Template — to be finalised and executed alongside the main service agreement. Bracketed [ ] items are completed per customer.
1. Definitions
“GDPR”, “Personal Data”, “Processing”, “Data Controller”, “Data Processor”, “Data Subject”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR. “Customer Personal Data” means Personal Data that Aula Magna Processes on behalf of the Customer under the service agreement.
2. Roles of the parties
The Customer is the Data Controller and Aula Magna is the Data Processor with respect to Customer Personal Data. Each party complies with its obligations under applicable data-protection law. Aula Magna Processes Customer Personal Data only to provide the service and only on the Customer’s documented instructions.
3. Subject-matter, duration, nature and purpose
- Subject-matter: provision of the Aula Magna student-engagement platform.
- Duration: the term of the service agreement, plus any period required for return or deletion (Section 11).
- Nature and purpose: hosting, storage, display and processing of academic and administrative data to operate the platform for the Customer’s students, faculty, staff and alumni.
- Categories of Data Subjects and Personal Data: as set out in Annex I.
4. Processor obligations (Article 28(3))
- Process Customer Personal Data only on the Customer’s documented instructions, including on international transfers, unless required by EU or Member-State law (in which case Aula Magna informs the Customer unless legally prohibited).
- Ensure persons authorised to Process the data are bound by confidentiality.
- Implement the technical and organisational security measures set out in Annex II (Article 32).
- Respect the conditions for engaging sub-processors in Section 5.
- Assist the Customer, by appropriate measures, in responding to Data-Subject rights requests (Chapter III).
- Assist the Customer in ensuring compliance with Articles 32–36 (security, breach notification, impact assessments, prior consultation), taking into account the nature of processing and the information available.
- At the Customer’s choice, delete or return all Customer Personal Data at the end of the service (Section 11).
- Make available all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits (Section 9).
5. Sub-processors
The Customer grants Aula Magna general written authorisation to engage the sub-processors listed on the Subprocessors page. Aula Magna imposes data-protection obligations on each sub-processor no less protective than those in this DPA and remains liable for their performance. Aula Magna gives the Customer advance notice of any intended addition or replacement of a sub-processor, and the Customer may object on reasonable data-protection grounds.
6. Security
Aula Magna implements and maintains the technical and organisational measures described in Annex II, appropriate to the risk, including encryption in transit and at rest, access control on a least-privilege basis, logging and monitoring, resilience and regular testing.
7. Personal Data Breach
Aula Magna notifies the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provides information reasonably available to assist the Customer in meeting its own notification obligations under Articles 33–34.
8. International transfers
Customer Personal Data is hosted in the region agreed with the Customer (see Annex I). Where processing entails a transfer outside the EEA, the parties rely on an appropriate transfer mechanism under Chapter V of the GDPR, including the European Commission’s Standard Contractual Clauses, which are incorporated by reference.
9. Audits
Aula Magna makes available information necessary to demonstrate compliance and, on reasonable prior notice and subject to confidentiality, allows the Customer (or an auditor it mandates) to conduct audits, including inspections, no more than once per year unless required by a Supervisory Authority or following a Personal Data Breach. Third-party audit reports and certifications may be provided to satisfy an audit request.
10. Data-Subject rights
Taking into account the nature of the processing, Aula Magna assists the Customer by appropriate technical and organisational measures — insofar as possible — to fulfil the Customer’s obligation to respond to requests to exercise Data-Subject rights (access, rectification, erasure, restriction, portability, objection).
11. Return and deletion
On termination or expiry of the service, and at the Customer’s choice, Aula Magna deletes or returns all Customer Personal Data and deletes existing copies, unless retention is required by EU or Member-State law. Backups are purged in accordance with the documented backup cycle.
12. Liability and governing law
Liability is subject to the limitations in the main service agreement. This DPA is governed by the law specified in the service agreement; absent such specification, by the law of the Customer’s Member State. In case of conflict, this DPA prevails on data-protection matters.
Annex I — Details of processing
- Data Subjects: the Customer’s students, applicants, faculty, staff, mentors and alumni.
- Categories of Personal Data: identity and contact data; academic records (programme, grades, attendance, assignments); profile content; communications and support requests; career data; usage and device metadata.
- Special categories: none processed by default.
- Hosting region: [EU / other, as agreed].
- Retention: [as per the Customer’s retention policy].
Annex II — Technical and organisational measures
- Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control on a least-privilege basis; multi-factor authentication for staff and administrator accounts.
- Audit logging of access to Personal Data; continuous security and uptime monitoring.
- Application hardening: Content-Security-Policy, HSTS, clickjacking and MIME-sniffing protections, rate limiting.
- Secure software development, dependency scanning and regular penetration testing.
- Automated, encrypted backups with tested restores and a documented disaster-recovery plan.
- Incident-response procedures including breach notification.
Annex III — Sub-processors
The current list of authorised sub-processors is maintained at /subprocessors and forms part of this DPA.