Data Processing Agreement
This Data Processing Agreement ("DPA") applies whenever an organisation uses Learnery to train its people. It forms part of our Terms and sets out how we handle personal data on your behalf under Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). Learnery is operated by . For any question about this document, write to [email protected].
How this becomes binding
You do not need to sign or return anything. This DPA takes effect automatically when your organisation creates an account and continues for as long as we hold personal data for you. If your procurement process requires a countersigned copy on your own paper, ask us through Contact and we will arrange it.
1. Roles
Your organisation is the controller: you decide whose data goes into Learnery and why. We are the processor: we act on your instructions. For our own website visitors, our own marketing, and for individuals who buy a single seat for themselves rather than through an employer, we are the controller instead, and our Privacy Policy governs that processing rather than this DPA.
2. Subject matter, duration, nature and purpose
The subject matter is the provision of online AI literacy training and the records that evidence it. The nature of the processing is collecting, storing, displaying, generating feedback on, and producing certificates and attestations from, the data described below. The purpose is limited to delivering the training your organisation bought and giving you the records that show it happened. Processing lasts for as long as your account exists, plus the retention periods in section 9.
3. Categories of data subject
The employees, contractors and other staff whom your organisation invites to train, and the administrators your organisation appoints to manage its account.
4. Types of personal data
We process only what the service needs:
- Identity and contact. Name, work email address, the role or subsector chosen for the person, and their account status.
- Authentication. A password hash, or a Google account identifier where the person signs in with Google, plus session and verification tokens.
- Training records. Which lessons and exercises a person has completed, their multiple choice answers, their prompt lab submissions and chat practice transcripts, certificate codes and issue dates, and whether an administrator has assigned them human oversight duties.
- Free text the learner writes. What a person types into the exercises, the chat practice, the prompt lab and the AI tutor. Learners are told, in the training itself, not to put personal data about third parties or company secrets into these boxes, but the field is free text and we treat whatever arrives in it as personal data.
- Technical. Truncated and hashed IP data used for rate limiting and abuse prevention, and privacy friendly page analytics that do not profile individuals.
We do not ask for and do not want special category data under Article 9. Please do not instruct us to process any.
5. Our obligations
- Documented instructions. We process personal data only on your documented instructions, which are given by your use of the service and by this DPA, including with regard to any transfer of personal data to a third country, unless EU or member state law requires otherwise. If we believe an instruction breaches data protection law, we will tell you.
- Confidentiality. Everyone we authorise to process your data is bound by an obligation of confidentiality.
- Security. We implement the technical and organisational measures set out in section 7, as required by Article 32.
- Sub processors. We use the sub processors listed in section 8, on the terms in that section.
- Assisting with data subject rights. Taking into account the nature of the processing, we assist you with appropriate measures so you can answer requests under Chapter III. In practice your administrators can already export and erase one of your people from the account itself, so a Chapter III request can be answered without involving us; where you need more, ask us.
- Assisting with security and breach duties. We assist you in meeting your obligations under Articles 32 to 36, taking into account the nature of the processing and the information available to us.
- Breach notification. We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information we have at the time, and follow up as we learn more.
- Deletion or return. At the end of the service we delete or return your personal data as set out in section 9.
- Demonstrating compliance. We make available the information needed to show we meet these obligations, and allow for and contribute to audits as described in section 10.
6. Your obligations
You confirm that you have a lawful basis for putting your people's data into Learnery and that you have told them about it as Articles 13 and 14 require. You are responsible for who you invite, for what your administrators do in the account, and for instructing us lawfully. You must not use free text fields to send us data you have no basis to share.
7. Security measures
Article 32 asks for measures appropriate to the risk. Ours, stated plainly rather than as a checklist:
- All traffic is served over HTTPS with HSTS, and the site redirects every other origin to one canonical HTTPS address.
- Passwords are stored as bcrypt hashes and are never stored or logged in readable form.
- Access is role based. An organisation administrator can only see their own organisation, and the checks are enforced on the server for every route and every action, not in the interface.
- Sessions use cookies restricted to the site, marked secure over HTTPS, and every state changing request carries a CSRF token.
- Rate limiting and abuse controls protect sign in, signup, invitations, password reset and the public forms, keyed so that one person cannot lock another out.
- Narration audio and learner records are served only to the person entitled to them, checked on every request rather than by having an unguessable address.
- Databases are backed up on a schedule and restores are tested rather than assumed.
- Personal data is minimised by design: we do not collect date of birth, home address, telephone number or any demographic data, because the service does not need them.
- Personal data is pseudonymised where the service does not need the original. An IP address is never stored: what is kept is a keyed hash of it that changes every day, so the same visitor cannot be followed from one day to the next. On erasure, the rows we keep for aggregate counts have every link back to the person removed rather than merely detached.
- Resilience and restoration: the database is dumped nightly, the dump is pulled to separate offsite storage, and restores are performed rather than assumed.
- These measures are tested on a schedule rather than asserted once. An automated suite exercises the access rules, the session and CSRF handling, the rate limits and the record and audio scoping on every change, and health checks run daily against the live system. That is the regular testing and evaluation Article 32(1)(d) asks for.
8. Sub processors
You give a general authorisation for the sub processors below. We impose data protection obligations on each of them that are no less protective than those in this DPA, and we remain responsible to you for what they do. This list is the same one published in section 5 of our Privacy Policy. Every one of them offers a processor agreement and, where it moves data outside the European Economic Area, a Chapter V transfer mechanism; a provider that offers neither does not go on this list, whatever it costs us. The current list, with the date each provider joined it, is always at learnery.io/subprocessors.
- OpenAI (Ireland and United States), our only AI provider and our safety screening. Receives the free text a learner types into the exercises, chat practice, prompt lab and AI tutor, in order to generate feedback and examples, and receives AI output for screening against harmful content. Our contract for European Economic Area data is with OpenAI Ireland Limited; onward transfers to the United States are made under the European Commission standard contractual clauses. Under its API terms this content is not used to train its models.
- Cloudflare (United States), the edge in front of learnery.io. Receives every request, including the IP address and the address requested, and filters attacks before they reach the origin. Transfers rely on the European Commission standard contractual clauses.
- Stripe (Ireland and United States), payment processing. Receives billing data. Card details go to Stripe directly and never reach our servers. Transfers rely on the European Commission standard contractual clauses.
- Google, where a person chooses to sign in with a Google account. Strictly this is not a sub processor: that person authenticates with Google directly, and Google acts as its own controller for the sign in under its own privacy policy. It is listed anyway, because you are entitled to know Google is involved at all.
- Google (Ireland and United States) and Meta (Ireland and United States), for advertising measurement, and only while we are advertising. When a customer who consented completes a purchase, our server sends each of them the click code that was in the link that customer arrived on, the purchase value and the time. No name, email address or telephone number is sent, in any form, and nothing at all is sent about a visitor who does not buy. Nothing is sent from the browser: there is no advertising pixel and no advertising cookie on any page. Transfers to the United States rely on the European Commission standard contractual clauses and on each company being certified under the EU and US Data Privacy Framework.
- DATAHOST and our email provider (Greece, European Union), which store the database in Greece and deliver transactional messages.
We will tell you at least 30 days before adding or replacing a sub processor, by email to your account administrators, and you may object on reasonable data protection grounds. If we cannot resolve the objection you may terminate the affected part of the service and receive a refund for the unused period.
9. Retention, deletion and return
While your account is active we keep your data so the service works and so training records stay verifiable. An administrator can delete an individual from the account at any time. When your account closes you choose whether we delete or return the personal data we hold as processor, and if you tell us nothing we delete it within 90 days, except where law requires us to keep something longer, for example billing records for tax. Certificates and attestations keep working for the person they were issued to, because their whole purpose is to be checkable afterwards; tell us if you need those revoked instead. On request before deletion we will return your data in a machine readable format.
10. Audits
On reasonable notice, no more than once a year unless a regulator or a breach makes more necessary, we will answer your written questions about this DPA and provide the documentation we have. Where that is genuinely not enough for your obligations, we will agree an on site audit with you, at your cost, conducted so it does not compromise the confidentiality of other customers.
11. International transfers
Your data is stored in the European Union, on servers in Greece. Where a sub processor moves data outside the European Economic Area, the safeguard is the standard contractual clauses adopted by the European Commission on 4 June 2021, and section 8 names the mechanism against each provider individually rather than in general terms. We do not rely on an Article 49 derogation for any of the transfers described here, because these transfers are systematic and repeated and the derogations are not available for that. Ask us and we will send you a copy of the clauses in force, and our our transfer impact assessment, which follows the six steps of EDPB Recommendations 01/2020 and states the residual risk it does not solve as well as the measures that do.
12. Changes to this DPA
We may update this DPA to reflect a change in the service or in the law. If a change materially reduces your protection we will tell your administrators by email before it takes effect. The version in force is the one published on this page, and the date it was last changed is shown at the top.