This Data Processing Addendum ("DPA") forms part of the DidactLabs Terms of Service (the "Terms") between the Customer and DidactLabs BV, a Belgian private limited company with registered address at Tabakvest 87 / bus 4610, Antwerp 2000, Belgium, and company number 1026.185.467 ("DidactLabs"). It applies whenever DidactLabs processes Customer Personal Data in the course of providing the Service.
If the Customer or its Institution has signed a separate data processing agreement with DidactLabs, including the Flemish model processor agreement for education (modelverwerkersovereenkomst), that agreement governs the processing it covers, and this DPA does not apply to that processing.
1. Definitions
Capitalized terms used but not defined in this DPA have the meanings given to them in the Terms, the Privacy Policy or the GDPR. For purposes of this DPA:
- "Customer" means the Educator who accepts the Terms or, where the Educator uses the Service for an Institution as described in Section 3, that Institution, represented by the Educator.
- "Customer Personal Data" means all personal data processed in the Service on the Customer's behalf. This includes Student identifiers (a self-chosen nickname or, when Students arrive through a learning management system, their name, institutional user identifier and course), User Content, Writing Process Data, conversations with the AI assistant and the analyses produced from them, grades and feedback, technical data about Students' use of the Service, and any personal data contained in Educator Content.
- "Account Data" means the Educator's own account, billing and communication data, which DidactLabs processes as a controller under the Privacy Policy and which is not Customer Personal Data.
- "Data Protection Law" means the GDPR, the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data, any Flemish rules applicable to education and, where applicable, the UK GDPR.
- "Institution" means a school, school board, university or other organisation for which an Educator teaches or works.
- "Sub-processor" means any third party engaged by DidactLabs that processes Customer Personal Data.
- "Personal Data Breach", "controller", "processor", "data subject" and "processing" have the meanings given to them in the GDPR.
2. Roles and Instructions
For Customer Personal Data, the Customer is the controller and DidactLabs is the processor.
DidactLabs processes Customer Personal Data only on the Customer's documented instructions, unless EU or Member State law requires otherwise, in which case DidactLabs will inform the Customer before processing unless that law prohibits it. The Customer's instructions are set out in the Terms, this DPA and Annex 1, and are given through the Customer's use and configuration of the Service, such as creating an assignment, configuring the AI assistant, connecting a learning management system or deleting a submission.
DidactLabs does not process Customer Personal Data for its own purposes. It will not sell it, use it for advertising, use it to train, fine-tune or evaluate artificial intelligence models, or use it for research or product development, except in the form of statistics that have been anonymised so that no Student or other person can be identified from them, and it will not combine it with data of other customers except as the shared infrastructure of the Service technically requires. If DidactLabs believes that an instruction infringes Data Protection Law, it will inform the Customer without delay and may suspend that instruction until the Customer confirms or changes it.
The Customer is responsible for the lawfulness of the processing it instructs. This includes having a legal basis for it, informing Students and, where required, their parents or legal guardians, obtaining any consent that is required, and not asking Students to provide special categories of personal data that the assignment does not need.
Account Data falls outside this DPA and is governed by the Privacy Policy.
3. Educators Using the Service for an Institution
An Educator who uses the Service with Students of a school or other Institution, in the course of their work for that Institution, does so on behalf of that Institution. In that case the Institution is the controller of the Customer Personal Data concerning its Students.
Before using the Service with those Students, the Educator represents and warrants that:
- the Institution has authorised the use of the Service, including the processing described in this DPA, or the Institution's policies allow Educators to choose such tools themselves;
- the Educator is authorised to accept this DPA on the Institution's behalf; and
- the use complies with the Institution's policies on privacy, information security and artificial intelligence, including any requirement to inform Students and their parents.
If any of these statements is not true, the Educator must not use the Service with those Students until it is. If the Educator nevertheless does so, the Educator, and not the Institution, is the controller of the Customer Personal Data concerning those Students, in the Educator's own name, until the Institution confirms its authorisation. A statement in this Section 3 that is untrue is a breach of the Terms, and Section 9 of the Terms (Indemnification) applies to its consequences, to the extent permitted by law. DidactLabs relies on the Educator's statements and is not required to verify them. A missing authorisation does not change DidactLabs' role: DidactLabs continues to act only as a processor, on the instructions described in Section 2.
An Institution may at any time confirm its authorisation in writing or sign a separate data processing agreement with DidactLabs.
An Educator who uses the Service independently of any Institution, for example as a private tutor, is the Customer and the controller.
4. Confidentiality
DidactLabs shall ensure that all persons it authorises to process Customer Personal Data are bound by an obligation of confidentiality, and that access is given only to those who need it to provide the Service.
5. Data Security
DidactLabs will implement and maintain the technical and organisational measures described in Annex 2, which are designed to ensure a level of security appropriate to the risks of the processing, in accordance with Article 32 GDPR. DidactLabs may update these measures from time to time, provided that the overall level of protection of Customer Personal Data is not reduced.
6. Sub-processors
The Customer grants DidactLabs a general authorisation to engage Sub-processors. The current list of Sub-processors, with the task each performs, the data it processes and its location, is published on the DidactLabs Subprocessors page.
DidactLabs shall enter into a written agreement with each Sub-processor imposing data protection obligations materially equivalent to those in this DPA, and remains responsible to the Customer for the acts and omissions of its Sub-processors.
DidactLabs will give at least 30 days' notice before adding or replacing a Sub-processor, or changing where a Sub-processor stores or processes Customer Personal Data, by publishing the change on the Subprocessors page and by showing a notice in the Service, in the same way as a change to the Terms. The notice will name the Sub-processor and state the task it will perform, the categories of data it will process, where it will process them and, for any transfer outside the European Economic Area, the transfer mechanism relied on.
The Customer may object to the change in writing within 30 days of the update, giving reasons related to data protection. The parties shall discuss the objection in good faith. If it cannot be resolved, DidactLabs will either not use that Sub-processor for the Customer or permit the Customer to terminate the Terms and close its account, with a pro-rata refund of any prepaid fees for the unused period.
7. Data Transfers
Customer Personal Data is stored within the European Economic Area. DidactLabs shall not transfer Customer Personal Data outside the European Economic Area except under a transfer mechanism recognised by Chapter V of the GDPR.
The Customer authorises the transfers made by Sub-processors as listed, together with their transfer mechanism, on the Subprocessors page, and remote administration and support of the Service by DidactLabs personnel located in countries for which the European Commission has adopted an adequacy decision.
8. Personal Data Breach
Upon becoming aware of a Personal Data Breach affecting Customer Personal Data, DidactLabs will notify the Customer without undue delay and, where feasible, within 48 hours. The notification will be sent to the Educator's account email and, where DidactLabs has its contact details, to the Institution.
The notification will describe, to the extent then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed, together with a contact point for further information. Where not all information is available at once, DidactLabs will provide it in stages without undue delay. DidactLabs will promptly take reasonable steps to contain and investigate the breach and will assist the Customer in meeting its obligations under Articles 33 and 34 GDPR.
DidactLabs' notification of or response to a Personal Data Breach under this Section 8 shall not be construed as an acknowledgment by DidactLabs of any fault or liability with respect to it.
9. Data Subject Rights and Assistance
The Service enables the Customer to view, export and delete Customer Personal Data. If DidactLabs receives a request from a data subject directly, it will not respond to it except to refer the person to their Educator or Institution, and it will inform the Customer promptly where it can identify the Customer.
Taking into account the nature of the processing and the information available to it, DidactLabs will provide reasonable assistance to the Customer in ensuring the security of the processing and in carrying out data protection impact assessments and prior consultations with supervisory authorities, in accordance with Articles 32 to 36 GDPR.
Assistance that goes beyond the self-service tools of the Service and the information DidactLabs publishes may be charged at a reasonable cost agreed in advance, unless it is needed because of DidactLabs' breach of this DPA.
10. Return or Deletion of Customer Personal Data
While the Customer uses the Service, it can export and delete Customer Personal Data at any time using the Service's tools.
When the Customer's account is closed or the Terms end, a Grace Period of 60 days applies, during which the Customer can still export its data. At the end of the Grace Period, DidactLabs permanently deletes Customer Personal Data from its production systems, and backups containing it are deleted within a further 30 days. The same applies when an Institution connected to the Service through its learning management system ends its use of the Service.
After deletion, DidactLabs keeps only a record of the deletion, containing the Customer's name or the Educator's email address, the dates and the number of records deleted but no content, as proof that the deletion took place, and records of AI usage, containing the model, the amount used, its cost and the date but no content and no identifier of any person, assignment or submission, for accounting purposes. DidactLabs will also retain any data that EU or Member State law requires it to keep, for as long as that law requires. On request, DidactLabs will confirm the deletion in writing.
11. Audits and Compliance Review
On request, DidactLabs will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the relevant part of its record of processing activities, a description of its security measures and, where their terms allow, its Sub-processors' certifications and agreements. DidactLabs will also answer a reasonable security questionnaire once per year.
Where that information is not sufficient, the Customer, or an independent auditor bound by confidentiality, may audit DidactLabs' compliance with this DPA. The Customer shall give at least 30 days' notice, the audit shall take place during business hours in a manner that causes the least possible disruption, and no more than one audit may be conducted in any 12-month period unless a Personal Data Breach or a supervisory authority requires it. Each party bears its own costs of an audit, unless the audit reveals material non-compliance by DidactLabs with this DPA.
12. Liability
Each party's liability under this DPA is subject to the limitation of liability in the Terms, except to the extent that Data Protection Law does not permit liability to be limited. Nothing in this DPA limits the rights of data subjects under Article 82 GDPR.
13. Term and Precedence
This DPA applies for as long as DidactLabs processes Customer Personal Data and survives termination of the Terms until deletion under Section 10 is complete.
In the event of any conflict concerning Customer Personal Data, this DPA prevails over the Terms and the Privacy Policy, and a separate signed data processing agreement prevails over this DPA. DidactLabs may update this DPA in the same way the Terms provide for changes to the Terms.
Annex 1: Details of Data Processing
Subject matter and duration. DidactLabs provides a writing environment in which Students write assignments with an AI assistant configured by the Educator, and the Educator sees the writing process, the AI conversation and an analysis of AI use. Processing lasts for as long as the Customer uses the Service, followed by the deletion periods in Section 10.
Nature and purposes of processing. DidactLabs processes Customer Personal Data only to provide the features of the Service the Customer uses, including assignments, the writing environment, the capture of the writing process, the AI assistant, analyses and reports, grades and feedback, and integration with learning management systems including grade passback; to store, back up and restore that data; to secure the Service through authentication, access control, logging and the prevention of abuse; to maintain and support the Service by fixing errors, investigating problems and answering the Customer's support requests; to measure the usage and cost of AI processing in order to apply plan limits and spending caps and to bill; and to export, delete and prove the deletion of data. Deletion of an Institution's data before the end of a Grace Period takes place only on a verified written request from the Institution. The Service makes no decision about a Student: every grade, mark and item of feedback is the Educator's, and the analyses the Service produces are information for the Educator.
Categories of data subjects. Students, and any other persons whose personal data appears in User Content or Educator Content.
Categories of personal data. The categories set out in the definition of Customer Personal Data in Section 1. DidactLabs never stores a Student's email address, even where a learning management system transmits one.
Special categories of personal data. Neither party intends DidactLabs to process special categories of personal data. Because Students write free text, the Customer should instruct them not to include such data where the assignment does not require it.
Retention. Customer Personal Data is kept for as long as the Customer keeps it in the Service and is deleted as described in Section 10. Security logs are kept for 30 days and audit logs for up to 400 days.
Location and Sub-processors. Customer Personal Data is processed within the European Economic Area, with the exceptions and by the Sub-processors listed on the DidactLabs Subprocessors page.
Annex 2: Technical and Organisational Security Measures
The Service's server-side infrastructure is hosted on Google Cloud Platform in Belgium, using managed services for computing, the database and file storage. The production environment is separated from development environments, each with its own database.
All data transferred between users' browsers and the Service is encrypted using TLS 1.2 or higher. Customer Personal Data is encrypted at rest using AES-256, including in the database, file storage and backups. The database is backed up daily with point-in-time recovery, and the infrastructure can be redeployed from source code.
Access to production systems and data follows the principle of least privilege and is limited to authorised personnel who need it to perform their duties, using personal accounts protected by multi-factor authentication. Secrets used by the Service are kept in a secrets manager, never in source code. All DidactLabs personnel are bound by confidentiality obligations.
Within the Service, access is role-based: Educators can only access data from assignments they created, and Students only their own submissions. Launches from learning management systems are cryptographically signed and validated, and submission identifiers cannot be guessed. The Service is designed to minimise the collection of Student data: Students do not create accounts, are identified on shared links only by a self-chosen nickname, and their email addresses are never stored. Error monitoring runs with the collection of personal data disabled and text masked.
DidactLabs monitors the Service through centralised logging with alerts, error monitoring, protection against brute-force attacks on accounts and automated alerts on vulnerable dependencies. It maintains a written incident response procedure and an incident register. Customer Personal Data is deleted automatically at the end of the Grace Period, and each deletion is recorded. Customer Personal Data is never used to train AI models, and the AI provider does not store conversations for the Service, except content that its abuse monitoring flags as potentially abusive, which it may retain within the European Union for a limited period for review, as described on the Subprocessors page.
If you have any questions about this DPA, please contact us at [email protected] or our Data Protection Officer at [email protected].