Educatly Data Protection Agreement
This Data Protection Agreement (the "Agreement") is entered into between Educatly Limited, a company incorporated in Ireland under company registration number 675774, with its registered office at 12 The Avenue, Oldbridge Ave, Baile Osbeirn, An Nas, Co. Kildare, W91 C3XD, Ireland ("Educatly"), and the customer identified in the Order Form ("Customer").
Educatly and the Customer are each a "Party" and together the "Parties". This Agreement takes effect on the effective date of the Order Form and forms an integral part of it.
1. How this Agreement applies
1.1 The Parties process Personal Data in two distinct capacities in connection with the services described in the Order Form (the "Services"). This Agreement addresses both.
1.2 Part A (Controller to Controller Terms) applies to the delivery of prospective student inquiries and applications by Educatly to the Customer. In relation to that activity each Party acts as an independent controller and determines the purposes and means of its own processing.
1.3 Part B (Processor Terms) applies only where and to the extent that Educatly processes Personal Data on the Customer's documented instructions, for example where Educatly hosts an application form on the Customer's behalf or administers applicant records within the Educatly platform at the Customer's direction. Where no such activity is agreed in the Order Form, Part B does not apply.
1.4 Part C (Common Terms) applies to all Personal Data processed by Educatly in connection with the Services under either Part A or Part B.
1.5 Educatly collects Personal Data from prospective students through its own platform, for its own purposes, and independently of any Order Form. Educatly is the controller of that Personal Data. Nothing in this Agreement makes Educatly a processor in respect of that collection.
2. Definitions
2.1 Unless otherwise defined in this Agreement, capitalised terms have the meanings given to them in the GDPR.
2.2 "Applicable Data Protection Law" means Regulation (EU) 2016/679 ("GDPR") and any applicable European Union, European Economic Area or Member State data protection and privacy legislation applicable to the processing of Personal Data under this Agreement.
2.3 "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Subprocessor" and "Personal Data Breach" have the meanings given to them in Article 4 GDPR.
2.4 "Services" means the services described in the Order Form.
2.5 "Shared Personal Data" means Personal Data disclosed by Educatly to the Customer under Part A, as described in Annex 1, Part A.
2.6 "Customer Personal Data" means Personal Data processed by Educatly on behalf of the Customer under Part B, as described in Annex 1, Part B.
2.7 "Standard Contractual Clauses" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission, in the module appropriate to the relevant transfer.
Part A Controller to Controller Terms
Part A applies to the disclosure of prospective student inquiries and applications by Educatly to the Customer.
A1. Independent controllers
A1.1 Each Party is an independent controller of the Shared Personal Data that it processes and determines the purposes and means of its own processing.
A1.2 Neither Party is a processor of the other, and neither Party acts under the instructions of the other, in respect of the Shared Personal Data.
A1.3 The Parties are not joint controllers. Each Party is individually responsible for its own compliance with Applicable Data Protection Law.
A1.4 Neither Party shall cause the other to breach Applicable Data Protection Law.
A2. Educatly obligations as disclosing controller
A2.1 Educatly shall ensure that it has a valid lawful basis under Applicable Data Protection Law for collecting the Shared Personal Data and for disclosing it to the Customer.
A2.2 Educatly shall provide Data Subjects with transparency information that meets the requirements of Articles 13 and 14 GDPR, including information that their Personal Data may be disclosed to educational institutions relevant to their stated interests.
A2.3 Educatly shall not disclose Shared Personal Data to the Customer where the relevant Data Subject has objected to or withdrawn consent for such disclosure, where consent is the applicable lawful basis.
A2.4 Educatly shall maintain records of the lawful basis relied upon and, on the Customer's reasonable written request, provide information sufficient for the Customer to satisfy itself that the Shared Personal Data was lawfully obtained and may lawfully be disclosed.
A2.5 Educatly shall notify the Customer without undue delay if it becomes aware that Shared Personal Data already disclosed was obtained or disclosed in a manner that does not comply with Applicable Data Protection Law.
A3. Customer obligations as receiving controller
A3.1 The Customer shall determine and document its own lawful basis for processing Shared Personal Data after receipt.
A3.2 The Customer shall provide Data Subjects with the transparency information required of it under Articles 13 and 14 GDPR, including information about the source of the Personal Data.
A3.3 The Customer shall process Shared Personal Data only for the purpose of responding to and progressing the relevant student inquiry or application and for related admissions and recruitment activity, and shall not use Shared Personal Data for any incompatible purpose.
A3.4 The Customer shall not sell Shared Personal Data or disclose it to any third party except to its own processors or where required by law.
A3.5 The Customer shall implement appropriate technical and organisational measures to protect Shared Personal Data, including appropriate security for any system receiving Shared Personal Data.
A3.6 The Customer shall retain Shared Personal Data only for as long as necessary for the purposes described in clause A3.3 and in accordance with its own retention policy and Applicable Data Protection Law.
A4. Data Subject rights under Part A
A4.1 Each Party shall be responsible for responding to requests from Data Subjects in relation to the Personal Data that it controls.
A4.2 Where a Party receives a request that relates to processing carried out by the other Party, it shall forward the request to the other Party without undue delay and shall provide reasonable assistance in responding to it.
A4.3 Where a Data Subject withdraws consent or objects to processing and notifies one Party, that Party shall inform the other Party without undue delay so that the objection can be given effect.
A4.4 Each Party shall provide the other with reasonable assistance and information necessary to enable the other to comply with its own obligations under Chapter III GDPR.
A5. Personal Data Breaches under Part A
A5.1 Each Party shall notify the other without undue delay of any Personal Data Breach affecting Shared Personal Data that is likely to be relevant to the other Party's obligations under Applicable Data Protection Law.
A5.2 The notifying Party shall provide sufficient information to enable the other Party to assess its own notification obligations, and shall provide further information in phases where not all information is immediately available.
A5.3 Each Party is responsible for making its own assessment of, and where required its own notification to, a supervisory authority and to affected Data Subjects.
A5.4 The Parties shall cooperate reasonably in the investigation and remediation of a Personal Data Breach affecting Shared Personal Data.
A6. Transfers under Part A
A6.1 Where a disclosure of Shared Personal Data by Educatly to the Customer constitutes a transfer of Personal Data outside the European Economic Area for which no adequacy decision applies, the Parties shall put in place the Standard Contractual Clauses in the controller to controller module, together with any supplementary measures required by Applicable Data Protection Law.
A6.2 Educatly shall enter into the Standard Contractual Clauses with the Customer on request where they are required in connection with the Services.
A7. Accountability under Part A
A7.1 Each Party shall maintain records of its own processing of Shared Personal Data as required by Article 30 GDPR.
A7.2 Each Party shall cooperate reasonably with the other in responding to any enquiry, investigation or request from a supervisory authority relating to Shared Personal Data.
A7.3 Each Party shall be responsible for its own liability arising from its own processing of Shared Personal Data.
Part B Processor Terms
Part B applies only where and to the extent that Educatly processes Personal Data on the Customer's documented instructions, as described in clause 1.3 and in Annex 1, Part B.
B1. Roles and instructions
B1.1 In relation to Customer Personal Data, the Customer acts as controller and Educatly acts as processor.
B1.2 Educatly shall process Customer Personal Data only in accordance with the Customer's documented instructions, the Order Form and this Agreement, and Applicable Data Protection Law.
B1.3 The Order Form, this Agreement and any further written instructions given by the Customer together constitute the Customer's documented instructions for the purposes of Article 28(3)(a) GDPR.
B1.4 Educatly shall not sell Customer Personal Data, use it for targeted advertising, or use it for any purpose unrelated to the Services, except where required by Applicable Data Protection Law.
B1.5 If Educatly is required by Applicable Data Protection Law to process Customer Personal Data otherwise than in accordance with the Customer's instructions, Educatly shall, to the extent legally permitted, inform the Customer of that requirement before carrying out the relevant processing.
B1.6 Educatly shall inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
B2. Confidentiality and personnel
B2.1 Educatly shall ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality.
B2.2 Educatly shall ensure that such persons receive appropriate instruction regarding the handling of Personal Data and access Customer Personal Data only to the extent necessary to perform their duties.
B3. Data Subject rights under Part B
B3.1 Taking into account the nature of the processing, Educatly shall reasonably assist the Customer, through appropriate technical and organisational measures, insofar as possible, in responding to requests from Data Subjects exercising their rights under Chapter III GDPR.
B3.2 If Educatly receives a request from a Data Subject relating to Customer Personal Data, Educatly shall, where legally permitted, promptly inform the Customer and shall not respond except on the Customer's documented instructions or where required by Applicable Data Protection Law.
B3.3 Educatly shall reasonably assist the Customer with the rectification, erasure or restriction of processing of Customer Personal Data where reasonably necessary for the Customer to comply with Applicable Data Protection Law.
B4. Assistance with compliance
B4.1 Taking into account the nature of processing and the information available to Educatly, Educatly shall reasonably assist the Customer in ensuring compliance with the Customer's obligations under Articles 32 to 36 GDPR insofar as they relate to processing performed by Educatly under Part B.
B4.2 Such assistance shall include, where reasonably applicable, providing information regarding the technical and organisational measures implemented by Educatly, assisting with Personal Data Breach investigations, providing information reasonably required for a data protection impact assessment, and providing reasonable assistance with consultations with a supervisory authority.
B4.3 The Customer shall reimburse Educatly for reasonable documented costs incurred in providing assistance that is materially beyond Educatly's ordinary obligations under the Services, provided that Educatly obtains the Customer's prior approval where reasonably practicable.
B5. Personal Data Breaches under Part B
B5.1 Educatly shall notify the Customer without undue delay and, where feasible, within 72 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data.
B5.2 The notification shall, to the extent information is available, include the nature of the Personal Data Breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.
B5.3 Where all relevant information is not immediately available, Educatly may provide it in phases without undue further delay.
B5.4 Educatly shall reasonably cooperate with the Customer in relation to the Customer's notification obligations, and shall not notify any supervisory authority or Data Subject in respect of such a breach without first consulting the Customer, unless required to do so by Applicable Data Protection Law.
B6. Return and deletion under Part B
B6.1 Upon termination or expiry of the Services, Educatly shall, at the Customer's choice, either return Customer Personal Data to the Customer in a reasonably accessible format or securely delete it.
B6.2 Unless the Customer requests return within thirty (30) days of termination or expiry, Educatly shall delete Customer Personal Data within ninety (90) days of termination or expiry, unless retention is required by Applicable Data Protection Law.
B6.3 Where the Customer requests deletion of specific Customer Personal Data during the term, Educatly shall delete or anonymise it without undue delay, subject to any legal obligation requiring retention.
B6.4 Where Customer Personal Data is retained solely because of a legal obligation, Educatly shall continue to protect it and shall process it only to the extent required by that obligation.
B7. Audit under Part B
B7.1 Educatly shall make available to the Customer information reasonably necessary to demonstrate compliance with its obligations under Article 28 GDPR and Part B.
B7.2 The Customer may submit reasonable written information requests to support@educatly.com.
B7.3 Where the information reasonably available to the Customer is insufficient, the Customer may conduct, or appoint an independent auditor to conduct, an audit of the relevant processing activities, subject to:
- at least thirty (30) days' prior written notice;
- audits being conducted during normal business hours;
- the audit being limited to matters relevant to Customer Personal Data;
- the auditor being subject to appropriate confidentiality obligations;
- the audit not unreasonably disrupting Educatly's operations or the security of other customers' data;
- the Customer bearing its own audit costs; and
- no more than one audit in any twelve month period, except where a Personal Data Breach, material security incident or reasonable regulatory requirement justifies an additional audit.
B7.4 Educatly may satisfy reasonable audit requests through relevant security certifications, independent audit reports, penetration test summaries, policies, questionnaires or other equivalent documentation where such documentation adequately demonstrates compliance.
B7.5 The Customer shall not obtain access to Personal Data belonging to other Educatly customers or to confidential information unrelated to the Customer's processing activities.
Part C Common Terms
Part C applies to all Personal Data processed by Educatly in connection with the Services, under both Part A and Part B.
C1. Security
C1.1 Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to the rights and freedoms of natural persons, Educatly shall implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to that Personal Data.
C1.2 Such measures are described in Annex 2 and include access control, authentication, encryption of Personal Data in transit and at rest, confidentiality obligations for personnel, backup and recovery, logging and monitoring, vulnerability management, incident response, and periodic review of the effectiveness of those measures.
C1.3 Personal Data is hosted using Microsoft Azure cloud infrastructure configured for European Economic Area data residency. Educatly stores Personal Data in Azure regions located within the European Economic Area.
C1.4 Educatly operates and maintains its own internally developed API and integration platform for the delivery of student inquiries and related Personal Data to the Customer's designated CRM or other receiving system.
C1.5 Educatly shall periodically review and, where appropriate, update its technical and organisational measures to maintain a level of security appropriate to the risks associated with the processing.
C2. Subprocessors and service providers
C2.1 Educatly engages third party service providers where reasonably necessary to provide the Services. Where such a provider processes Personal Data on Educatly's behalf, it acts as a subprocessor in relation to Part B and as a processor of Educatly in relation to Part A.
C2.2 Educatly engages such providers in the following categories: cloud infrastructure and hosting; communication and messaging services used to contact Data Subjects; customer relationship and integration services used to deliver Personal Data to the Customer; and operational, analytics, monitoring and support services used in the provision and maintenance of the Services.
C2.3 Educatly maintains a current list of the providers engaged in the provision of the Services. The Customer may obtain that list at any time by contacting support@educatly.com.
C2.4 Educatly shall ensure that each such provider is subject to written contractual obligations concerning Personal Data that provide a level of data protection and security appropriate to the obligations imposed on Educatly under this Agreement, as required by Article 28 GDPR.
C2.5 Educatly shall remain responsible for the performance of its subprocessors' obligations to the extent required by Applicable Data Protection Law.
C2.6 Educatly may appoint or replace such providers where reasonably necessary for the provision of the Services, and shall notify the Customer of material additions or replacements affecting the processing of Personal Data under this Agreement.
C2.7 The Customer may object to the appointment of a new subprocessor on reasonable data protection grounds within fourteen (14) days of receiving notice. The Parties shall work in good faith to resolve the objection.
C2.8 If the Parties cannot resolve a reasonable objection, Educatly may, at its option, use commercially reasonable efforts to make an alternative arrangement or allow the Customer to terminate the affected Services upon written notice, without affecting any accrued payment obligations.
C3. International transfers and remote access
C3.1 Personal Data is stored within the European Economic Area. Educatly is, however, a globally distributed organisation, and Educatly personnel and authorised service providers may access Personal Data from locations outside the European Economic Area on a remote access basis for the purpose of providing, operating, supporting and maintaining the Services.
C3.2 Where such access or any other transfer of Personal Data outside the European Economic Area takes place, Educatly shall ensure that the transfer is permitted under Applicable Data Protection Law and that an appropriate transfer mechanism under Chapter V GDPR is in place where required.
C3.3 Where no adequacy decision applies, Educatly shall implement an appropriate safeguard, such as the Standard Contractual Clauses, together with any supplementary measures required by Applicable Data Protection Law.
C3.4 All access to Personal Data from outside the European Economic Area remains subject to the access controls, authentication requirements, confidentiality obligations and other technical and organisational measures described in Annex 2.
C3.5 Educatly shall inform the Customer of any material change to the processing arrangements involving a transfer of Personal Data outside the European Economic Area where such notification is required under Applicable Data Protection Law.
C4. Retention and backups
C4.1 Educatly shall retain Personal Data only for as long as reasonably necessary for the purposes described in this Agreement or as required by Applicable Data Protection Law.
C4.2 Where Personal Data has been delivered to the Customer's designated CRM or other receiving system, the Customer is responsible for retention of that copy in accordance with its own retention policies and Applicable Data Protection Law.
C4.3 Backup copies may remain for a limited period in accordance with Educatly's ordinary backup and disaster recovery procedures, and are deleted in accordance with the standard backup retention cycle, ordinarily within thirty five (35) days. Such copies remain protected and are not restored or actively processed except where necessary for disaster recovery, security or legal compliance.
C5. Government and legal requests
C5.1 If Educatly receives a legally binding request from a public authority for disclosure of Personal Data processed under this Agreement, Educatly shall, to the extent legally permitted, inform the Customer before disclosing it.
C5.2 Educatly shall reasonably cooperate with the Customer in challenging or limiting such disclosure where the Customer reasonably requests such assistance and where legally permissible.
C5.3 Nothing in this section requires Educatly to breach a legal obligation binding upon it.
C6. Confidentiality
C6.1 Personal Data processed under this Agreement shall be treated as confidential information.
C6.2 The confidentiality obligations in this Agreement are in addition to those contained in the Order Form and shall survive termination for so long as the relevant information remains confidential or is protected under Applicable Data Protection Law.
C7. Liability
C7.1 Nothing in this Agreement shall be interpreted as creating a separate or unlimited liability regime between the Parties.
C7.2 The liability of the Parties in connection with this Agreement shall be subject to the liability provisions applicable to the Order Form, except to the extent that Applicable Data Protection Law requires otherwise.
C7.3 Nothing in this Agreement shall exclude or limit any liability that cannot lawfully be excluded or limited under Applicable Data Protection Law.
C8. Term and termination
C8.1 This Agreement enters into force on the effective date of the Order Form and remains in force for as long as Educatly processes Personal Data in connection with the Services.
C8.2 This Agreement terminates automatically when such processing ceases, subject to provisions which by their nature survive termination, including confidentiality, deletion, audit rights relating to historical processing, and any applicable liability provisions.
C8.3 Termination shall not affect the validity of the Order Form or any rights or obligations accrued before termination.
C9. Order of precedence
C9.1 This Agreement supplements the Order Form and the other contractual terms governing the Services.
C9.2 In the event of any conflict in relation to the processing of Personal Data, the following order of precedence applies: first, the Standard Contractual Clauses where they apply; second, this Agreement; third, the Order Form; fourth, the Educatly Terms of Use.
C9.3 In the event of any conflict between Part A and Part B, the Part governing the relevant processing activity prevails in respect of that activity.
C9.4 For all other matters, the order of precedence applicable under the Order Form remains unchanged.
C10. Changes to this Agreement
C10.1 Educatly may update this Agreement from time to time to reflect changes to the Services, to its technical and organisational measures, or to Applicable Data Protection Law, provided that no update shall materially reduce the protections afforded to Personal Data.
C10.2 Educatly shall notify the Customer of material changes affecting the processing of Personal Data under this Agreement, and shall publish the date on which this Agreement was last updated.
C10.3 The Parties shall cooperate in good faith to amend this Agreement where reasonably necessary to comply with material changes to Applicable Data Protection Law.
C10.4 Where a competent supervisory authority or court determines that a provision of this Agreement does not satisfy a mandatory requirement of Applicable Data Protection Law, the Parties shall cooperate in good faith to replace the affected provision with a legally compliant provision that most closely reflects the original commercial and legal intent.
C11. Governing law
C11.1 This Agreement is governed by the same governing law as the Order Form.
C11.2 The courts having jurisdiction under the Order Form shall have jurisdiction over disputes arising under this Agreement, subject to any mandatory jurisdiction applicable under Applicable Data Protection Law.
C12. General
C12.1 This Agreement constitutes the agreement between the Parties regarding the processing of Personal Data in connection with the Services.
C12.2 Where the Order Form incorporates this Agreement by reference, no separate signature is required and this Agreement binds both Parties on the effective date of the Order Form. Educatly will execute a separate counterpart of this Agreement on request.
C12.3 If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions remain in full force and effect.
C12.4 Neither Party may assign this Agreement except as permitted under the Order Form, provided that such assignment does not adversely affect the protection of Personal Data.
C12.5 Questions, requests and notices relating to this Agreement may be sent to support@educatly.com.
Annex 1 Description of processing
Part A Controller to controller disclosure
Subject matter. Disclosure by Educatly to the Customer of prospective student inquiries and applications relating to the Customer's educational programmes, including through an API based integration with the Customer's CRM or other designated receiving system.
Duration. Disclosures take place during the term of the Services as set out in the Order Form. Each Party thereafter retains the Personal Data it controls in accordance with its own retention policy and Applicable Data Protection Law.
Nature of processing. Collection by Educatly from Data Subjects, recording, organisation, storage, retrieval, transmission through Educatly's API and integration platform, and disclosure to the Customer's designated receiving system.
Purposes. For Educatly: operating its platform, matching prospective students with relevant educational programmes, and delivering relevant inquiries to institutions. For the Customer: responding to and progressing student inquiries and applications, and related admissions and recruitment activity.
Categories of Data Subjects. Prospective students, applicants, and individuals expressing interest in the Customer's educational programmes.
Categories of Personal Data. Depending on the information submitted by a Data Subject: name, email address, telephone number, country of residence or nationality, educational background, programme or course of interest, study preferences, application or inquiry information, information voluntarily provided in connection with an inquiry or application, communication preferences, and source or campaign information associated with the inquiry.
Special categories. The Services are not intended to involve special categories of Personal Data as defined in Article 9 GDPR. Where a Data Subject voluntarily provides such information in free text, each Party shall process it only to the extent necessary and in accordance with Applicable Data Protection Law.
Part B Processing on the Customer's instructions
Application. This Part applies only where the Order Form provides for Educatly to process Personal Data on the Customer's documented instructions.
Subject matter. Processing of applicant and prospective student Personal Data by Educatly on behalf of the Customer, for example where Educatly hosts an application or inquiry form on the Customer's behalf, or administers applicant records within the Educatly platform at the Customer's direction.
Duration. The term of the Services, and thereafter only for the limited period necessary to return or delete the Customer Personal Data or to comply with Applicable Data Protection Law.
Nature of processing. Collection on the Customer's behalf, recording, organisation, storage, retrieval, transmission, delivery to the Customer's designated receiving system, correction or deletion at the Customer's documented instruction, and other processing strictly necessary to provide the Services.
Purposes. To provide the Services described in the Order Form on the Customer's instructions.
Categories of Data Subjects and Personal Data. As described in Part A of this Annex, together with any additional categories specified in the Order Form.
Annex 2 Technical and organisational measures
Educatly maintains technical and organisational measures appropriate to the risk of processing Personal Data, including the following.
1. Access control
- Role based access controls.
- Access granted on a need to know basis.
- User authentication controls, including multi factor authentication where appropriate.
- Periodic review of access permissions.
- Prompt revocation of access when personnel no longer require it.
2. Confidentiality
- Personnel with access to Personal Data are subject to confidentiality obligations.
- Access is restricted to authorised personnel whose duties require it.
- Personnel receive appropriate data protection and security guidance.
3. Data transmission security
- Personal Data transmitted between systems is encrypted in transit using industry standard transport encryption.
- API connections use appropriate authentication and access controls.
- Credentials and authentication information are protected against unauthorised access.
4. Data storage
- Personal Data is hosted using Microsoft Azure cloud infrastructure, in Azure regions located within the European Economic Area.
- Personal Data is encrypted at rest using industry standard encryption provided by the underlying cloud infrastructure.
- Appropriate access controls are applied to hosted environments.
- Data is protected against unauthorised access, alteration or destruction.
5. Availability and resilience
- Appropriate backup and recovery procedures are maintained.
- Measures are implemented to support availability and resilience of systems processing Personal Data.
- Disaster recovery procedures are maintained appropriate to the nature of the Services.
6. Vulnerability and security management
- Security updates and patches are applied as appropriate.
- Security vulnerabilities are identified and addressed through appropriate engineering and operational processes.
- Systems are monitored and maintained by Educatly's engineering and technical teams.
7. Incident management
- Educatly maintains procedures for identifying, assessing and responding to suspected security incidents.
- Security incidents are investigated and remediated using appropriate technical and organisational measures.
- Personal Data Breaches are handled in accordance with clause A5 or B5 as applicable.
8. Data minimisation
- Educatly processes only Personal Data reasonably necessary for the purposes described in this Agreement.
- The Services are not designed to require special category Personal Data.
9. Secure development
- Educatly maintains internally developed software and API and integration infrastructure.
- Security considerations are incorporated into the development and maintenance of systems used to process Personal Data.
- Appropriate controls are applied to software changes and system access.
10. Remote access
- Access to Personal Data by personnel located outside the European Economic Area is subject to the same access controls, authentication requirements and confidentiality obligations set out in this Annex.
11. Regular review
- Educatly periodically reviews its technical and organisational measures and updates them where reasonably necessary to maintain an appropriate level of security.
Annex 3 Service providers
Educatly engages third party service providers in the following categories in connection with the Services:
| Category | Purpose |
|---|---|
| Cloud infrastructure and hosting | Hosting, storage, compute and related cloud services used to operate the Educatly platform. |
| Communication and messaging services | Delivery of messages to Data Subjects in connection with inquiries and applications. |
| Customer relationship and integration services | Delivery and synchronisation of Personal Data to the Customer's designated receiving system. |
| Operational, analytics, monitoring and support services | Service performance measurement, system monitoring, incident detection and user support in the provision and maintenance of the Services. |
Educatly maintains a current list of the specific providers engaged within these categories. The Customer may obtain that list at any time by contacting support@educatly.com. Educatly may update the list in accordance with clause C2 of this Agreement.