Data Processing Agreement
This Data Processing Agreement ("DPA") applies whenever an organisation uses Learnery to train its people. It forms part of our Terms and sets out how we handle personal data on your behalf under Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). Learnery is operated by . For any question about this document, write to [email protected].
How this becomes binding
You do not need to sign or return anything. This DPA takes effect automatically when your organisation creates an account and continues for as long as we hold personal data for you. If your procurement process requires a countersigned copy on your own paper, ask us through Contact and we will arrange it.
1. Roles
Your organisation is the controller: you decide whose data goes into Learnery and why. We are the processor: we act on your instructions. For our own website visitors, our own marketing, and for individuals who buy a single seat for themselves rather than through an employer, we are the controller instead, and our Privacy Policy governs that processing rather than this DPA.
2. Subject matter, duration, nature and purpose
The subject matter is the provision of online AI literacy training and the records that evidence it. The nature of the processing is collecting, storing, displaying, generating feedback on, and producing certificates and attestations from, the data described below. The purpose is limited to delivering the training your organisation bought and giving you the records that show it happened. Processing lasts for as long as your account exists, plus the retention periods in section 9.
3. Categories of data subject
The employees, contractors and other staff whom your organisation invites to train, and the administrators your organisation appoints to manage its account.
4. Types of personal data
We process only what the service needs:
- Identity and contact. Name, work email address, the role or subsector chosen for the person, and their account status.
- Authentication. A password hash, or a Google account identifier where the person signs in with Google, plus session and verification tokens.
- Training records. Which lessons and exercises a person has completed, their multiple choice answers, their prompt lab submissions and chat practice transcripts, certificate codes and issue dates, and whether an administrator has assigned them human oversight duties.
- Free text the learner writes. What a person types into the exercises, the chat practice, the prompt lab and the AI tutor. Learners are told, in the training itself, not to put personal data about third parties or company secrets into these boxes, but the field is free text and we treat whatever arrives in it as personal data.
- Technical. Truncated and hashed IP data used for rate limiting and abuse prevention, and privacy friendly page analytics that do not profile individuals.
We do not ask for and do not want special category data under Article 9. Please do not instruct us to process any.
5. Our obligations
- Documented instructions. We process personal data only on your documented instructions, which are given by your use of the service and by this DPA, unless EU or member state law requires otherwise. If we believe an instruction breaches data protection law, we will tell you.
- Confidentiality. Everyone we authorise to process your data is bound by an obligation of confidentiality.
- Security. We implement the technical and organisational measures set out in section 7, as required by Article 32.
- Sub processors. We use the sub processors listed in section 8, on the terms in that section.
- Assisting with data subject rights. Taking into account the nature of the processing, we assist you with appropriate measures so you can answer requests under Chapter III. In practice your administrators can already export and delete a person's data from the account itself; where you need more, ask us.
- Assisting with security and breach duties. We assist you in meeting your obligations under Articles 32 to 36, taking into account the nature of the processing and the information available to us.
- Breach notification. We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information we have at the time, and follow up as we learn more.
- Deletion or return. At the end of the service we delete or return your personal data as set out in section 9.
- Demonstrating compliance. We make available the information needed to show we meet these obligations, and allow for and contribute to audits as described in section 10.
6. Your obligations
You confirm that you have a lawful basis for putting your people's data into Learnery and that you have told them about it as Articles 13 and 14 require. You are responsible for who you invite, for what your administrators do in the account, and for instructing us lawfully. You must not use free text fields to send us data you have no basis to share.
7. Security measures
Article 32 asks for measures appropriate to the risk. Ours, stated plainly rather than as a checklist:
- All traffic is served over HTTPS with HSTS, and the site redirects every other origin to one canonical HTTPS address.
- Passwords are stored as bcrypt hashes and are never stored or logged in readable form.
- Access is role based. An organisation administrator can only see their own organisation, and the checks are enforced on the server for every route and every action, not in the interface.
- Sessions use cookies restricted to the site, marked secure over HTTPS, and every state changing request carries a CSRF token.
- Rate limiting and abuse controls protect sign in, signup, invitations, password reset and the public forms, keyed so that one person cannot lock another out.
- Narration audio and learner records are served only to the person entitled to them, checked on every request rather than by having an unguessable address.
- Databases are backed up on a schedule and restores are tested rather than assumed.
- Personal data is minimised by design: we do not collect date of birth, home address, telephone number or any demographic data, because the service does not need them.
8. Sub processors
You give a general authorisation for the sub processors below. We impose data protection obligations on each of them that are no less protective than those in this DPA, and we remain responsible to you for what they do. This list is the same one published in section 5 of our Privacy Policy.
- DeepSeek (China), our primary AI provider. Receives the free text a learner types into the exercises, chat practice, prompt lab and AI tutor, in order to generate feedback and examples.
- OpenAI (United States), our reserve AI provider and safety screening. Receives the same free text when DeepSeek cannot be reached, and receives AI output for screening against harmful content. Transfers rely on the European Commission standard contractual clauses. Under its API terms this content is not used to train its models.
- Stripe (Ireland and United States), payment processing. Receives billing data. Card details go to Stripe directly and never reach our servers.
- Google (Ireland and United States), only where a person chooses to sign in with a Google account.
- Our hosting and email providers (European Union), which store the database and deliver transactional messages.
We will tell you before adding or replacing a sub processor, by email to your account administrators, and you may object on reasonable data protection grounds. If we cannot resolve the objection you may terminate the affected part of the service and receive a refund for the unused period.
9. Retention, deletion and return
While your account is active we keep your data so the service works and so training records stay verifiable. An administrator can delete an individual from the account at any time. When your account closes, we delete the personal data we hold as processor within 90 days, except where law requires us to keep something longer, for example billing records for tax. Certificates and attestations keep working for the person they were issued to, because their whole purpose is to be checkable afterwards; tell us if you need those revoked instead. On request before deletion we will return your data in a machine readable format.
10. Audits
On reasonable notice, no more than once a year unless a regulator or a breach makes more necessary, we will answer your written questions about this DPA and provide the documentation we have. Where that is genuinely not enough for your obligations, we will agree an on site audit with you, at your cost, conducted so it does not compromise the confidentiality of other customers.
11. International transfers
Where a sub processor is outside the European Economic Area, transfers rely on appropriate safeguards under Chapter V, in practice the European Commission standard contractual clauses. Section 8 states which providers this applies to and where they are.
12. Changes to this DPA
We may update this DPA to reflect a change in the service or in the law. If a change materially reduces your protection we will tell your administrators by email before it takes effect. The version in force is the one published on this page, and the date it was last changed is shown at the top.