buys one themselves — and the two records are kept distinct.
What we process, and why
On a controller's instructions we process: name, email address, organisation membership and role, enrolment and progress records, assessment results, certificates issued, and login timestamps. We process it to deliver the learning the controller has bought and to report on it to them. We do not use it to train models, and we do not sell or share it.
Sub-processors
| Sub-processor | Purpose | Location | |---|---|---| | The hosting provider for this deployment | Application and database hosting | United Kingdom | | The email delivery provider | Transactional email (invitations, receipts, certificates) | Configured per deployment | | Stripe | Card payment processing, where enabled | EU / US, under standard contractual clauses |
We will give a controller reasonable notice before adding a sub-processor, and a controller may object.
Security
The measures we apply are set out on our Security page, which is a live document rather than a schedule to this one, so it stays accurate.
Personal data breach
We will notify an affected controller without undue delay and within 72 hours of becoming aware of a personal data breach affecting their data, with what we know at the time, what we are doing, and who to contact. We will not wait until we have a complete picture before telling you.
Your people's rights
We will assist a controller in responding to access, rectification, erasure, restriction, portability and objection requests. A controller can export their own learners' records at any time without asking us.
Deletion and return
On termination we will delete or return personal data on the controller's instruction, except where we must keep it — issued certificates keep the name they were issued under because third parties have relied on them, and financial records are kept for the statutory period.
Audit
We will make available the information a controller reasonably needs to demonstrate compliance, and will allow an audit on reasonable notice.
---
This document is the standard basis on which we process data for organisation customers. If your procurement requires a signed agreement on your own paper, or terms differing from these, contact us and we will work through it. (rewritten)
Questions about this document? Get in touch.