DATA PROCESSING ADDENDUM (DPA)
for the elevialms.com platform | controller-processor relationship
1. Parties and roles
This Data Processing Addendum ("DPA") governs the processing of personal data where the customer of the Elevia platform ("Customer") acts as controller and ELEVIA LIMITED, a private company limited by shares incorporated under the laws of Ireland, registered with the Companies Registration Office under number 819393, with its registered office at 77 Camden Street Lower, Dublin, D02 XE80, Ireland ("Provider"), acts as processor within the meaning of Article 28 GDPR.
This DPA forms an integral part of the agreement for the provision of the Service between the parties. Terms not defined in this DPA have the meaning given to them in the GDPR and the Terms.
2. Subject matter, duration, nature and purpose of processing
The subject matter of processing is the provision of the cloud platform elevialms.com and related services, in particular hosting, account administration, training records, notifications, customer support, creation and management of educational content, automated workflows and, to the extent activated, the use of AI Features.
Processing lasts for the term of the contractual relationship and thereafter for the period necessary to fulfil obligations upon termination of cooperation, secure data export, demonstrate compliance and meet statutory archival or protective periods.
The nature of processing operations may include in particular collection, recording, organisation, storage, retrieval, consultation, use, transmission, disclosure, combination, restriction, erasure or destruction of personal data.
3. Categories of data subjects and types of data
Data subjects may include in particular employees, training candidates, contractors, Customer administrators, lecturers, external users and other persons to whom the Customer enables access to the Service.
Types of personal data may include in particular identification and contact details, work or organisational role, login and audit records, data on completion of training, test results, notification preferences and data contained in uploaded documents and other Customer Content.
Special categories of data and biometric data are not intended for standard use of the Service. If the Customer wishes to use functionality that processes such data, that use must be separately approved in advance and the Customer must demonstrate compliance with all statutory requirements.
4. Controller instructions
The Provider processes personal data only on documented instructions from the Customer, including instructions contained in the agreement, Terms, this DPA and properly configured Service settings.
If the Provider believes that an instruction from the Customer infringes the GDPR or another serious legal requirement, the Provider will inform the Customer without undue delay, unless prohibited by law.
5. Confidentiality and authorised persons
The Provider will ensure that persons authorised to process personal data are bound by confidentiality or a statutory duty of confidentiality and have access only to the extent necessary to perform their tasks.
The Provider will ensure appropriate access management, records of permissions and internal discipline when handling personal data.
6. Technical and organisational measures
The Provider will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in particular measures protecting the confidentiality, integrity, availability and resilience of systems and services.
Measures may include in particular access management, segmentation of rights, encryption in transit and, where appropriate, at rest, logging, backup, recovery, restrictions on subcontractor access, recovery rules, security testing and incident management processes. An indicative overview of measures is set out in Annex 1 to this DPA.
7. Subprocessors
The Customer grants the Provider general written authorisation to engage additional processors (subprocessors) where necessary to provide the Service.
The Provider will maintain a current list of subprocessors in an annex, separate document or on its website and will make it available to the Customer upon request. When adding or replacing a subprocessor, the Provider will provide the Customer with reasonable information and the opportunity to raise justified objections where required by the nature of the change.
The Provider will impose on each subprocessor substantially the same data protection obligations as those imposed on the Provider under this DPA, in particular in relation to security, confidentiality and processing only on instructions.
8. International transfers
If personal data is transferred outside the EEA in the provision of the Service, the Provider will ensure that the transfer is based on a valid transfer mechanism under the GDPR, in particular an adequacy decision, standard contractual clauses or another lawful mechanism.
Upon the Customer’s request, the Provider will provide reasonable information on the transfer mechanism used, unless prevented by confidentiality obligations or security restrictions.
9. Assistance to the controller
Taking into account the nature of processing and the information available to it, the Provider will provide the Customer with reasonable assistance in handling data subject requests and fulfilling GDPR obligations, in particular in relation to processing security, notification of personal data breaches, impact assessments and consultations with a supervisory authority.
If the Provider receives a request directly from a data subject or supervisory authority, it will forward it to the Customer without undue delay, unless such notification is prohibited by law.
10. Security incident and personal data breach
If the Provider becomes aware of a personal data breach affecting data processed under this DPA, it will notify the Customer without undue delay after becoming reliably aware of it.
The notice will, to a reasonable extent, include a description of the nature of the incident, categories and possible scope of affected data, likely consequences and measures taken or proposed to mitigate the consequences, where such information is available to the Provider.
11. Audit and demonstration of compliance
Upon the Customer’s reasonable request, the Provider will provide information necessary to demonstrate compliance with its processor obligations under Article 28 GDPR.
An audit or other review will be carried out by prior agreement, to a reasonable extent, without unjustified disruption of the Provider’s operations and subject to confidentiality. Instead of an onsite audit, the Provider may primarily provide current certifications, a questionnaire, report or another reasonable form of evidence of compliance, if this meets the purpose of the request.
12. Return or deletion of data after termination
After termination of the contractual relationship, the Provider will delete or return personal data on the Customer’s instruction, unless law requires further storage. The practical method of export and applicable periods may be set out in the agreement, SLA or support policy.
Backups are deleted or overwritten within the Provider’s normal retention cycles where immediate deletion is not technically reasonable or possible.
13. Governing law and final provisions
This DPA is governed by the laws of Ireland and interpreted in accordance with the GDPR.
In the event of conflict between this DPA and other contractual documentation, this DPA prevails in matters concerning the processing of personal data.
Annex 1. Indicative overview of technical and organisational measures
| Area | Measure |
|---|---|
| Access management | Access is granted by role and need, with the possibility to restrict or remove permissions. |
| Authentication | Use of appropriate authentication mechanisms and protection of login credentials and administrative access. |
| Encryption | Encryption of communications in transit; appropriate measures to protect data at rest according to the infrastructure used. |
| Logging and audit | Recording of relevant system and security events to an appropriate extent. |
| Backup and recovery | Use of appropriate backup and recovery processes according to service criticality. |
| Incident management | Process for receiving, assessing, resolving and documenting security incidents. |
| Subprocessors | Use of appropriately assessed suppliers and contractual transfer of relevant obligations. |
Annex 2. Indicative list of subprocessors
| Subprocessor | Purpose | Location / note |
|---|---|---|
| Hetzner | hosting / server infrastructure | EEA |
| Microsoft | email, office and cloud services | EEA / according to contractual configuration |
| n8n | automated workflows, if activated | according to contractual configuration |
| ElevenLabs | AI audio / voice features, if activated | according to contractual configuration |