1. Purpose
This Data Processing Addendum ("DPA") forms part of, and is incorporated into, any agreement ("Principal Agreement") between REWTTEERS UNIVERSITY ("Processor," "Service Provider," "we," "our," or "us") and the institutional, corporate, enterprise, governmental, or other customer ("Controller," "Customer," or "Client") for the provision of educational services, learning management services, training programs, certifications, consulting, or related services.
This DPA establishes the obligations of the parties concerning the processing of Personal Data in accordance with applicable data protection laws, including:
- Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)
- UK GDPR and the Data Protection Act 2018
- California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), where applicable
- Other applicable national or regional privacy laws
2. Definitions
For purposes of this DPA:
Controller means the entity that determines the purposes and means of processing Personal Data.
Processor means REWTTEERS UNIVERSITY when processing Personal Data on behalf of the Controller.
Personal Data means any information relating to an identified or identifiable natural person, as defined by applicable data protection law.
Processing means any operation performed on Personal Data, including collection, recording, storage, organization, use, disclosure, transmission, analysis, deletion, or destruction.
Data Subject means the individual to whom Personal Data relates.
Sub-processor means any third party engaged by REWTTEERS UNIVERSITY to process Personal Data on behalf of the Controller.
Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
3. Roles of the Parties
Where REWTTEERS UNIVERSITY processes Personal Data solely on behalf of a Client:
- The Client acts as the Controller.
- REWTTEERS UNIVERSITY acts as the Processor.
Where REWTTEERS UNIVERSITY independently determines the purposes and means of processing—for example, for its own administrative, legal, accounting, compliance, or marketing activities—it acts as an independent Controller.
Each party shall comply with the obligations applicable to its respective role under applicable data protection laws.
4. Scope and Processing Instructions
REWTTEERS UNIVERSITY shall process Personal Data only:
- On documented instructions from the Controller.
- As necessary to perform the services described in the Principal Agreement.
- To comply with applicable legal obligations.
- As otherwise required by applicable law.
The Processor shall not:
- Sell Personal Data.
- Share Personal Data for cross-context behavioral advertising unless expressly authorized and permitted by law.
- Use Personal Data for purposes unrelated to providing the contracted services.
If the Processor believes that an instruction violates applicable law, it shall promptly inform the Controller unless prohibited by law.
5. Categories of Personal Data
Depending on the services provided, Personal Data processed may include:
- Names
- Email addresses
- Telephone numbers
- Business contact information
- Student identification numbers
- Employee identification numbers
- Enrollment records
- Training progress
- Assessment results
- Certifications
- Attendance records
- Login credentials (where applicable)
- Technical information (such as IP addresses and device identifiers)
- Payment-related information (excluding full payment card numbers where processed by third-party payment providers)
Special categories of Personal Data will only be processed where necessary, lawful, and authorized.
6. Categories of Data Subjects
Data Subjects may include:
- Students
- Employees
- Contractors
- Faculty
- Instructors
- Administrators
- Corporate trainees
- Applicants
- Institutional representatives
- Authorized users of the Client
7. Confidentiality Obligations
REWTTEERS UNIVERSITY shall ensure that all personnel authorized to process Personal Data:
- Are bound by confidentiality obligations.
- Receive appropriate privacy and security training.
- Access Personal Data only where necessary for their duties.
- Continue to observe confidentiality obligations after their employment or engagement ends.
8. Technical and Organizational Security Measures
REWTTEERS UNIVERSITY maintains reasonable technical and organizational measures designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction.
Such measures may include:
- Encryption of data in transit using industry-standard protocols.
- Encryption of data at rest where appropriate.
- Role-based access controls.
- Strong authentication mechanisms.
- Multi-factor authentication for administrative access where practicable.
- Regular software updates and security patching.
- Network security controls, including firewalls and intrusion detection.
- Logging and monitoring of system activity.
- Secure backup and disaster recovery procedures.
- Secure development and change management practices.
- Employee security awareness training.
Security measures will be reviewed periodically and updated as appropriate.
9. Sub-processors
The Controller authorizes REWTTEERS UNIVERSITY to engage Sub-processors to support the delivery of the services.
Examples may include providers of:
- Cloud hosting
- Learning Management Systems
- Email delivery
- Video conferencing
- Payment processing
- Customer support
- Analytics
- Data storage
REWTTEERS UNIVERSITY shall:
- Exercise appropriate due diligence before engaging a Sub-processor.
- Enter into written agreements imposing data protection obligations substantially equivalent to those in this DPA.
- Remain responsible for the performance of its Sub-processors to the extent required by applicable law.
Upon reasonable request, REWTTEERS UNIVERSITY will provide information regarding its current Sub-processors, subject to confidentiality and security considerations.
10. International Data Transfers
Where Personal Data is transferred outside the country of origin, REWTTEERS UNIVERSITY shall implement appropriate safeguards as required by applicable law.
Such safeguards may include:
- European Commission Standard Contractual Clauses (SCCs).
- UK International Data Transfer Agreement (IDTA) or the UK Addendum to the SCCs.
- Transfers to jurisdictions benefiting from an adequacy decision.
- Other lawful transfer mechanisms recognized under applicable law.
The parties agree to cooperate in implementing any additional measures required to support lawful international data transfers.
11. Assistance with Data Subject Rights
Taking into account the nature of the processing, REWTTEERS UNIVERSITY shall provide reasonable assistance to the Controller in responding to requests from Data Subjects, including requests to:
- Access Personal Data.
- Correct inaccurate Personal Data.
- Delete Personal Data.
- Restrict processing.
- Object to processing where applicable.
- Receive Personal Data in a portable format.
- Withdraw consent where processing is based on consent.
The Controller remains responsible for determining whether and how such requests should be fulfilled under applicable law.
12. Personal Data Breach Notification
If REWTTEERS UNIVERSITY becomes aware of a confirmed Personal Data Breach affecting Personal Data processed under this DPA, it shall:
- Notify the Controller without undue delay after becoming aware of the breach.
- Provide available information regarding the nature of the incident.
- Describe the categories of affected data.
- Describe the likely consequences of the breach, where known.
- Describe the measures taken or proposed to address the breach.
- Cooperate with the Controller in investigating and responding to the incident.
Nothing in this DPA requires REWTTEERS UNIVERSITY to disclose information that would compromise ongoing security investigations or violate applicable law.
13. Data Retention and Deletion
REWTTEERS UNIVERSITY shall retain Personal Data only for as long as necessary to perform the services or comply with applicable legal obligations.
Upon termination of the Principal Agreement, and subject to applicable law, the Controller may instruct REWTTEERS UNIVERSITY to:
- Return Personal Data in a commonly used electronic format, where technically feasible.
- Securely delete Personal Data.
- Anonymize Personal Data where appropriate.
REWTTEERS UNIVERSITY may retain limited information where required by law or for the establishment, exercise, or defense of legal claims.
14. Audit Rights
Upon reasonable written request and no more than once annually (unless required by law or following a material security incident), the Controller may request information reasonably necessary to demonstrate REWTTEERS UNIVERSITY's compliance with this DPA.
Where appropriate, REWTTEERS UNIVERSITY may satisfy such requests by providing:
- Independent security certifications.
- Compliance reports.
- Audit summaries.
- Security questionnaires.
- Other relevant documentation.
Any on-site audit shall:
- Be conducted during normal business hours.
- Be subject to reasonable advance notice.
- Minimize operational disruption.
- Be subject to appropriate confidentiality obligations.
- Not compromise the security or confidentiality of other customers.
15. Governing Law
This DPA shall be governed by the law specified in the Principal Agreement.
Where the Principal Agreement is silent, the governing law shall be the law of the jurisdiction in which REWTTEERS UNIVERSITY is organized, unless mandatory data protection laws require otherwise.
Any disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the Principal Agreement.
16. Standard Contractual Clauses (Where Applicable)
Where required by applicable law for international transfers of Personal Data, the parties agree that the European Commission's Standard Contractual Clauses (or any successor mechanism), together with the UK International Data Transfer Addendum where applicable, are incorporated into this DPA by reference and shall apply to the relevant transfers.
The parties agree to execute any additional documentation reasonably necessary to ensure the lawful transfer of Personal Data across jurisdictions.
17. Liability
Each party shall be responsible for its own compliance with applicable data protection laws.
Nothing in this DPA limits or excludes liability where such limitation or exclusion is prohibited by applicable law.
Liability between the parties shall otherwise be governed by the limitations of liability contained in the Principal Agreement.
18. Amendments
REWTTEERS UNIVERSITY may update this DPA to reflect changes in applicable law, regulatory guidance, security practices, or service offerings.
Material amendments will be communicated to affected Clients in accordance with the Principal Agreement.
19. Contact Information
Questions regarding this Data Processing Addendum or data protection practices should be directed to:
REWTTEERS UNIVERSITY
Data Protection Officer / Privacy Office
Email: [privacy@rewtteersuniversity.com]
Website: [WWW.REWTTEERSUNIVERSITY.COM]
The parties acknowledge that this DPA forms an integral part of the Principal Agreement and agree to comply with its terms throughout the duration of the services involving the processing of Personal Data.
